Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- date/time : 2011-07-06, 23:29:55, 593ms
- computer name : FEDIA22-162B7A5
- user name : Fedia22 <admin>
- registered owner : Fedia22
- operating system : Windows XP Service Pack 3 build 2600
- system language : Russian
- system up time : 8 hours 46 minutes
- program up time : 1 minute 4 seconds
- processor : AMD Sempron(tm) Processor 3000+
- physical memory : 651/1534 MB (free/total)
- free disk space : (C:) 2,73 GB
- display mode : 1280x1024, 32 bit
- process id : $d3c
- allocated memory : 32,75 MB
- executable : qip.exe
- exec. date/time : 2011-06-24 15:17
- version : 3.0.0.5768
- compiled with : Delphi 7
- madExcept version : 3.0k
- contact name : Fedia22
- contact email : Fedia22@fedia22.ru
- callstack crc : $00000000, $132085cf, $b927acdd
- exception number : 1
- exception class : EAccessViolation
- exception message : Access violation at address 00000000. Read of address 00000000.
- thread $13ec:
- 00000000 +000 ???
- 0069e906 +152 qip.exe OverbyteIcsHttpProt 2043 +38 THttpCli.Abort
- 006fd2d9 +031 qip.exe u_bb_ImagesDM 1178 +3 THttpDM.AbortThread
- 006fcec5 +019 qip.exe u_bb_ImagesDM 1060 +2 TCustomDM.Abort
- 006fe9e7 +11f qip.exe u_bb_Images 827 +42 TThinGraphic.SetStatus
- 006ff35a +01a qip.exe u_bb_Images 1053 +4 TThinGraphic.ReleaseDM
- 006fe2a1 +049 qip.exe u_bb_Images 569 +12 TThinGraphic.Destroy
- 006fe1c4 +034 qip.exe u_bb_Images 539 +7 TThinGraphic._Release
- 00705597 +027 qip.exe RVItem 2961 +5 TRVGraphicItemInfo.FreeAndNilImage
- 0070553c +010 qip.exe RVItem 2945 +1 TRVGraphicItemInfo.Destroy
- 0090ff79 +061 qip.exe u_bb_rvControls 318 +19 TRVGraphicItemInfoBB.Destroy
- 00403cec +008 qip.exe System 8393 +1 TObject.Free
- 006515da +046 qip.exe CRVData 1843 +12 TCustomRVData.InternalFreeItem
- 0064b01f +00b qip.exe CRVFData 6792 +5 TCustomRVFormattedData.InternalFreeItem
- 00651653 +06f qip.exe CRVData 1854 +5 TCustomRVData.FreeItem
- 00651702 +086 qip.exe CRVData 1871 +11 TCustomRVData.Clear
- 0063db2a +052 qip.exe CRVFData 860 +7 TCustomRVFormattedData.Clear
- 0065038a +012 qip.exe CRVData 1080 +1 TCustomRVData.Destroy
- 0063d918 +03c qip.exe CRVFData 799 +7 TCustomRVFormattedData.Destroy
- 00611c14 +030 qip.exe RVTable 2985 +4 TRVTableCellData.Destroy
- 00403cec +008 qip.exe System 8393 +1 TObject.Free
- 005c9529 +019 qip.exe RVClasses 144 +2 TRVList.Clear
- 005c9577 +00f qip.exe RVClasses 164 +1 TRVList.Destroy
- 00613892 +012 qip.exe RVTable 3924 +1 TRVTableRows.Destroy
- 00403cec +008 qip.exe System 8393 +1 TObject.Free
- 00616760 +018 qip.exe RVTable 5442 +2 TRVTableItemInfo.Destroy
- 00403cec +008 qip.exe System 8393 +1 TObject.Free
- 006515da +046 qip.exe CRVData 1843 +12 TCustomRVData.InternalFreeItem
- 0064b01f +00b qip.exe CRVFData 6792 +5 TCustomRVFormattedData.InternalFreeItem
- 00651653 +06f qip.exe CRVData 1854 +5 TCustomRVData.FreeItem
- 00651702 +086 qip.exe CRVData 1871 +11 TCustomRVData.Clear
- 0063db2a +052 qip.exe CRVFData 860 +7 TCustomRVFormattedData.Clear
- 0063ba77 +03b qip.exe RVRVData 1231 +13 TRichViewRVData.Clear
- 0062ba50 +018 qip.exe RichView 1456 +2 TCustomRichView.Clear
- 0062b79b +01f qip.exe RichView 1347 +10 TCustomRichView.Destroy
- 0062f2a2 +026 qip.exe RichView 4301 +5 TCustomRichView2.Destroy
- 00764f7c +01c qip.exe RVSmartScroll 184 +2 TRichView.Destroy
- 004e3c9c +0b0 qip.exe Controls 5429 +16 TWinControl.Destroy
- 004c4010 +028 qip.exe Forms 2076 +3 TScrollingWinControl.Destroy
- 004c4c03 +0ab qip.exe Forms 2640 +10 TCustomForm.Destroy
- 00403cec +008 qip.exe System 8393 +1 TObject.Free
- 004c8868 +000 qip.exe Forms 4568 +0 TCustomForm.CMRelease
- 004e220b +1df qip.exe Controls 4645 +53 TControl.WndProc
- 004e5f1a +18e qip.exe Controls 6342 +33 TWinControl.WndProc
- 004c5b39 +421 qip.exe Forms 3099 +103 TCustomForm.WndProc
- 0052086d +085 qip.exe TntControls 679 +19 TWinControlTrap.WindowProc
- 004e5aec +034 qip.exe Controls 6237 +3 TWinControl.MainWndProc
- 0047b2f4 +014 qip.exe Classes 10966 +8 StdWndProc
- 7e37a034 +016 user32.dll CallWindowProcW
- 005204a0 +048 qip.exe TntControls 564 +12 TWinControlTrap.Win32Proc
- 0047b2f4 +014 qip.exe Classes 10966 +8 StdWndProc
- 7e3696c2 +00a user32.dll DispatchMessageA
- 004cc053 +083 qip.exe Forms 6874 +13 TApplication.ProcessMessage
- 004cc08a +00a qip.exe Forms 6893 +1 TApplication.HandleMessage
- 004cc2aa +096 qip.exe Forms 6977 +16 TApplication.Run
- 0092cdb3 +15f qip.exe qip 208 +60 initialization
- thread $10a0:
- 7c90df48 +a ntdll.dll NtWaitForMultipleObjects
- thread $7d0 (TPainterThread): <suspended>
- 005b2b6e +3e qip.exe ImagingComponents 2219 +5 TPainterThread.Create
- thread $724:
- 7c90df48 +0a ntdll.dll NtWaitForMultipleObjects
- 7c80958a +00 kernel32.dll WaitForMultipleObjectsEx
- 7e3695f3 +00 user32.dll MsgWaitForMultipleObjectsEx
- 7e3696a3 +1a user32.dll MsgWaitForMultipleObjects
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 4ebf7b7f +00 gdiplus.dll
- thread $998 (TPainterThread): <suspended>
- 03b847bb MRA.dll
- thread $17c: <priority:1>
- 7c90da48 +0a ntdll.dll NtRemoveIoCompletion
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by thread $34c at:
- 71a3d926 +00 mswsock.dll
- thread $f50 (TShowIconThread): <suspended>
- 7c90de48 +0a ntdll.dll NtSuspendThread
- 7c83973e +0c kernel32.dll SuspendThread
- 004799f1 +31 qip.exe Classes 9648 +5 TThread.Suspend
- 0074acb2 +d2 qip.exe u_trayicon 114 +25 TShowIconThread.Execute
- 004794fa +36 qip.exe Classes 9372 +7 ThreadProc
- 00404bb8 +28 qip.exe System 11562 +33 ThreadWrapper
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 0074ad64 +70 qip.exe u_trayicon 140 +11 TTrayIcon.Create
- thread $f7c:
- 7c90df58 +0a ntdll.dll NtWaitForSingleObject
- 7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
- 7c80253d +0d kernel32.dll WaitForSingleObject
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 71a9d374 +00 WS2_32.dll
- thread $103c: <priority:2>
- 7c90df48 +0a ntdll.dll NtWaitForMultipleObjects
- 7c80958a +00 kernel32.dll WaitForMultipleObjectsEx
- 7c80a110 +13 kernel32.dll WaitForMultipleObjects
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 04ab4593 +00 voip.dll
- thread $78c:
- 7c90df48 +0a ntdll.dll NtWaitForMultipleObjects
- 7c80958a +00 kernel32.dll WaitForMultipleObjectsEx
- 7c80a110 +13 kernel32.dll WaitForMultipleObjects
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 04ab4593 +00 voip.dll
- thread $17f8: <priority:15>
- 7c90df48 +0a ntdll.dll NtWaitForMultipleObjects
- 7c80958a +00 kernel32.dll WaitForMultipleObjectsEx
- 7c80a110 +13 kernel32.dll WaitForMultipleObjects
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 72ce328c +00 wdmaud.drv
- thread $4b4:
- 7c90daa8 +0a ntdll.dll NtReplyWaitReceivePortEx
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 77e7df2e +00 RPCRT4.dll
- thread $f58:
- 7c90d218 +0a ntdll.dll NtDelayExecution
- 7c8023eb +4b kernel32.dll SleepEx
- 7c802450 +0a kernel32.dll Sleep
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 7751fd64 +00 ole32.dll
- thread $1404:
- 7c90daa8 +0a ntdll.dll NtReplyWaitReceivePortEx
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by thread $4b4 at:
- 77e7df2e +00 RPCRT4.dll
- thread $7ac: <priority:-1>
- 7c90df48 +0a ntdll.dll NtWaitForMultipleObjects
- 7c80958a +00 kernel32.dll WaitForMultipleObjectsEx
- 7c80a110 +13 kernel32.dll WaitForMultipleObjects
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 04ab4593 +00 voip.dll
- thread $136c:
- 7c90df48 +0a ntdll.dll NtWaitForMultipleObjects
- 7c80958a +00 kernel32.dll WaitForMultipleObjectsEx
- 7e3695f3 +00 user32.dll MsgWaitForMultipleObjectsEx
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 04ab4593 +00 voip.dll
- thread $145c:
- 7e3691ec +26 user32.dll GetMessageW
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 04ab28a5 +00 voip.dll
- thread $43c:
- 7c90da48 +0a ntdll.dll NtRemoveIoCompletion
- 7c80a7e0 +23 kernel32.dll GetQueuedCompletionStatus
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 03fc5015 +00 SIP.dll
- thread $de8:
- 7c90da48 +0a ntdll.dll NtRemoveIoCompletion
- 7c80a7e0 +23 kernel32.dll GetQueuedCompletionStatus
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 03fc5015 +00 SIP.dll
- thread $a20 (TShowIconThread): <suspended>
- 03b847bb MRA.dll
- thread $17b8 (TWorkerThread):
- 7e37f406 +44 user32.dll SendMessageA
- 0054471a +3a qip.exe VirtualTrees 5197 +2 TWorkerThread.ChangeTreeStates
- 005447e7 +c3 qip.exe VirtualTrees 5238 +28 TWorkerThread.Execute
- 004513af +2b qip.exe madExcept HookedTThreadExecute
- 004794fa +36 qip.exe Classes 9372 +7 ThreadProc
- 00404bb8 +28 qip.exe System 11562 +33 ThreadWrapper
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 00544682 +16 qip.exe VirtualTrees 5176 +1 TWorkerThread.Create
- thread $7e4:
- 7c90d218 +0a ntdll.dll NtDelayExecution
- 7c8023eb +4b kernel32.dll SleepEx
- 7c802450 +0a kernel32.dll Sleep
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 03a37984 +00 Jabber.dll
- thread $ae8:
- 7c90d218 +0a ntdll.dll NtDelayExecution
- 7c8023eb +4b kernel32.dll SleepEx
- 7c802450 +0a kernel32.dll Sleep
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 03a37984 +00 Jabber.dll
- thread $e28:
- 7c90d218 +0a ntdll.dll NtDelayExecution
- 7c8023eb +4b kernel32.dll SleepEx
- 7c802450 +0a kernel32.dll Sleep
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 03a37984 +00 Jabber.dll
- thread $4fc:
- 7c90d218 +0a ntdll.dll NtDelayExecution
- 7c8023eb +4b kernel32.dll SleepEx
- 7c802450 +0a kernel32.dll Sleep
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 03a37984 +00 Jabber.dll
- thread $1144:
- 7c90df58 +0a ntdll.dll NtWaitForSingleObject
- 71a94d13 +5e WS2_32.dll WSARecv
- 71ab2e9e +2e wsock32.dll recv
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by main thread ($13ec) at:
- 03a37b7d +00 Jabber.dll
- thread $12dc:
- 7c90d218 +a ntdll.dll NtDelayExecution
- thread $1448:
- 7c90da48 +a ntdll.dll NtRemoveIoCompletion
- thread $13cc:
- 7c90df48 +0a ntdll.dll NtWaitForMultipleObjects
- 7c80958a +00 kernel32.dll WaitForMultipleObjectsEx
- 7c80a110 +13 kernel32.dll WaitForMultipleObjects
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by thread $1144 at:
- 03a37b7d +00 Jabber.dll
- thread $e9c:
- 7c90df48 +a ntdll.dll NtWaitForMultipleObjects
- thread $cc8:
- 7c90df48 +00a ntdll.dll NtWaitForMultipleObjects
- 7c80958a +000 kernel32.dll WaitForMultipleObjectsEx
- 7c80a110 +013 kernel32.dll WaitForMultipleObjects
- 00451291 +00d qip.exe madExcept CallThreadProcSafe
- 004512fb +037 qip.exe madExcept ThreadExceptFrame
- >> created by thread $b80 at:
- 769a887a +273 USERENV.dll RegisterGPNotification
- thread $adc:
- 7c90d218 +0a ntdll.dll NtDelayExecution
- 7c8023eb +4b kernel32.dll SleepEx
- 7c802450 +0a kernel32.dll Sleep
- 00451291 +0d qip.exe madExcept CallThreadProcSafe
- 004512fb +37 qip.exe madExcept ThreadExceptFrame
- >> created by thread $b80 at:
- 4d56cadd +00 WINHTTP.dll
- thread $ff4:
- >> stack not accessible
- thread $10c4:
- >> stack not accessible
- modules:
- 00340000 Normaliz.dll 6.0.5441.0 C:\WINDOWS\system32
- 00400000 qip.exe 3.0.0.5768 C:\Program Files\QIP 2010
- 02990000 WebWindow.dll C:\Program Files\QIP 2010\Core
- 036f0000 InfICQ.dll C:\Program Files\QIP 2010\Protos\InfICQ
- 03a30000 Jabber.dll 0.1.1.15 C:\Program Files\QIP 2010\Protos\Jabber
- 03b60000 MRA.dll 1.0.0.4 C:\Program Files\QIP 2010\Protos\MRA
- 03fa0000 pics.dll C:\Program Files\QIP 2010\Protos\MRA
- 03fb0000 SIP.dll 0.1.0.1 C:\Program Files\QIP 2010\Protos\SIP
- 040b0000 Social.dll C:\Program Files\QIP 2010\Protos\Social
- 042f0000 XIMSS.dll 0.1.4.4 C:\Program Files\QIP 2010\Protos\XIMSS
- 04540000 pcaplsp.dll 3.2.4.0 C:\WINDOWS\system32
- 04a70000 voip.dll C:\Program Files\QIP 2010\Core
- 05590000 xpsp2res.dll 5.1.2600.5512 C:\WINDOWS\system32
- 10000000 vksaver3.dll 3.0.0.2 C:\DOCUME~1\ALLUSE~1\APPLIC~1\VKSaver
- 12220000 OPENLIBEAY32.dll 0.9.8.11 C:\Program Files\QIP 2010\Core
- 12440000 OPENSSLEAY32.DLL 0.9.8.11 C:\Program Files\QIP 2010\Core
- 16080000 mdnsNSP.dll 1.0.3.1 C:\Program Files\Bonjour
- 1a400000 urlmon.dll 8.0.6001.18702 C:\WINDOWS\system32
- 4d550000 WINHTTP.dll 5.1.2600.5868 C:\WINDOWS\system32
- 4ebe0000 gdiplus.dll 5.2.6001.22319 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df
- 58be0000 icm32.dll 5.1.2600.5512 C:\WINDOWS\system32
- 58f10000 wship6.dll 5.1.2600.5512 C:\WINDOWS\System32
- 5b260000 uxtheme.dll 6.0.2900.5512 C:\WINDOWS\system32
- 5bd50000 NETAPI32.dll 5.1.2600.5694 C:\WINDOWS\system32
- 5dca0000 iertutil.dll 8.0.6001.18702 C:\WINDOWS\system32
- 5f2f0000 olepro32.dll 5.1.2600.5512 C:\WINDOWS\system32
- 61880000 oleacc.dll 7.0.2600.5884 C:\WINDOWS\system32
- 63000000 wininet.dll 8.0.6001.18702 C:\WINDOWS\system32
- 68000000 rsaenh.dll 5.1.2600.5507 C:\WINDOWS\system32
- 68100000 dssenh.dll 5.1.2600.5507 C:\WINDOWS\system32
- 698b0000 hnetcfg.dll 5.1.2600.5512 C:\WINDOWS\system32
- 71a30000 mswsock.dll 5.1.2600.5625 C:\WINDOWS\System32
- 71a70000 wshtcpip.dll 5.1.2600.5512 C:\WINDOWS\System32
- 71a80000 WS2HELP.dll 5.1.2600.5512 C:\WINDOWS\system32
- 71a90000 WS2_32.dll 5.1.2600.5512 C:\WINDOWS\system32
- 71ab0000 wsock32.dll 5.1.2600.5512 C:\WINDOWS\system32
- 71f60000 security.dll 5.1.2600.5512 C:\WINDOWS\system32
- 72290000 sensapi.dll 5.1.2600.5512 C:\WINDOWS\system32
- 72cd0000 msacm32.drv 5.1.2600.0 C:\WINDOWS\system32
- 72ce0000 wdmaud.drv 5.1.2600.5512 C:\WINDOWS\system32
- 72fc0000 winspool.drv 5.1.2600.5512 C:\WINDOWS\system32
- 73670000 msdmo.dll 6.5.2600.5512 C:\WINDOWS\system32
- 73720000 DDRAW.dll 5.3.2600.5512 C:\WINDOWS\system32
- 73af0000 mscms.dll 5.1.2600.5627 C:\WINDOWS\system32
- 73b40000 avicap32.dll 5.1.2600.0 C:\WINDOWS\system32
- 73b80000 DCIMAN32.dll 5.1.2600.5512 C:\WINDOWS\system32
- 73ed0000 dsound.dll 5.3.2600.5512 C:\WINDOWS\system32
- 746e0000 MSCTF.dll 5.1.2600.5512 C:\WINDOWS\system32
- 75310000 msctfime.ime 5.1.2600.5768 C:\WINDOWS\system32
- 75a40000 MSVFW32.dll 5.1.2600.5512 C:\WINDOWS\system32
- 76350000 msimg32.dll 5.1.2600.5512 C:\WINDOWS\system32
- 76360000 imm32.dll 5.1.2600.5512 C:\WINDOWS\system32
- 76380000 comdlg32.dll 6.0.2900.5512 C:\WINDOWS\system32
- 765b0000 devenum.dll 6.5.2600.5512 C:\WINDOWS\system32
- 76770000 cryptdll.dll 5.1.2600.5512 C:\WINDOWS\system32
- 767d0000 schannel.dll 5.1.2600.5834 C:\WINDOWS\system32
- 769a0000 USERENV.dll 5.1.2600.5512 C:\WINDOWS\system32
- 76b20000 winmm.dll 5.1.2600.5512 C:\WINDOWS\system32
- 76c20000 WINTRUST.dll 5.131.2600.5709 C:\WINDOWS\system32
- 76c80000 IMAGEHLP.dll 5.1.2600.5512 C:\WINDOWS\system32
- 76d50000 iphlpapi.dll 5.1.2600.5512 C:\WINDOWS\system32
- 76e70000 rtutils.dll 5.1.2600.5512 C:\WINDOWS\system32
- 76e80000 rasman.dll 5.1.2600.5512 C:\WINDOWS\system32
- 76ea0000 TAPI32.dll 5.1.2600.5512 C:\WINDOWS\system32
- 76ed0000 RASAPI32.dll 5.1.2600.5512 C:\WINDOWS\system32
- 76f10000 DNSAPI.dll 5.1.2600.5797 C:\WINDOWS\system32
- 76f50000 WLDAP32.dll 5.1.2600.5512 C:\WINDOWS\system32
- 76fa0000 winrnr.dll 5.1.2600.5512 C:\WINDOWS\System32
- 76fb0000 rasadhlp.dll 5.1.2600.5512 C:\WINDOWS\system32
- 76fc0000 CLBCATQ.DLL 2001.12.4414.700 C:\WINDOWS\system32
- 77040000 COMRes.dll 2001.12.4414.700 C:\WINDOWS\system32
- 77110000 oleaut32.dll 5.1.2600.5512 C:\WINDOWS\system32
- 773c0000 comctl32.dll 6.0.2900.5512 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83
- 774d0000 ole32.dll 5.1.2600.5512 C:\WINDOWS\system32
- 77910000 setupapi.dll 5.1.2600.5512 C:\WINDOWS\system32
- 77a70000 CRYPT32.dll 5.131.2600.5709 C:\WINDOWS\system32
- 77b10000 MSASN1.dll 5.1.2600.5875 C:\WINDOWS\system32
- 77bc0000 midimap.dll 5.1.2600.5512 C:\WINDOWS\system32
- 77bd0000 MSACM32.dll 5.1.2600.5512 C:\WINDOWS\system32
- 77bf0000 version.dll 5.1.2600.5512 C:\WINDOWS\system32
- 77c00000 msvcrt.dll 7.0.2600.5512 C:\WINDOWS\system32
- 77c60000 msv1_0.dll 5.1.2600.5876 C:\WINDOWS\system32
- 77dc0000 advapi32.dll 5.1.2600.5755 C:\WINDOWS\system32
- 77e70000 RPCRT4.dll 5.1.2600.5795 C:\WINDOWS\system32
- 77f10000 GDI32.dll 5.1.2600.5698 C:\WINDOWS\system32
- 77f60000 SHLWAPI.dll 6.0.2900.5512 C:\WINDOWS\system32
- 77fe0000 Secur32.dll 5.1.2600.5834 C:\WINDOWS\system32
- 7c800000 kernel32.dll 5.1.2600.5781 C:\WINDOWS\system32
- 7c900000 ntdll.dll 5.1.2600.5755 C:\WINDOWS\system32
- 7c9c0000 shell32.dll 6.0.2900.5853 C:\WINDOWS\system32
- 7e360000 user32.dll 5.1.2600.5512 C:\WINDOWS\system32
- processes:
- 000 Idle 0 0
- 004 System 0 0 normal
- 548 smss.exe 0 0 normal C:\WINDOWS\system32
- 5e8 csrss.exe 0 0
- 618 winlogon.exe 49 15 high C:\WINDOWS\system32
- 644 services.exe 4 2 normal C:\WINDOWS\system32
- 650 lsass.exe 4 2 normal C:\WINDOWS\system32
- 6f8 Ati2evxx.exe 11 6 normal C:\WINDOWS\system32
- 70c svchost.exe 4 1 normal C:\WINDOWS\system32
- 768 svchost.exe 0 0
- 0e4 svchost.exe 11 40 normal C:\WINDOWS\System32
- 150 svchost.exe 0 0
- 27c Ati2evxx.exe 11 6 normal C:\WINDOWS\system32
- 2a8 svchost.exe 0 0
- 380 spoolsv.exe 4 5 normal C:\WINDOWS\system32
- 5dc svchost.exe 0 0
- 690 avp.exe 32 34 normal C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011
- 680 mDNSResponder.exe 4 2 normal C:\Program Files\Bonjour
- 0b0 G6FTPSERVER.EXE 5 7 normal C:\Program Files\Gene6 FTP Server
- 414 nlsvc.exe 4 3 normal C:\Program Files\NetLimiter 3
- 5b0 PnkBstrA.exe 4 1 normal C:\WINDOWS\system32
- 114 svchost.exe 9 5 normal C:\WINDOWS\system32
- a58 alg.exe 0 0
- d70 Explorer.EXE 354 142 normal C:\WINDOWS
- 9b0 avp.exe 50 31 normal C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011
- ad0 MAgent.exe 671 278 normal C:\Program Files\Mail.Ru\Agent
- b94 vsnp2std.exe 30 29 normal C:\WINDOWS
- b54 ctfmon.exe 28 11 normal C:\WINDOWS\system32
- 878 uTorrent.exe 121 41 normal C:\Program Files\uTorrent
- ca0 DTLite.exe 154 54 normal C:\Program Files\DAEMON Tools Lite
- d40 MOM.exe 12 16 normal C:\Program Files\ATI Technologies\ATI.ACE\Core-Static
- 19c Dropbox.exe 51 28 normal C:\Documents and Settings\Fedia22\Application Data\Dropbox\bin
- b10 ccc.exe 49 56 normal C:\Program Files\ATI Technologies\ATI.ACE\Core-Static
- ccc dmaster.exe 1787 702 normal C:\Program Files\Download Master
- 0cc opera.exe 148 71 normal C:\Program Files\Opera
- d3c qip.exe 1599 347 normal C:\Program Files\QIP 2010
- active control:
- TVirtualDrawTree "ContactList" []
- TInfuPanel "PanelContainer" [, FreeNotification]
- TfrmCL "frmCL" [, FreeNotification]
- memory info:
- - AvailPageFile: Integer = -1827880960
- - AvailPhysicalMemory: Integer = 678395904
- - AvailVirtualMemory: Integer = 1982988288
- - MemoryLoad: Integer = 57
- - TotalPageFile: Integer = -704425984
- - TotalPhysicalMemory: Integer = 1608957952
- - TotalVirtualMemory: Integer = 2147352576
- cpu registers:
- eax = 082a0204
- ebx = 00000000
- ecx = 082a0200
- edx = 00000000
- esi = 082a0000
- edi = 08297e20
- eip = 00000000
- esp = 0012f854
- ebp = 0012f87c
- stack dump:
- 0012f854 0c e9 69 00 20 7e 29 08 - 00 00 2a 08 00 00 00 00 ..i..~)...*.....
- 0012f864 04 f7 74 00 01 00 00 00 - 87 01 75 00 34 5b 40 00 ..t.......u.4[@.
- 0012f874 8b 3e 40 00 04 02 2a 08 - 98 f8 12 00 de d2 6f 00 .>@...*.......o.
- 0012f884 94 16 2a 08 70 7d 29 08 - ff ff ff ff c8 ce 6f 00 ..*.p}).......o.
- 0012f894 70 7d 29 08 c4 f8 12 00 - ea e9 6f 00 20 7e 29 08 p}).......o..~).
- 0012f8a4 30 f9 12 00 c4 44 40 00 - c4 f8 12 00 94 16 2a 08 0....D@.......*.
- 0012f8b4 70 7d 29 08 70 7d 29 08 - 00 00 00 00 00 00 00 00 p}).p}).........
- 0012f8c4 e8 f8 12 00 5f f3 6f 00 - 01 00 00 00 a6 e2 6f 00 ...._.o.......o.
- 0012f8d4 00 00 00 00 70 7d 29 08 - c7 e1 6f 00 94 16 2a 08 ....p})...o...*.
- 0012f8e4 e4 16 2a 08 54 f9 12 00 - 9c 55 70 00 70 7d 29 08 ..*.T....Up.p}).
- 0012f8f4 00 20 3e 00 41 55 70 00 - 94 16 2a 08 01 20 3e 00 ..>.AUp...*...>.
- 0012f904 7e ff 90 00 d0 79 29 08 - 01 00 00 01 ef 3c 40 00 ~....y)......<@.
- 0012f914 df 15 65 00 d0 79 29 08 - b0 34 61 00 2c c0 60 00 ..e..y)..4a.,.`.
- 0012f924 24 b0 64 00 2c c0 60 00 - 56 16 65 00 5c f9 12 00 $.d.,.`.V.e.\...
- 0012f934 c4 44 40 00 54 f9 12 00 - d0 79 29 08 03 00 00 00 .D@.T....y).....
- 0012f944 01 00 00 00 00 00 00 00 - 94 16 2a 08 68 79 29 01 ..........*.hy).
- 0012f954 78 f9 12 00 07 17 65 00 - 80 f9 12 00 c4 44 40 00 x.....e......D@.
- 0012f964 78 f9 12 00 74 2b 61 00 - 00 00 00 00 d0 79 29 01 x...t+a......y).
- 0012f974 d0 79 29 08 98 f9 12 00 - 2f db 63 00 40 fa 12 00 .y)...../.c.@...
- 0012f984 c4 44 40 00 98 f9 12 00 - d8 da 63 00 f1 3e 40 00 .D@.......c..>@.
- disassembling:
- [...]
- 0069e8df 2040 xor ecx, ecx
- 0069e8e1 mov edx, [ebp-4]
- 0069e8e4 mov eax, [ebp-4]
- 0069e8e7 mov ebx, [eax]
- 0069e8e9 call dword ptr [ebx+$dc]
- 0069e8e9
- 0069e8ef jmp loc_69e8ff
- 0069e8ef
- 0069e8ef ; ---------------------------------------------------------
- 0069e8ef
- 0069e8f1 loc_69e8f1:
- 0069e8f1 2042 mov eax, [ebp-4]
- 0069e8f4 mov eax, [eax+$6c]
- 0069e8f7 mov edx, [eax]
- 0069e8f9 call dword ptr [edx+$120]
- 0069e8f9
- 0069e8ff loc_69e8ff:
- 0069e8ff 2043 xor edx, edx
- 0069e901 mov eax, [ebp-4]
- 0069e904 mov ecx, [eax]
- 0069e906 > call dword ptr [ecx+$f8]
- 0069e906
- 0069e90c loc_69e90c:
- 0069e90c 2044 pop edi
- 0069e90d pop esi
- 0069e90e pop ebx
- 0069e90f mov esp, ebp
- 0069e911 pop ebp
- 0069e912 ret
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement