Advertisement
Guest User

Untitled

a guest
Mar 28th, 2019
283
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 40.17 KB | None | 0 0
  1. date/time : 2019-03-28, 21:21:27, 786ms
  2. computer name : JESSE
  3. user name : Jesse <admin>
  4. registered owner : redherochild@hotmail.com
  5. operating system : Windows 10 x64 build 18362
  6. system language : English
  7. system up time : 13 hours 25 minutes
  8. program up time : 50 seconds
  9. processors : 8x Intel(R) Core(TM) i7-4810MQ CPU @ 2.80GHz
  10. physical memory : 5709/16303 MB (free/total)
  11. free disk space : (C:) 13.94 GB (D:) 45.92 GB
  12. display mode : 1440x810, 32 bit
  13. process id : $2f5c
  14. allocated memory : 2.34 GB
  15. largest free block : 131025.51 GB
  16. executable : DynDOLODx64_SSE.exe
  17. exec. date/time : 2019-03-27 21:59
  18. version : 2.59.0.0
  19. compiled with : Delphi 10.2 Tokyo
  20. madExcept version : 5.0.0
  21. callstack crc : $b4d9a7a0, $1a922465, $62dbb214
  22. exception number : 1
  23. exception class : EAccessViolation
  24. exception message : Access violation at address 0000000001584BC3 in module 'DynDOLODx64_SSE.exe'. Read of address 0000000000000000.
  25.  
  26. main thread ($2844):
  27. 01584bc3 +053 DynDOLODx64_SSE.exe wbScriptAdapterDynDOLOD 570 +5 FileByLoadOrder
  28. 0158e26d +06d DynDOLODx64_SSE.exe wbScriptAdapterDynDOLOD 2258 +4 FileNameToLoadOrder
  29. 01595e2b +5cb DynDOLODx64_SSE.exe wbScriptAdapterDynDOLOD 2953 +29 LoadOSLFromFile2
  30. 015ee8a5 +0b5 DynDOLODx64_SSE.exe wbScriptAdapterDynDOLOD 14760 +2 Dyn_LoadOSLFromFile2
  31. 013d5cdf +0bf DynDOLODx64_SSE.exe JvInterpreter 4316 +10 GetFun
  32. 013d66fb +31b DynDOLODx64_SSE.exe JvInterpreter 4514 +96 TJvInterpreterAdapter.GetValue
  33. 013dcd9c +09c DynDOLODx64_SSE.exe JvInterpreter 6277 +4 TJvInterpreterExpression.GetValue
  34. 013ddede +0ae DynDOLODx64_SSE.exe JvInterpreter 6568 +17 TJvInterpreterFunction.GetValue
  35. 013e3b95 +045 DynDOLODx64_SSE.exe JvInterpreter 8277 +1 TJvInterpreterUnit.GetValue
  36. 013dbec0 +260 DynDOLODx64_SSE.exe JvInterpreter 6062 +31 TJvInterpreterExpression.InternalGetValue
  37. 013df4ae +07e DynDOLODx64_SSE.exe JvInterpreter 6979 +8 TJvInterpreterFunction.InterpretIdentifier
  38. 013de0e0 +0e0 DynDOLODx64_SSE.exe JvInterpreter 6606 +6 TJvInterpreterFunction.InterpretStatement
  39. 013df671 +111 DynDOLODx64_SSE.exe JvInterpreter 7015 +19 TJvInterpreterFunction.InterpretBegin
  40. 013ddcb9 +059 DynDOLODx64_SSE.exe JvInterpreter 6517 +11 TJvInterpreterFunction.InFunction
  41. 013e4188 +0d8 DynDOLODx64_SSE.exe JvInterpreter 8368 +14 TJvInterpreterUnit.ExecFunction
  42. 013e3d94 +244 DynDOLODx64_SSE.exe JvInterpreter 8308 +32 TJvInterpreterUnit.GetValue
  43. 013dbec0 +260 DynDOLODx64_SSE.exe JvInterpreter 6062 +31 TJvInterpreterExpression.InternalGetValue
  44. 013d9f79 +4d9 DynDOLODx64_SSE.exe JvInterpreter 5620 +14 Expression
  45. 013da852 +db2 DynDOLODx64_SSE.exe JvInterpreter 5738 +132 Expression
  46. 013daf9f +05f DynDOLODx64_SSE.exe JvInterpreter 5830 +5 TJvInterpreterExpression.Expression1
  47. 013db0c9 +039 DynDOLODx64_SSE.exe JvInterpreter 5852 +4 TJvInterpreterExpression.Expression2
  48. 013df730 +030 DynDOLODx64_SSE.exe JvInterpreter 7031 +2 TJvInterpreterFunction.InterpretIf
  49. 013de139 +139 DynDOLODx64_SSE.exe JvInterpreter 6618 +18 TJvInterpreterFunction.InterpretStatement
  50. 013df671 +111 DynDOLODx64_SSE.exe JvInterpreter 7015 +19 TJvInterpreterFunction.InterpretBegin
  51. 013de12f +12f DynDOLODx64_SSE.exe JvInterpreter 6616 +16 TJvInterpreterFunction.InterpretStatement
  52. 013dfe86 +2a6 DynDOLODx64_SSE.exe JvInterpreter 7197 +34 TJvInterpreterFunction.InterpretFor
  53. 013de157 +157 DynDOLODx64_SSE.exe JvInterpreter 6626 +26 TJvInterpreterFunction.InterpretStatement
  54. 013df671 +111 DynDOLODx64_SSE.exe JvInterpreter 7015 +19 TJvInterpreterFunction.InterpretBegin
  55. 013de12f +12f DynDOLODx64_SSE.exe JvInterpreter 6616 +16 TJvInterpreterFunction.InterpretStatement
  56. 013df7af +0af DynDOLODx64_SSE.exe JvInterpreter 7052 +23 TJvInterpreterFunction.InterpretIf
  57. 013de139 +139 DynDOLODx64_SSE.exe JvInterpreter 6618 +18 TJvInterpreterFunction.InterpretStatement
  58. 013e1303 +103 DynDOLODx64_SSE.exe JvInterpreter 7580 +24 TJvInterpreterFunction.InterpretTry
  59. 013de173 +173 DynDOLODx64_SSE.exe JvInterpreter 6632 +32 TJvInterpreterFunction.InterpretStatement
  60. 013df671 +111 DynDOLODx64_SSE.exe JvInterpreter 7015 +19 TJvInterpreterFunction.InterpretBegin
  61. 013ddcb9 +059 DynDOLODx64_SSE.exe JvInterpreter 6517 +11 TJvInterpreterFunction.InFunction
  62. 013e4188 +0d8 DynDOLODx64_SSE.exe JvInterpreter 8368 +14 TJvInterpreterUnit.ExecFunction
  63. 013e4672 +222 DynDOLODx64_SSE.exe JvInterpreter 8427 +27 TJvInterpreterUnit.CallFunctionEx
  64. 013e43eb +0eb DynDOLODx64_SSE.exe JvInterpreter 8390 +1 TJvInterpreterUnit.CallFunction
  65. 0151f60e +19e DynDOLODx64_SSE.exe frmViewMain 7946 +10 TfrmMain.ApplyScript$ActRec.$0$Body
  66. 01550bb8 +268 DynDOLODx64_SSE.exe frmViewMain 13969 +30 TfrmMain.PerformLongAction
  67. 015214d4 +724 DynDOLODx64_SSE.exe frmViewMain 7935 +74 TfrmMain.ApplyScript
  68. 0150c896 +2c6 DynDOLODx64_SSE.exe frmViewMain 4742 +25 TfrmMain.DoRunScript
  69. 0156160b +04b DynDOLODx64_SSE.exe frmViewMain 16523 +8 TfrmMain.tmrGeneratorTimer
  70. 00788090 +020 DynDOLODx64_SSE.exe Vcl.ExtCtrls TTimer.Timer
  71. 00787eb8 +038 DynDOLODx64_SSE.exe Vcl.ExtCtrls TTimer.WndProc
  72. 005e3cb3 +023 DynDOLODx64_SSE.exe System.Classes StdWndProc
  73. 7ffee0be +1ed USER32.dll DispatchMessageW
  74. 00843e1e +12e DynDOLODx64_SSE.exe Vcl.Forms TApplication.ProcessMessage
  75. 00843e93 +013 DynDOLODx64_SSE.exe Vcl.Forms TApplication.HandleMessage
  76. 008442e1 +0e1 DynDOLODx64_SSE.exe Vcl.Forms TApplication.Run
  77. 0162395e +0ce DynDOLODx64_SSE.exe DynDOLOD 162 +18 initialization
  78. 7ffee05b +00e KERNEL32.DLL BaseThreadInitThunk
  79. 7ffee24a +01b ntdll.dll RtlUserThreadStart
  80.  
  81. thread $c60:
  82. 7ffee05b +0e KERNEL32.DLL BaseThreadInitThunk
  83. 7ffee24a +1b ntdll.dll RtlUserThreadStart
  84.  
  85. thread $3f70:
  86. 7ffee05b +0e KERNEL32.DLL BaseThreadInitThunk
  87. 7ffee24a +1b ntdll.dll RtlUserThreadStart
  88.  
  89. thread $21cc:
  90. 7ffee05b +0e KERNEL32.DLL BaseThreadInitThunk
  91. 7ffee24a +1b ntdll.dll RtlUserThreadStart
  92.  
  93. thread $33e0:
  94. 7ffee0bf +97 USER32.dll MsgWaitForMultipleObjectsEx
  95. 7ffee0bf +3e USER32.dll MsgWaitForMultipleObjects
  96. 7ffee05b +0e KERNEL32.DLL BaseThreadInitThunk
  97. 7ffee24a +1b ntdll.dll RtlUserThreadStart
  98.  
  99. thread $3a70:
  100. 7ffedf40 +8c KERNELBASE.dll WaitForSingleObjectEx
  101. 0085aece +2e DynDOLODx64_SSE.exe VirtualTrees.WorkerThread 155 +4 TWorkerThread.Execute
  102. 00507e44 +24 DynDOLODx64_SSE.exe madExcept HookedTThreadExecute
  103. 005de530 +40 DynDOLODx64_SSE.exe System.Classes ThreadProc
  104. 0041155a +3a DynDOLODx64_SSE.exe System ThreadWrapper
  105. 00507d19 +49 DynDOLODx64_SSE.exe madExcept ThreadExceptFrame
  106. 7ffee05b +0e KERNEL32.DLL BaseThreadInitThunk
  107. 7ffee24a +1b ntdll.dll RtlUserThreadStart
  108.  
  109. thread $3960:
  110. 7ffedf42 +100 KERNELBASE.dll WaitForMultipleObjectsEx
  111. 00507d19 +049 DynDOLODx64_SSE.exe madExcept ThreadExceptFrame
  112. 7ffee05b +00e KERNEL32.DLL BaseThreadInitThunk
  113. 7ffee24a +01b ntdll.dll RtlUserThreadStart
  114.  
  115. thread $1984:
  116. 7ffee05b +0e KERNEL32.DLL BaseThreadInitThunk
  117. 7ffee24a +1b ntdll.dll RtlUserThreadStart
  118.  
  119. thread $33fc:
  120. 7ffee05b +0e KERNEL32.DLL BaseThreadInitThunk
  121. 7ffee24a +1b ntdll.dll RtlUserThreadStart
  122.  
  123. modules:
  124. 00400000 DynDOLODx64_SSE.exe 2.59.0.0 D:\downloads\DynDOLOD
  125. 7ffeb1c9 dataexchange.dll 10.0.18362.1 C:\WINDOWS\system32
  126. 7ffeb8c8 FaultRep.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  127. 7ffebe41 oledlg.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  128. 7ffec0ed oleacc.dll 7.2.18362.1 C:\WINDOWS\SYSTEM32
  129. 7ffec0ff winspool.drv 10.0.18362.1 C:\WINDOWS\SYSTEM32
  130. 7ffec3a4 MSFTEDIT.DLL 10.0.18362.1 C:\WINDOWS\SYSTEM32
  131. 7ffecbcc COMCTL32.dll 6.10.18362.1 C:\WINDOWS\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1_none_d1d7e625244f8f11
  132. 7ffecbf5 gdiplus.dll 10.0.18362.1 C:\WINDOWS\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.18362.1_none_519f554337e7ab39
  133. 7ffecc34 wininet.dll 11.0.18362.1 C:\WINDOWS\SYSTEM32
  134. 7ffecd33 dbghelp.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  135. 7ffece98 dbgcore.DLL 10.0.18362.1 C:\WINDOWS\SYSTEM32
  136. 7ffeceed wsock32.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  137. 7ffecefb mpr.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  138. 7ffed0d0 DWrite.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  139. 7ffed41d iertutil.dll 11.0.18362.1 C:\WINDOWS\System32
  140. 7ffed595 TextInputFramework.dll 10.0.18362.1 C:\WINDOWS\System32
  141. 7ffed8ae version.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  142. 7ffed940 netapi32.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  143. 7ffed974 WindowsCodecs.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  144. 7ffed9d9 CoreUIComponents.dll 10.0.18362.1 C:\WINDOWS\System32
  145. 7ffeda35 wintypes.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  146. 7ffeda88 wtsapi32.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  147. 7ffedaaa WINMMBASE.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  148. 7ffedab4 winmm.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  149. 7ffedb0f PROPSYS.dll 7.0.18362.1 C:\WINDOWS\SYSTEM32
  150. 7ffedc36 d3d11.dll 10.0.18362.1 C:\WINDOWS\system32
  151. 7ffedcb6 dcomp.dll 10.0.18362.1 C:\WINDOWS\system32
  152. 7ffedd0c CoreMessaging.dll 10.0.18362.1 C:\WINDOWS\System32
  153. 7ffedd44 apphelp.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  154. 7ffedd58 uxtheme.dll 10.0.18362.1 C:\WINDOWS\system32
  155. 7ffedd6f twinapi.appcore.dll 10.0.18362.1 C:\WINDOWS\system32
  156. 7ffedda4 DWMAPI.DLL 10.0.18362.1 C:\WINDOWS\SYSTEM32
  157. 7ffeddb5 RMCLIENT.dll 10.0.18362.1 C:\WINDOWS\system32
  158. 7ffede04 dxcore.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  159. 7ffede06 dxgi.dll 10.0.18362.1 C:\WINDOWS\system32
  160. 7ffede42 WINSTA.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  161. 7ffede52 ntmarta.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  162. 7ffede8e IPHLPAPI.DLL 10.0.18362.1 C:\WINDOWS\SYSTEM32
  163. 7ffede9f NETUTILS.DLL 10.0.18362.1 C:\WINDOWS\SYSTEM32
  164. 7ffedf20 SspiCli.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  165. 7ffedf31 UMPDC.dll C:\WINDOWS\System32
  166. 7ffedf32 profapi.dll 10.0.18362.1 C:\WINDOWS\System32
  167. 7ffedf34 kernel.appcore.dll 10.0.18362.1 C:\WINDOWS\System32
  168. 7ffedf38 powrprof.dll 10.0.18362.1 C:\WINDOWS\System32
  169. 7ffedf3d KERNELBASE.dll 10.0.18362.1 C:\WINDOWS\System32
  170. 7ffedf68 cryptsp.dll 10.0.18362.1 C:\WINDOWS\System32
  171. 7ffedf6a win32u.dll 10.0.18362.1 C:\WINDOWS\System32
  172. 7ffedf6d gdi32full.dll 10.0.18362.1 C:\WINDOWS\System32
  173. 7ffedf87 windows.storage.dll 10.0.18362.1 C:\WINDOWS\System32
  174. 7ffedfff ucrtbase.dll 10.0.18362.1 C:\WINDOWS\System32
  175. 7ffee00f bcryptPrimitives.dll 10.0.18362.1 C:\WINDOWS\System32
  176. 7ffee02d bcrypt.dll 10.0.18362.1 C:\WINDOWS\System32
  177. 7ffee041 msvcp_win.dll 10.0.18362.1 C:\WINDOWS\System32
  178. 7ffee04b cfgmgr32.dll 10.0.18362.1 C:\WINDOWS\System32
  179. 7ffee050 msvcrt.dll 7.0.18362.1 C:\WINDOWS\System32
  180. 7ffee05a KERNEL32.DLL 10.0.18362.1 C:\WINDOWS\System32
  181. 7ffee066 clbcatq.dll 2001.12.10941.16384 C:\WINDOWS\System32
  182. 7ffee071 shcore.dll 10.0.18362.1 C:\WINDOWS\System32
  183. 7ffee07d GDI32.dll 10.0.18362.1 C:\WINDOWS\System32
  184. 7ffee080 combase.dll 10.0.18362.1 C:\WINDOWS\System32
  185. 7ffee0b4 IMM32.DLL 10.0.18362.1 C:\WINDOWS\System32
  186. 7ffee0bd USER32.dll 10.0.18362.1 C:\WINDOWS\System32
  187. 7ffee0d7 oleaut32.dll 10.0.18362.1 C:\WINDOWS\System32
  188. 7ffee0ff WS2_32.dll 10.0.18362.1 C:\WINDOWS\System32
  189. 7ffee107 advapi32.dll 10.0.18362.1 C:\WINDOWS\System32
  190. 7ffee112 ole32.dll 10.0.18362.1 C:\WINDOWS\System32
  191. 7ffee130 MSCTF.dll 10.0.18362.1 C:\WINDOWS\System32
  192. 7ffee144 SHLWAPI.dll 10.0.18362.1 C:\WINDOWS\System32
  193. 7ffee199 sechost.dll 10.0.18362.1 C:\WINDOWS\System32
  194. 7ffee1a9 PSAPI.dll 10.0.18362.1 C:\WINDOWS\System32
  195. 7ffee1aa comdlg32.dll 10.0.18362.1 C:\WINDOWS\System32
  196. 7ffee1be RPCRT4.dll 10.0.18362.1 C:\WINDOWS\System32
  197. 7ffee1d2 SHELL32.dll 10.0.18362.1 C:\WINDOWS\System32
  198. 7ffee244 ntdll.dll 10.0.18362.1 C:\WINDOWS\SYSTEM32
  199.  
  200. processes:
  201. 0000 Idle 0 0 0
  202. 0004 System 0 0 0
  203. 0078 Registry 0 0 0
  204. 0184 smss.exe 0 0 0
  205. 023c csrss.exe 0 0 0
  206. 02a8 wininit.exe 0 0 0
  207. 02b0 csrss.exe 1 0 0
  208. 02f0 services.exe 0 0 0
  209. 0304 lsass.exe 0 0 0
  210. 0380 svchost.exe 0 0 0
  211. 039c svchost.exe 0 0 0
  212. 03b0 fontdrvhost.exe 0 0 0
  213. 03bc WUDFHost.exe 0 0 0
  214. 01f0 svchost.exe 0 0 0
  215. 0224 svchost.exe 0 0 0
  216. 03b8 winlogon.exe 1 0 0
  217. 042c fontdrvhost.exe 1 0 0
  218. 0470 dwm.exe 1 0 0
  219. 0498 svchost.exe 0 0 0
  220. 04a0 svchost.exe 0 0 0
  221. 0538 svchost.exe 0 0 0
  222. 0540 svchost.exe 0 0 0
  223. 0588 svchost.exe 0 0 0
  224. 05b8 svchost.exe 0 0 0
  225. 05c4 svchost.exe 0 0 0
  226. 05d8 svchost.exe 0 0 0
  227. 0628 svchost.exe 0 0 0
  228. 0670 svchost.exe 0 0 0
  229. 06e0 svchost.exe 0 0 0
  230. 0738 svchost.exe 0 0 0
  231. 077c svchost.exe 0 0 0
  232. 07ac SynTPEnhService.exe 0 0 0
  233. 07bc svchost.exe 0 0 0
  234. 07e0 svchost.exe 0 0 0
  235. 0770 svchost.exe 0 0 0
  236. 0890 NVDisplay.Container.exe 0 0 0
  237. 08a8 svchost.exe 0 0 0
  238. 08dc svchost.exe 0 0 0
  239. 0924 svchost.exe 0 0 0
  240. 0950 svchost.exe 0 0 0
  241. 0958 svchost.exe 0 0 0
  242. 0960 svchost.exe 0 0 0
  243. 09a8 svchost.exe 0 0 0
  244. 09e8 Memory Compression 0 0 0
  245. 0a28 svchost.exe 0 0 0
  246. 0a50 svchost.exe 0 0 0
  247. 0a60 svchost.exe 0 0 0
  248. 0a8c igfxCUIService.exe 0 0 0
  249. 0aec svchost.exe 0 0 0
  250. 0afc svchost.exe 0 0 0
  251. 0b80 svchost.exe 0 0 0
  252. 0c08 svchost.exe 0 0 0
  253. 0c78 svchost.exe 0 0 0
  254. 0c80 svchost.exe 0 0 0
  255. 0c88 svchost.exe 0 0 0
  256. 0d2c svchost.exe 0 0 0
  257. 0da8 svchost.exe 0 0 0
  258. 0de8 svchost.exe 0 0 0
  259. 0e6c spoolsv.exe 0 0 0
  260. 0ea8 svchost.exe 0 0 0
  261. 0f20 AdminService.exe 0 0 0
  262. 0f30 AppleMobileDeviceService.exe 0 0 0
  263. 0f50 svchost.exe 0 0 0
  264. 0f64 svchost.exe 0 0 0
  265. 0f70 dnscrypt-proxy.exe 0 0 0
  266. 0f78 svchost.exe 0 0 0
  267. 0f80 OfficeClickToRun.exe 0 0 0
  268. 0fac svchost.exe 0 0 0
  269. 0e18 MBAMService.exe 0 0 0
  270. 0ec8 MSIService.exe 0 0 0
  271. 1010 ChargeService.exe 0 0 0
  272. 1060 NvTelemetryContainer.exe 0 0 0
  273. 1068 runSW.exe 0 0 0
  274. 1070 svchost.exe 0 0 0
  275. 107c RtlService.exe 0 0 0
  276. 1088 svchost.exe 0 0 0
  277. 10cc svchost.exe 0 0 0
  278. 10d4 SurSvc.exe 0 0 0
  279. 1110 VSSVC.exe 0 0 0
  280. 1134 svchost.exe 0 0 0
  281. 1148 svchost.exe 0 0 0
  282. 11ec svchost.exe 0 0 0
  283. 1234 svchost.exe 0 0 0
  284. 125c dasHost.exe 0 0 0
  285. 1278 wlanext.exe 0 0 0
  286. 12ac KillerNetworkService.exe 0 0 0
  287. 12c0 conhost.exe 0 0 0
  288. 12c8 svchost.exe 0 0 0
  289. 1464 SwUSB.exe 1 0 0
  290. 1498 xTendUtilityService.exe 0 0 0
  291. 16bc svchost.exe 0 0 0
  292. 17a0 xTendUtility.exe 0 0 0
  293. 17c0 conhost.exe 0 0 0
  294. 1968 svchost.exe 0 0 0
  295. 1a28 dasHost.exe 0 0 0
  296. 1a8c NVDisplay.Container.exe 1 0 0
  297. 18d4 SearchIndexer.exe 0 0 0
  298. 1150 GamingServicesNet.exe 0 0 0
  299. 1ec4 svchost.exe 0 0 0
  300. 1d38 svchost.exe 0 0 0
  301. 1128 dllhost.exe 0 0 0
  302. 11b4 svchost.exe 0 0 0
  303. 1224 svchost.exe 0 0 0
  304. 12bc svchost.exe 0 0 0
  305. 1938 jhi_service.exe 0 0 0
  306. 0368 LMS.exe 0 0 0
  307. 06f4 SgrmBroker.exe 0 0 0
  308. 051c svchost.exe 0 0 0
  309. 0230 svchost.exe 0 0 0
  310. 0c9c svchost.exe 0 0 0
  311. 07f8 GamingServices.exe 0 0 0
  312. 1194 svchost.exe 0 0 0
  313. 0c44 svchost.exe 0 0 0
  314. 02c8 svchost.exe 0 0 0
  315. 1ff4 svchost.exe 0 0 0
  316. 0b74 SecurityHealthService.exe 0 0 0
  317. 11a0 mbamtray.exe 1 33 38 normal C:\Program Files\Malwarebytes\Anti-Malware
  318. 0e1c sihost.exe 1 0 13 normal C:\Windows\System32
  319. 14a8 svchost.exe 1 0 1 normal C:\Windows\System32
  320. 05d0 PresentationFontCache.exe 0 0 0
  321. 0984 svchost.exe 1 0 4 normal C:\Windows\System32
  322. 1de8 taskhostw.exe 1 8 6 normal C:\Windows\System32
  323. 2004 svchost.exe 0 0 0
  324. 2038 ctfmon.exe 1 2 22 high C:\Windows\System32
  325. 2160 igfxEM.exe 1 10 14 normal C:\Windows\System32
  326. 217c igfxHK.exe 1 10 13 normal C:\Windows\System32
  327. 21fc explorer.exe 1 1259 528 normal C:\Windows
  328. 22dc StartMenu.exe 1 0 5 normal C:\Program Files\Classic Start
  329. 2300 svchost.exe 1 36 15 normal C:\Windows\System32
  330. 23d4 SynTPEnh.exe 1 88 46 above normal C:\Windows\System32
  331. 20d4 A7000.EXE 1 0 0
  332. 20f8 svchost.exe 0 0 0
  333. 233c SynTPHelper.exe 1 0 5 above normal C:\Windows\System32
  334. 241c StartMenuExperienceHost.exe 1 0 13 normal C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy
  335. 24bc RuntimeBroker.exe 1 40 2 normal C:\Windows\System32
  336. 2530 SearchUI.exe 1 12 43 normal C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy
  337. 25c0 RuntimeBroker.exe 1 36 2 normal C:\Windows\System32
  338. 27f4 RuntimeBroker.exe 1 0 1 normal C:\Windows\System32
  339. 07a8 dllhost.exe 1 2 4 normal C:\Windows\System32
  340. 279c SecurityHealthSystray.exe 1 7 5 normal C:\Windows\System32
  341. 2264 ApplicationFrameHost.exe 1 36 31 normal C:\Windows\System32
  342. 2370 Music.UI.exe 1 13 30 normal C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19011.11311.0_x64__8wekyb3d8bbwe
  343. 2ab8 Discord.exe 1 84 50 normal C:\Users\Jesse\AppData\Local\Discord\app-0.0.305
  344. 2bc0 Discord.exe 1 7 10 normal C:\Users\Jesse\AppData\Local\Discord\app-0.0.305
  345. 0ca8 Discord.exe 1 0 3 normal C:\Users\Jesse\AppData\Local\Discord\app-0.0.305
  346. 22f8 Discord.exe 1 5 11 normal C:\Users\Jesse\AppData\Local\Discord\app-0.0.305
  347. 2cf4 ShellExperienceHost.exe 1 13 62 normal C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy
  348. 2d94 RuntimeBroker.exe 1 40 12 normal C:\Windows\System32
  349. 27ec Discord.exe 1 2 12 normal C:\Users\Jesse\AppData\Local\Discord\app-0.0.305
  350. 2e3c Discord.exe 1 1 1 normal C:\Users\Jesse\AppData\Local\Discord\app-0.0.305
  351. 2fbc svchost.exe 1 0 1 normal C:\Windows\System32
  352. 1aa0 Steam.exe 1 606 156 normal C:\Program Files (x86)\Steam
  353. 2b00 steamwebhelper.exe 1 21 25 normal C:\Program Files (x86)\Steam\bin\cef\cef.win7x64
  354. 0b3c steamwebhelper.exe 1 0 4 normal C:\Program Files (x86)\Steam\bin\cef\cef.win7x64
  355. 2874 steamwebhelper.exe 1 1 1 normal C:\Program Files (x86)\Steam\bin\cef\cef.win7x64
  356. 2320 steamwebhelper.exe 1 0 0 above normal C:\Program Files (x86)\Steam\bin\cef\cef.win7x64
  357. 2ecc steamwebhelper.exe 1 0 0 normal C:\Program Files (x86)\Steam\bin\cef\cef.win7x64
  358. 28ec WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe 1 0 24 normal C:\Windows\SystemApps\InputApp_cw5n1h2txyewy
  359. 0cd4 palemoon.exe 1 126 123 normal C:\Program Files\Pale Moon
  360. 0cc8 svchost.exe 0 0 0
  361. 01d8 SystemSettingsBroker.exe 1 0 6 normal C:\Windows\System32
  362. 12b8 svchost.exe 0 0 0
  363. 2b10 iPodService.exe 0 0 0
  364. 2e74 SyncServer.exe 1 0 1 normal C:\Program Files (x86)\Common Files\Apple\Mobile Device Support
  365. 2df8 conhost.exe 1 0 1 normal C:\Windows\System32
  366. 255c Microsoft.Photos.exe 1 0 9 normal C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.19031.14910.0_x64__8wekyb3d8bbwe
  367. 01a4 RuntimeBroker.exe 1 36 7 normal C:\Windows\System32
  368. 2918 svchost.exe 0 0 0
  369. 2650 svchost.exe 0 0 0
  370. 0080 svchost.exe 0 0 0
  371. 084c YourPhone.exe 1 0 9 normal C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19031.61.0_x64__8wekyb3d8bbwe
  372. 228c RuntimeBroker.exe 1 0 1 normal C:\Windows\System32
  373. 2e98 smartscreen.exe 1 0 5 normal C:\Windows\System32
  374. 2a1c dllhost.exe 1 0 3 normal C:\Windows\System32
  375. 3788 RuntimeBroker.exe 1 36 5 normal C:\Windows\System32
  376. 3020 SearchProtocolHost.exe 0 0 0
  377. 3150 svchost.exe 0 0 0
  378. 2c18 audiodg.exe 0 0 0
  379. 3888 RuntimeBroker.exe 1 41 16 normal C:\Windows\System32
  380. 34ac rundll32.exe 1 0 2 normal C:\Windows\System32
  381. 1d68 PaintDotNet.exe 1 250 205 normal D:\Program Files\paint.net
  382. 3ee8 MicrosoftEdge.exe 1 11 59 normal C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe
  383. 3f50 browser_broker.exe 1 0 3 normal C:\Windows\System32
  384. 3cec MicrosoftEdgeSH.exe 1 0 9 normal C:\Windows\System32
  385. 3f08 MicrosoftEdgeCP.exe 1 0 49 normal C:\Windows\System32
  386. 388c WmiPrvSE.exe 0 0 0
  387. 3adc WmiPrvSE.exe 0 0 0
  388. 3a64 svchost.exe 0 0 0
  389. 2f5c DynDOLODx64_SSE.exe 1 202 89 normal D:\Downloads\DynDOLOD
  390.  
  391. hardware:
  392. + {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
  393. - Fax
  394. - HPE143C1 (HP ENVY 4520 series)
  395. - Microsoft Print to PDF
  396. - Microsoft XPS Document Writer
  397. - Root Print Queue
  398. - Send To OneNote 2016
  399. + {36fc9e60-c465-11cf-8056-444553540000}
  400. - Apple Mobile Device USB Driver (driver 6.0.9999.69)
  401. - Generic USB Hub
  402. - Generic USB Hub
  403. - Intel(R) 8 Series/C220 Series USB EHCI #1 - 8C26
  404. - Intel(R) 8 Series/C220 Series USB EHCI #2 - 8C2D
  405. - Intel(R) USB 3.0 eXtensible Host Controller - 1.0 (Microsoft)
  406. - USB Composite Device
  407. - USB Root Hub
  408. - USB Root Hub
  409. - USB Root Hub (USB 3.0)
  410. + {4d36e965-e325-11ce-bfc1-08002be10318}
  411. - TSSTcorp BDDVDW SN-506BB
  412. + {4d36e966-e325-11ce-bfc1-08002be10318}
  413. - ACPI x64-based PC
  414. + {4d36e967-e325-11ce-bfc1-08002be10318}
  415. - HGST HTS721010A9E630
  416. - TOSHIBA THNSNH128GMCT
  417. + {4d36e968-e325-11ce-bfc1-08002be10318}
  418. - Intel(R) HD Graphics 4600 (driver 20.19.15.5063)
  419. - NVIDIA GeForce GTX 880M (driver 25.21.14.2511)
  420. + {4d36e96a-e325-11ce-bfc1-08002be10318}
  421. - Intel(R) 8 Series Chipset Family SATA AHCI Controller (driver 14.8.18.1066)
  422. + {4d36e96b-e325-11ce-bfc1-08002be10318}
  423. - HID Keyboard Device
  424. - SteelSeries PS/2 Keyboard (driver 1.0.10.0)
  425. + {4d36e96c-e325-11ce-bfc1-08002be10318}
  426. - High Definition Audio Device
  427. + {4d36e96e-e325-11ce-bfc1-08002be10318}
  428. - Generic PnP Monitor
  429. + {4d36e96f-e325-11ce-bfc1-08002be10318}
  430. - HID-compliant mouse
  431. - Synaptics PS/2 Port Compatible TouchPad (driver 19.0.24.1)
  432. + {4d36e970-e325-11ce-bfc1-08002be10318}
  433. - Realtek PCIE CardReader (driver 10.0.17134.21306)
  434. + {4d36e972-e325-11ce-bfc1-08002be10318}
  435. - Killer E2200 Gigabit Ethernet Controller (driver 9.0.0.46)
  436. - Killer Wireless-N 1202 Network Adapter (driver 10.0.0.355)
  437. - Microsoft Kernel Debug Network Adapter
  438. - Microsoft Wi-Fi Direct Virtual Adapter #16
  439. - Microsoft Wi-Fi Direct Virtual Adapter #17
  440. - NETGEAR A7000 WiFi USB3.0 Adapter (driver 1030.25.701.2017)
  441. - VirtualBox Host-Only Ethernet Adapter (driver 6.0.4.0)
  442. - WAN Miniport (IKEv2)
  443. - WAN Miniport (IP)
  444. - WAN Miniport (IPv6)
  445. - WAN Miniport (L2TP)
  446. - WAN Miniport (Network Monitor)
  447. - WAN Miniport (PPPOE)
  448. - WAN Miniport (PPTP)
  449. - WAN Miniport (SSTP)
  450. + {4d36e979-e325-11ce-bfc1-08002be10318}
  451. - HP ENVY 4520 series (driver 20.79.1.6594)
  452. + {4d36e97b-e325-11ce-bfc1-08002be10318}
  453. - Microsoft Storage Spaces Controller
  454. - Xvdd SCSI Miniport (driver 10.0.18345.1)
  455. + {4d36e97d-e325-11ce-bfc1-08002be10318}
  456. - ACPI Fixed Feature Button
  457. - ACPI Lid
  458. - ACPI Power Button
  459. - ACPI Thermal Zone
  460. - Charge Arbitration Driver
  461. - Composite Bus Enumerator
  462. - Direct memory access controller
  463. - High Definition Audio Controller
  464. - High precision event timer
  465. - Intel(R) 8 Series/C220 Series PCI Express Root Port #1 - 8C10 (driver 10.1.1.38)
  466. - Intel(R) 8 Series/C220 Series PCI Express Root Port #3 - 8C14 (driver 10.1.1.38)
  467. - Intel(R) 8 Series/C220 Series PCI Express Root Port #4 - 8C16 (driver 10.1.1.38)
  468. - Intel(R) 8 Series/C220 Series PCI Express Root Port #5 - 8C18 (driver 10.1.1.38)
  469. - Intel(R) Extreme Tuning Utility Device Driver (driver 14.35.1.69)
  470. - Intel(R) HM87 LPC Controller - 8C4B (driver 10.1.1.38)
  471. - Intel(R) Management Engine Interface (driver 11.7.0.1057)
  472. - Intel(R) Watchdog Timer Driver (Intel(R) WDT) (driver 11.0.0.1007)
  473. - Intel(R) Xeon(R) processor E3 - 1200 v3/4th Gen Core processor DRAM Controller - 0C04 (driver 10.1.1.38)
  474. - Intel(R) Xeon(R) processor E3 - 1200 v3/4th Gen Core processor PCI Express x16 Controller - 0C01 (driver 10.1.1.38)
  475. - Legacy device
  476. - Microsoft ACPI-Compliant Embedded Controller
  477. - Microsoft ACPI-Compliant System
  478. - Microsoft Basic Display Driver
  479. - Microsoft Basic Render Driver
  480. - Microsoft Hyper-V Virtualization Infrastructure Driver
  481. - Microsoft System Management BIOS Driver
  482. - Microsoft UEFI-Compliant System
  483. - Microsoft Virtual Drive Enumerator
  484. - Microsoft Windows Management Interface for ACPI
  485. - Microsoft Windows Management Interface for ACPI
  486. - Motherboard resources
  487. - Motherboard resources
  488. - Motherboard resources
  489. - NDIS Virtual Network Adapter Enumerator
  490. - Numeric data processor
  491. - PCI Express Root Complex
  492. - Plug and Play Software Device Enumerator
  493. - Programmable interrupt controller
  494. - Remote Desktop Camera Bus
  495. - Remote Desktop Device Redirector Bus
  496. - Remote Desktop USB Hub
  497. - SteelSeries Universal Bus Enumerator (driver 2.4.3.2)
  498. - Synaptics SMBus Driver (driver 19.0.24.1)
  499. - System CMOS/real time clock
  500. - System timer
  501. - UMBus Enumerator
  502. - UMBus Enumerator
  503. - UMBus Enumerator
  504. - UMBus Root Bus Enumerator
  505. - Volume Manager
  506. + {50127dc3-0f36-415e-a6cc-4cb3be910b65}
  507. - Intel(R) Core(TM) i7-4810MQ CPU @ 2.80GHz
  508. - Intel(R) Core(TM) i7-4810MQ CPU @ 2.80GHz
  509. - Intel(R) Core(TM) i7-4810MQ CPU @ 2.80GHz
  510. - Intel(R) Core(TM) i7-4810MQ CPU @ 2.80GHz
  511. - Intel(R) Core(TM) i7-4810MQ CPU @ 2.80GHz
  512. - Intel(R) Core(TM) i7-4810MQ CPU @ 2.80GHz
  513. - Intel(R) Core(TM) i7-4810MQ CPU @ 2.80GHz
  514. - Intel(R) Core(TM) i7-4810MQ CPU @ 2.80GHz
  515. + {5c4c3332-344d-483c-8739-259e934c9cc8}
  516. - Killer Networking Software (driver 1.6.2142.0)
  517. + {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
  518. - Bluetooth
  519. - HP ENVY 4520 series [E143C1]
  520. - HPE143C1 (HP ENVY 4520 series)
  521. - HPE143C1 (HP ENVY 4520 series)
  522. - Microsoft Device Association Root Enumerator
  523. - Microsoft GS Wavetable Synth
  524. - Microsoft Radio Device Enumeration Bus
  525. - Microsoft RRAS Root Enumerator
  526. - Wi-Fi 2
  527. + {6bdd1fc6-810f-11d0-bec7-08002be2092f}
  528. - HPE143C1 (HP ENVY 4520 series)
  529. + {72631e54-78a4-11d0-bcf7-00aa00b7b32a}
  530. - Microsoft AC Adapter
  531. - Microsoft ACPI-Compliant Control Method Battery
  532. + {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
  533. - HID-compliant consumer control device
  534. - HID-compliant vendor-defined device
  535. - HID-compliant wireless radio controls
  536. - Radio Switch Device (driver 1.1.8.0)
  537. - USB Input Device
  538. - USB Input Device
  539. - USB Input Device
  540. - USB Input Device
  541. + {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
  542. - Digital Audio (S/PDIF) (High Definition Audio Device)
  543. - Microphone (High Definition Audio Device)
  544. - Speakers (High Definition Audio Device)
  545. + {c30ecea0-11ef-4ef9-b02e-6af81e6e65c0}
  546. - HPE143C1 (HP ENVY 4520 series)
  547. + {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
  548. - Qualcomm Atheros AR3012 Bluetooth 4.0 (driver 10.0.3.14)
  549. + {eec5ad98-8080-425f-922a-dabf3de3f69a}
  550. - Apple iPhone
  551. + {f2e7dd72-6468-4e36-b6f1-6488f42c1b52}
  552. - LENOVO H110 System Firmware 0.30 (driver 0.0.0.30)
  553.  
  554. cpu registers:
  555. rax = 0000000000000000
  556. rbx = 0000000001d6cf88
  557. rcx = 0000000000000000
  558. rdx = 000000000000001c
  559. rsi = 000000000000001c
  560. rdi = 0000000000000041
  561. rip = 0000000001584bc3
  562. rsp = 0000000001d6cef0
  563. rbp = 0000000001d6cf40
  564. r8 = 0000000000000000
  565. r9 = 0000000000000014
  566. r10 = 00000000006e0055
  567. r11 = 00000000006b0053
  568. r12 = 0000000000000113
  569. r13 = 0000000000000041
  570. r14 = 0000000000000116
  571. r15 = 0000000000000000
  572.  
  573. stack dump:
  574. 01d6cef0 cb 03 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
  575. 01d6cf00 9e 09 09 00 00 00 00 00 - c4 00 00 00 00 00 00 00 ................
  576. 01d6cf10 10 d1 d6 01 00 00 00 00 - e0 6a be e0 fe 7f 00 00 .........j......
  577. 01d6cf20 02 00 6e 09 00 00 00 00 - 01 00 00 00 00 00 00 00 ..n.............
  578. 01d6cf30 00 00 00 00 00 00 00 00 - 12 00 00 80 00 00 00 00 ................
  579. 01d6cf40 00 00 00 00 00 00 00 00 - 40 d0 d6 01 00 00 00 00 ........@.......
  580. 01d6cf50 04 00 00 00 00 00 00 00 - 90 d7 d6 01 00 00 00 00 ................
  581. 01d6cf60 01 00 00 00 00 00 00 00 - 84 00 00 00 00 00 00 00 ................
  582. 01d6cf70 00 00 00 00 00 00 00 00 - 00 00 00 00 12 00 00 80 ................
  583. 01d6cf80 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
  584. 01d6cf90 48 fc ef 08 00 00 00 00 - 04 00 00 00 00 00 00 00 H...............
  585. 01d6cfa0 48 00 00 00 00 00 00 00 - 01 00 00 00 fe 7f 00 00 H...............
  586. 01d6cfb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
  587. 01d6cfc0 70 00 00 00 00 00 00 00 - ff ff ff ff ff ff ff ff p...............
  588. 01d6cfd0 ff ff ff ff ff ff ff ff - a4 66 be e0 fe 7f 00 00 .........f......
  589. 01d6cfe0 e0 6a be e0 fe 7f 00 00 - 2e a9 56 09 00 00 00 00 .j........V.....
  590. 01d6cff0 00 d1 d6 01 00 00 00 00 - e1 3a 6e df fe 7f 00 00 .........:n.....
  591. 01d6d000 2e a9 56 09 00 00 00 00 - 01 00 00 00 00 00 00 00 ..V.............
  592. 01d6d010 02 00 00 00 00 00 00 00 - 70 35 49 e2 fe 7f 00 00 ........p5I.....
  593. 01d6d020 00 00 d6 01 00 00 00 00 - 00 00 01 f5 ff ff ff ff ................
  594.  
  595. disassembling:
  596. [...]
  597. 01584baf 570 movsxd r13, edi
  598. 01584bb2 mov rax, [$175ad30]
  599. 01584bb9 mov rax, [rax]
  600. 01584bbc mov rax, [rax+r13*8]
  601. 01584bc0 mov rcx, rax
  602. 01584bc3 > mov rax, [rax]
  603. 01584bc6 call qword ptr [rax+$4a8]
  604. 01584bcc shr eax, $10
  605. 01584bcf movsx rax, ax
  606. 01584bd3 cmp eax, esi
  607. 01584bd5 jnz loc_1584bef
  608. [...]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement