$ strace ssh -p 40022 ld4rapidappd306.uk.db.com --- Process 12012 created --- Process 12012 loaded C:\Windows\System32\ntdll.dll at 00000000773d0000 --- Process 12012 loaded C:\Windows\System32\kernel32.dll at 00000000771b0000 --- Process 12012 loaded C:\Windows\System32\KernelBase.dll at 000007fefd040000 --- Process 12012 loaded C:\Windows\System32\sysfer.dll at 0000000074b60000 --- Process 12012 loaded C:\Windows\System32\advapi32.dll at 000007fefe010000 --- Process 12012 loaded C:\Windows\System32\msvcrt.dll at 000007fefe550000 --- Process 12012 loaded C:\Windows\System32\sechost.dll at 000007fefdae0000 --- Process 12012 loaded C:\Windows\System32\rpcrt4.dll at 000007fefdb00000 --- Process 12012 loaded C:\Users\goryvad\work\programs\cygwin64\bin\cygcrypto-1.1.dll at 0000000408c60000 --- Process 12012 loaded C:\Users\goryvad\work\programs\cygwin64\bin\cygwin1.dll at 0000000180040000 --- Process 12012 loaded C:\Users\goryvad\work\programs\cygwin64\bin\cygz.dll at 00000003fa1d0000 --- Process 12012 loaded C:\Users\goryvad\work\programs\cygwin64\bin\cyggssapi_krb5-2.dll at 000000048b7e0000 --- Process 12012 loaded C:\Users\goryvad\work\programs\cygwin64\bin\cygk5crypto-3.dll at 000000048adc0000 --- Process 12012 loaded C:\Users\goryvad\work\programs\cygwin64\bin\cygkrb5support-0.dll at 000000048acd0000 --- Process 12012 loaded C:\Users\goryvad\work\programs\cygwin64\bin\cygintl-8.dll at 00000003ff320000 --- Process 12012 loaded C:\Users\goryvad\work\programs\cygwin64\bin\cygiconv-2.dll at 00000003ff370000 --- Process 12012 loaded C:\Users\goryvad\work\programs\cygwin64\bin\cygkrb5-3.dll at 000000048acf0000 --- Process 12012 loaded C:\Users\goryvad\work\programs\cygwin64\bin\cygcom_err-2.dll at 00000003fab10000 --- Process 12012 loaded C:\Users\goryvad\work\programs\cygwin64\bin\cyggcc_s-seh-1.dll at 00000003fa2f0000 1 1 [main] ssh (12012) ********************************************** 164 165 [main] ssh (12012) Program name: W:\programs\cygwin64\bin\ssh.exe (windows pid 12012) 71 236 [main] ssh (12012) OS version: Windows NT-6.1 59 295 [main] ssh (12012) ********************************************** --- Process 12012 loaded C:\Windows\System32\cryptbase.dll at 000007fefc4c0000 2556 2851 [main] ssh (12012) sigprocmask: 0 = sigprocmask (0, 0x0, 0x18030AD30) 816 3667 [main] ssh (12012) open_shared: name shared.5, n 5, shared 0x180030000 (wanted 0x180030000), h 0xAC, *m 6 95 3762 [main] ssh (12012) user_heap_info::init: heap base 0x600000000, heap top 0x600000000, heap size 0x20000000 (536870912) 104 3866 [main] ssh (12012) open_shared: name S-1-5-21-1606980848-1965331169-1417001333-1876650.1, n 1, shared 0x180020000 (wanted 0x180020000), h 0xA8, *m 6 74 3940 [main] ssh (12012) user_info::create: opening user shared for 'S-1-5-21-1606980848-1965331169-1417001333-1876650' at 0x180020000 79 4019 [main] ssh (12012) user_info::create: user shared version AB1FCCE8 111 4130 [main] ssh (12012) fhandler_pipe::create: name \\.\pipe\cygwin-50c2c237f7a4b788-12012-sigwait, size 11440, mode PIPE_TYPE_MESSAGE 124 4254 [main] ssh (12012) fhandler_pipe::create: pipe read handle 0xC0 63 4317 [main] ssh (12012) fhandler_pipe::create: CreateFile: name \\.\pipe\cygwin-50c2c237f7a4b788-12012-sigwait 129 4446 [main] ssh (12012) fhandler_pipe::create: pipe write handle 0xC4 86 4532 [main] ssh (12012) dll_crt0_0: finished dll_crt0_0 initialization --- Process 12012 loaded C:\PROGRA~1\Citrix\System32\MfApHook64.dll at 000007fefce30000 --- Process 12012 loaded C:\Windows\System32\user32.dll at 00000000772d0000 --- Process 12012 loaded C:\Windows\System32\gdi32.dll at 000007fefdc30000 --- Process 12012 loaded C:\Windows\System32\lpk.dll at 000007fefd910000 --- Process 12012 loaded C:\Windows\System32\usp10.dll at 000007fefd790000 --- Process 12012 loaded C:\Windows\System32\imm32.dll at 000007fefd860000 --- Process 12012 loaded C:\Windows\System32\msctf.dll at 000007fefdca0000 --- Process 12012 loaded C:\Windows\System32\lsihok64.dll at 0000000074c00000 --- Process 12012 thread 17256 created --- Process 12012 loaded C:\Windows\System32\VSMAPIMon.dll at 000007fefac60000 --- Process 12012 loaded C:\PROGRA~1\Citrix\System32\MfApHook64.dll at 0000000000350000 --- Process 12012 unloaded DLL at 0000000000350000 --- Process 12012 loaded C:\Program Files\Citrix\ICAService\picaFullScreenHookX64.dll at 000007fefcd20000 --- Process 12012 loaded C:\Program Files\Citrix\ICAService\ShellHook64.dll at 000007fefc430000 --- Process 12012 loaded C:\Windows\System32\shell32.dll at 000007fefe870000 --- Process 12012 loaded C:\Windows\System32\shlwapi.dll at 000007fefd890000 --- Process 12012 loaded C:\Program Files\Citrix\ICAService\SCardHook64.dll at 000007fefcba0000 --- Process 12012 loaded C:\Program Files\Citrix\ICAService\cxinjime64.dll at 000007fefce00000 --- Process 12012 loaded C:\Program Files\Citrix\ICAService\PicaWtsHook64.dll at 000007fefcb50000 --- Process 12012 loaded C:\Program Files\Avecto\Privilege Guard Client\PGHook.dll at 000007fefc980000 --- Process 12012 loaded C:\Windows\System32\api-ms-win-core-synch-l1-2-0.dll at 000007fefc970000 --- Process 12012 loaded C:\Windows\System32\cryptsp.dll at 000007fefc520000 --- Process 12012 loaded C:\Windows\System32\rsaenh.dll at 000007fefc4d0000 --- Process 12012, exception c0000005 at 0000000180139674 --- Process 12012 thread 14108 exited with status 0xc0000005 --- Process 12012 exited with status 0xc0000005 Segmentation fault