nt!RtlpBreakWithStatusInstruction: 80522ba8 cc int 3 kd> kp ChildEBP RetAddr f6fdf4f0 8047e128 nt!RtlpBreakWithStatusInstruction f6fdf520 8047d6f5 nt!KiBugCheckDebugBreak(unsigned long StatusCode = 3)+0x38 [d:\reactos-trunk\reactos\ntoskrnl\ke\bug.c @ 538] f6fdf8c0 8047d0c0 nt!KeBugCheckWithTf(unsigned long BugCheckCode = 0x50, unsigned long BugCheckParameter1 = 0xe1c74719, unsigned long BugCheckParameter2 = 0, unsigned long BugCheckParameter3 = 0xf6fdfafc, unsigned long BugCheckParameter4 = 2, struct _KTRAP_FRAME * TrapFrame = 0xf6fdfafc)+0x595 [d:\reactos-trunk\reactos\ntoskrnl\ke\bug.c @ 1102] f6fdf8e0 804a02c8 nt!KeBugCheckEx(unsigned long BugCheckCode = 0x50, unsigned long BugCheckParameter1 = 0xe1c74719, unsigned long BugCheckParameter2 = 0, unsigned long BugCheckParameter3 = 0xf6fdfafc, unsigned long BugCheckParameter4 = 2)+0x20 [d:\reactos-trunk\reactos\ntoskrnl\ke\bug.c @ 1462] f6fdfa60 804c3b6d nt!MmArmAccessFault(unsigned char StoreInstruction = 0x00 '', void * Address = 0xe1c74719, char Mode = 0n0 '', void * TrapInformation = 0xf6fdfafc)+0x2e8 [d:\reactos-trunk\reactos\ntoskrnl\mm\arm3\pagfault.c @ 1769] f6fdfa84 8050678a nt!MmAccessFault(unsigned char StoreInstruction = 0x00 '', void * Address = 0xe1c74719, char Mode = 0n0 '', void * TrapInformation = 0xf6fdfafc)+0xdd [d:\reactos-trunk\reactos\ntoskrnl\mm\mmfault.c @ 251] f6fdfaf4 804036ff nt!KiTrap0EHandler(struct _KTRAP_FRAME * TrapFrame = 0xf6fdfafc)+0x30a [d:\reactos-trunk\reactos\ntoskrnl\ke\i386\traphdlr.c @ 1345] f6fdfaf4 f7643195 nt!KiTrap0E+0x8f f6fdfb74 f763364d win32k!RtlStringCopyWorkerW(unsigned short * pszDest = 0xe1a898f8, unsigned int cchDest = 0x40, wchar_t * pszSrc = 0xe1c74719 "--- memory read error at address 0xe1c74719 ---")+0x25 [d:\reactos-trunk\reactos\sdk\include\ddk\ntstrsafe.h @ 1607] f6fdfb8c f76a1d92 win32k!RtlStringCbCopyW(unsigned short * pszDest = 0xe1a898f8, unsigned int cbDest = 0x80, wchar_t * pszSrc = 0xe1c74719 "--- memory read error at address 0xe1c74719 ---")+0x3d [d:\reactos-trunk\reactos\sdk\include\ddk\ntstrsafe.h @ 192] f6fdfc34 f76a2240 win32k!FontFamilyFillInfo(struct tagFONTFAMILYINFO * Info = 0xe1a8989c, wchar_t * FaceName = 0xe1a695f8 "ADMUI3Lg", wchar_t * FullName = 0xe1c74719 "--- memory read error at address 0xe1c74719 ---", struct _FONTGDI * FontGDI = 0xe17e8778)+0x302 [d:\reactos-trunk\reactos\win32ss\gdi\ntgdi\freetype.c @ 2341] f6fdfc78 f76aa8b9 win32k!GetFontFamilyInfoForList(struct tagLOGFONTW * LogFont = 0xf6fdfc8c, struct tagFONTFAMILYINFO * Info = 0xe1a87000, unsigned long * Count = 0xf6fdfcf4, unsigned long Size = 0x40, struct _LIST_ENTRY * Head = 0xf7777bdc [ 0xe166d210 - 0xe1a0ff90 ])+0x110 [d:\reactos-trunk\reactos\win32ss\gdi\ntgdi\freetype.c @ 2499] f6fdfcfc 805075db win32k!NtGdiGetFontFamilyInfo(struct HDC__ * Dc = 0x1901010c, struct tagLOGFONTW * UnsafeLogFont = 0x0012e10c, struct tagFONTFAMILYINFO * UnsafeInfo = 0x03a6d008, unsigned long Size = 0x40)+0x89 [d:\reactos-trunk\reactos\win32ss\gdi\ntgdi\freetype.c @ 5065] f6fdfd1c 8050580f nt!KiSystemCallTrampoline(void * Handler = 0xf76aa830, void * Arguments = 0x0012df34, unsigned long StackBytes = 0x10)+0x1b [d:\reactos-trunk\reactos\ntoskrnl\include\internal\i386\ke.h @ 748] f6fdfd5c 80403e23 nt!KiSystemServiceHandler(struct _KTRAP_FRAME * TrapFrame = 0xf6fdfd64, void * Arguments = 0x0012df34)+0x22f [d:\reactos-trunk\reactos\ntoskrnl\ke\i386\traphdlr.c @ 1815] f6fdfd5c 7c92c85e nt!KiFastCallEntry+0x8c WARNING: Frame IP not in any known module. Following frames may be wrong. 0012e0d8 7c60ac8a 0x7c92c85e 0012e0ec 05a4e823 0x7c60ac8a 0012e174 05a44fee 0x5a4e823 0012e1ac 05a4507c 0x5a44fee 0012e1cc 05a36822 0x5a4507c 0012e220 05aa4a89 0x5a36822 0012e810 05aa50fa 0x5aa4a89 0012e870 05b10d9e 0x5aa50fa 0012e8a4 00cd4fbf 0x5b10d9e 0012ea10 00cc2af3 0xcd4fbf 0012ea9c 00cd70f0 0xcc2af3 00000000 00000000 0xcd70f0