port-securty - EEM tcl access violation

Hi all!

I have problem with regexp expression inside my script.

I need to have two variables, one for PortID i.e. Ge, Fe, Ethernet and the other the MAC address which is a cause of breach of policy, where events happen I see that my regexp is not workin. Please help me or point in the right direction)

=

21:45:23.516 Jul 13: [fh_event_reqinfo_cmd]
* 21:45:23.516 Jul 13: [fh_process_event_reqinfo]
* 21:45:23.516 Jul 13: [fh_event_reqinfo_cmd] event_trigger_num 1 19 21 event_pub_sec 1468446323 event_pub_msec 160 event_pub_time 1468446323.160 job_id event_id event_type {41} event_type_string {syslog} event_severity {gravity-major} msg_count {1} {critical} priority msg {}
{* 21:45:23.161 Jul 13: % PORT_SECURITY-2-PSECURE_VIOLATION: security breach took place, caused by MAC address aabb.cc00.0100 on port Ethernet0/0.} timestamp sequence {} {* 21:45:23.161 Jul 13} mnemonic installation {PORT_SECURITY} {PSECURE_VIOLATION}
* 21:45:23.517 Jul 13: [fh_cli_debug_cmd]
* 21:45:23.517 Jul 13: % HA_EM-6-LOG: test.tcl: DEBUG (cli_lib): IN: switch > activate
* 21:45:23.517 Jul 13: [fh_tty_write_cmd]
* 21:45:23.517 Jul 13: [fh_tty_write_cmd] cmd = enable, cmdsize = 6
* 21:45:23.517 Jul 13: [fh_sys_reqinfo_routername_cmd]
* 21:45:23.535 Jul 13: [fh_tty_read_cmd]
* 21:45:23.535 Jul 13: [fh_tty_read_cmd] read not ready
* 21:45:23.638 Jul 13: [fh_tty_read_cmd]
* 21:45:23.638 Jul 13: [fh_tty_read_cmd] size = 9
* 21:45:23.638 Jul 13: [fh_tty_prompt_cmd]
* 21:45:23.738 Jul 13: [fh_cli_debug_cmd]
* 21:45:23.738 Jul 13: % HA_EM-6-LOG: test.tcl: DEBUG (cli_lib): OUT: switch #.
* 21:45:23.738 Jul 13: [fh_cli_debug_cmd]
* 21:45:23.738 Jul 13: % HA_EM-6-LOG: test.tcl: DEBUG (cli_lib): IN: terminal #configure switch
* 21:45:23.738 Jul 13: [fh_tty_write_cmd]
* 21:45:23.738 Jul 13: [fh_tty_write_cmd] cmd = configure terminal, cmdsize = 18
* 21:45:23.739 Jul 13: [fh_sys_reqinfo_routername_cmd]
* 21:45:23.750 Jul 13: [fh_tty_read_cmd]
* 21:45:23.750 Jul 13: [fh_tty_read_cmd] read not ready
* 21:45:23.860 Jul 13: [fh_tty_read_cmd]
* 21:45:23.860 Jul 13: [fh_tty_read_cmd] size = 80
* 21:45:23.860 Jul 13: [fh_tty_prompt_cmd]
* 21:45:23.967 Jul 13: [fh_cli_debug_cmd]
* 21:45:23.967 Jul 13: % HA_EM-6-LOG: test.tcl: DEBUG (cli_lib): OUT: enter configuration commands, one per line. End with CNTL/Z.
* 21:45:23.967 Jul 13:
Switch #% HA_EM-6-LOG: test.tcl: DEBUG (cli_lib): OUT: Switch (config) #.
* 21:45:23.967 Jul 13: [fh_cli_debug_cmd]
* 21:45:23.967 Jul 13: % HA_EM-6-LOG: test.tcl: DEBUG (cli_lib): IN: Switch (config) #file quiet quickly
* 21:45:23.967 Jul 13: [fh_tty_write_cmd]
* 21:45:23.967 Jul 13: [fh_tty_write_cmd] cmd = quiet prompt file, cmdsize = 17
* 21:45:23.972 Jul 13: [fh_sys_reqinfo_routername_cmd]
* 21:45:23.992 Jul 13: [fh_tty_read_cmd]
* 21:45:23.992 Jul 13: [fh_tty_read_cmd] read not ready
* 21:45:24.100 Jul 13: [fh_tty_read_cmd]
* 21:45:24.100 Jul 13: [fh_tty_read_cmd] size = 17
* 21:45:24.100 Jul 13: [fh_tty_prompt_cmd]
* 21:45:24.171 Jul 13: % LINEPROTO-5-UPDOWN: Line protocol on Interface Ethernet0/0, changed State to down
* 21:45:24.200 Jul 13: [fh_cli_debug_cmd]
* 21:45:24.200 Jul 13: % HA_EM-6-LOG: test.tcl: DEBUG (cli_lib): OUT: Switch (config) #.
* 21:45:24.200 Jul 13: [fh_cli_debug_cmd]
* 21:45:24.200 Jul 13: % HA_EM-6-LOG: test.tcl: DEBUG (cli_lib): IN: Switch (config) #interface IDE oucederomsurlesecondport Ethernet0/0.
* 21:45:24.200 Jul 13: [fh_tty_write_cmd]
* 21:45:24.200 Jul 13: [fh_tty_write_cmd] cmd = interface Ethernet0/0 IDE oucederomsurlesecondport., cmdsize = 30
* 21:45:24.200 Jul 13: [fh_sys_reqinfo_routername_cmd]
* 21:45:24.218 Jul 13: [fh_tty_read_cmd]
* 21:45:24.218 Jul 13: [fh_tty_read_cmd] read not ready
* 21:45:24.323 Jul 13: [fh_tty_read_cmd]
* 21:45:24.323 Jul 13: [fh_tty_read_cmd] read not ready
* 21:45:24.426 Jul 13: [fh_tty_read_cmd]
* 21:45:24.426 Jul 13: size [fh_tty_read_cmd] =

==

: model cisco::eem:event_register_syslog ' % PORT_SECURITY-2-PSECURE_VIOLATION: "maxrun 600
import namespace: cisco::eem: *.
import namespace: cisco::lib: *.

Table game rn [sys_reqinfo_routername]
the value of hostname $rn (routername)
Set the SERVER "192.168.116.1".
set the 'nuk.
set PASSWORD "malina".

If {{[result catch {cli_open}]}
Output 1
} else {}

Table game arr_einfo [event_reqinfo]
Set _regexp_result [regexp {caused by MAC address (. +) on the port (. +).} $arr_einfo (msg) MAC PORT]

Try this one.

Table game arr_einfo [event_reqinfo]

Set the msg '$arr_einfo (msg).

If [regexp {caused by MAC address ([0 - 9 - f\ a.] +) on the port ([a-zA-Z0-9 /-.] +)} $msg game PORT MAC] {}

} else {}

action_syslog msg 'Unable to parse syslog message.

}

Tags: Cisco Network

Similar Questions

  • How to fix and debug an error of access violation.

    Hello

    I'm stuck with an access violation error that requires my exe to stop construction. I tried also to the development environment, but it's the same here. The error occurs after 5-60 minutes.

    I played a bit with the disabling of a portion of the program where it was possible and I think that I am now able to accuse the vi 'gastimer.vi '. But since this vi leads through the measurement procedure, there are some commands coming out which I was not able to map one to one.

    My question is: what are the causes access violation errors? I have no call from dll, no third-party library, the communication of material is made series of COM ports. The principle of the architecture is something adapted from producer to consumer loop, except that I often have more than one consumer, so I called them like loop controller - multiple tasks. Communication within this loop (tasks) are by cluster queue enumerator with a Variant.

    Indictments vi 'gastimer.vi' is passed an older and simpler architecture. This vi works with the structure of sequence and a large number of local variables.

    Since I test the sensors on their reaction to the concentration of gas I have 10 agrees to which I am listening at the same time.

    What styles or architecture are subject to access violations? Where can they go? where should I look more carefully in the code?

    How can I use the desktop execution trace toolkit for more information on the cause of access violation?

    Attached are two different lvlog, but I guess having the same source of error. In the second lvlog are two named vi. What do have to do with the access violation error? Can what information I get these files lvlog?

    Last attachment shows a fatal runtime error that happens quite a bit frequently in the recent time when working with this project. Could there be a connection, probably a vi crashed, typedef or something else?

    Thanks for any help

    U. Siegenthaler

    I solved the problem. The accident moved no more.

    I found a bug in my queue reference interview. I have a record where can I register reference queue and remove them again of this register. The bug was that under certain conditions, I deleted the reference of the bad queue from the registry. This bug had to the fact that there was a reference to queue in the registry that should have been removed. The application now tried to place an element in this Ref queue where, at the same time elsewhere in the application process tried to release this reference to queue. Apparently, if these two events occure at the same time, or when a synchronization that gives an access violation crash.

    My suggestion for all of you with an access violation crash: take a look at your reference to queue maintaince and check if you publish queues at the same time you're items from the queue.

    Best regards and thanks for the help

    URS

  • Fatal error of VMware Workstation (vmui) Exception 0xc0000005 (access violation) occurred.

    Hello

    Have work and Workstation 7.1.5 - 491717 fine.  I then uninstall and install 8.0.0 - 471780 or 8.0.2 - 591240

    And now, when you try to run VMWare Workstation I get

    Fatal error of VMware Workstation (vmui)
    Exception 0xc0000005 (access violation) occurred.

    I'm on Windows 7 Pro 64-bit.  If I uninstall 8 and return to 7, it is fine.  Workstation 8 works well on my laptop though.

    It is the newspaper that VMware leaves when it crashes.

    2012 03-04 T 03: 00:33.837Z | vmui | I120: Log for VMware Workstation pid = 8072 version 8.0.2 = build = build-591240 option = output
    2012 03-04 T 03: 00:33.837Z | vmui | I120: The process is 32-bit.
    2012 03-04 T 03: 00:33.837Z | vmui | I120: Host = encoding windows-1252 = windows-1252 codepage
    2012 03-04 T 03: 00:33.837Z | vmui | I120: Host is Windows 7 Professional 64-bit Service Pack 1 (Build 7601)
    2012 03-04 T 03: 00:33.828Z | vmui | I120: SURVEY using the implementation of the API WSAPoll for PollDefault
    2012 03-04 T 03: 00:33.830Z | vmui | I120: Msg_Reset:
    2012 03-04 T 03: 00:33.830Z | vmui | I120: [msg.dictionary.load.openFailed] cannot open the file 'C:\Users\Me\AppData\Roaming\VMware\config.ini': the system cannot find the specified file.
    2012 03-04 T 03: 00:33.830Z | vmui | I120: ----------------------------------------
    2012 03-04 T 03: 00:33.830Z | vmui | I120: Optional preferences PREFS not found in C:\Users\Me\AppData\Roaming\VMware\config.ini file. Using the default values.
    2012 03-04 T 03: 00:33.830Z | vmui | I120: FILE: FileLockDynaLink: other process validation tools are: available
    2012 03-04 T 03: 00:33.837Z | vmui | I120: Token of type = full elevation: the process has full administrator rights.
    2012 03-04 T 03: 00:34.322Z | vmui | I120: vmxFilePath = "F:\Program files (x 86) \VMware\VMware Workstation\x64\vmware-vmx.exe.
    2012 03-04 T 03: 00:34.322Z | vmui | I120: vmxFilePathDebug = "F:\Program files (x 86) \VMware\VMware Workstation\x64\vmware-vmx-debug.exe.
    2012 03-04 T 03: 00:34.322Z | vmui | I120: vmxFilePathStats = "F:\Program files (x 86) \VMware\VMware Workstation\x64\vmware-vmx-stats.exe.
    2012 03-04 T 03: 00:34.353Z | vmui | I120: HostDeviceInfo: unable to enumerate ports Parallels host via the registry. Could not open the card parallel port device registry key.
    2012 03-04 T 03: 00:34.406Z | vmui | I120: host operating system: "Windows 7 Professional, 64-bit 6.1.7601, Service Pack 1", type '1', the mask away ' 0 x 0100.
    2012 03-04 T 03: 00:34.490Z | vmui | I120: Foundry Init: establishing a global state (thread 1 survey, 0 worker threads).
    2012 03-04 T 03: 00:34.490Z | vmui | I120: Vix_InitializeGlobalState: vixLogLevel = 0
    2012 03-04 T 03: 00:34.490Z | vmui | I120: Vix_InitializeGlobalState: vixApiTraceLevel = 0
    2012 03-04 T 03: 00:34.490Z | vmui | I120: Vix_InitializeGlobalState: vixDebugPanicOnVixAssert = 0
    2012 03-04 T 03: 00:34.490Z | vmui | I120: Vix_InitializeGlobalState: vixLogRefcountOnFinalRelease = 0
    2012 03-04 T 03: 00:34.490Z | vmui | I120: Vix_InitializeGlobalState: asyncOpWarningThreshold = 1000000
    2012 03-04 T 03: 00:34.490Z | vmui | I120: Vix_InitializeGlobalState: enableSyncOpSelection = FALSE
    2012 03-04 T 03: 00:34.490Z | vmui | I120: Vix_InitializeGlobalState: enableExternalThreadInterface = TRUE
    2012 03-04 T 03: 00:34.490Z | vmui | I120: Vix_InitializeGlobalState: enableVigor = FALSE
    2012 03-04 T 03: 00:34.490Z | vmui | I120: REGIONAL windows-1252-> user NULL = 809 system settings = 809
    2012 03-04 T 03: 00:34.490Z | vmui | I120: VixHost_ConnectEx: version - 1, host name (null), hostPort 0, hostType 3 options 8707
    2012 03-04 T 03: 00:34.502Z | vmui | I120: CD: initialization of a CD client update 1.0 for product ws-windows, version 8.0.2 (C:\Users\Me\AppData\Local\VMware\vmware-custData-1F88 workspace)
    2012 03-04 T 03: 00:34.502Z | vmui | I120: REGIONAL windows-1252-> user NULL = 809 system settings = 809
    2012 03-04 T 03: 00:34.531Z | vmui | W110: Unhandled Win32 SEH Exception
    2012 03-04 T 03: 00:34.531Z | vmui | W110: - Win32 exception caught, exceptionCode 0xc0000005 (access violation).


    2012 03-04 T 03: 00:34.531Z | vmui | W110: IP 0x67dadf76 eflags 00010246 rwFlags 0000000000 badAddr 0 x 0 x 00000003
    2012 03-04 T 03: 00:34.531Z | vmui | W110: eax ebx ecx edx 0xffffffff 0x04d63098 0x04d62fc8 0xffffffff
    2012 03-04 T 03: 00:34.531Z | vmui | W110: esi 0x04d63098 edi 0x0020f6a4 ebp 0x0020f600 esp 0x0020f600
    2012 03-04 T 03: 00:34.531Z | vmui | W110: The following data was delivered to the exception:
    2012 03-04 T 03: 00:34.531Z | vmui | W110 :--0000000000
    2012 03-04 T 03: 00:34.531Z | vmui | W110 :--0 X 00000003
    2012 03-04 T 03: 00:34.532Z | vmui | W110: CoreDump: minidump wrote to C:\Users\Me\AppData\Local\Temp\vmware-Me\vmware-8072.dmp
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the amount of basic 0x0x002c0000 module 0 x 0 00204000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x0020f701 timestamp 0x4f175719
    2012 03-04 T 03: 00:34.589Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\vmware.exe
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 8.0.2.28060 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the amount of basic 0x0x77bf0000 module 0 x 0 00180000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x0014909f timestamp 0x4ec49b8f
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\ntdll.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 6.1.7601.17725 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the amount of basic 0x0x75a10000 module 0 x 0 00110000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x001164fd timestamp 0x4e211318
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\kernel32.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 6.1.7601.17651 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 75660000 0 x 0 00046000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x0004bbea timestamp 0x4e211319
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\KERNELBASE.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 6.1.7601.17651 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the base 0x0x74fe0000 size 0x0x000a3000 module
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x000a4db7 timestamp 0x4dace5b9
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 9.0.30729.6161 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the amount of basic 0x0x75bb0000 module 0 x 0 00090000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0 x 00059851 timestamp 0x4ce7ba53
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\gdi32.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 76060000 0 x 0x00100000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x000d5873 timestamp 0x4ce7ba59
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\user32.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the base 0x0x761b0000 size 0x0x000a0000 module
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x000a1449 timestamp 0x4ce7b706
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\advapi32.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the module base dimension 0x0x000ac000 0 x 0 x 75330000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x000a8f06 timestamp 0x4eeaf722
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\msvcrt.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 7.0.7601.17744 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 75600000 0 x 0 00019000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0 x 00025332 timestamp 0x4a5bdb04
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\sechost.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the module base dimension 0x0x000f0000 0 x 0 x 75910000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x000afaa0 timestamp 0x4ce7ba59
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\rpcrt4.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the amount of basic 0x0x752d0000 module 0 x 0 00060000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x0001aecb timestamp 0x4ec49b90
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\sspicli.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 6.1.7601.17725 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the base 0x0x752c0000 size 0x0x0000c000 module
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0 x 00014593 timestamp 0x4a5bbf41
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\CRYPTBASE.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the base 0x0x755f0000 size 0x0x0000a000 module
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x0001268a timestamp 0x4a5bdb3b
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\lpk.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the module base dimension 0x0x0009d000 0 x 0 x 77120000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x000a2ada timestamp 0x4ce7ba29
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\usp10.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 1.626.7601.17514 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the base 0x0x72c90000 size 0x0x0019e000 module
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x0019ca5f timestamp 0x4ce7b71c
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 6.10.7601.17514 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 75590000 0 x 0 00057000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x0005db58 timestamp 0x4ce7b9e2
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\shlwapi.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the base 0x0x75c40000 size 0x0x0007b000 module
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x0007bc98 timestamp 0x4ce7b82d
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\comdlg32.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the module base dimension 0x0x00c4a000 0 x 0 x 76490000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x00c530fd timestamp 0x4f0412de
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\shell32.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 6.1.7601.17755 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the amount of basic 0x0x71a00000 module 0 x 0 00190000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0 x 00191664 timestamp 0x4ce7b714
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the base 0x0x756b0000 size 0x0x0015c000 module
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x00164a37 timestamp 0x4ce7b96f
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\SysWOW64\ole32.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 73250000 0 x 0 00080000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x000479e1 timestamp 0x4a5bdb3c
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\System32\uxtheme.dll image file
    2012 03-04 T 03: 00:34.589Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the Basic module 0 x 0 x 10000000 size 0 x 0 00013000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0x00015a50 timestamp 0x4de5b18b
    2012 03-04 T 03: 00:34.589Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\sigc-2.0.dll
    2012 03-04 T 03: 00:34.589Z | vmui | I120: 2.2.9.1 file version
    2012 03-04 T 03: 00:34.589Z | vmui | I120: CoreDump: including the module base dimension 0x0x0008e000 0 x 0 x 71370000
    2012 03-04 T 03: 00:34.589Z | vmui | I120: checksum 0 x 00098094 timestamp 0x4dace5bd
    2012 03-04 T 03: 00:34.589Z | vmui | I120: C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 9.0.30729.6161 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 00270000 0 x 0 00048000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x0004fdca timestamp 0x4cad407c
    2012 03-04 T 03: 00:34.590Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\gobject-2.0.dll
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 2.22.4.0 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the amount of basic 0x0x006f0000 module 0 x 0 00108000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x0010d783 timestamp 0x4cad4074
    2012 03-04 T 03: 00:34.590Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\glib-2.0.dll
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 2.22.4.0 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 00210000 0 x 0 00017000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x0002355e timestamp 0x4b5660be
    2012 03-04 T 03: 00:34.590Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\intl.dll
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 0.14.6.1 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 x 00800000 0 x 0 00114000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x001159ee timestamp 0x4b56605a
    2012 03-04 T 03: 00:34.590Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\iconv.dll
    2012 03-04 T 03: 00:34.590Z | vmui | I120: 1.9.0.1 file version
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 75620000 0 x 0 00035000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x0003f60a timestamp 0x4ce7ba68
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\SysWOW64\ws2_32.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the amount of basic 0x0x75a00000 module 0 x 0 00006000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x00004fe4 timestamp 0x4a5bdad9
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\SysWOW64\nsi.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the amount of basic 0x0x66d50000 module 0 x 0 00517000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x00516fd3 timestamp 0x4f173cb7
    2012 03-04 T 03: 00:34.590Z | vmui | I120: F:\Program files (x 86) \VMware\VMware Workstation\vmapputil image file. DLL
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 8.0.2.28060 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the base 0x0x75b20000 size 0x0x0008f000 module
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x0008f8ac timestamp 0x4e58702a
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\SysWOW64\oleaut32.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 6.1.7601.17676 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 67450000 0 x 0 00442000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x0043d9b4 timestamp 0x4f17392d
    2012 03-04 T 03: 00:34.590Z | vmui | I120: F:\Program files (x 86) \VMware\VMware Workstation\vmwarebase image file. DLL
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 8.0.2.28060 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 73210000 0 x 0 00032000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0 x 00035432 timestamp 0x4ce7ba42
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\System32\winmm.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the base 0x0x75cc0000 size 0x0x0011b000 module
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x00121bcd timestamp 0x4ee81076
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\SysWOW64\wininet.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 9.0.8112.16441 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the amount of basic 0x0x77bc0000 module 0 x 0 00003000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x0000f8d7 timestamp 0x4a5bdad4
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\SysWOW64\normaliz.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the base 0x0x75ea0000 size 0x0x001b8000 module
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x001b5a06 timestamp 0x4ee80f4f
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\SysWOW64\iertutil.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 9.0.8112.16441 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 76370000 0 x 0 00111000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x00112ae0 timestamp 0x4ee810a7
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\SysWOW64\urlmon.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 9.0.8112.16441 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the amount of basic 0x0x74e60000 module 0 x 0 00012000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x0001055d timestamp 0x4a5bda36
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\System32\mpr.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the amount of basic 0x0x74ed0000 module 0 x 0 00017000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x0001bf8b timestamp 0x4ce7ba28
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\System32\userenv.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the base 0x0x74ec0000 size 0x0x0000b000 module
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x000126fb timestamp 0x4a5bbf41
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\System32\profapi.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the base 0x0x753e0000 size 0x0x0019d000 module
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x0019856c timestamp 0x4ce7b9d9
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\SysWOW64\setupapi.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the amount of basic 0x0x771c0000 module 0 x 0 00027000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0 x 00030928 timestamp 0x4ddb8851
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\SysWOW64\cfgmgr32.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 6.1.7601.17621 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the amount of basic 0x0x771f0000 module 0 x 0 00012000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x0001812f timestamp 0x4ddb887d
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\SysWOW64\devobj.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 6.1.7601.17621 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the module base dimension 0x0x0011d000 0 x 0 x 77210000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x00123fb4 timestamp 0x4ce7b841
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\SysWOW64\crypt32.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the base 0x0x770e0000 size 0x0x0000c000 module
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x00017de5 timestamp 0x4ce7b8c9
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\SysWOW64\msasn1.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 73580000 0 x 0 00051000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x0005ce01 timestamp 0x4ce7ba4b
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\System32\winspool.drv image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the amount of basic 0x0x751e0000 module 0 x 0 00009000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x000138c1 timestamp 0x4a5bdb2b
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\System32\version.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 73330000 0 x 0 00012000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x0001b476 timestamp 0x4a5bd9b5
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\System32\dhcpcsvc.dll image file
    2012 03-04 T 03: 00:34.590Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.590Z | vmui | I120: CoreDump: including the amount of basic 0x0x732d0000 module 0 x 0 00058000
    2012 03-04 T 03: 00:34.590Z | vmui | I120: checksum 0x0005818e timestamp 0x4ce7ba3e
    2012 03-04 T 03: 00:34.590Z | vmui | I120: C:\Windows\System32\winhttp.dll image file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the base 0x0x686c0000 size 0x0x0004f000 module
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x00052ff5 timestamp 0x4ec49b76
    2012 03-04 T 03: 00:34.591Z | vmui | I120: C:\Windows\System32\webio.dll image file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 6.1.7601.17725 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the base 0x0x685c0000 size 0x0x000f8000 module
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x000fe631 timestamp 0x4ce7b847
    2012 03-04 T 03: 00:34.591Z | vmui | I120: C:\Windows\System32\cryptui.dll image file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 68590000 0 x 0 00023000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x0002bcb4 timestamp 0x4ce7ba48
    2012 03-04 T 03: 00:34.591Z | vmui | I120: C:\Windows\System32\WinSCard.dll image file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the module base dimension 0x0x0012e000 0 x 0 x 00920000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x0012ca08 timestamp 0x4acd3026
    2012 03-04 T 03: 00:34.591Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\libxml2.dll
    2012 03-04 T 03: 00:34.591Z | vmui | I120: 0.0.0.0 file version
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the amount of basic 0x0x74f50000 module 0 x 0 00007000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x00005f90 timestamp 0x4a5bdb63
    2012 03-04 T 03: 00:34.591Z | vmui | I120: C:\Windows\System32\wsock32.dll image file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 76160000 0 x 0 00045000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x0004a021 timestamp 0x4ce7ba62
    2012 03-04 T 03: 00:34.591Z | vmui | I120: C:\Windows\SysWOW64\Wldap32.dll image file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the amount of basic 0x0x67b30000 module 0 x 0 00799000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x007959f1 timestamp 0x4f173a31
    2012 03-04 T 03: 00:34.591Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\vmwarecui.dll
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 8.0.2.28060 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the base 0x0x00a50000 size 0x0x000a0000 module
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x000a53e3 timestamp 0x4afb6001
    2012 03-04 T 03: 00:34.591Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\glibmm-2.4.dll
    2012 03-04 T 03: 00:34.591Z | vmui | I120: 0.0.0.0 file version
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the amount of basic 0x0x005c0000 module 0 x 0 00007000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x00008b8d timestamp 0x4cad4077
    2012 03-04 T 03: 00:34.591Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\gmodule-2.0.dll
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 2.22.4.0 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the base 0x0x74b10000 size 0x0x0000e000 module
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x00014f34 timestamp 0x4f173a17
    2012 03-04 T 03: 00:34.591Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\vmwarestring.dll
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 8.0.2.28060 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the amount of basic 0x0x00af0000 module 0 x 0 00020000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x000277c3 timestamp 0x4e1ca868
    2012 03-04 T 03: 00:34.591Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\libcds.dll
    2012 03-04 T 03: 00:34.591Z | vmui | I120: 0.0.0.0 file version
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the amount of basic 0x0x69c30000 module 0 x 0 00240000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x002401e0 timestamp 0x4ce7b902
    2012 03-04 T 03: 00:34.591Z | vmui | I120: C:\Windows\System32\msi.dll image file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 5.0.7601.17514 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the base 0x0x770f0000 size 0x0x0002d000 module
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x0002a3e7 timestamp 0x4ce7ba52
    2012 03-04 T 03: 00:34.591Z | vmui | I120: C:\Windows\SysWOW64\wintrust.dll image file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the amount of basic 0x0x00b20000 module 0 x 0 00053000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0 x 00060645 timestamp 0x4abd1a53
    2012 03-04 T 03: 00:34.591Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\libcurl.dll
    2012 03-04 T 03: 00:34.591Z | vmui | I120: 0.0.0.0 file version
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the amount of basic 0x0x00b90000 module 0 x 0 00036000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x0004211f timestamp 0x4dddb957
    2012 03-04 T 03: 00:34.591Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\ssleay32.dll
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 0.9.8.18 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the base 0x0x00be0000 size 0x0x000fe000 module
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x00102e04 timestamp 0x4dddb932
    2012 03-04 T 03: 00:34.591Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\libeay32.dll
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 0.9.8.18 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the amount of basic 0x0x00cf0000 module 0 x 0 00054000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x000569d5 timestamp 0x4abd17ec
    2012 03-04 T 03: 00:34.591Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\libldap_r.dll
    2012 03-04 T 03: 00:34.591Z | vmui | I120: 0.0.0.0 file version
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the amount of basic 0x0x00d60000 module 0 x 0 00027000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x0002ff88 timestamp 0x4abd17c8
    2012 03-04 T 03: 00:34.591Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\liblber.dll
    2012 03-04 T 03: 00:34.591Z | vmui | I120: 0.0.0.0 file version
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the amount of basic 0x0x00da0000 module 0 x 0 00013000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x00019b7d timestamp 0x4abc5dbb
    2012 03-04 T 03: 00:34.591Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\zlib1.dll
    2012 03-04 T 03: 00:34.591Z | vmui | I120: 1.2.3.0 file version
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the amount of basic 0x0x668d0000 module 0 x 0 00476000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x004641ef timestamp 0x4f173a8d
    2012 03-04 T 03: 00:34.591Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\vmwarewui.dll
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 8.0.2.28060 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 75120000 0 x 0 00011000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x0001148b timestamp 0x4ce7b913
    2012 03-04 T 03: 00:34.591Z | vmui | I120: C:\Windows\System32\netapi32.dll image file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the amount of basic 0x0x742d0000 module 0 x 0 00009000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x0000dbc3 timestamp 0x4ce795a6
    2012 03-04 T 03: 00:34.591Z | vmui | I120: C:\Windows\System32\netutils.dll image file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 74490000 0 x 0 00019000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x00017d8f timestamp 0x4ce7ba1f
    2012 03-04 T 03: 00:34.591Z | vmui | I120: C:\Windows\System32\srvcli.dll image file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the module base dimension 0x0x0000f000 0 x 0 x 75110000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x00010d3b timestamp 0x4ce795a7
    2012 03-04 T 03: 00:34.591Z | vmui | I120: C:\Windows\System32\wkscli.dll image file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the amount of basic 0x0x72e90000 module 0 x 0 00005000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x0000b835 timestamp 0x4a5bdaa0
    2012 03-04 T 03: 00:34.591Z | vmui | I120: C:\Windows\System32\msimg32.dll image file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the amount of basic 0x0x75e40000 module 0 x 0 00060000
    2012 03-04 T 03: 00:34.591Z | vmui | I120: checksum 0x0002c2aa timestamp 0x4ce7ba53
    2012 03-04 T 03: 00:34.591Z | vmui | I120: C:\Windows\SysWOW64\imm32.dll image file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.591Z | vmui | I120: CoreDump: including the module base dimension 0x0x000cc000 0 x 0 x 75810000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x000cb820 timestamp 0x4a5bda69
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\SysWOW64\msctf.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the amount of basic 0x0x714d0000 module 0 x 0 00008000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x0000ccb4 timestamp 0x4ec49b63
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\secur32.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: version of the 6.1.7601.17725 file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the base 0x0x00de0000 size 0x0x000c6000 module
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x000c65a3 timestamp 0x4e20ebaa
    2012 03-04 T 03: 00:34.592Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\vixDiskMountApi.dll
    2012 03-04 T 03: 00:34.592Z | vmui | I120: version of the 4.0.1.15 file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the base 0x0x6c500000 size 0x0x0011a000 module
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x0011d6da timestamp 0x4dfb827e
    2012 03-04 T 03: 00:34.592Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\sysimgbase.dll
    2012 03-04 T 03: 00:34.592Z | vmui | I120: version of the 5.0.0.457 file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the base 0x0x69f10000 size 0x0x0046b000 module
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0 x 00468474 timestamp 0x4f1737e1
    2012 03-04 T 03: 00:34.592Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\gvmomi.dll
    2012 03-04 T 03: 00:34.592Z | vmui | I120: version of the 8.0.2.28060 file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the base 0x0x00f00000 size 0x0x0004d000 module
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x00054bd2 timestamp 0x4eef85d3
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\SysWOW64\guard32.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: version of the 5.9.23139.2195 file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the amount of basic 0x0x751d0000 module 0 x 0 00007000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x0000e62a timestamp 0x4a5bd9f3
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\fltLib.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the amount of basic 0x0x74bd0000 module 0 x 0 00021000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x0002760c timestamp 0x4a5bdae9
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\ntmarta.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the amount of basic 0x0x74fb0000 module 0 x 0 00016000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0 x 00017990 timestamp 0x4a5bda3d
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\cryptsp.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the base 0x0x74f70000 size 0x0x0003b000 module
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x000401a8 timestamp 0x4a5bdae0
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\rsaenh.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 01010000 0 x 0 00036000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x0003d749 timestamp 0x4ef0d2f7
    2012 03-04 T 03: 00:34.592Z | vmui | I120: F:\Program files (x86)\DisplayFusion\Hooks\AppHookx86_8eac620e-0f0e-49bd-a51a-dc87843f053e.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: 3.4.1.4 file version
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 75580000 0 x 0 00005000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x0000ccd3 timestamp 0x4a5bdace
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\SysWOW64\psapi.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 71240000 0 x 0 00047000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x0004d81a timestamp 0x4f173caa
    2012 03-04 T 03: 00:34.592Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\vmdbCOM.dll
    2012 03-04 T 03: 00:34.592Z | vmui | I120: version of the 8.0.2.28060 file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 74970000 0 x 0 00061000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x00067e45 timestamp 0x4f173cca
    2012 03-04 T 03: 00:34.592Z | vmui | I120: F:\Program files (x 86) image file \VMware\VMware Workstation\vmappsdk.dll
    2012 03-04 T 03: 00:34.592Z | vmui | I120: version of the 8.0.2.28060 file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the amount of basic 0x0x70aa0000 module 0 x 0 00039000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x0003dfbb timestamp 0x4ce7b892
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\MMDevAPI.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the base 0x0x714e0000 size 0x0x000f5000 module
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x000fa310 timestamp 0x4ce7b983
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\propsys.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: version of the 7.0.7601.17514 file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the amount of basic 0x0x65b30000 module 0 x 0 00030000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x0002d412 timestamp 0x4ce7ba26
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\wdmaud.drv image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 73190000 0 x 0 00004000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x0000dc4d timestamp 0x4a5bdab3
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\ksuser.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 67390000 0 x 0 00007000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x0000910a timestamp 0x4a5bd998
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\avrt.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the amount of basic 0x0x70d10000 module 0 x 0 00036000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x0003cd0f timestamp 0x4ce7b725
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\AudioSes.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the amount of basic 0x0x65b20000 module 0 x 0 00008000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x000106aa timestamp 0x4a5bda4f
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\msacm32.drv image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the amount of basic 0x0x750f0000 module 0 x 0 00014000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x0001dea3 timestamp 0x4a5bda4e
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\msacm32.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the amount of basic 0x0x65b10000 module 0 x 0 00007000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x0000580e timestamp 0x4a5bda84
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\midimap.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 73400000 0 x 0x00010000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0 x 00013875 timestamp 0x4ce7b90f
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\nlaapi.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the amount of basic 0x0x733f0000 module 0 x 0x00010000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0x0000eecd timestamp 0x4a5bda6d
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\NapiNSP.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 73390000 0 x 0 00012000
    2012 03-04 T 03: 00:34.592Z | vmui | I120: checksum 0 x 00011079 timestamp 0x4a5bdaf6
    2012 03-04 T 03: 00:34.592Z | vmui | I120: C:\Windows\System32\pnrpnsp.dll image file
    2012 03-04 T 03: 00:34.592Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.592Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 73360000 0 x 0 00027000
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0x00027de0 timestamp 0x4c991ceb
    2012 03-04 T 03: 00:34.593Z | vmui | I120: image file C:\Program Files (x 86) \Common Files\Microsoft Shared WLIDNSP. DLL
    2012 03-04 T 03: 00:34.593Z | vmui | I120: version of the 7.250.4225.0 file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including the base 0x0x74f10000 size 0x0x0003c000 module
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0x000446f8 timestamp 0x4ce7b8e8
    2012 03-04 T 03: 00:34.593Z | vmui | I120: C:\Windows\System32\mswsock.dll image file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 74280000 0 x 0 00044000
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0x0004c8e2 timestamp 0x4d6f2733
    2012 03-04 T 03: 00:34.593Z | vmui | I120: C:\Windows\System32\dnsapi.dll image file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: version of the 6.1.7601.17570 file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 73350000 0 x 0 00008000
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0x000059ac timestamp 0x4a5bdb44
    2012 03-04 T 03: 00:34.593Z | vmui | I120: C:\Windows\System32\winrnr.dll image file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including the base 0x0x74e90000 size 0x0x0001c000 module
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0 x 00025653 timestamp 0x4ce7b859
    2012 03-04 T 03: 00:34.593Z | vmui | I120: image C:\Windows\System32\IPHLPAPI file. DLL
    2012 03-04 T 03: 00:34.593Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including the amount of basic 0x0x74e80000 module 0 x 0 00007000
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0x00006a64 timestamp 0x4a5bdb43
    2012 03-04 T 03: 00:34.593Z | vmui | I120: C:\Windows\System32\winnsi.dll image file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including the amount of basic 0x0x694b0000 module 0 x 0 00038000
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0 x 00043802 timestamp 0x4ce7b832
    2012 03-04 T 03: 00:34.593Z | vmui | I120: image C:\Windows\System32\FWPUCLNT file. DLL
    2012 03-04 T 03: 00:34.593Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including the amount of basic 0x0x731d0000 module 0 x 0 00006000
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0x0000fb04 timestamp 0x4a5bdad6
    2012 03-04 T 03: 00:34.593Z | vmui | I120: C:\Windows\System32\rasadhlp.dll image file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 76250000 0 x 0 00083000
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0x0008558c timestamp 0x4a5bd9b1
    2012 03-04 T 03: 00:34.593Z | vmui | I120: C:\Windows\SysWOW64\clbcatq.dll image file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: version of the 2001.12.8530.16385 file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including the module base dimension 0x0x0000a000 0 x 0 x 70660000
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0x00016bbd timestamp 0x4a5bdb2f
    2012 03-04 T 03: 00:34.593Z | vmui | I120: C:\Windows\System32\wbem\wbemprox.dll image file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including the module base dimension 0x0x0005c000 0 x 0 x 70600000
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0x0006018b timestamp 0x4ce7ba25
    2012 03-04 T 03: 00:34.593Z | vmui | I120: C:\Windows\System32\wbemcomn.dll image file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including the base 0x0x74f60000 size 0x0x0000e000 module
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0x0000d0fe timestamp 0x4ce7992f
    2012 03-04 T 03: 00:34.593Z | vmui | I120: C:\Windows\System32\RpcRtRemote.dll image file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including the module base dimension 0x0x0000f000 0 x 0 x 70420000
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0x0000fc58 timestamp 0x4a5bdb30
    2012 03-04 T 03: 00:34.593Z | vmui | I120: C:\Windows\System32\wbem\wbemsvc.dll image file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 70380000 0 x 0 00096000
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0x0009fd4f timestamp 0x4ce7b809
    2012 03-04 T 03: 00:34.593Z | vmui | I120: C:\Windows\System32\wbem\fastprox.dll image file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 70360000 0 x 0 00018000
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0x00020d5a timestamp 0x4a5bdade
    2012 03-04 T 03: 00:34.593Z | vmui | I120: C:\Windows\System32\ntdsapi.dll image file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including the base 0x0x6eda0000 size 0x0x000eb000 module
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0x000db0aa timestamp 0x4ce7b7bc
    2012 03-04 T 03: 00:34.593Z | vmui | I120: C:\Windows\System32\dbghelp.dll image file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: version of the 6.1.7601.17514 file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including the Basic module size 0 x 0 71150000 0 x 0 00025000
    2012 03-04 T 03: 00:34.593Z | vmui | I120: checksum 0x00026df1 timestamp 0x4a5bdb0c
    2012 03-04 T 03: 00:34.593Z | vmui | I120: C:\Windows\System32\powrprof.dll image file
    2012 03-04 T 03: 00:34.593Z | vmui | I120: 6.1.7600.16385 file version
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including wire 8500
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including wire 4476
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including wire 5456
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including wire 3968
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including wire 8932
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including wire 7656
    2012 03-04 T 03: 00:34.593Z | vmui | I120: CoreDump: including wire 7396
    2012 03-04 T 03: 00:34.753Z | vmui | I120: backtrace [00] framework 0x0020f600 IP 0x67dadf76 params 0x20f624 0xffffffffffffffff 0 cui::inventory:FolderNode:UnloadObject + 0 0x20f638 x 0146 [F:\Program files (x 86) \VMware\VMware Workstation\vmwarecui.dll base 0x67b30000 0x0001: 0x0027cf76]
    2012 03-04 T 03: 00:34.753Z | vmui | I120: backtrace [01] framework 0x0020f62c IP 0x67dae23b params 0x20f6a4 0x4b5d2a0 0 x 1 0 cui::inventory:FolderNode:AddChild + 0x006b [F:\Program files (x 86) \VMware\VMware Workstation\vmwarecui.dll base 0x67b30000 0x0001: 0x0027d23b]
    2012 03-04 T 03: 00:34.753Z | vmui | I120: backtrace [02] frame IP 0x67db3c2f params 0x4b99280 0x499595fe 0x74b11530 0x2c8a4e0 0x0020f794 cui::inventory:LocalInventory:LoadFromDictionary + 0x067f [F:\Program files (x 86) \VMware\VMware Workstation\vmwarecui.dll base 0x67b30000 0x0001: 0x00282c2f]
    2012 03-04 T 03: 00:34.753Z | vmui | I120: backtrace [03] setting IP 0x67db4f1d params 0x49959a6e 0x2c54c88 0x2c8a4e0 0x2c330a8 0x0020f7dc cui::inventory:LocalInventory:LoadFromDisk + 0x00ed [F:\Program files (x 86) \VMware\VMware Workstation\vmwarecui.dll base 0x67b30000 0x0001: 0x00283f1d]
    2012 03-04 T 03: 00:34.753Z | vmui | I120: backtrace [04] framework 0x0020f84c IP 0x67db5a19 params 0x4998bff2 0 0x6695df30 0 cui::inventory:LocalInventory:LocalInventory + 0x01b9 [F:\Program files (x 86) \VMware\VMware Workstation\vmwarecui.dll base 0x67b30000 0x0001: 0x00284a19]
    2012 03-04 T 03: 00:34.754Z | vmui | I120: backtrace [05] framework 0x0020f8d0 IP 0x002f57ac params 0x2c8a4e0 0x4998bd42 0x42f72c 0 x 1? [F:\Program files (x 86) \VMware\VMware Workstation\vmware.exe base 0x002c0000 0x0001: 0x000347ac]
    2012 03-04 T 03: 00:34.754Z | vmui | I120: backtrace [06] framework 0x0020fa60 IP 0x002c77fc params 0x2c0000 0 0x5f2a28 0 x 1? [F:\Program files (x 86) \VMware\VMware Workstation\vmware.exe base 0x002c0000 0x0001: 0x000067fc]
    2012 03-04 T 03: 00:34.754Z | vmui | I120: backtrace [07] framework 0x0020faf4 IP 0x002c119b 0x7efde000 0x20fb40 0x77c29ef2 0x7efde000 params? [F:\Program files (x 86) \VMware\VMware Workstation\vmware.exe base 0x002c0000 0x0001: 0x0000019b]
    2012 03-04 T 03: 00:34.756Z | vmui | I120: backtrace [08] framework 0x0020fb00 IP 0x75a2339a 0x7efde000 0x73df374d 0 BaseThreadInitThunk 0 + 0 x 0012 params [C:\Windows\syswow64\kernel32.dll base 0x75a10000 0x0001: 0x0000339a]
    2012 03-04 T 03: 00:34.759Z | vmui | I120: backtrace [09] framework 0x0020fb40 IP 0x77c29ef2 0x2c130a 0x7efde000 0 RtlInitializeExceptionChain 0 + 0 x 0063 params [C:\Windows\SysWOW64\ntdll.dll base 0x77bf0000 0x0001: 0x00029ef2]
    2012 03-04 T 03: 00:34.759Z | vmui | I120: backtrace [10] framework 0x0020fb58 IP 0x77c29ec5 0x2c130a 0x7efde000 0 RtlInitializeExceptionChain 0 + 0 x 0036 params [C:\Windows\SysWOW64\ntdll.dll base 0x77bf0000 0x0001: 0x00029ec5]
    2012 03-04 T 03: 00:34.759Z | vmui | I120: Msg_Post: error
    2012 03-04 T 03: 00:34.759Z | vmui | I120: fatal error [msg.log.error.unrecoverable] VMware Workstation: (vmui)
    2012 03-04 T 03: 00:34.759Z | vmui | I120 + Exception 0xc0000005 (access violation) occurred.
    2012 03-04 T 03: 00:34.759Z | vmui | I120: [msg.panic.haveLog], a log file is available in "C:\Users\Me\AppData\Local\Temp\vmware-Me\vmware-ui-Me-8072.log".
    2012 03-04 T 03: 00:34.759Z | vmui | I120: [msg.panic.haveCore] a core file is available in "C:\Users\Me\AppData\Local\Temp\vmware-Me\vmware-8072.dmp".
    2012 03-04 T 03: 00:34.759Z | vmui | I120: [msg.panic.requestSupport.withLogAndCore] you can ask support and include the contents of the log file and the base file.
    2012 03-04 T 03: 00:34.759Z | vmui | I120: [msg.panic.requestSupport.vmSupport.windowsOrLinux]
    2012 03-04 T 03: 00:34.759Z | vmui | I120 + to collect data to be submitted to VMware support, choose "Collect load data" in the Help menu.
    2012 03-04 T 03: 00:34.759Z | vmui | I120 + you can also run the script 'vm-support' in the folder my computer directly.
    2012 03-04 T 03: 00:34.759Z | vmui | I120: [msg.panic.response] we will respond on the basis of your entitlement to support.
    2012 03-04 T 03: 00:34.759Z | vmui | I120: ----------------------------------------
    2012 03-04 T 03: 00:36.174Z | vmui | I120: You quit abnormally.

    I have Win7 x 64, 7 Workastation running. I tried to upgrade to Workstation 8 (30 days trial) and ran into the same problem.

    For me it turns out be related to my "Favorites". I finally got it works by moving the "C:\Users\johna\AppData\Roaming\VMware\favorites.vmls" file out of the folder it is (temporarily) then started VMWare. This time, he began. Once launched, it genearted a new file called "inventory.vmls", I then landed my file in the folder, just in case I need to return to Workstation7.

    I guess you might be able to accomplish the same thing by removing all your Favorites, but I don't know.

    Hope this helps someone with this problem.

  • When closing Firefox 13.01 I always get this pop-up: Exception EAccessViolation in module ntdll.dll to 000222 B 2. Access violation at address 77BF22B2 in module

    When closing Firefox 13.01 I always get this popup:
    Exception EAccessViolation in module ntdll.dll to 000222B 2. Access violation at address 77BF22B2 in module 'ntdll.dll '. Writing of
    address 00000008.
    With previous versions of FF it never happened.
    Any solution?

    Hello

    Please check if this happens in a new profile. If the new profile is correct, you can then reset Firefox on the old (previous) profile via the help (Alt + H) > troubleshooting information.

  • Skype has stopped working! Access violation

    I get this error whenever I try to start Skype: Access violation at address 6A0CC01F in module 'mshtml.dll. Read of address 06DAB589.

    What can I do?

    Thank you!

    I'm sorry, but 'forward' is not 'now '.

    Update your installation of Windows 7 SP1 last.

    http://Windows.Microsoft.com/en-us/Windows7/install-Windows-7-Service-Pack-1

    Install the version of Internet Explorer IE9:

    http://Windows.Microsoft.com/en-us/Internet-Explorer/IE-9-worldwide-languages

  • Access violation 0019DE4C

    So my Skype has stopped working suddenly and said that I had an access violation

    I'm on Windows 10 and Skype version 7.18.0.112

  • CVI executable causes an on update of Windows 10 anniversary 0xC0000005 Access Violation.

    Created executables always causes an Access Violation (0xc0000005 exception) to the closing period on Windows 10 RS1 (update of the anniversary).

    This problem occurs in LabWindows CVI 2015 and 2015 SP1.

    How to reproduce: simple program to create and compile with the (x 86) release profile by default.

    for example:

    #include "test.h".

    int ph;

    int __stdcall WinMain (HINSTANCE hInstance, HINSTANCE hPrevInstance,
    LPSTR lpszCmdLine, int nCmdShow)
    {
    If (InitCVIRTE (hInstance, 0, 0) == 0)
    Returns - 1; / * memory * /.

    pH = LoadPanel (0, "test.uir", group of EXPERTS);
    DisplayPanel (ph);
    RunUserInterface();

    return 0;
    }

    int CVICALLBACK CallExit (int, int int event, control panel,
    void * callbackData, int eventData1, int eventData2)
    {
    switch (event)
    {
    case EVENT_COMMIT:
    QuitUserInterface (0);
    break;
    }
    return 0;
    }

    The problem is visible on the control panel > reliability history > Error Reporting:

    Also the code of the executable file (exit code) is always 0xc0000005 instead of zero.

    To check out more easily code can be called the executable through file .bat:

    off @echo
    Test.exe
    echo ExitCode = %ERRORLEVEL%
    pause

    I have observed that if multiple instances of the same program are running, only block when the last instance is closed. It seems that the problem occurs at the time that the CVI runtime is released from the ram. (The latter is only a guess)

    Hello

    We did some research and saw that the failure is related to some police files in

    c:\Windows\SysWOW64\cvirte\fonts

    c:\Windows\System32\cvirte\fonts

    Could you try deleting these files and see if the heater is always performed. If this isn't the case, it would be a work around if you do not use these fonts.

    We continue the investigation to see the exact cause

  • Library of nivision - imaqMakeRect: access violation writing location

    I am writing a script of image acquisition using the nivision and libraries niimaqdx in python 2.7 using types. When I use the imaqMakeRect function to make a Rect structure to be used in the imaqImagetoArray function, I get a write error access violation.

    It's the line that causes the problem - imaqMakeRect (c_int32 (0), c_int32 (0), c_int32 (0x7FFFFFFF), c_int32 (0x7FFFFFFF)).

    which results in the error: WindowsError: exception: breach of writing 0 x 00000008 access

    The location of access violation seems to depend on the value of the first argument. Any ideas on what could happen? and how to fix it?

    Thank you!

    Thaks for the suggestions!

    This problem himself.

    types import *.
    IMAQ = windll.nivision

    class Rect (Structure):
    _fields_ =]
    ('top', c_int32);
    ('left', c_int32);
    ('height', c_int32);
    ("width", c_int32);
    ]

    imaq.imaqMakeRect.restype = Rect.

    IMAQ_NO_RECT = imaq.imaqMakeRect (c_int32 (0), c_int32 (0), c_int32 (100), c_int32 (100))

  • Collage error: runtime error. Error: access violation, address of the error: 0000 P 280, the Module name: GFSData.DLL

    Hello to all on the forum,

    I am running DIAdem 2015 (15.0.0f6005) on a Windows 7 Pro SP1 i3 4 GB RAM machine.

    I want to evaluate a test. Data are expressed as 25 .txt files. I need to plot, one of the values on the whole test time. I tried to combine the data from all 25 in one file .tdm .txt files. I came far enough until I met my problem. After gathering around 15 .txt files in a .tdm, tiara doesn't let me continue. It gives this error message (in German, I'll translate as good as possible):

    "When executing command 'DataBlClpPaste('1-52',1859122,0)' a rumtime error has occurred.

    Error: ACCESS VIOLATION

    Address of the error: 0000 P 280

    "Name of the module: FGSData.DLL.

    I will describe my procedure in which this happened:

    -Open the .txt with plugin I had created the first import

    -Ribbon with two windows view channel: have the target in a secondary window group, drag the newly imported from .txt in the other channels

    -In the secondary window with new data, select the lines I want to add to the data target group by clicking on the first line, then scroll to the last row and shift-select that. CTRL + c to copy the data

    -In the target group, click the first empty line, and then ctrl + v to paste data here

    After the last step, instead of pasting the new data in the target dataset, the above message error. I can't do anything, but click on 'ok '. After ok, the program window will not respond to any click except for switching between Navigator / View / analysis /... I have to close DIAdem, where I can always select "close and save", that works too.

    I could go a few times after reopening DIAdem, but finally, which stopped working. It now gives me the error message whenever I try to do this routine. The .tdm file is 21Mo now, the .tdx is 1.1 GB.

    I appreciate any help on this, I really would prefer combining data using DIAdem on trying to copy and paste around 1 GB of data .txt into one giant .txt file. It takes very long to not even open a .txt of 50 MB file, I fear this would be a messy process.

    Best regards

    Simon

    If you are using DIAdem 2015, there is a new entry in context menu where you can select Add.

    Maybe it helps.

    The help of DIAdem 2015:

    Adding data


    Adding data to merge similar series ratings data in order to deal with them. In the process, DIAdem adds the data to load for existing channels with the same name in the data portal instead of storing data in new channels. Perform the following steps to add the external data area data channels in the data portal:

    1. Open the NAVIGATOR tiara.


    2. Select remove internal data to delete the data in the data portal.


    3. Find the Demo1.tdm file in the file browser.


    4. Drag and drop the file in the data portal.


    5. Select the Demo2.tdm file in the file browser.


    6. Open the context menu of the file and select Add data.


    Tiara adds the data in channels that have the same name in the data portal. In the properties of the Data Portal window, you can see that the number of values in the channels has doubled.

  • NI MAX with USB devices access violation

    I found a lot of messages about access violation, but most of them are about LabView and not MAX OR, as is the case here.

    I get an access violation error (0xC0000005 at PPC = 0x106399AE) whenever I try to create a new task of MAX OR by selecting a USB DAQ device. I tried with USB-6009 and USB-6211, same problem. The device is properly recognized (test) but when I try to create a new task I complete all the procedure, and when cliquerai I finish I get the error. This also causes LabView programs that use the tasks of MAX OR crashing.

    First of all, this happened after the NI DAQmx drivers update to a new version, but then I recognized that this version was incompatible with Labview installed on this machine (8.6). I tried to fall back by using a restore point in windows and reinstall the 9.5.1 DAQmx drivers (the latest drivers supported by the version of LabView.

    I tried to 'Reset Configuration data' MAX OR (under the Tools menu) without success. The WindowsXPUSBhotfix is also installed in the system. Any help?

    I also sent a support NC ticket: c82f5b4f-d774-40a2-8341-4dbeee9df876

    Specifications of the PC:

    Windows XP SP3

    LabVIEW 8.6

    NOR-DAQmx 9.5.1

    The error was eventually resolved by uninstalling OR MAX and LabView and then reinstall all the software needed. In particular, the configuration that worked was:

    -NI MAX 5.1 (includes NOT-DAQmx 9.5.1)

    -LabView 8.6

    -2.6 OR-488. 2 (including NI-VISA 4.4.1)

    the last of them was necessary to connect to another device to purchase. With the above configuration, the wizard DAQ worked and generated a task, but when the program was launched, the task was not able to recognize the good device (unit name is an empty string). So I converted it to a NOR-DAQmx task, and now it works. (Don't really know if this quick passage would have been a good work around from the beginning.)

  • Error connecting to a remote database access violation

    I have the software on my machine (written in-house by a company I work for) to connect to a remote database from home. I have connected several times without problem, but recently I immediately get an error message as follows: "Access violation at address...". ' followed by the hexadecimal address number, when I click on the "connect" button after entering the login information. The only thing I can think of that is different is that I have changed recently, is my anti-virus software. I tried to uninstall the new software temporarily, and disable the Windows Firewall, but the problem persists. So I just can't connect to the database. This who should I look to fix this? Thank you

    Hello

    Check with a different user profile

    If you do not have a different user account, you will need to create a (see link below). If everything works fine with a different user profile, you can infer that the user profile is damaged, click on the link to find out how to solve this problem.

    Create-a-user account

    http://Windows.Microsoft.com/en-us/Windows-Vista/create-a-user-account

    Difficulty of a corrupted user profile

    http://Windows.Microsoft.com/en-us/Windows-Vista/fix-a-corrupted-user-profile

    You can also try contacting the Publisher of the software and for further assistance.

  • Get an Access Violation error when playing games

    OP: Access Violation errors!

    I have download games on a game site that I trust and don't usually have problems. In the last 4 months, some of the new games that I downloaded and tried to play, give me the Access Violation error when I try to open the game to play the demo. Now just recently I noticed that several of my games that I bought and played for months, give me also Access Violation errors. I worked on it for months with people in customer service (on the site of games) and have not solved. The strange thing is, I can play some of these games on different websites without any problems or Violations of access at all. Yet the customer service people keep trying to 'fix' my computer, as if it were from my computer something to make this happen. At this point, I'm so frustrated that I had to try to get you all to see if anyone has experience this problem before and/or solved this kind of case before. I tried to turn off my Norton before download and play without success. I've updated everything that could be updated in regards to drivers, and such go.
    My system is Vista 32 bit, IE8, Norton Security and anti-virus.  Thanks for any help!

    Hello saund477,

    My research, I find that it is a known problem with Big fish games. I also see that some users were able to solve this problem and play games by disabling the antivirus program on their computer.

    I suggest that you turn off the Anti Virus program and check if you are able to play the game.

    Note: Please make sure that you enable the antivirus software after the test to keep your computer protected.

    You can refer to the thread below that I found that the forum of Big fish:

    http://forums.bigfishgames.com/posts/list/4106.page

    I also suggest that you post your question to the Bigfish forum for a better answer to this question, because the problem is only with Bigfish games:

    http://forums.bigfishgames.com/games/list.page

    About the error when you try to run the command, it seems that you type the command correctly, make sure that you type the command correctly.

    Thank you
    Irfan H, Engineer Support Microsoft Answers. Visit our Microsoft answers feedback Forum and let us know what you think.

  • Error "Library not registered" and "access violation at address 00000000. Read of address 00000000 "while trying to play Call of Duty 2 on Windows 7 64 bit

    Original title: Call of Duty 2 on windows 7: first window said: library not registered. After a minute, seven or more pop-up windows to say the same thing: access violation at address 00000000. Read of address 00000000

    I tried to play Call Of Duty 2 on windows 7 64 premium.  After installation, if I choose to click on the shortcut on the desktop, it keeps invites me to insert the correct CD in the drive.  That right is already in the drive.  If I have the game from the CD autorun, it invites library not registered.  Then opens upward of seven windows or more with the same message: access violation at address 00000000. Read of address 00000000.  the map system, game and video have all been updated and installed the latest patch for Call of Duty 2.  The funky thing is, if I use the fix offered for Vista I can get the multiplayer game to work, but the single player mode is still inaccessible.  I tried changing the compatibility, tried to use the option of windows XP mode and tried to open it in a new window and ran it under administrator.  nothing has worked, suggestions?

    I have thought about it myself, do what I tried above and activate the function of compatibility with Windows Vista service pack 2.  If you do not know the fix vista, click Start, Control Panel, hardware and sound, click sound, and then click the recording TAB.  Right click on a space in the tab itself, when see her disable devices is displayed click on to show them.  stereo mix is show in the tab, right click on that and turn on.  Only, remember, insert the CD, do not autorun installation just right click on the icon setup on the CD itself and open a new window.  run as administrator and install.  After that, go ahead and install the latest version of Patch 1.3 for Call of Duty 2.  When all is said and done don't forget to change the compatibility mode to Windows Vista service Pack 2. Note to Microsoft: Windows XP mode is a great idea, except that you dropped the ball twice, #1 - should have a version of it to support windows 7 Edition home premium for topics such as this for the public #2 - you must enable a way to get the video settings within the windows XP mode , in short to make a windows operating system that will play a game out there that has already been done to PC.

  • Error messages and access violations.

    I downloaded this game called "Diamon Jones - Eye of the Dragon" when I tried to play the game I get the error message: access violation error at 0 00464438 (try to read 0 x 00000000) x game.exe has stopped working I tried everything, the only thing I have not done, it is again my computer. I think I spent over $ 200.00, try to fix the problem for regcue, unbile, registry easy, driver dective, etc.. Whenever I get help just what everyone wants you to do is buy it soft. I like the new gimiks try our free scan products oh! We cannot clean you system for you except if you buy the full product.  Can someone help me please?  The game has been downloaded from Bigfish.

    Thank you

    Baggetel

    Hi Baggetel,

    Since you get the access violation error, try to run the game as administrator and see if it works.

    To do this, right click on the exe of the game and run it as an administrator.

    If this does not work, turn user account control off.

    To disable the user account control:

    1. open Control Panel.

    2. under the user account and family settings click on the "add user account / remove."

    3. click on one of the user accounts, for example, you can use the guest account.

    4. in the user account, click on the link "go to the main page of the user account.

    5. under "Make changes to your user account", click on the link "change security settings".

    6. in him "turn User Account Control (UAC) to make your computer more secure" click to deselect the "use User Account Control (UAC) to help protect your computer. Click the Ok button.

    7. you will be asked to restart your computer. Do when you're ready.

    After the PC restarts, try to install the game. Check if it works.

    Then, enable the user account control.

    1. to do this, follow steps 1 through 5 above.

    2 Select "Use User Account Control (UAC) to help protect your computer" click on the Ok button.

    3. restart when you are prompted to

    It should work.

    Kind regards

    Shinmila H - Microsoft Support

  • access violation

    OXOOBECA58 {tried to read 0 X 0080001} was abolished an access violation when trying to play a game that I downloaded. I have Windows xp home edition

    Hello

    first of all, you should check your RAM for errors using Memtest +.
    Access violations are often caused by memory problems.

    Concerning

Maybe you are looking for