Analyzed 17 dump

Top 1: total counts = 3

045cfdb8 5e6f6fb9 NetULEx+0x11613
045cfee0 5e712288 LockScreen!FullScreenAdConfigTask::Run+0x239
045cff24 5e7124ea LockScreen!ScheduledTasksMgr::TaskDispatcher+0x88
045cff44 5e6fd2ca LockScreen!std::_LaunchPad >,std::default_delete > > > >::_Go+0x8a
045cff4c 5e76c872 LockScreen!CImageDownload::DownloadThread+0xa
045cff88 74f7344d LockScreen!thread_start+0x57
045cff94 77599802 kernel32!BaseThreadInitThunk+0xe
045cffd4 775997d5 ntdll!__RtlUserThreadStart+0x70
045cffec 00000000 ntdll!_RtlUserThreadStart+0x1b

8df79892f0485728084dd6569a2dca81_000.dmp
962435ba2746b038c4b2c851ea1c200f_000.dmp
85632d16060e878705d76ba99e42510b_001.dmp

Top 2: total counts = 1

ChildEBP RetAddr  
0019ef94 0048a511 ntdll!RtlEnterCriticalSection+0x15
0019f190 000105c0 dolphinsrv!WTL::CDCT<1>::DeleteDC+0x21
WARNING: Frame IP not in any known module. Following frames may be wrong.
0019f198 76f43163 0x105c0
0019f1c4 76f33f56 user32!_InternalCallWinProc+0x2b
0019f2bc 76f32815 user32!UserCallWinProcCheckWow+0x4c6
0019f338 76f32360 user32!DispatchMessageWorker+0x4a5
0019f344 00415b61 user32!DispatchMessageW+0x10
0019f368 00408ffa dolphinsrv!WTL::CMessageLoop::Run+0xc1
0019fe80 00408a2e dolphinsrv!Run+0xaa
0019ff28 005422dc dolphinsrv!wWinMain+0x47e
0019ff74 75b07ba9 dolphinsrv!__scrt_common_main_seh+0xf8
0019ff84 7713c0cb kernel32!BaseThreadInitThunk+0x19
0019ffdc 7713c04f ntdll!__RtlUserThreadStart+0x2b
0019ffec 00000000 ntdll!_RtlUserThreadStart+0x1b

9e3d60d81fd1941dcf1656d0dfee8f64_000.dmp

Top 3: total counts = 1

0019f324 00416571 user32!DispatchMessageW+0x10
WARNING: Stack unwind information not available. Following frames may be wrong.
0019f348 004096ea dolphinsrv+0x16571
0019fe6c 0040911e dolphinsrv+0x96ea
0019ff24 0054c7ec dolphinsrv+0x911e
0019ff70 776cf989 dolphinsrv+0x14c7ec
0019ff80 77e57084 kernel32!BaseThreadInitThunk+0x19
0019ffdc 77e57054 ntdll!__RtlUserThreadStart+0x2f
0019ffec 00000000 ntdll!_RtlUserThreadStart+0x1b

4f3f9824928df638447189e29edd1dea_000.dmp

Top 4: total counts = 1

ChildEBP RetAddr  
02fafae8 7774bf89 ntdll!TppRaiseInvalidParameter+0x37
02fafb00 777089c8 ntdll!TppCancelWait+0x4352c
02fafb24 776d7770 ntdll!TpSetWaitEx+0x68
02fafb74 751bc65b ntdll!RtlDeregisterWaitEx+0x70
02fafb84 7653c79d KERNELBASE!UnregisterWaitEx+0x1b
02fafb9c 7651e84e crypt32!I_UnregisterWaitEx+0x11
02fafbb0 7651e221 crypt32!RegStoreProvClose+0xde
02fafbf4 7651e0f6 crypt32!CloseStore+0xb1
02fafc10 7651e59b crypt32!CertCloseStore+0x86
02fafc54 7651e0f6 crypt32!CloseStore+0x42b
02fafc70 7651e59b crypt32!CertCloseStore+0x86
02fafcb4 7651e0f6 crypt32!CloseStore+0x42b
02fafcd0 7651e59b crypt32!CertCloseStore+0x86
02fafd14 7651e0f6 crypt32!CloseStore+0x42b
02fafd30 765a15f2 crypt32!CertCloseStore+0x86
02fafd48 765a034b crypt32!CCertChainEngine::~CCertChainEngine+0x153
02fafd5c 765a48ef crypt32!CertFreeCertificateChainEngine+0x2b
02fafd7c 7655b466 crypt32!CDefaultChainEngineMgr::AutoFlushEngineInfoCallback+0xcd
02fafd94 77708c98 crypt32!AutoFlushEngineTimerCallback+0x19fd6
02fafdc0 77706adb ntdll!TppTimerpExecuteCallback+0x98
02faff70 75d86359 ntdll!TppWorkerThread+0x73b
02faff80 77717a94 kernel32!BaseThreadInitThunk+0x19
02faffdc 77717a64 ntdll!__RtlUserThreadStart+0x2f
02faffec 00000000 ntdll!_RtlUserThreadStart+0x1b

0dddfa1fb0ec3fdfc9ffad3dc6c4615a_001.dmp

Top 5: total counts = 1

ChildEBP RetAddr  
WARNING: Stack unwind information not available. Following frames may be wrong.
0a3bf3ec 0c7d637e SogouPY+0x3d55e9
0a3bf498 0c7d8836 SogouPY+0x3d637e
0a3bf4e0 0c7bec0b SogouPY+0x3d8836
0a3bf540 0c79b9df SogouPY+0x3bec0b
0a3bff18 0c79a893 SogouPY+0x39b9df
0a3bff34 0c7668c3 SogouPY+0x39a893
0a3bff70 7733fcc9 SogouPY+0x3668c3
0a3bff80 77b482ae kernel32!BaseThreadInitThunk+0x19
0a3bffdc 77b4827e ntdll!__RtlUserThreadStart+0x2f
0a3bffec 00000000 ntdll!_RtlUserThreadStart+0x1b

7a6367433433ddc5ac9859ee981c1a76_000.dmp

Top 6: total counts = 1

07e4f8f4 03f4374a shell32!ShellExecuteW+0x77
07e4ff48 03f0f5b9 SogouPy+0x6374a
07e4ff88 7626ef8c SogouPy+0x2f5b9
07e4ff94 76dd367a kernel32!BaseThreadInitThunk+0xe
07e4ffd4 76dd364d ntdll!__RtlUserThreadStart+0x70
07e4ffec 00000000 ntdll!_RtlUserThreadStart+0x1b

fc2bc9323528028639c354ecfcadb1e1_001.dmp

Top 7: total counts = 1

079def58 10049144 msvcrt!malloc+0x8d
WARNING: Stack unwind information not available. Following frames may be wrong.
079df20c 75f33d70 1_SangforTcp+0x49144
079df270 75f3e5a4 ws2_32!WSASocketW+0xe6
079df50c 761b6ff3 ws2_32!WSASocketA+0x5b
079df550 761b6f8e wininet!CWxSocket::Initialize+0x3a
079df590 761b6bea wininet!CWxSocket::CreateInstance+0x6e
079df5e8 761b5bf6 wininet!ICSocket::InitializeSocket+0xa5
079df6c8 761b5852 wininet!ICSocket::Connect_Start+0x1fd
079df6e0 7620e9d1 wininet!CFsm_SocketConnect::RunSM+0x2a
079df734 7620eda9 wininet!CFsm::Run+0x161
079df75c 761b597e wininet!DoFsm+0x5e
079df770 7623264d wininet!ICSocket::Connect+0x5e
079df910 7620f3b1 wininet!HTTP_REQUEST_HANDLE_OBJECT::OpenConnection_Fsm+0xd0e
079df928 7620e9d1 wininet!CFsm_OpenConnection::RunSM+0x29
079df97c 7620eda9 wininet!CFsm::Run+0x161
079df9a4 7620faf6 wininet!DoFsm+0x5e
079df9b8 7620f9db wininet!HTTP_REQUEST_HANDLE_OBJECT::OpenConnection+0x7d
079df9dc 7620f952 wininet!HTTP_REQUEST_HANDLE_OBJECT::MakeConnection_Fsm+0x68
079df9f4 7620e9d1 wininet!CFsm_MakeConnection::RunSM+0x2a
079dfa48 7620eda9 wininet!CFsm::Run+0x161
079dfa70 7620f609 wininet!DoFsm+0x5e
079dfbc4 7620f4b1 wininet!HTTP_REQUEST_HANDLE_OBJECT::SendRequest_Fsm+0x13b
079dfbdc 7620e9d1 wininet!CFsm_SendRequest::RunSM+0x29
079dfc30 7620eda9 wininet!CFsm::Run+0x161
079dfc58 7620f462 wininet!DoFsm+0x5e
079dfc9c 7620ec08 wininet!HTTP_REQUEST_HANDLE_OBJECT::HttpSendRequest_Start+0x8da
079dfcb4 7620e9d1 wininet!CFsm_HttpSendRequest::RunSM+0x77
079dfd08 76216c28 wininet!CFsm::Run+0x161
079dfde4 76216ff1 wininet!CFsm::RunWorkItem+0x234
079dfe18 77497cfa wininet!FailFastThreadPoolCallback<&CFsm::RunWorkItemWrapper>+0x21
079dfe38 774809b1 ntdll!TppSimplepExecuteCallback+0x102
079dff88 76e0344d ntdll!TppWorkerThread+0x562
079dff94 77469802 kernel32!BaseThreadInitThunk+0xe
079dffd4 774697d5 ntdll!__RtlUserThreadStart+0x70
079dffec 00000000 ntdll!_RtlUserThreadStart+0x1b

5cabfe4f06240fdf4b8c2518f959580e_000.dmp

Top 8: total counts = 1

ChildEBP RetAddr  
0d29fad8 77ba7d23 ntdll!TppRaiseInvalidParameter+0x37
0d29faf0 77ba7bd5 ntdll!TppCancelWait+0xbb
0d29fb10 77b980d0 ntdll!TpSetWaitEx+0x55
0d29fb60 7685fc1b ntdll!RtlDeregisterWaitEx+0x70
0d29fb70 773b37bc KERNELBASE!UnregisterWaitEx+0x1b
0d29fb88 773affca crypt32!I_UnregisterWaitEx+0x11
0d29fb94 773add24 crypt32!FreeRegistryStoreChange+0x28
0d29fba0 773a406b crypt32!RegStoreProvClose+0x14
0d29fbe4 773a3cde crypt32!CloseStore+0x30b
0d29fc04 773a400e crypt32!CertCloseStore+0x7e
0d29fc48 773a3cde crypt32!CloseStore+0x2ae
0d29fc68 773a400e crypt32!CertCloseStore+0x7e
0d29fcac 773a3cde crypt32!CloseStore+0x2ae
0d29fccc 773a400e crypt32!CertCloseStore+0x7e
0d29fd10 773a3cde crypt32!CloseStore+0x2ae
0d29fd30 773928cb crypt32!CertCloseStore+0x7e
0d29fd48 7739277b crypt32!CCertChainEngine::~CCertChainEngine+0x136
0d29fd5c 7742b256 crypt32!CertFreeCertificateChainEngine+0x2b
0d29fd7c 773de16b crypt32!CDefaultChainEngineMgr::AutoFlushEngineInfoCallback+0xcd
0d29fd94 77ba57fa crypt32!AutoFlushEngineTimerCallback+0x1b1db
0d29fdbc 77ba5fde ntdll!TppTimerpExecuteCallback+0x8a
0d29ff70 775800c9 ntdll!TppWorkerThread+0x66e
0d29ff80 77bd7b4e kernel32!BaseThreadInitThunk+0x19
0d29ffdc 77bd7b1e ntdll!__RtlUserThreadStart+0x2f
0d29ffec 00000000 ntdll!_RtlUserThreadStart+0x1b

cd983e1053179b8a4356793de9ddc138_000.dmp

Top 9: total counts = 1

0018f1b8 00412ee6 ntdll!RtlFreeHeap+0x105
WARNING: Stack unwind information not available. Following frames may be wrong.
0018f1dc 5e6b36a0 dolphinsrv+0x12ee6
0018f2dc 75f777c4 LockScreen!__from_strstr_to_strchr+0x3902
0018f32c 75fda6b5 user32!DispatchMessageWorker+0x3b5
0018fe94 00408a69 user32!wcscpy_s+0xa
0018ff3c 0054502c dolphinsrv+0x8a69
0018ff88 7635343d dolphinsrv+0x14502c
0018ffc4 77234dcc kernel32!BaseThreadInitThunk+0xe
0018ffd4 771f9805 ntdll!SQM_SETIFMIN_DWORD+0x4
0018ffec 00000000 ntdll!_RtlUserThreadStart+0x1b

11d3e53fee46000ebccbd6fa6a6ec088_000.dmp

Top 10: total counts = 1

036ffa94 559f285f urlmon!URLDownloadToCacheFileW+0x84
036ffef0 559f2574 LockScreen!CLdsStatisticImpl::InternalDownloadFile+0x8f
036fff4c 55a2c872 LockScreen!CLdsStatisticImpl::DownloadThreadProc+0x124
036fff88 7659343d LockScreen!thread_start+0x57
036fff94 77739802 kernel32!BaseThreadInitThunk+0xe
036fffd4 777397d5 ntdll!__RtlUserThreadStart+0x70
036fffec 00000000 ntdll!_RtlUserThreadStart+0x1b

923988827079f73f28f1cd3e9b64811d_001.dmp

Top 11: total counts = 1

ChildEBP RetAddr  
0ae4faec 635d368c KERNELBASE!RaiseException+0x62
WARNING: Stack unwind information not available. Following frames may be wrong.
0ae4fb00 00000000 NetULEx+0x1368c

2b9e2f19532cc9e213152bb9ebdb0a9c_000.dmp

Top 12: total counts = 1

ChildEBP RetAddr  
WARNING: Stack unwind information not available. Following frames may be wrong.
0549fec8 55793e19 NetULEx+0x13e19
0549ff74 771a7ba9 NetULEx+0x13e19
0549ff84 77bec36b kernel32!BaseThreadInitThunk+0x19
0549ffdc 77bec2ef ntdll!__RtlUserThreadStart+0x2b
0549ffec 00000000 ntdll!_RtlUserThreadStart+0x1b

26279c2119307ec10a7456b192b2efa8_000.dmp

Top 13: total counts = 1

ChildEBP RetAddr  
0490fb70 775d0d43 KERNELBASE!RaiseException+0x62
0490fb78 775d0c36 ntdll!RtlpFreeHeap+0x15e3
0490fcb0 77610a5d ntdll!RtlpFreeHeap+0x14d6
0490fd0c 02d03958 ntdll!RtlpFreeHeapInternal+0x796
WARNING: Frame IP not in any known module. Following frames may be wrong.
0490fd54 775cf6e6 0x2d03958
0490fd60 00000000 ntdll!RtlFreeHeap+0x46

45941586304117d5adba326c758e2731_000.dmp

Top 14: total counts = 1

ChildEBP RetAddr  
0019ed70 61b4455e LockScreen!FullScreenAdWnd::DoClose+0x42
0019ed94 0048c8d8 LockScreen!CLockScreenImpl::Uninit+0x9e
0019eda4 004a2919 dolphinsrv!CLockScreenWrap::Uninit+0x38
0019edec 00412df6 dolphinsrv!CMainFrame::OnDestroy+0x99
0019ee10 00417337 dolphinsrv!CMainFrame::ProcessWindowMessage+0x136
0019ee6c 6fa118d6 dolphinsrv!ATL::CWindowImplBaseT >::WindowProc+0x67
0019ee8c 76b0157b atlthunk!AtlThunk_0x02+0x36
0019eeb8 76af7c5a user32!_InternalCallWinProc+0x2b
0019efa0 76af7870 user32!UserCallWinProcCheckWow+0x33a
0019f004 76afbd3f user32!DispatchClientMessage+0x190
0019f040 771556cd user32!__fnDWORD+0x3f
0019f078 770b19ac ntdll!KiUserCallbackDispatcher+0x4d
0019f07c 0040f6a4 win32u!NtUserDestroyWindow+0xc
0019f08c 004a55ed dolphinsrv!ATL::CWindowImplBaseT >::DestroyWindow+0x14
0019f104 00413786 dolphinsrv!CMainFrame::OnExit+0x27d
0019f128 00417337 dolphinsrv!CMainFrame::ProcessWindowMessage+0xac6
0019f184 6fa118d6 dolphinsrv!ATL::CWindowImplBaseT >::WindowProc+0x67
0019f1a4 76b0157b atlthunk!AtlThunk_0x02+0x36
0019f1d0 76af7c5a user32!_InternalCallWinProc+0x2b
0019f2b8 76af6500 user32!UserCallWinProcCheckWow+0x33a
0019f334 76af6030 user32!DispatchMessageWorker+0x4c0
0019f340 00415b61 user32!DispatchMessageW+0x10
0019f364 00408ffa dolphinsrv!WTL::CMessageLoop::Run+0xc1
0019fe7c 00408a2e dolphinsrv!Run+0xaa
0019ff24 005422dc dolphinsrv!wWinMain+0x47e
0019ff70 7632fcc9 dolphinsrv!__scrt_common_main_seh+0xf8
0019ff80 771482ae kernel32!BaseThreadInitThunk+0x19
0019ffdc 7714827e ntdll!__RtlUserThreadStart+0x2f
0019ffec 00000000 ntdll!_RtlUserThreadStart+0x1b

41a01a5e5141ef954568244e884b122f_000.dmp

Top 15: total counts = 1

ChildEBP RetAddr  
09aafb3c 772e6572 ntdll!TppRaiseInvalidParameter+0x37
09aafb54 772fd4b3 ntdll!TppCancelWait+0xc4
09aafb78 7566ad85 ntdll!TpWaitForWait+0x53
09aafba0 7566a7e9 crypt32!RegStoreProvClose+0x35
09aafbe8 7566a6a6 crypt32!CloseStore+0xb9
09aafc04 7566ab6d crypt32!CertCloseStore+0x86
09aafc4c 7566a6a6 crypt32!CloseStore+0x43d
09aafc68 7566ab6d crypt32!CertCloseStore+0x86
09aafcb0 7566a6a6 crypt32!CloseStore+0x43d
09aafccc 7566ab6d crypt32!CertCloseStore+0x86
09aafd14 7566a6a6 crypt32!CloseStore+0x43d
09aafd30 756e9880 crypt32!CertCloseStore+0x86
09aafd48 756e82eb crypt32!CCertChainEngine::~CCertChainEngine+0x14f
09aafd5c 756ed7f0 crypt32!CertFreeCertificateChainEngine+0x2b
09aafd7c 7569e6cd crypt32!CDefaultChainEngineMgr::AutoFlushEngineInfoCallback+0xcd
09aafd94 772e517a crypt32!AutoFlushEngineTimerCallback+0x1ba8d
09aafdbc 772f643d ntdll!TppTimerpExecuteCallback+0x8a
09aaff74 75335d49 ntdll!TppWorkerThread+0x74d
09aaff84 7730d03b kernel32!BaseThreadInitThunk+0x19
09aaffdc 7730cfc1 ntdll!__RtlUserThreadStart+0x2b
09aaffec 00000000 ntdll!_RtlUserThreadStart+0x1b

cab7f1fb0ee6b118bb6b353c8e18c206_000.dmp