Bug Report
Bug Report
thread $118c:
7796f8da +0e ntdll.dll NtWaitForSingleObject
758515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75d3118f +3e kernel32.dll WaitForSingleObjectEx
75d31143 +0d kernel32.dll WaitForSingleObject
75d33368 +10 kernel32.dll BaseThreadInitThunk
thread $1138:
77970166 +0e ntdll.dll NtWaitForMultipleObjects
75d33368 +10 kernel32.dll BaseThreadInitThunk
thread $498:
77970166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
75d33368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($ec8) at:
73002713 +24f netbios.dll Netbios
thread $fec:
7796f8da +0e ntdll.dll NtWaitForSingleObject
758515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75d3118f +3e kernel32.dll WaitForSingleObjectEx
75d31143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
75d33368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($ec8) at:
73144c95 +00 winspool.drv
thread $11ec:
77971f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75d33368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
002f0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
06290000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
705b0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
70fd0000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
71040000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
71560000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71600000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71840000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71860000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71990000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71b20000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71b70000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71bd0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
726c0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
726e0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72780000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
727c0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72970000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72990000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
729a0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72bf0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73000000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73010000 security.dll 6.1.7600.16385 C:\Windows\
system32
73020000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73030000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73130000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73250000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73260000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
732a0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73e80000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73e90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73eb0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73ec0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73f80000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74000000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74040000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74260000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74280000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74310000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74360000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74390000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743c0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74400000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74420000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74430000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74440000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
744a0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74510000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746b0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746c0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751e0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
751f0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75250000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
752f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
753f0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75590000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75840000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75890000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
758a0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
758b0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75af0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b20000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b30000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75b40000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75c90000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75d20000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75e30000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75f00000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f10000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76b60000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76b80000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76c70000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76da0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76e20000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76ec0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76f20000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76f60000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76f90000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77080000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
770a0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77100000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77110000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77150000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
771f0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77200000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77220000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77230000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77280000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77330000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
773e0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
773f0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77920000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77950000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0310 svchost.exe 0 0 0
038c svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0430 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0668 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0790 NetExpressUpdater.exe 0 0 0
0428 svchost.exe 0 0 0
0564 scpbradserv.exe 0 0 0
0774 core.exe 0 0 0
0940 RapportInjService_x64.exe 0 0 0
09f8 fbserver.exe 0 0 0
0b48 WUDFHost.exe 0 0 0
09ec NisSrv.exe 0 0 0
0e70 WmiPrvSE.exe 0 0 0
0e9c OSPPSVC.EXE 0 0 0
0fc4 taskhost.exe 1 26 22 normal
0fe0 core.exe 1 9 23 normal
0ce8 sppsvc.exe 0 0 0
0e4c GoogleCrashHandler.exe 0 0 0
0e54 GoogleCrashHandler64.exe 0 0 0
0ef8 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0efc RapportInjService_x64.exe 1 4 3 normal
09cc svchost.exe 0 0 0
0508 SearchIndexer.exe 0 0 0
0f78 PresentationFontCache.exe 0 0 0
0d60 dwm.exe 1 17 4 high
0cb0 explorer.exe 1 405 234 normal
05d4 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
016c igfxEM.exe 1 14 13 normal
0e0c igfxHK.exe 1 14 13 normal
0dcc msseces.exe 1 143 59 normal
06a0 PrnStatusMX.exe 1 23 20 normal
03d8 wuauclt.exe 1 12 7 normal
1160 wmpnetwk.exe 0 0 0
1084 audiodg.exe 0 0 0
1134 WmiPrvSE.exe 0 0 0
13c8 Store.exe 1 217 259 normal C:\Program Files (x86)\Store
107c splwow64.exe 1 11 3 normal
0f8c chrome.exe 1 27 57 normal
0ac4 chrome.exe 1 9 4 normal
13dc chrome.exe 1 7 7 above normal
13d0 chrome.exe 1 4 1 normal
10e0 chrome.exe 1 4 1 normal
13f8 chrome.exe 1 4 3 normal
1178 chrome.exe 1 4 1 idle
0d70 chrome.exe 1 4 1 idle
0fa8 OIS.EXE 1 130 43 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 04493c20
ebx = 0a438370
ecx = 000204b0
edx = 04484501
esi = 0a438370
edi = 000002a8
eip = 00340039
esp = 0018e0ac
ebp = 0018e0c0
stack dump:
0018e0ac 2b 00 18 00 f7 75 40 00 - e4 5b 6f 00 ac 7c 40 00 +....u@..[o..|@.
0018e0bc 30 42 41 04 d0 e0 18 00 - d3 9c 6f 00 70 83 43 01 0BA.......o.p.C.
0018e0cc 30 42 41 04 2c e1 18 00 - f7 75 40 00 47 38 ed 00 0BA.,[email protected]..
0018e0dc 34 e1 18 00 0c 89 40 00 - 2c e1 18 00 00 00 00 00 4.....@.,.......
0018e0ec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0fc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e10c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e11c 00 00 00 00 00 00 00 00 - 20 85 41 0a b0 10 41 04 ........ .A...A.
0018e12c b0 e1 18 00 c9 cf ec 00 - 18 e5 18 00 0c 89 40 00 ..............@.
0018e13c b0 e1 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e14c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e15c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e16c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e17c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e18c 70 83 43 0a c0 97 4b 04 - 60 9a 4b 04 00 9d 4b 04 p.C...K.`.K...K.
0018e19c 00 b2 4b 04 20 80 4b 04 - 60 85 4b 04 c0 82 4b 04 ..K. .K.`.K...K.
0018e1ac b0 10 41 04 00 e3 18 00 - 81 03 53 00 70 83 43 0a ..A.......S.p.C.
0018e1bc c7 33 55 00 68 e3 18 00 - f6 42 62 00 4c 42 62 00 .3U.h....Bb.LBb.
0018e1cc 68 e3 18 00 f5 3e 55 00 - 70 83 43 0a 28 fe 52 00 h....>U.p.C.(.R.
0018e1dc 68 e3 18 00 48 e5 18 00 - 70 83 43 0a f3 00 00 00 h...H...p.C.....
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 708 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $118c:
7796f8da +0e ntdll.dll NtWaitForSingleObject
758515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75d3118f +3e kernel32.dll WaitForSingleObjectEx
75d31143 +0d kernel32.dll WaitForSingleObject
75d33368 +10 kernel32.dll BaseThreadInitThunk
thread $1138:
77970166 +0e ntdll.dll NtWaitForMultipleObjects
75d33368 +10 kernel32.dll BaseThreadInitThunk
thread $498:
77970166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
75d33368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($ec8) at:
73002713 +24f netbios.dll Netbios
thread $fec:
7796f8da +0e ntdll.dll NtWaitForSingleObject
758515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75d3118f +3e kernel32.dll WaitForSingleObjectEx
75d31143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
75d33368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($ec8) at:
73144c95 +00 winspool.drv
thread $11ec:
77971f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75d33368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
002f0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
06290000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
705b0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
70fd0000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
71040000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
71560000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71600000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71840000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71860000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71990000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71b20000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71b70000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71bd0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
726c0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
726e0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72780000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
727c0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72970000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72990000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
729a0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72bf0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73000000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73010000 security.dll 6.1.7600.16385 C:\Windows\
system32
73020000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73030000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73130000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73250000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73260000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
732a0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73e80000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73e90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73eb0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73ec0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73f80000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74000000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74040000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74260000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74280000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74310000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74360000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74390000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743c0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74400000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74420000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74430000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74440000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
744a0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74510000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746b0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746c0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751e0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
751f0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75250000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
752f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
753f0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75590000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75840000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75890000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
758a0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
758b0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75af0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b20000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b30000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75b40000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75c90000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75d20000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75e30000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75f00000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f10000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76b60000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76b80000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76c70000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76da0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76e20000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76ec0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76f20000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76f60000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76f90000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77080000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
770a0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77100000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77110000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77150000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
771f0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77200000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77220000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77230000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77280000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77330000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
773e0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
773f0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77920000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77950000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0310 svchost.exe 0 0 0
038c svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0430 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0668 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0790 NetExpressUpdater.exe 0 0 0
0428 svchost.exe 0 0 0
0564 scpbradserv.exe 0 0 0
0774 core.exe 0 0 0
0940 RapportInjService_x64.exe 0 0 0
09f8 fbserver.exe 0 0 0
0b48 WUDFHost.exe 0 0 0
09ec NisSrv.exe 0 0 0
0e70 WmiPrvSE.exe 0 0 0
0e9c OSPPSVC.EXE 0 0 0
0fc4 taskhost.exe 1 26 24 normal
0fe0 core.exe 1 9 23 normal
0ce8 sppsvc.exe 0 0 0
0e4c GoogleCrashHandler.exe 0 0 0
0e54 GoogleCrashHandler64.exe 0 0 0
0ef8 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0efc RapportInjService_x64.exe 1 4 3 normal
09cc svchost.exe 0 0 0
0508 SearchIndexer.exe 0 0 0
0f78 PresentationFontCache.exe 0 0 0
0d60 dwm.exe 1 17 4 high
0cb0 explorer.exe 1 405 235 normal
05d4 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
016c igfxEM.exe 1 14 13 normal
0e0c igfxHK.exe 1 14 13 normal
0dcc msseces.exe 1 143 59 normal
06a0 PrnStatusMX.exe 1 23 20 normal
03d8 wuauclt.exe 1 12 7 normal
1160 wmpnetwk.exe 0 0 0
1084 audiodg.exe 0 0 0
1134 WmiPrvSE.exe 0 0 0
13c8 Store.exe 1 214 239 normal C:\Program Files (x86)\Store
107c splwow64.exe 1 11 3 normal
0f8c chrome.exe 1 27 57 normal
0ac4 chrome.exe 1 9 4 normal
13dc chrome.exe 1 7 7 above normal
13d0 chrome.exe 1 4 1 normal
10e0 chrome.exe 1 4 1 normal
13f8 chrome.exe 1 4 3 normal
1178 chrome.exe 1 4 1 idle
0d70 chrome.exe 1 4 1 idle
0fa8 OIS.EXE 1 130 43 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 063f4b80
ebx = 00003303
ecx = 00000000
edx = 02642ac8
esi = 0018ebb4
edi = 0066c9e4
eip = 0066e902
esp = 0018eb78
ebp = 0018ebe0
stack dump:
0018eb78 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018eb88 8c eb 18 00 02 e9 66 00 - 80 4b 3f 06 03 33 00 00 ......f..K?..3..
0018eb98 b4 eb 18 00 e4 c9 66 00 - e0 eb 18 00 a8 eb 18 00 ......f.........
0018eba8 20 d2 46 06 0e e9 66 00 - 34 e8 67 00 00 00 00 00 .F...f.4.g.....
0018ebb8 20 d2 46 06 00 00 00 00 - 2f e7 67 00 ec eb 18 00 .F...../.g.....
0018ebc8 0c 89 40 00 e0 eb 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018ebd8 69 e8 67 01 20 d2 46 06 - 08 ec 18 00 87 e7 67 00 i.g. .F.......g.
0018ebe8 a6 4b 67 00 20 ec 18 00 - 0c 89 40 00 08 ec 18 00 .Kg. .....@.....
0018ebf8 20 d2 46 06 00 00 00 00 - 00 00 00 00 20 d2 46 06 .F......... .F.
0018ec08 34 ec 18 00 4a 91 67 00 - 05 00 00 00 ac 3a 62 00 4...J.g......:b.
0018ec18 01 00 00 00 77 72 65 00 - 40 ec 18 00 0c 89 40 00 ....wre.@.....@.
0018ec28 34 ec 18 00 60 bf 4d 04 - 20 d2 46 06 04 ed 18 00 4...`.M. .F.....
0018ec38 be 70 65 00 88 ba 16 01 - 0c ed 18 00 0c 89 40 00 .pe...........@.
0018ec48 04 ed 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ec58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ec68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ec78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ec88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ec98 00 00 00 00 00 00 00 00 - 00 7c e5 40 a0 b9 3f 06 .........|.@..?.
0018eca8 00 00 00 00 fa a4 4f fa - 1f 7c e5 40 00 00 00 00 ......O..|.@....
disassembling:
[...]
0116ba5f mov eax, [ebp-$18]
0116ba62 mov eax, [eax+$250]
0116ba68 mov ecx, [eax]
0116ba6a call dword ptr [ecx+$38]
0116ba6d 425 mov edx, $116cac0
0116ba72 mov eax, [ebp-$18]
0116ba75 mov eax, [eax+$250]
0116ba7b mov ecx, [eax]
0116ba7d call dword ptr [ecx+$38]
0116ba80 427 mov eax, [ebp-$18]
0116ba83 > call -$b149d4 ($6570b4) ; Data.DB.TDataSet.Open
0116ba88 428 mov eax, [ebp-$18]
0116ba8b call -$b12114 ($65997c) ; Data.DB.TDataSet.First
0116ba90 429 mov eax, [ebp-$18]
0116ba93 cmp byte ptr [eax+$a9], 0
0116ba9a jz loc_116baa8
0116ba9c mov eax, [ebp-$18]
0116ba9f cmp byte ptr [eax+$a8], 0
0116baa6 jnz loc_116bab7
0116baa8 431 mov eax, [ebp-4]
0116baab call +$32fe8 ($119ea98) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $118c:
7796f8da +0e ntdll.dll NtWaitForSingleObject
758515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75d3118f +3e kernel32.dll WaitForSingleObjectEx
75d31143 +0d kernel32.dll WaitForSingleObject
75d33368 +10 kernel32.dll BaseThreadInitThunk
thread $1138:
77970166 +0e ntdll.dll NtWaitForMultipleObjects
75d33368 +10 kernel32.dll BaseThreadInitThunk
thread $498:
77970166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
75d33368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($ec8) at:
73002713 +24f netbios.dll Netbios
thread $fec:
7796f8da +0e ntdll.dll NtWaitForSingleObject
758515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75d3118f +3e kernel32.dll WaitForSingleObjectEx
75d31143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
75d33368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($ec8) at:
73144c95 +00 winspool.drv
thread $13a8:
77971f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75d33368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
002f0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
06290000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
705b0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
70fd0000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
71040000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
71560000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71600000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71840000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71860000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71990000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71b20000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71b70000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71bd0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
726c0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
726e0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72780000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
727c0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72970000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72990000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
729a0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72bf0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73000000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73010000 security.dll 6.1.7600.16385 C:\Windows\
system32
73020000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73030000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73130000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73250000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73260000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
732a0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73e80000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73e90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73eb0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73ec0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73f80000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74000000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74040000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74260000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74280000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74310000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74360000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74390000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743c0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74400000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74420000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74430000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74440000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
744a0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74510000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746b0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746c0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751e0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
751f0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75250000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
752f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
753f0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75590000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75840000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75890000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
758a0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
758b0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75af0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b20000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b30000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75b40000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75c90000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75d20000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75e30000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75f00000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f10000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76b60000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76b80000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76c70000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76da0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76e20000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76ec0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76f20000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76f60000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76f90000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77080000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
770a0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77100000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77110000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77150000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
771f0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77200000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77220000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77230000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77280000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77330000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
773e0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
773f0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77920000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77950000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0310 svchost.exe 0 0 0
038c svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0430 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0668 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0790 NetExpressUpdater.exe 0 0 0
0428 svchost.exe 0 0 0
0564 scpbradserv.exe 0 0 0
0774 core.exe 0 0 0
0940 RapportInjService_x64.exe 0 0 0
09f8 fbserver.exe 0 0 0
0b48 WUDFHost.exe 0 0 0
09ec NisSrv.exe 0 0 0
0e70 WmiPrvSE.exe 0 0 0
0e9c OSPPSVC.EXE 0 0 0
0fc4 taskhost.exe 1 26 22 normal
0fe0 core.exe 1 9 21 normal
0ce8 sppsvc.exe 0 0 0
0e4c GoogleCrashHandler.exe 0 0 0
0e54 GoogleCrashHandler64.exe 0 0 0
0ef8 RapportService.exe 1 15 18 normal C:\Program Files (x86)\Trusteer\
Rapport\bin
0efc RapportInjService_x64.exe 1 4 3 normal
09cc svchost.exe 0 0 0
0508 SearchIndexer.exe 0 0 0
0f78 PresentationFontCache.exe 0 0 0
0d60 dwm.exe 1 18 4 high
0cb0 explorer.exe 1 432 281 normal
05d4 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\scpbrad
016c igfxEM.exe 1 14 13 normal
0e0c igfxHK.exe 1 14 13 normal
0dcc msseces.exe 1 143 59 normal
06a0 PrnStatusMX.exe 1 23 20 normal
03d8 wuauclt.exe 1 12 7 normal
1160 wmpnetwk.exe 0 0 0
13c8 Store.exe 1 1185 122 normal C:\Program Files (x86)\Store
107c splwow64.exe 1 11 5 normal
0528 Store.exe 1 136 203 normal C:\Program Files (x86)\Store
0f6c OIS.EXE 1 102 43 normal
10f4 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1204 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a366f80
ebx = 00000002
ecx = 00000000
edx = 0a3cc801
esi = 0a3bbb10
edi = 04414230
eip = 004075f4
esp = 0018fee8
ebp = 0018fef4
stack dump:
0018fee8 68 5b 6f 00 ac 7c 40 00 - 30 42 41 04 04 ff 18 00 h[o..|@.0BA.....
0018fef8 d3 9c 6f 00 e9 2d 53 01 - 30 42 41 04 40 ff 18 00 ..o..-S.0BA.@...
0018ff08 3d 1b 53 00 00 ce 44 06 - f8 a1 4f 04 10 bb 3b 0a =.S...D...O...;.
0018ff18 00 00 00 00 2c 9f 60 00 - 10 bb 3b 0a f0 f8 4a 04 ....,.`...;...J.
0018ff28 06 b1 60 00 78 ff 18 00 - 0c 89 40 00 40 ff 18 00 ..`.x.....@.@...
0018ff38 f8 a1 4f 01 10 bb 3b 0a - 88 ff 18 00 56 03 49 00 ..O...;.....V.I.
0018ff48 54 e0 60 01 18 0b 61 01 - c8 8c 60 00 02 8d 60 00 T.`...a...`...`.
0018ff58 0c 1e 45 00 e4 1d 45 00 - af 90 40 00 88 ff 18 00 ..E...E...@.....
0018ff68 00 00 00 00 00 00 00 00 - 00 e0 fd 7e 29 21 5e 01 ...........~)!^.
0018ff78 c4 ff 18 00 dc 8b 40 00 - 88 ff 18 00 00 00 00 00 ......@.........
0018ff88 94 ff 18 00 6a 33 d3 75 - 00 e0 fd 7e d4 ff 18 00 ....j3.u...~....
0018ff98 f2 98 98 77 00 e0 fd 7e - 82 d1 b1 77 00 00 00 00 ...w...~...w....
0018ffa8 00 00 00 00 00 e0 fd 7e - 00 00 00 00 b9 6c 7a 77 .......~.....lzw
0018ffb8 00 00 00 00 a0 ff 18 00 - 00 00 00 00 ff ff ff ff ................
0018ffc8 45 58 9c 77 76 e8 3e 00 - 00 00 00 00 ec ff 18 00 EX.wv.>.........
0018ffd8 c5 98 98 77 70 20 5e 01 - 00 e0 fd 7e 00 00 00 00 ...wp ^....~....
0018ffe8 00 00 00 00 00 00 00 00 - 00 00 00 00 70 20 5e 01 ............p ^.
0018fff8 00 e0 fd 7e 00 00 00 00 ...~....
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 708 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $e80:
7796f8da +0e ntdll.dll NtWaitForSingleObject
758515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75d3118f +3e kernel32.dll WaitForSingleObjectEx
75d31143 +0d kernel32.dll WaitForSingleObject
75d33368 +10 kernel32.dll BaseThreadInitThunk
thread $12c4:
77970166 +0e ntdll.dll NtWaitForMultipleObjects
75d33368 +10 kernel32.dll BaseThreadInitThunk
thread $a20:
7796f8da +0e ntdll.dll NtWaitForSingleObject
758515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75d3118f +3e kernel32.dll WaitForSingleObjectEx
75d31143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
75d33368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($17bc) at:
73374c95 +00 winspool.drv
thread $1418:
77971f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75d33368 +10 kernel32.dll BaseThreadInitThunk
modules:
002d0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
062d0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06400000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
07930000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70600000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
70fc0000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
714d0000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
71560000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71600000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71840000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71860000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71990000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71b20000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71b70000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71bd0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
726c0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
726e0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72780000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
727c0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72970000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72990000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
729a0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73000000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
730c0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73280000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
732b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
732c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
732d0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73360000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73d30000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73e80000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73e90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73eb0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73ec0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73f80000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74000000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74040000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74260000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74280000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74310000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74360000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74390000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743c0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74400000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74420000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74430000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74440000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
744a0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74510000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746b0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746c0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751e0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
751f0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75250000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
752f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
753f0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75590000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75840000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75890000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
758a0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
758b0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75af0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b20000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b30000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75b40000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75c90000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75d20000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75e30000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75f00000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f10000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76b60000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76b80000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76c70000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76da0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76e20000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76ec0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76f20000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76f60000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76f90000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77080000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
770a0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77100000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77110000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77150000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
771f0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77200000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77220000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77230000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77280000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77330000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
773e0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
773f0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77920000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77950000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0310 svchost.exe 0 0 0
038c svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0430 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0668 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0790 NetExpressUpdater.exe 0 0 0
0428 svchost.exe 0 0 0
0564 scpbradserv.exe 0 0 0
0774 core.exe 0 0 0
0940 RapportInjService_x64.exe 0 0 0
09f8 fbserver.exe 0 0 0
0b48 WUDFHost.exe 0 0 0
09ec NisSrv.exe 0 0 0
0e70 WmiPrvSE.exe 0 0 0
0e9c OSPPSVC.EXE 0 0 0
0fc4 taskhost.exe 1 26 23 normal
0fe0 core.exe 1 9 21 normal
0ce8 sppsvc.exe 0 0 0
0e4c GoogleCrashHandler.exe 0 0 0
0e54 GoogleCrashHandler64.exe 0 0 0
0ef8 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0efc RapportInjService_x64.exe 1 4 3 normal
09cc svchost.exe 0 0 0
0508 SearchIndexer.exe 0 0 0
0f78 PresentationFontCache.exe 0 0 0
0d60 dwm.exe 1 18 4 high
0cb0 explorer.exe 1 447 312 normal
05d4 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
016c igfxEM.exe 1 14 13 normal
0e0c igfxHK.exe 1 14 13 normal
0dcc msseces.exe 1 143 59 normal
06a0 PrnStatusMX.exe 1 23 20 normal
03d8 wuauclt.exe 1 12 6 normal
1160 wmpnetwk.exe 0 0 0
0f6c OIS.EXE 1 123 43 normal
10f4 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1680 Store.exe 1 327 202 normal C:\Program Files (x86)\Store
0fec chrome.exe 1 27 51 normal
0b98 chrome.exe 1 9 4 normal
0da4 chrome.exe 1 7 7 above normal
1414 chrome.exe 1 4 1 normal
1568 chrome.exe 1 4 1 normal
15e8 chrome.exe 1 4 1 idle
103c chrome.exe 1 4 3 normal
1634 splwow64.exe 1 11 4 normal
0a50 audiodg.exe 0 0 0
0eb0 WMIC.exe 0 0 0
1184 conhost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 069f75a0
ebx = 00003303
ecx = 00000000
edx = 02622ac8
esi = 0018ec80
edi = 0066c9e4
eip = 0066e902
esp = 0018ec44
ebp = 0018ecac
stack dump:
0018ec44 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018ec54 58 ec 18 00 02 e9 66 00 - a0 75 9f 06 03 33 00 00 X.....f..u...3..
0018ec64 80 ec 18 00 e4 c9 66 00 - ac ec 18 00 74 ec 18 00 ......f.....t...
0018ec74 00 b2 4d 04 0e e9 66 00 - 34 e8 67 00 00 00 00 00 ..M...f.4.g.....
0018ec84 00 b2 4d 04 00 00 00 00 - 2f e7 67 00 b8 ec 18 00 ..M...../.g.....
0018ec94 0c 89 40 00 ac ec 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018eca4 69 e8 67 01 00 b2 4d 04 - d4 ec 18 00 87 e7 67 00 i.g...M.......g.
0018ecb4 a6 4b 67 00 ec ec 18 00 - 0c 89 40 00 d4 ec 18 00 .Kg.......@.....
0018ecc4 00 b2 4d 04 00 00 00 00 - 00 00 00 00 00 b2 4d 04 ..M...........M.
0018ecd4 00 ed 18 00 4a 91 67 00 - 11 00 00 00 ac 3a 62 00 ....J.g......:b.
0018ece4 01 00 00 00 77 72 65 00 - 0c ed 18 00 0c 89 40 00 ....wre.......@.
0018ecf4 00 ed 18 00 00 d5 26 0a - 00 b2 4d 04 34 ed 18 00 ......&...M.4...
0018ed04 be 70 65 00 3c 48 17 01 - 68 ef 18 00 0c 89 40 00 .pe.<H..h.....@.
0018ed14 34 ed 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 4...............
0018ed24 00 00 00 00 00 d5 26 0a - 00 b2 4d 04 a0 b9 44 06 ......&...M...D.
0018ed34 58 ed 18 00 81 03 53 00 - 00 d5 26 0a b1 3a 62 00 X.....S...&..:b.
0018ed44 9b 3a 62 00 d4 ee 18 00 - ac 39 62 00 00 d5 26 0a .:b......9b...&.
0018ed54 01 00 00 00 c8 ee 18 00 - b9 07 53 00 11 00 00 00 ..........S.....
0018ed64 09 00 00 00 00 00 00 00 - d4 ee 18 00 00 d5 26 0a ..............&.
0018ed74 35 08 53 00 09 00 11 00 - d4 ee 18 00 fc 02 17 00 5.S.............
disassembling:
[...]
01174811 push $11749d8
01174816 lea eax, [ebp-$10]
01174819 mov edx, 3
0117481e call -$d6a073 ($40a7b0) ; System.@UStrCatN
01174823 mov edx, [ebp-$10]
01174826 mov eax, [ebp-8]
01174829 mov eax, [eax+$250]
0117482f mov ecx, [eax]
01174831 call dword ptr [ecx+$38]
01174834 1051 mov eax, [ebp-8]
01174837 > call -$b1d788 ($6570b4) ; Data.DB.TDataSet.Open
0117483c 1053 mov eax, [$160cdb0]
01174841 mov eax, [eax]
01174843 mov eax, [eax+$27c]
01174849 mov edx, $11749ec
0117484e call -$b1c41f ($658434) ; Data.DB.TDataSet.FieldByName
01174853 lea edx, [ebp-$14]
01174856 mov ecx, [eax]
01174858 call dword ptr [ecx+$80]
0117485e mov eax, [ebp-$14]
01174861 mov edx, $1174a10
[...]
thread $1388:
77c2f8da +0e ntdll.dll NtWaitForSingleObject
766d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
765c118f +3e kernel32.dll WaitForSingleObjectEx
765c1143 +0d kernel32.dll WaitForSingleObject
765c3368 +10 kernel32.dll BaseThreadInitThunk
thread $f04:
77c30166 +0e ntdll.dll NtWaitForMultipleObjects
765c3368 +10 kernel32.dll BaseThreadInitThunk
thread $f0c:
77c30166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
765c3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1590) at:
73c32713 +24f netbios.dll Netbios
thread $17ec:
77c2f8da +0e ntdll.dll NtWaitForSingleObject
766d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
765c118f +3e kernel32.dll WaitForSingleObjectEx
765c1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
765c3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1590) at:
73464c95 +00 winspool.drv
thread $a48:
77c31f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
765c3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02670000 WINPPLA.DLL C:\Program
Files (x86)\Store
026b0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
026e0000 BCLW32.dll C:\Program
Files (x86)\Store
062b0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063c0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
095f0000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6d0b0000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
6d0f0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
6daa0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
71330000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
71400000 slc.dll 6.1.7600.16385 C:\Windows\
system32
71740000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
717b0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71810000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71a60000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71be0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71d80000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71da0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
72080000 webio.dll 6.1.7601.23375 C:\Windows\
system32
720d0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72130000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72980000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
729a0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a40000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a80000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
732c0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
732f0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73350000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73450000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
734b0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73c30000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73c40000 security.dll 6.1.7600.16385 C:\Windows\
system32
73c50000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73d90000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73da0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73dc0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73dd0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73fe0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74000000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
745d0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74620000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74650000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74680000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
746c0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
746e0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
746f0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74700000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74760000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
747d0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74970000 version.dll 6.1.7600.16385 C:\Windows\
system32
74980000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
754a0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
754b0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75510000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75670000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75710000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
757b0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
759f0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75a10000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75a60000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75b10000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b40000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b50000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75b60000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75b70000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75c60000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75c70000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75e10000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75e80000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75ea0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75f50000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f60000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75ff0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
762a0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
762b0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
762f0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
763a0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
763b0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76440000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76570000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76580000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76590000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
765b0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
766c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76710000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
773f0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77550000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
77620000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77680000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
776e0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77710000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77be0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77c10000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 wininit.exe 0 0 0
0260 csrss.exe 1 0 0
0290 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
0308 svchost.exe 0 0 0
03f4 svchost.exe 0 0 0
041c svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
066c svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0784 svchost.exe 0 0 0
07a0 NetExpressUpdater.exe 0 0 0
01e4 svchost.exe 0 0 0
0554 scpbradserv.exe 0 0 0
06d0 svchost.exe 0 0 0
0708 core.exe 0 0 0
0928 RapportInjService_x64.exe 0 0 0
09b8 fbserver.exe 0 0 0
0b00 WUDFHost.exe 0 0 0
0bd0 NisSrv.exe 0 0 0
0e7c taskhost.exe 1 26 23 normal
0e94 core.exe 1 9 21 normal
0f58 sppsvc.exe 0 0 0
0cd8 GoogleCrashHandler.exe 0 0 0
0d08 GoogleCrashHandler64.exe 0 0 0
0d38 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0dd0 PresentationFontCache.exe 0 0 0
0de0 dwm.exe 1 17 4 high
0dfc explorer.exe 1 464 347 normal
0e28 RapportInjService_x64.exe 1 4 3 normal
0f68 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
00d8 igfxEM.exe 1 14 13 normal
03e4 igfxHK.exe 1 14 12 normal
0ec0 msseces.exe 1 143 59 normal
08f0 PrnStatusMX.exe 1 23 20 normal
10f0 svchost.exe 0 0 0
11e0 SearchIndexer.exe 0 0 0
1318 wmpnetwk.exe 0 0 0
12b8 WmiPrvSE.exe 0 0 0
12c4 OSPPSVC.EXE 0 0 0
13f4 chrome.exe 1 79 59 normal
11f8 chrome.exe 1 9 4 normal
0dcc chrome.exe 1 13 6 above normal
04b0 chrome.exe 1 4 1 normal
1780 slui.exe 1 48 31 normal
15cc wuauclt.exe 1 12 6 normal
0cc4 chrome.exe 1 4 1 normal
040c chrome.exe 1 4 1 idle
0c74 chrome.exe 1 4 3 normal
15a8 Store.exe 1 2124 432 normal C:\Program Files (x86)\Store
152c Store.exe 1 610 191 normal C:\Program Files (x86)\Store
14b4 splwow64.exe 1 11 4 normal
0f9c DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
0bfc chrome.exe 1 4 1 idle
15ac audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 06a22b78
ebx = 00003303
ecx = 00000000
edx = 00282ac8
esi = 0018e4b4
edi = 0066c9e4
eip = 0066e902
esp = 0018e478
ebp = 0018e4e0
stack dump:
0018e478 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018e488 8c e4 18 00 02 e9 66 00 - 78 2b a2 06 03 33 00 00 ......f.x+...3..
0018e498 b4 e4 18 00 e4 c9 66 00 - e0 e4 18 00 a8 e4 18 00 ......f.........
0018e4a8 50 50 52 06 0e e9 66 00 - 34 e8 67 00 00 00 00 00 PPR...f.4.g.....
0018e4b8 50 50 52 06 00 00 00 00 - 2f e7 67 00 ec e4 18 00 PPR...../.g.....
0018e4c8 0c 89 40 00 e0 e4 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e4d8 69 e8 67 01 50 50 52 06 - 08 e5 18 00 87 e7 67 00 i.g.PPR.......g.
0018e4e8 a6 4b 67 00 20 e5 18 00 - 0c 89 40 00 08 e5 18 00 .Kg. .....@.....
0018e4f8 50 50 52 06 00 00 00 00 - 00 00 00 00 50 50 52 06 PPR.........PPR.
0018e508 34 e5 18 00 4a 91 67 00 - bc e7 18 00 0c 03 53 00 4...J.g.......S.
0018e518 01 00 00 00 77 72 65 00 - 40 e5 18 00 0c 89 40 00 ....wre.@.....@.
0018e528 34 e5 18 00 f0 52 4a 06 - 50 50 52 06 04 e6 18 00 4....RJ.PPR.....
0018e538 be 70 65 00 88 ba 16 01 - 6c e9 18 00 0c 89 40 00 .pe.....l.....@.
0018e548 04 e6 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e558 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e568 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e578 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e588 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e598 00 00 00 00 00 00 00 00 - 80 75 e5 40 f0 52 4a 06 [email protected].
0018e5a8 00 00 00 00 fa a4 4f fa - 3f 7c e5 40 00 00 00 00 ......O.?|.@....
disassembling:
[...]
0116ba5f mov eax, [ebp-$18]
0116ba62 mov eax, [eax+$250]
0116ba68 mov ecx, [eax]
0116ba6a call dword ptr [ecx+$38]
0116ba6d 425 mov edx, $116cac0
0116ba72 mov eax, [ebp-$18]
0116ba75 mov eax, [eax+$250]
0116ba7b mov ecx, [eax]
0116ba7d call dword ptr [ecx+$38]
0116ba80 427 mov eax, [ebp-$18]
0116ba83 > call -$b149d4 ($6570b4) ; Data.DB.TDataSet.Open
0116ba88 428 mov eax, [ebp-$18]
0116ba8b call -$b12114 ($65997c) ; Data.DB.TDataSet.First
0116ba90 429 mov eax, [ebp-$18]
0116ba93 cmp byte ptr [eax+$a9], 0
0116ba9a jz loc_116baa8
0116ba9c mov eax, [ebp-$18]
0116ba9f cmp byte ptr [eax+$a8], 0
0116baa6 jnz loc_116bab7
0116baa8 431 mov eax, [ebp-4]
0116baab call +$32fe8 ($119ea98) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $1388:
77c2f8da +0e ntdll.dll NtWaitForSingleObject
766d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
765c118f +3e kernel32.dll WaitForSingleObjectEx
765c1143 +0d kernel32.dll WaitForSingleObject
765c3368 +10 kernel32.dll BaseThreadInitThunk
thread $f04:
77c30166 +0e ntdll.dll NtWaitForMultipleObjects
765c3368 +10 kernel32.dll BaseThreadInitThunk
thread $f0c:
77c30166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
765c3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1590) at:
73c32713 +24f netbios.dll Netbios
thread $17ec:
77c2f8da +0e ntdll.dll NtWaitForSingleObject
766d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
765c118f +3e kernel32.dll WaitForSingleObjectEx
765c1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
765c3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1590) at:
73464c95 +00 winspool.drv
thread $1070:
77c31f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
765c3368 +10 kernel32.dll BaseThreadInitThunk
thread $998:
77c31f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
765c3368 +10 kernel32.dll BaseThreadInitThunk
thread $11b4:
77c31f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
765c3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02670000 WINPPLA.DLL C:\Program
Files (x86)\Store
026b0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
026e0000 BCLW32.dll C:\Program
Files (x86)\Store
062b0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063c0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
095f0000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6d0b0000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
6d0f0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
6daa0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
71330000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
71400000 slc.dll 6.1.7600.16385 C:\Windows\
system32
71740000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
717b0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71810000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71a60000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71be0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71d80000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71da0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
72080000 webio.dll 6.1.7601.23375 C:\Windows\
system32
720d0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72130000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72980000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
729a0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a40000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a80000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
732c0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
732f0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73350000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73450000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
734b0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73c30000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73c40000 security.dll 6.1.7600.16385 C:\Windows\
system32
73c50000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73d90000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73da0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73dc0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73dd0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73fe0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74000000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
745d0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74620000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74650000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74680000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
746c0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
746e0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
746f0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74700000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74760000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
747d0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74970000 version.dll 6.1.7600.16385 C:\Windows\
system32
74980000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
754a0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
754b0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75510000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75660000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75670000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75710000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
757b0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
759f0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75a10000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75a60000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75b10000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b40000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b50000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75b60000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75b70000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75c60000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75c70000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75e10000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75e80000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75ea0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75f50000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f60000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75ff0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
762a0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
762b0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
762f0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
763a0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
763b0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76440000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76570000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76580000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76590000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
765b0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
766c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76710000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
773f0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77550000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
77620000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77680000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
776e0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77710000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77be0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77c10000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 wininit.exe 0 0 0
0260 csrss.exe 1 0 0
0290 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
0308 svchost.exe 0 0 0
03f4 svchost.exe 0 0 0
041c svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
066c svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0784 svchost.exe 0 0 0
07a0 NetExpressUpdater.exe 0 0 0
01e4 svchost.exe 0 0 0
0554 scpbradserv.exe 0 0 0
06d0 svchost.exe 0 0 0
0708 core.exe 0 0 0
0928 RapportInjService_x64.exe 0 0 0
09b8 fbserver.exe 0 0 0
0b00 WUDFHost.exe 0 0 0
0bd0 NisSrv.exe 0 0 0
0e7c taskhost.exe 1 26 24 normal
0e94 core.exe 1 9 21 normal
0f58 sppsvc.exe 0 0 0
0cd8 GoogleCrashHandler.exe 0 0 0
0d08 GoogleCrashHandler64.exe 0 0 0
0d38 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0dd0 PresentationFontCache.exe 0 0 0
0de0 dwm.exe 1 16 4 high
0dfc explorer.exe 1 411 458 normal
0e28 RapportInjService_x64.exe 1 4 3 normal
0f68 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
00d8 igfxEM.exe 1 14 13 normal
03e4 igfxHK.exe 1 14 12 normal
0ec0 msseces.exe 1 143 59 normal
08f0 PrnStatusMX.exe 1 23 20 normal
10f0 svchost.exe 0 0 0
11e0 SearchIndexer.exe 0 0 0
1318 wmpnetwk.exe 0 0 0
12b8 WmiPrvSE.exe 0 0 0
12c4 OSPPSVC.EXE 0 0 0
13f4 chrome.exe 1 81 58 normal
11f8 chrome.exe 1 9 4 normal
0dcc chrome.exe 1 13 6 above normal
04b0 chrome.exe 1 4 1 normal
15cc wuauclt.exe 1 12 6 normal
0cc4 chrome.exe 1 4 1 normal
040c chrome.exe 1 4 1 idle
0c74 chrome.exe 1 4 3 normal
15a8 Store.exe 1 5092 899 normal C:\Program Files (x86)\Store
14b4 splwow64.exe 1 11 6 normal
0f9c DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
148c chrome.exe 1 4 1 idle
102c OIS.EXE 1 102 50 normal
0a44 OIS.EXE 1 117 49 normal
07dc audiodg.exe 0 0 0
0790 WmiPrvSE.exe 0 0 0
1524 VSSVC.exe 0 0 0
15e8 svchost.exe 0 0 0
11f0 rundll32.exe 1 116 51 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 045b35b0
ebx = 055ad2d0
ecx = 00000000
edx = 006ec401
esi = 00593a80
edi = 0018ea48
eip = 004075f4
esp = 0018e8b0
ebp = 0018e8c4
stack dump:
0018e8b0 35 72 6f 00 0f 00 00 00 - b0 35 5b 04 00 00 00 00 5ro......5[.....
0018e8c0 d0 2a 1e 0b d8 e8 18 00 - a8 f5 6f 00 d0 d2 5a 05 .*........o...Z.
0018e8d0 d0 d2 5a 05 30 cb 4e 06 - 3c ea 18 00 81 03 53 00 ..Z.0.N.<.....S.
0018e8e0 d0 d2 5a 05 85 3a 59 00 - 2a 08 53 00 12 00 0b 00 ..Z..:Y.*.S.....
0018e8f0 12 00 00 00 0b 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e900 21 00 00 00 16 00 00 00 - 12 00 0b 00 d0 d2 5a 05 !.............Z.
0018e910 48 ea 18 00 28 fe 52 00 - 12 00 0b 00 44 eb 18 00 H...(.R.....D...
0018e920 d0 d2 5a 05 d0 d2 5a 05 - cb 01 00 00 0b 00 00 00 ..Z...Z.........
0018e930 00 00 00 00 b0 e9 18 00 - 1f b0 9a 72 78 8e d9 05 ...........rx...
0018e940 74 03 36 00 02 02 00 00 - 0f 00 00 00 cb 01 0b 00 t.6.............
0018e950 00 00 00 00 bb 80 9a 72 - 8e 81 9a 72 00 00 00 00 .......r...r....
0018e960 cb 01 0b 00 74 03 36 00 - 00 00 00 00 00 00 00 00 ....t.6.........
0018e970 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e980 00 00 00 00 00 00 00 00 - 00 00 00 00 bb 80 9a 72 ...............r
0018e990 01 00 00 00 2c ea 18 00 - 00 00 00 00 00 00 01 00 ....,...........
0018e9a0 00 00 00 01 07 00 00 00 - 00 00 00 00 2c af 3f b6 ............,.?.
0018e9b0 dc e9 18 00 fa 62 72 77 - 74 03 36 00 02 02 00 00 .....brwt.6.....
0018e9c0 00 00 00 00 cb 01 0b 00 - bb 80 9a 72 cd ab ba dc ...........r....
0018e9d0 00 00 00 00 00 00 00 00 - f4 e9 18 00 63 fa 52 00 ............c.R.
0018e9e0 d0 d2 5a 05 0a b0 00 00 - 00 00 00 00 12 00 0b 00 ..Z.............
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 708 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $1388:
77c2f8da +0e ntdll.dll NtWaitForSingleObject
766d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
765c118f +3e kernel32.dll WaitForSingleObjectEx
765c1143 +0d kernel32.dll WaitForSingleObject
765c3368 +10 kernel32.dll BaseThreadInitThunk
thread $f04:
77c30166 +0e ntdll.dll NtWaitForMultipleObjects
765c3368 +10 kernel32.dll BaseThreadInitThunk
thread $f0c:
77c30166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
765c3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1590) at:
73c32713 +24f netbios.dll Netbios
thread $17ec:
77c2f8da +0e ntdll.dll NtWaitForSingleObject
766d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
765c118f +3e kernel32.dll WaitForSingleObjectEx
765c1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
765c3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1590) at:
73464c95 +00 winspool.drv
thread $b40:
77c31f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
765c3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02670000 WINPPLA.DLL C:\Program
Files (x86)\Store
026b0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
026e0000 BCLW32.dll C:\Program
Files (x86)\Store
062b0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063c0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
095f0000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6d0b0000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
6d0f0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
6daa0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
71330000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
71400000 slc.dll 6.1.7600.16385 C:\Windows\
system32
71740000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
717b0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71810000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71a60000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71be0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71d80000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71da0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
72080000 webio.dll 6.1.7601.23375 C:\Windows\
system32
720d0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72130000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72980000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
729a0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a40000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a80000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
732c0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
732f0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73350000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73450000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
734b0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73c30000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73c40000 security.dll 6.1.7600.16385 C:\Windows\
system32
73c50000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73d90000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73da0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73dc0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73dd0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73fe0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74000000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
745d0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74620000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74650000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74680000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
746c0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
746e0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
746f0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74700000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74760000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
747d0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74970000 version.dll 6.1.7600.16385 C:\Windows\
system32
74980000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
754a0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
754b0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75510000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75660000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75670000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75710000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
757b0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
759f0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75a10000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75a60000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75b10000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b40000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b50000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75b60000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75b70000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75c60000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75c70000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75e10000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75e80000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75ea0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75f50000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f60000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75ff0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
762a0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
762b0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
762f0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
763a0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
763b0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76440000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76570000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76580000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76590000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
765b0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
766c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76710000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
773f0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77550000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
77620000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77680000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
776e0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77710000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77be0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77c10000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 wininit.exe 0 0 0
0260 csrss.exe 1 0 0
0290 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
0308 svchost.exe 0 0 0
03f4 svchost.exe 0 0 0
041c svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
066c svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0784 svchost.exe 0 0 0
07a0 NetExpressUpdater.exe 0 0 0
01e4 svchost.exe 0 0 0
0554 scpbradserv.exe 0 0 0
06d0 svchost.exe 0 0 0
0708 core.exe 0 0 0
0928 RapportInjService_x64.exe 0 0 0
09b8 fbserver.exe 0 0 0
0b00 WUDFHost.exe 0 0 0
0bd0 NisSrv.exe 0 0 0
0e7c taskhost.exe 1 26 24 normal
0e94 core.exe 1 9 21 normal
0f58 sppsvc.exe 0 0 0
0cd8 GoogleCrashHandler.exe 0 0 0
0d08 GoogleCrashHandler64.exe 0 0 0
0d38 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0dd0 PresentationFontCache.exe 0 0 0
0de0 dwm.exe 1 16 4 high
0dfc explorer.exe 1 413 497 normal
0e28 RapportInjService_x64.exe 1 4 3 normal
0f68 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
00d8 igfxEM.exe 1 14 13 normal
03e4 igfxHK.exe 1 14 12 normal
0ec0 msseces.exe 1 143 59 normal
08f0 PrnStatusMX.exe 1 23 20 normal
10f0 svchost.exe 0 0 0
11e0 SearchIndexer.exe 0 0 0
1318 wmpnetwk.exe 0 0 0
12b8 WmiPrvSE.exe 0 0 0
12c4 OSPPSVC.EXE 0 0 0
13f4 chrome.exe 1 81 58 normal
11f8 chrome.exe 1 9 4 normal
0dcc chrome.exe 1 13 6 above normal
04b0 chrome.exe 1 4 1 normal
15cc wuauclt.exe 1 12 6 normal
0cc4 chrome.exe 1 4 1 normal
040c chrome.exe 1 4 1 idle
0c74 chrome.exe 1 4 3 normal
15a8 Store.exe 1 6453 1279 normal C:\Program Files (x86)\
Store
14b4 splwow64.exe 1 11 4 normal
0f9c DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
148c chrome.exe 1 4 1 idle
102c OIS.EXE 1 102 50 normal
0a44 OIS.EXE 1 117 49 normal
0818 audiodg.exe 0 0 0
14a0 rundll32.exe 1 116 53 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = fffffffc
ecx = 00000000
edx = 00000004
esi = 0b547754
edi = 0b547758
eip = 77c5eb23
esp = 0018da90
ebp = 0018dae0
stack dump:
0018da90 54 77 54 0b 58 77 54 0b - 28 db 18 00 00 00 00 00 TwT.XwT.(.......
0018daa0 00 00 00 00 54 0c 97 0c - 00 00 00 00 50 35 54 04 ....T.......P5T.
0018dab0 c8 da 18 00 36 57 55 55 - 55 55 55 a9 05 40 00 04 ....6WUUUUU..@..
0018dac0 10 79 1c 0f fc da 18 00 - 59 0d 6f 00 00 00 00 00 .y......Y.o.....
0018dad0 00 00 00 00 00 00 00 00 - 00 d0 fd 7e 80 04 00 00 ...........~....
0018dae0 08 db 18 00 32 ea c5 77 - 00 00 00 00 00 00 00 00 ....2..w........
0018daf0 28 db 18 00 ec d3 2e 0f - ff ff ff 00 04 00 00 00 (...............
0018db00 00 00 00 00 01 00 00 00 - 20 db 18 00 9d 42 50 00 ........ ....BP.
0018db10 54 77 54 0b 16 54 50 00 - c0 4b 31 0f c0 4b 31 0f TwT..TP..K1..K1.
0018db20 18 dc 18 00 df 54 50 00 - 00 00 00 00 ff ff ff 00 .....TP.........
0018db30 00 00 00 00 00 00 00 00 - 64 db 18 00 20 b6 8f 0f ........d... ...
0018db40 96 3c 6f 00 5c de 18 00 - 80 3a 59 00 20 b6 8f 0f .<o.\....:Y. ...
0018db50 00 00 00 00 89 00 00 00 - 50 19 00 00 11 12 00 00 ........P.......
0018db60 18 1a 00 00 29 2a 55 c1 - fe ff ff ff 51 6d 72 77 ....)*U.....Qmrw
0018db70 c4 77 72 77 00 00 00 00 - 54 0c 97 0c a6 09 0f 00 .wrw....T.......
0018db80 00 04 00 00 32 00 00 00 - 00 00 00 00 38 77 54 0b ....2.......8wT.
0018db90 e2 77 72 77 bd 9c 3f b6 - 00 00 00 00 00 00 10 ae .wrw..?.........
0018dba0 0a 40 00 00 69 07 73 77 - 00 00 00 00 00 00 00 c8 [email protected]........
0018dbb0 05 40 00 00 94 db 18 00 - 01 00 00 00 64 00 00 00 [email protected]...
0018dbc0 00 dc 18 00 50 e0 5d 01 - 00 00 00 00 50 dc 18 00 ....P.].....P...
disassembling:
[...]
006f3c66 jnz loc_6f3cba
006f3c68 3271 mov eax, [ebp-4]
006f3c6b mov eax, [eax+$300]
006f3c71 mov eax, [eax+$36c]
006f3c77 call +$18ea0 ($70cb1c) ; QRPrntr.TQRPrinter.GetCanvas
006f3c7c mov [ebp-$8c], eax
006f3c82 3273 mov eax, [ebp-$8c]
006f3c88 mov eax, [eax+$48]
006f3c8b mov edx, [ebp-4]
006f3c8e mov edx, [edx+$74]
006f3c91 > call -$1ee80e ($505488) ; Vcl.Graphics.TBrush.SetColor
006f3c96 3274 mov eax, [ebp-$8c]
006f3c9c mov eax, [eax+$48]
006f3c9f xor edx, edx
006f3ca1 call -$1ee69e ($505608) ; Vcl.Graphics.TBrush.SetStyle
006f3ca6 3275 mov eax, [ebp-4]
006f3ca9 lea edx, [eax+$2bc]
006f3caf mov eax, [ebp-$8c]
006f3cb5 mov ecx, [eax]
006f3cb7 call dword ptr [ecx+$54]
006f3cba 3278 mov eax, [ebp-4]
[...]
thread $c80:
77c2f8da +0e ntdll.dll NtWaitForSingleObject
766d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
765c118f +3e kernel32.dll WaitForSingleObjectEx
765c1143 +0d kernel32.dll WaitForSingleObject
765c3368 +10 kernel32.dll BaseThreadInitThunk
thread $5ec:
77c30166 +0e ntdll.dll NtWaitForMultipleObjects
765c3368 +10 kernel32.dll BaseThreadInitThunk
thread $16fc:
77c2f8da +0e ntdll.dll NtWaitForSingleObject
766d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
765c118f +3e kernel32.dll WaitForSingleObjectEx
765c1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
765c3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($11c4) at:
73464c95 +00 winspool.drv
thread $afc:
77c31f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
765c3368 +10 kernel32.dll BaseThreadInitThunk
thread $1074:
77c31f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
765c3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00390000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
062c0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063d0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06590000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6daa0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
71740000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
717b0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71810000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71a60000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71be0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71d80000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71da0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
72080000 webio.dll 6.1.7601.23375 C:\Windows\
system32
720d0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72130000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72980000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
729a0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a40000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a80000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
732c0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
732f0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73350000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73450000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
734b0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73c40000 security.dll 6.1.7600.16385 C:\Windows\
system32
73c50000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73d90000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73da0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73dc0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73dd0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73fe0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74000000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74620000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74650000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74680000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
746c0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
746e0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
746f0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74700000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74760000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
747d0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74970000 version.dll 6.1.7600.16385 C:\Windows\
system32
74980000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
754a0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
754b0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75510000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75660000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75670000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75710000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
757b0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
759f0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75a10000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75a60000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75b10000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b40000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b50000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75b60000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75b70000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75c60000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75c70000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75e10000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75e80000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75ea0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75f50000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f60000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75ff0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
762a0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
762b0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
762f0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
763a0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
763b0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76440000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76570000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76580000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76590000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
765b0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
766c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76710000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
773f0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77550000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
77620000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77680000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
776e0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77710000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77be0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77c10000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 wininit.exe 0 0 0
0260 csrss.exe 1 0 0
0290 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
0308 svchost.exe 0 0 0
03f4 svchost.exe 0 0 0
041c svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
066c svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0784 svchost.exe 0 0 0
07a0 NetExpressUpdater.exe 0 0 0
01e4 svchost.exe 0 0 0
0554 scpbradserv.exe 0 0 0
06d0 svchost.exe 0 0 0
0708 core.exe 0 0 0
0928 RapportInjService_x64.exe 0 0 0
09b8 fbserver.exe 0 0 0
0b00 WUDFHost.exe 0 0 0
0bd0 NisSrv.exe 0 0 0
0e7c taskhost.exe 1 26 23 normal
0e94 core.exe 1 9 21 normal
0f58 sppsvc.exe 0 0 0
0cd8 GoogleCrashHandler.exe 0 0 0
0d08 GoogleCrashHandler64.exe 0 0 0
0d38 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0dd0 PresentationFontCache.exe 0 0 0
0de0 dwm.exe 1 17 4 high
0dfc explorer.exe 1 451 508 normal
0e28 RapportInjService_x64.exe 1 4 3 normal
0f68 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
00d8 igfxEM.exe 1 14 13 normal
03e4 igfxHK.exe 1 14 12 normal
0ec0 msseces.exe 1 143 59 normal
08f0 PrnStatusMX.exe 1 23 20 normal
10f0 svchost.exe 0 0 0
11e0 SearchIndexer.exe 0 0 0
1318 wmpnetwk.exe 0 0 0
12b8 WmiPrvSE.exe 0 0 0
12c4 OSPPSVC.EXE 0 0 0
13f4 chrome.exe 1 81 57 normal
11f8 chrome.exe 1 9 4 normal
0dcc chrome.exe 1 13 6 above normal
04b0 chrome.exe 1 4 1 normal
15cc wuauclt.exe 1 12 6 normal
0cc4 chrome.exe 1 4 1 idle
040c chrome.exe 1 4 1 idle
0c74 chrome.exe 1 4 3 normal
15a8 Store.exe 1 6428 1264 normal C:\Program Files (x86)\
Store
14b4 splwow64.exe 1 11 6 normal
0f9c DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
148c chrome.exe 1 4 1 idle
102c OIS.EXE 1 102 50 normal
0a44 OIS.EXE 1 117 49 normal
0818 audiodg.exe 0 0 0
0f18 Store.exe 1 512 170 normal C:\Program Files (x86)\
Store
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0018fe28
ebx = 004075b1
ecx = 00000007
edx = 00000000
esi = 004075b1
edi = 042e4e90
eip = 766cc54f
esp = 0018fe28
ebp = 0018fe78
stack dump:
0018fe28 de fa ed 0e 01 00 00 00 - 00 00 00 00 4f c5 6c 76 ............O.lv
0018fe38 07 00 00 00 b1 75 40 00 - 58 80 3d 04 b1 75 40 00 [email protected].=..u@.
0018fe48 b1 75 40 00 90 4e 2e 04 - c4 fe 18 00 ac fe 18 00 [email protected]..........
0018fe58 df 60 4d 00 90 4e 2e 04 - b1 75 40 00 c4 fe 18 00 .`M..N...u@.....
0018fe68 7c fe 18 00 b1 75 40 00 - 4c fe 18 00 dc da 44 00 |[email protected].
0018fe78 c4 fe 18 00 b1 75 40 00 - de fa ed 0e 01 00 00 00 .....u@.........
0018fe88 07 00 00 00 90 fe 18 00 - b1 75 40 00 58 80 3d 04 [email protected].=.
0018fe98 b1 75 40 00 b1 75 40 00 - 90 4e 2e 04 c4 fe 18 00 [email protected]@..N......
0018fea8 ac fe 18 00 02 00 00 00 - f4 4c 40 00 00 c4 17 0b .........L@.....
0018feb8 00 c4 17 0b 37 4d 40 00 - 00 c4 17 02 f4 fe 18 00 ....7M@.........
0018fec8 b1 75 40 00 00 c4 17 0b - 5c 76 4d 00 01 27 01 8a .u@.....\vM..'..
0018fed8 cc 3c 48 00 80 bf 60 0a - 02 00 00 00 f7 75 40 00 .<H...`......u@.
0018fee8 5a 5b 6f 00 ac 7c 40 00 - 90 4e 2e 04 04 ff 18 00 Z[o..|@..N......
0018fef8 d3 9c 6f 00 e9 2d 53 01 - 90 4e 2e 04 40 ff 18 00 ..o..-S..N..@...
0018ff08 3d 1b 53 00 00 66 47 06 - f8 a1 3c 04 80 bf 60 0a =.S..fG...<...`.
0018ff18 00 00 00 00 2c 9f 60 00 - 80 bf 60 0a 50 e0 38 04 ....,.`...`.P.8.
0018ff28 06 b1 60 00 78 ff 18 00 - 0c 89 40 00 40 ff 18 00 ..`.x.....@.@...
0018ff38 f8 a1 3c 01 80 bf 60 0a - 88 ff 18 00 56 03 49 00 ..<...`.....V.I.
0018ff48 54 e0 60 01 18 0b 61 01 - c8 8c 60 00 02 8d 60 00 T.`...a...`...`.
0018ff58 0c 1e 45 00 e4 1d 45 00 - af 90 40 00 88 ff 18 00 ..E...E...@.....
disassembling:
004075a0 public System.TObject.FreeInstance: ; function entry point
004075a0 708 push ebx
004075a1 mov ebx, eax
004075a3 mov eax, ebx
004075a5 call +$a6 ($407650) ; System.TObject.CleanupInstance
004075aa mov eax, ebx
004075ac call -$29fd ($404bb4) ; System.@FreeMem
004075b1 > pop ebx
004075b2 ret
thread $1104:
76ed0166 +0e ntdll.dll NtWaitForMultipleObjects
749e3368 +10 kernel32.dll BaseThreadInitThunk
thread $1050:
76ed0166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
749e3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1194) at:
731a2713 +24f netbios.dll Netbios
thread $1058:
76ecf8da +0e ntdll.dll NtWaitForSingleObject
75ca15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
749e118f +3e kernel32.dll WaitForSingleObjectEx
749e1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
749e3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1194) at:
73344c95 +00 winspool.drv
thread $c08:
76ed1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
749e3368 +10 kernel32.dll BaseThreadInitThunk
thread $1578:
76ed1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
749e3368 +10 kernel32.dll BaseThreadInitThunk
modules:
002b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00390000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
04400000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06330000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06bb0000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70760000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
709e0000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
70a00000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
70a10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70a40000 webio.dll 6.1.7601.23375 C:\Windows\
system32
70a90000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70ad0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
70c70000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
70d00000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
70d10000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70d30000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
70d40000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
70d90000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
70da0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71030000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71740000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71760000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71a50000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
71ce0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71d20000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
71ed0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
71ef0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
71f00000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72590000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
72cf0000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
72fb0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73030000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73040000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73060000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73070000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
730a0000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
73100000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73110000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73120000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73170000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
731a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
731b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
731c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
731d0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73230000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73330000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73480000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73870000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
738c0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
738f0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73920000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73960000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73980000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73990000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
739a0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
739b0000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
73a00000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73a40000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
73a50000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
73a70000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73c10000 version.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74740000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74750000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
747b0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
74840000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
748c0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
748f0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74940000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
749d0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
74ae0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74af0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75740000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75870000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75880000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75980000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
759e0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75c90000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75ce0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75cf0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75d10000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75db0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75e50000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75e80000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75ec0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75ee0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76040000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76050000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76060000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76070000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76340000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76350000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
764f0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76570000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76580000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76630000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76690000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
766a0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
766b0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76800000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76900000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
769b0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
769c0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76e80000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76eb0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0344 svchost.exe 0 0 0
021c svchost.exe 0 0 0
042c svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0650 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
0764 fbguard.exe 0 0 0
0784 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
046c svchost.exe 0 0 0
059c scpbradserv.exe 0 0 0
06cc svchost.exe 0 0 0
0814 core.exe 0 0 0
0864 RapportInjService_x64.exe 0 0 0
0a10 fbserver.exe 0 0 0
0b84 WUDFHost.exe 0 0 0
05e4 NisSrv.exe 0 0 0
0f08 WmiPrvSE.exe 0 0 0
0f38 OSPPSVC.EXE 0 0 0
0e50 taskhost.exe 1 26 24 normal
0e6c core.exe 1 9 20 normal
0ef8 sppsvc.exe 0 0 0
0144 GoogleCrashHandler.exe 0 0 0
0494 GoogleCrashHandler64.exe 0 0 0
0d78 svchost.exe 0 0 0
0db0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0884 PresentationFontCache.exe 0 0 0
0e2c dwm.exe 1 17 4 high
09f4 explorer.exe 1 421 260 normal
0a20 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f04 igfxEM.exe 1 14 14 normal
0f4c igfxHK.exe 1 14 12 normal
0d90 RapportInjService_x64.exe 1 4 3 normal
0894 msseces.exe 1 143 59 normal
0ef0 PrnStatusMX.exe 1 23 20 normal
11dc SearchIndexer.exe 0 0 0
1268 wmpnetwk.exe 0 0 0
1190 Store.exe 1 1050 371 normal C:\Program Files (x86)\Store
1060 slui.exe 1 47 31 normal
1040 wuauclt.exe 1 12 6 normal
10b0 splwow64.exe 1 9 2 normal
12f8 chrome.exe 1 26 51 normal
0858 chrome.exe 1 9 4 normal
0d64 chrome.exe 1 7 6 above normal
0d44 chrome.exe 1 4 1 normal
1748 chrome.exe 1 4 1 normal
1434 chrome.exe 1 4 3 normal
06d8 OIS.EXE 1 133 51 normal
1170 audiodg.exe 0 0 0
0544 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0047002e
ebx = 044f4000
ecx = 006f73dc
edx = 044f4000
esi = 0447464f
edi = 00000000
eip = 006d0069
esp = 0018cc88
ebp = 0018cca4
stack dump:
0018cc88 67 d2 70 00 34 ce 18 00 - 0c 89 40 00 a4 cc 18 00 g.p.4.....@.....
0018cc98 64 ce 18 00 18 2f 41 00 - 00 40 4f 04 b4 cc 18 00 d..../A..@O.....
0018cca8 2c 74 6f 00 64 ce 18 00 - 50 46 47 04 e0 cd 18 00 ,to.d...PFG.....
0018ccb8 28 fe 52 00 00 00 00 00 - 41 04 b9 06 50 46 47 04 (.R.....A...PFG.
0018ccc8 50 46 47 04 7c ce 18 00 - 28 fe 52 00 01 00 00 00 PFG.|...(.R.....
0018ccd8 41 04 b9 06 50 46 47 04 - 9c cc 18 00 01 00 00 00 A...PFG.........
0018cce8 18 cf 18 00 b6 a6 87 76 - 04 5a ff 7c fe ff ff ff .......v.Z.|....
0018ccf8 51 6d 81 76 3f 0d 82 76 - 00 00 00 00 18 2f 41 00 Qm.v?..v...../A.
0018cd08 4e 05 0e 00 30 00 00 00 - be 0f 0a 77 01 00 00 00 N...0......w....
0018cd18 00 00 00 00 00 00 00 00 - 30 00 00 00 50 46 47 04 ........0...PFG.
0018cd28 04 c4 6e 00 00 00 00 00 - 50 cd 18 00 65 0d 82 76 ..n.....P...e..v
0018cd38 18 2f 41 00 4e 05 0e 00 - 30 00 00 00 be 0f 0a 77 ./A.N...0......w
0018cd48 01 00 00 00 00 00 00 00 - a4 ce 18 00 85 48 53 00 .............HS.
0018cd58 18 2f 41 00 4e 05 0e 00 - 30 00 00 00 be 0f 0a 77 ./A.N...0......w
0018cd68 01 00 00 00 a4 ce 18 00 - 50 46 47 04 50 46 47 04 ........PFG.PFG.
0018cd78 fc ce 18 00 28 fe 52 00 - 50 46 47 04 50 46 47 04 ....(.R.PFG.PFG.
0018cd88 50 46 47 04 ef 47 ee 76 - 01 00 00 00 00 00 40 00 PFG..G.v......@.
0018cd98 00 00 00 00 00 00 00 00 - a4 cd 18 00 f4 fa 66 0a ..............f.
0018cda8 5c ce 18 00 44 aa 81 76 - 00 00 01 00 14 ce 18 00 \...D..v........
0018cdb8 00 00 00 00 00 00 00 46 - 2f 01 00 00 b2 00 00 00 .......F/.......
disassembling:
[...]
0070d240 cmp byte ptr [eax+$8d], 1
0070d247 jnz loc_70d251
0070d249 mov eax, [ebp-4]
0070d24c call -$341 ($70cf10) ; QRPrntr.TQRPrinter.Cancel
0070d251 3858 mov eax, [ebp-4]
0070d254 cmp word ptr [eax+$1a], 0
0070d259 jz loc_70d267
0070d25b 3859 mov ebx, [ebp-4]
0070d25e mov edx, [ebp-4]
0070d261 mov eax, [ebx+$1c]
0070d264 > call dword ptr [ebx+$18]
0070d267 xor eax, eax
0070d269 pop edx
0070d26a pop ecx
0070d26b pop ecx
0070d26c mov fs:[eax], edx
0070d26f push $70d294
0070d274 3861 mov eax, [ebp-4]
0070d277 mov dl, [ebp-5]
0070d27a mov [eax+$8c], dl
0070d280 ret
[...]
thread $110c:
76ecf8da +0e ntdll.dll NtWaitForSingleObject
75ca15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
749e118f +3e kernel32.dll WaitForSingleObjectEx
749e1143 +0d kernel32.dll WaitForSingleObject
749e3368 +10 kernel32.dll BaseThreadInitThunk
thread $1104:
76ed0166 +0e ntdll.dll NtWaitForMultipleObjects
749e3368 +10 kernel32.dll BaseThreadInitThunk
thread $1050:
76ed0166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
749e3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1194) at:
731a2713 +24f netbios.dll Netbios
thread $1058:
76ecf8da +0e ntdll.dll NtWaitForSingleObject
75ca15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
749e118f +3e kernel32.dll WaitForSingleObjectEx
749e1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
749e3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1194) at:
73344c95 +00 winspool.drv
thread $c08:
76ed1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
749e3368 +10 kernel32.dll BaseThreadInitThunk
thread $1578:
76ed1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
749e3368 +10 kernel32.dll BaseThreadInitThunk
modules:
002b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00390000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
04400000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06330000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06bb0000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70760000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
709e0000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
70a00000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
70a10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70a40000 webio.dll 6.1.7601.23375 C:\Windows\
system32
70a90000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70ad0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
70c70000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
70d00000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
70d10000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70d30000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
70d40000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
70d90000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
70da0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71030000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71740000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71760000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71a50000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
71ce0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71d20000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
71ed0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
71ef0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
71f00000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72590000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
72cf0000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
72fb0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73030000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73040000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73060000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73070000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
730a0000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
73100000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73110000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73120000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73170000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
731a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
731b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
731c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
731d0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73230000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73330000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73480000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73870000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
738c0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
738f0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73920000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73960000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73980000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73990000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
739a0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
739b0000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
73a00000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73a40000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
73a50000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
73a70000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73c10000 version.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74740000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74750000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
747b0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
74840000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
748c0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
748f0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74940000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
749d0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
74ae0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74af0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75740000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75870000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75880000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75980000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
759e0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75c90000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75ce0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75cf0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75d10000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75db0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75e50000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75e80000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75ec0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75ee0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76040000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76050000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76060000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76070000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76340000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76350000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
764f0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76570000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76580000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76630000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76690000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
766a0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
766b0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76800000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76900000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
769b0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
769c0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76e80000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76eb0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0344 svchost.exe 0 0 0
021c svchost.exe 0 0 0
042c svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0650 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
0764 fbguard.exe 0 0 0
0784 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
046c svchost.exe 0 0 0
059c scpbradserv.exe 0 0 0
06cc svchost.exe 0 0 0
0814 core.exe 0 0 0
0864 RapportInjService_x64.exe 0 0 0
0a10 fbserver.exe 0 0 0
0b84 WUDFHost.exe 0 0 0
05e4 NisSrv.exe 0 0 0
0f08 WmiPrvSE.exe 0 0 0
0f38 OSPPSVC.EXE 0 0 0
0e50 taskhost.exe 1 26 23 normal
0e6c core.exe 1 9 20 normal
0ef8 sppsvc.exe 0 0 0
0144 GoogleCrashHandler.exe 0 0 0
0494 GoogleCrashHandler64.exe 0 0 0
0d78 svchost.exe 0 0 0
0db0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0884 PresentationFontCache.exe 0 0 0
0e2c dwm.exe 1 17 4 high
09f4 explorer.exe 1 421 264 normal
0a20 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f04 igfxEM.exe 1 14 14 normal
0f4c igfxHK.exe 1 14 12 normal
0d90 RapportInjService_x64.exe 1 4 3 normal
0894 msseces.exe 1 143 59 normal
0ef0 PrnStatusMX.exe 1 23 20 normal
11dc SearchIndexer.exe 0 0 0
1268 wmpnetwk.exe 0 0 0
1190 Store.exe 1 1035 365 normal C:\Program Files (x86)\Store
1060 slui.exe 1 47 31 normal
1040 wuauclt.exe 1 12 6 normal
10b0 splwow64.exe 1 9 2 normal
12f8 chrome.exe 1 26 51 normal
0858 chrome.exe 1 9 4 normal
0d64 chrome.exe 1 7 6 above normal
0d44 chrome.exe 1 4 1 normal
1748 chrome.exe 1 4 1 normal
1434 chrome.exe 1 4 3 normal
06d8 OIS.EXE 1 133 51 normal
1170 audiodg.exe 0 0 0
0544 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 044f4c00
ebx = 0aff6280
ecx = 000204b0
edx = 044e4701
esi = 0aff627f
edi = 0018e368
eip = 00340037
esp = 0018e0b0
ebp = 0018e0c0
stack dump:
0018e0b0 f7 75 40 00 e4 5b 6f 00 - ac 7c 40 00 50 46 47 04 .u@..[o..|@.PFG.
0018e0c0 d0 e0 18 00 d3 9c 6f 00 - 80 62 ff 01 50 46 47 04 ......o..b..PFG.
0018e0d0 2c e1 18 00 f7 75 40 00 - 47 38 ed 00 34 e1 18 00 ,[email protected]...
0018e0e0 0c 89 40 00 2c e1 18 00 - 00 00 00 00 00 00 00 00 ..@.,...........
0018e0f0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e100 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e110 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e120 00 00 00 00 d0 02 28 0b - b0 52 47 04 b0 e1 18 00 ......(..RG.....
0018e130 c9 cf ec 00 18 e5 18 00 - 0c 89 40 00 b0 e1 18 00 ..........@.....
0018e140 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e150 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e160 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e170 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e180 00 00 00 00 00 00 00 00 - 00 00 00 00 80 62 ff 0a .............b..
0018e190 20 7f 52 04 c0 81 52 04 - 60 84 52 04 60 99 52 04 .R...R.`.R.`.R.
0018e1a0 80 67 52 04 c0 6c 52 04 - 20 6a 52 04 b0 52 47 04 .gR..lR. jR..RG.
0018e1b0 00 e3 18 00 81 03 53 00 - 80 62 ff 0a c7 33 55 00 ......S..b...3U.
0018e1c0 68 e3 18 00 f6 42 62 00 - 4c 42 62 00 68 e3 18 00 h....Bb.LBb.h...
0018e1d0 f5 3e 55 00 80 62 ff 0a - 28 fe 52 00 68 e3 18 00 .>U..b..(.R.h...
0018e1e0 48 e5 18 00 80 62 ff 0a - f3 00 00 00 05 8b 83 76 H....b.........v
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 708 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $528:
76f9f8da +0e ntdll.dll NtWaitForSingleObject
74e515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
764b118f +3e kernel32.dll WaitForSingleObjectEx
764b1143 +0d kernel32.dll WaitForSingleObject
764b3368 +10 kernel32.dll BaseThreadInitThunk
thread $118c:
76fa0166 +0e ntdll.dll NtWaitForMultipleObjects
764b3368 +10 kernel32.dll BaseThreadInitThunk
thread $e00:
76fa0166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
764b3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($378) at:
72fc2713 +24f netbios.dll Netbios
thread $16a4:
76f9f8da +0e ntdll.dll NtWaitForSingleObject
74e515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
764b118f +3e kernel32.dll WaitForSingleObjectEx
764b1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
764b3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($378) at:
72544c95 +00 winspool.drv
thread $132c:
76fa1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
764b3368 +10 kernel32.dll BaseThreadInitThunk
thread $1290:
76fa1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
764b3368 +10 kernel32.dll BaseThreadInitThunk
thread $d80:
76fa1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
764b3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00350000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00380000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
06290000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063a0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70bd0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70f30000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70f70000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70f90000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
70fc0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71150000 webio.dll 6.1.7601.23375 C:\Windows\
system32
711a0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71200000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71a70000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71a90000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71db0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71df0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
71fa0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
71fc0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
71fd0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
722a0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
723a0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
723d0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
72430000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72530000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
72590000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
72fc0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
72fd0000 security.dll 6.1.7600.16385 C:\Windows\
system32
72fe0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
72ff0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73070000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
733c0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
734a0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73520000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73530000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73550000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73560000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73940000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73990000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
739c0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
739f0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73a30000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73a50000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73a60000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73a70000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73ad0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73b40000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73ce0000 version.dll 6.1.7600.16385 C:\Windows\
system32
73cf0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74810000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74820000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74880000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
74970000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
74980000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
749e0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
74a70000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
74b10000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74b20000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
74bb0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
74be0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
74c20000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
74c30000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
74d60000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
74e40000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74e90000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
74f50000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75ba0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75bb0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75c80000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75d80000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d90000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75da0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75e20000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75e30000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75f90000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75fa0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76040000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76090000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
760a0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
761f0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
764a0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
765b0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
765e0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76660000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76680000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76690000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76830000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76850000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
768b0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76f50000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76f80000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02cc svchost.exe 0 0 0
03f0 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
055c svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06e8 atkexComSvc.exe 0 0 0
072c svchost.exe 0 0 0
0750 fbguard.exe 0 0 0
0774 svchost.exe 0 0 0
0788 NetExpressUpdater.exe 0 0 0
07f0 svchost.exe 0 0 0
04e0 scpbradserv.exe 0 0 0
0498 svchost.exe 0 0 0
074c core.exe 0 0 0
0908 RapportInjService_x64.exe 0 0 0
09ec fbserver.exe 0 0 0
0b6c WUDFHost.exe 0 0 0
05bc NisSrv.exe 0 0 0
0d70 taskhost.exe 1 26 21 normal
0d88 core.exe 1 9 21 normal
0edc sppsvc.exe 0 0 0
0d84 RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0fb0 RapportInjService_x64.exe 1 4 3 normal
07e4 GoogleCrashHandler.exe 0 0 0
016c GoogleCrashHandler64.exe 0 0 0
0eec svchost.exe 0 0 0
10c8 WmiPrvSE.exe 0 0 0
10f4 OSPPSVC.EXE 0 0 0
11d0 PresentationFontCache.exe 0 0 0
11d8 dwm.exe 1 17 4 high
11e4 explorer.exe 1 647 447 normal
1228 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
12b8 igfxEM.exe 1 14 13 normal
12c8 igfxHK.exe 1 14 13 normal
1360 msseces.exe 1 143 59 normal
1368 PrnStatusMX.exe 1 23 20 normal
1184 SearchIndexer.exe 0 0 0
0dc0 wmpnetwk.exe 0 0 0
1134 wuauclt.exe 1 12 7 normal
1124 Store.exe 1 2591 638 normal C:\Program Files (x86)\Store
0814 chrome.exe 1 75 52 normal
12a8 chrome.exe 1 9 4 normal
0e04 chrome.exe 1 12 6 above normal
0e74 chrome.exe 1 4 1 normal
0b50 chrome.exe 1 4 1 normal
16cc chrome.exe 1 4 1 idle
1784 chrome.exe 1 4 3 normal
04ac splwow64.exe 1 9 3 normal
1588 slui.exe 1 43 31 normal
06e0 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
07f8 OIS.EXE 1 102 44 normal
10a8 OIS.EXE 1 131 50 normal
073c OIS.EXE 1 106 46 normal
163c rundll32.exe 1 116 53 normal
0300 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 0a562780
ecx = 04482190
edx = 0447e570
esi = 00593a80
edi = 0018de5c
eip = 006ff5b1
esp = 0018dce0
ebp = 0018dcec
stack dump:
0018dce0 80 27 56 0a 80 27 56 0a - 70 c1 ff 0a 50 de 18 00 .'V..'V.p...P...
0018dcf0 81 03 53 00 80 27 56 0a - 85 3a 59 00 2a 08 53 00 ..S..'V..:Y.*.S.
0018dd00 10 00 08 00 10 00 00 00 - 08 00 00 00 00 00 00 00 ................
0018dd10 00 00 00 00 21 00 00 00 - 16 00 00 00 10 00 08 00 ....!...........
0018dd20 80 27 56 0a 5c de 18 00 - 28 fe 52 00 10 00 08 00 .'V.\...(.R.....
0018dd30 58 df 18 00 80 27 56 0a - 80 27 56 0a c9 01 00 00 X....'V..'V.....
0018dd40 08 00 00 00 00 00 00 00 - c4 dd 18 00 1f b0 a9 71 ...............q
0018dd50 c8 be 2c 0a 38 07 0b 00 - 02 02 00 00 0f 00 00 00 ..,.8...........
0018dd60 c9 01 08 00 00 00 00 00 - bb 80 a9 71 8e 81 a9 71 ...........q...q
0018dd70 00 00 00 00 c9 01 08 00 - 38 07 0b 00 00 00 00 00 ........8.......
0018dd80 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd90 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dda0 bb 80 a9 71 01 00 00 00 - 40 de 18 00 00 00 00 00 ...q....@.......
0018ddb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ddc0 a2 f8 ba a0 f0 dd 18 00 - fa 62 c9 75 38 07 0b 00 .........b.u8...
0018ddd0 02 02 00 00 00 00 00 00 - c9 01 08 00 bb 80 a9 71 ...............q
0018dde0 cd ab ba dc 00 00 00 00 - 00 00 00 00 08 de 18 00 ................
0018ddf0 63 fa 52 00 80 27 56 0a - 0a b0 00 00 00 00 00 00 c.R..'V.........
0018de00 10 00 08 00 01 00 00 00 - 3c de 18 00 d5 3e 53 00 ........<....>S.
0018de10 10 00 08 00 10 1a 48 04 - 00 00 00 00 00 00 00 00 ......H.........
disassembling:
[...]
006ff58a test al, al
006ff58c jnz loc_6ff59e
006ff58e 402 mov eax, [ebp-4]
006ff591 mov eax, [eax+$460]
006ff597 call +$eb20 ($70e0bc) ; QRPrntr.TQRPrinter.Print
006ff59c jmp loc_6ff5d3
006ff59e 405 mov eax, [$16148d8]
006ff5a3 call -$84ac ($6f70fc) ; QuickRpt.TCustomQuickRep.Print
006ff5a8 407 mov eax, [ebp-4]
006ff5ab mov eax, [eax+$3cc]
006ff5b1 > cmp dword ptr [eax+$2b8], 0
006ff5b8 jnz loc_6ff5d3
006ff5ba 409 mov eax, [$16148d8]
006ff5bf mov edx, [eax+$36c]
006ff5c5 mov eax, [ebp-4]
006ff5c8 mov eax, [eax+$3cc]
006ff5ce call +$a6f5 ($709cc8) ; QRPrntr.TQRPreview.SetQRPrinter
006ff5d3 412 pop ebx
006ff5d4 pop ecx
006ff5d5 pop ecx
006ff5d6 pop ebp
[...]
thread $11d8:
7741f8da +0e ntdll.dll NtWaitForSingleObject
76cd15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7634118f +3e kernel32.dll WaitForSingleObjectEx
76341143 +0d kernel32.dll WaitForSingleObject
76343368 +10 kernel32.dll BaseThreadInitThunk
thread $11dc:
77420166 +0e ntdll.dll NtWaitForMultipleObjects
76343368 +10 kernel32.dll BaseThreadInitThunk
thread $11f4:
77420166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
76343368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($11c4) at:
739a2713 +24f netbios.dll Netbios
thread $11a8:
7741f8da +0e ntdll.dll NtWaitForSingleObject
76cd15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7634118f +3e kernel32.dll WaitForSingleObjectEx
76341143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
76343368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($11c4) at:
737f4c95 +00 winspool.drv
thread $760:
77421f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76343368 +10 kernel32.dll BaseThreadInitThunk
modules:
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02670000 WINPPLA.DLL C:\Program
Files (x86)\Store
026b0000 BCLW32.dll C:\Program
Files (x86)\Store
04720000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062f0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70f10000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71050000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
710f0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71110000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71430000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
715d0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71620000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71680000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72170000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72190000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72230000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72270000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72420000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72440000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72450000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72c60000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73480000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
734b0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73510000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
737e0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73930000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73940000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73960000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73970000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
739a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
739b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
739c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73a10000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73a60000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73ab0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73d10000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73d30000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73dc0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73e10000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73e40000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73e70000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73eb0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73ed0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73ee0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73ef0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73f50000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73fc0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74160000 version.dll 6.1.7600.16385 C:\Windows\
system32
74170000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74c90000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74ca0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74d00000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74d60000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74d70000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
74ea0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
74eb0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74f60000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75bb0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75c80000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75d30000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d40000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75dd0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75e00000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75f00000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75f40000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
760e0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
760f0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76100000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76110000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76120000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76140000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
761a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76200000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76290000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76330000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76440000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76450000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
765a0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
767e0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76940000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76bf0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76c10000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76cb0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76cc0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76d10000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76dc0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76ec0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76ee0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76f80000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
773d0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77400000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0344 svchost.exe 0 0 0
0218 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0520 igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0654 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
03f4 svchost.exe 0 0 0
0564 scpbradserv.exe 0 0 0
041c svchost.exe 0 0 0
0748 core.exe 0 0 0
094c RapportInjService_x64.exe 0 0 0
09e8 fbserver.exe 0 0 0
0b4c WUDFHost.exe 0 0 0
0988 NisSrv.exe 0 0 0
0e84 WmiPrvSE.exe 0 0 0
0eb0 OSPPSVC.EXE 0 0 0
0d04 taskhost.exe 1 26 23 normal
0d3c core.exe 1 9 21 normal
0dd8 sppsvc.exe 0 0 0
02f8 GoogleCrashHandler.exe 0 0 0
03d4 GoogleCrashHandler64.exe 0 0 0
0864 RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0a30 RapportInjService_x64.exe 1 4 3 normal
0720 svchost.exe 0 0 0
0fa8 PresentationFontCache.exe 0 0 0
0dcc dwm.exe 1 20 5 high
0c90 explorer.exe 1 621 399 normal
0a48 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f14 igfxEM.exe 1 14 13 normal
0b10 igfxHK.exe 1 14 13 normal
0890 msseces.exe 1 143 59 normal
065c SearchIndexer.exe 0 0 0
0f08 PrnStatusMX.exe 1 23 20 normal
126c wmpnetwk.exe 0 0 0
11c0 Store.exe 1 3909 721 normal C:\Program Files (x86)\Store
10a4 wuauclt.exe 1 12 6 normal
0d48 splwow64.exe 1 9 4 normal
0770 OIS.EXE 1 117 49 normal
1240 OIS.EXE 1 137 50 normal
1554 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
1740 OIS.EXE 1 107 47 normal
0664 OIS.EXE 1 102 44 normal
0ce8 OIS.EXE 1 139 53 normal
1494 OIS.EXE 1 121 50 normal
14bc chrome.exe 1 28 50 normal
15e4 chrome.exe 1 9 4 normal
06c0 chrome.exe 1 7 7 above normal
12fc chrome.exe 1 4 1 normal
11bc chrome.exe 1 4 1 normal
0868 chrome.exe 1 4 1 idle
0478 chrome.exe 1 4 3 normal
04c0 OIS.EXE 1 122 51 normal
1440 OIS.EXE 1 139 54 normal
12dc OIS.EXE 1 127 56 normal
1550 audiodg.exe 0 0 0
14d4 rundll32.exe 1 116 52 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 0a3f0020
ecx = 00705ab8
edx = 0018df01
esi = 00593a80
edi = 0018de5c
eip = 0070c5fe
esp = 0018dc90
ebp = 0018dc98
stack dump:
0018dc90 ac 7c 40 00 f0 3f 50 04 - b8 dc 18 00 fd bf 70 00 .|@..?P.......p.
0018dca0 00 00 00 00 80 01 00 01 - 06 00 00 00 80 3a 59 00 .............:Y.
0018dcb0 c0 bf 65 01 f0 3f 50 04 - d8 dc 18 00 f7 75 40 00 ..e..?P......u@.
0018dcc0 f4 71 6f 00 41 72 6f 00 - 0f 00 00 00 10 3e 50 04 .qo.Aro......>P.
0018dcd0 80 b5 09 0c c0 bf 65 0d - ec dc 18 00 a8 f5 6f 00 ......e.......o.
0018dce0 20 00 3f 0a 20 00 3f 0a - 90 82 43 06 50 de 18 00 .?. .?...C.P...
0018dcf0 81 03 53 00 20 00 3f 0a - 85 3a 59 00 2a 08 53 00 ..S. .?..:Y.*.S.
0018dd00 13 00 04 00 13 00 00 00 - 04 00 00 00 00 00 00 00 ................
0018dd10 00 00 00 00 21 00 00 00 - 16 00 00 00 13 00 04 00 ....!...........
0018dd20 20 00 3f 0a 5c de 18 00 - 28 fe 52 00 13 00 04 00 .?.\...(.R.....
0018dd30 58 df 18 00 20 00 3f 0a - 20 00 3f 0a cc 01 00 00 X... .?. .?.....
0018dd40 04 00 00 00 00 00 00 00 - c4 dd 18 00 1f b0 19 72 ...............r
0018dd50 00 f1 34 00 de 08 05 00 - 02 02 00 00 0f 00 00 00 ..4.............
0018dd60 cc 01 04 00 00 00 00 00 - bb 80 19 72 8e 81 19 72 ...........r...r
0018dd70 00 00 00 00 cc 01 04 00 - de 08 05 00 00 00 00 00 ................
0018dd80 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd90 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dda0 bb 80 19 72 01 00 00 00 - 40 de 18 00 00 00 00 00 ...r....@.......
0018ddb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ddc0 43 76 4d e4 f0 dd 18 00 - fa 62 e1 75 de 08 05 00 CvM......b.u....
disassembling:
0070c5ec public QRPrntr.TQRPrinter.GetUseStandardPrinter: ; function entry
point
0070c5ec 3461 push ebp
0070c5ed mov ebp, esp
0070c5ef add esp, -8
0070c5f2 mov [ebp-4], eax
0070c5f5 3462 mov eax, [ebp-4]
0070c5f8 mov eax, [eax+$b8]
0070c5fe > mov al, [eax+$22]
0070c601 mov [ebp-5], al
0070c604 3463 mov al, [ebp-5]
0070c607 pop ecx
0070c608 pop ecx
0070c609 pop ebp
0070c60a ret
thread $11d8:
7741f8da +0e ntdll.dll NtWaitForSingleObject
76cd15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7634118f +3e kernel32.dll WaitForSingleObjectEx
76341143 +0d kernel32.dll WaitForSingleObject
76343368 +10 kernel32.dll BaseThreadInitThunk
thread $11dc:
77420166 +0e ntdll.dll NtWaitForMultipleObjects
76343368 +10 kernel32.dll BaseThreadInitThunk
thread $11f4:
77420166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
76343368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($11c4) at:
739a2713 +24f netbios.dll Netbios
thread $11a8:
7741f8da +0e ntdll.dll NtWaitForSingleObject
76cd15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7634118f +3e kernel32.dll WaitForSingleObjectEx
76341143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
76343368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($11c4) at:
737f4c95 +00 winspool.drv
thread $760:
77421f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76343368 +10 kernel32.dll BaseThreadInitThunk
thread $1638:
77421f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76343368 +10 kernel32.dll BaseThreadInitThunk
thread $17fc:
77421f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76343368 +10 kernel32.dll BaseThreadInitThunk
modules:
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02670000 WINPPLA.DLL C:\Program
Files (x86)\Store
026b0000 BCLW32.dll C:\Program
Files (x86)\Store
04720000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062f0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70f10000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71050000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
710f0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71110000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71430000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
715d0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71620000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71680000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72170000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72190000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72230000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72270000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72420000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72440000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72450000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72c60000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73480000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
734b0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73510000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
737e0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73930000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73940000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73960000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73970000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
739a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
739b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
739c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73a10000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73a60000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73ab0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73d10000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73d30000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73dc0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73e10000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73e40000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73e70000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73eb0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73ed0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73ee0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73ef0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73f50000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73fc0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74160000 version.dll 6.1.7600.16385 C:\Windows\
system32
74170000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74c90000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74ca0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74d00000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74d60000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74d70000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
74ea0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
74eb0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74f60000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75bb0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75c80000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75d30000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d40000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75dd0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75e00000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75f00000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75f40000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
760e0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
760f0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76100000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76110000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76120000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76140000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
761a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76200000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76290000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76330000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76440000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76450000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
765a0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
767e0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76940000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76bf0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76c10000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76cb0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76cc0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76d10000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76dc0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76eb0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76ec0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76ee0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76f80000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
773d0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77400000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0344 svchost.exe 0 0 0
0218 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0520 igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0654 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
03f4 svchost.exe 0 0 0
0564 scpbradserv.exe 0 0 0
041c svchost.exe 0 0 0
0748 core.exe 0 0 0
094c RapportInjService_x64.exe 0 0 0
09e8 fbserver.exe 0 0 0
0b4c WUDFHost.exe 0 0 0
0988 NisSrv.exe 0 0 0
0e84 WmiPrvSE.exe 0 0 0
0eb0 OSPPSVC.EXE 0 0 0
0d04 taskhost.exe 1 26 23 normal
0d3c core.exe 1 9 21 normal
0dd8 sppsvc.exe 0 0 0
02f8 GoogleCrashHandler.exe 0 0 0
03d4 GoogleCrashHandler64.exe 0 0 0
0864 RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0a30 RapportInjService_x64.exe 1 4 3 normal
0720 svchost.exe 0 0 0
0fa8 PresentationFontCache.exe 0 0 0
0dcc dwm.exe 1 20 5 high
0c90 explorer.exe 1 609 393 normal
0a48 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f14 igfxEM.exe 1 14 13 normal
0b10 igfxHK.exe 1 14 13 normal
0890 msseces.exe 1 143 59 normal
065c SearchIndexer.exe 0 0 0
0f08 PrnStatusMX.exe 1 23 20 normal
126c wmpnetwk.exe 0 0 0
11c0 Store.exe 1 3910 727 normal C:\Program Files (x86)\Store
10a4 wuauclt.exe 1 12 6 normal
0d48 splwow64.exe 1 9 4 normal
0770 OIS.EXE 1 117 49 normal
1240 OIS.EXE 1 137 50 normal
1554 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
1740 OIS.EXE 1 107 47 normal
0664 OIS.EXE 1 102 44 normal
0ce8 OIS.EXE 1 139 53 normal
1494 OIS.EXE 1 121 50 normal
14bc chrome.exe 1 28 50 normal
15e4 chrome.exe 1 9 4 normal
06c0 chrome.exe 1 7 7 above normal
12fc chrome.exe 1 4 1 normal
11bc chrome.exe 1 4 1 normal
0868 chrome.exe 1 4 1 idle
0478 chrome.exe 1 4 3 normal
04c0 OIS.EXE 1 122 51 normal
1440 OIS.EXE 1 139 54 normal
12dc OIS.EXE 1 127 56 normal
1550 audiodg.exe 0 0 0
14d4 rundll32.exe 1 116 51 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0047002e
ebx = 04503ff0
ecx = 006f73dc
edx = 04503ff0
esi = 0d65bfbf
edi = 00000000
eip = 006d0069
esp = 0018cc88
ebp = 0018cca4
stack dump:
0018cc88 67 d2 70 00 34 ce 18 00 - 0c 89 40 00 a4 cc 18 00 g.p.4.....@.....
0018cc98 64 ce 18 00 18 2f 41 00 - f0 3f 50 04 b4 cc 18 00 d..../A..?P.....
0018cca8 2c 74 6f 00 64 ce 18 00 - c0 bf 65 0d e0 cd 18 00 ,to.d.....e.....
0018ccb8 28 fe 52 00 00 00 00 00 - 99 00 7a 06 c0 bf 65 0d (.R.......z...e.
0018ccc8 c0 bf 65 0d 7c ce 18 00 - 28 fe 52 00 01 00 00 00 ..e.|...(.R.....
0018ccd8 99 00 7a 06 c0 bf 65 0d - 9c cc 18 00 01 00 00 00 ..z...e.........
0018cce8 18 cf 18 00 b6 a6 e7 75 - 62 c9 b4 91 fe ff ff ff .......ub.......
0018ccf8 51 6d e1 75 3f 0d e2 75 - 00 00 00 00 18 2f 41 00 Qm.u?..u...../A.
0018cd08 c0 07 2d 00 30 00 00 00 - dc 1f 0a bb 01 00 00 00 ..-.0...........
0018cd18 00 00 00 00 00 00 00 00 - 30 00 00 00 c0 bf 65 0d ........0.....e.
0018cd28 04 c4 6e 00 00 00 00 00 - 50 cd 18 00 65 0d e2 75 ..n.....P...e..u
0018cd38 18 2f 41 00 c0 07 2d 00 - 30 00 00 00 dc 1f 0a bb ./A...-.0.......
0018cd48 01 00 00 00 00 00 00 00 - a4 ce 18 00 85 48 53 00 .............HS.
0018cd58 18 2f 41 00 c0 07 2d 00 - 30 00 00 00 dc 1f 0a bb ./A...-.0.......
0018cd68 01 00 00 00 a4 ce 18 00 - c0 bf 65 0d c0 bf 65 0d ..........e...e.
0018cd78 fc ce 18 00 28 fe 52 00 - c0 bf 65 0d c0 bf 65 0d ....(.R...e...e.
0018cd88 c0 bf 65 0d ef 47 43 77 - 01 00 00 00 00 00 40 00 ..e..GCw......@.
0018cd98 00 00 00 00 00 00 00 00 - a4 cd 18 00 92 69 4d e4 .............iM.
0018cda8 5c ce 18 00 44 aa e1 75 - 00 00 01 00 14 ce 18 00 \...D..u........
0018cdb8 00 00 00 00 00 00 00 46 - 2f 01 00 00 b2 00 00 00 .......F/.......
disassembling:
[...]
0070d240 cmp byte ptr [eax+$8d], 1
0070d247 jnz loc_70d251
0070d249 mov eax, [ebp-4]
0070d24c call -$341 ($70cf10) ; QRPrntr.TQRPrinter.Cancel
0070d251 3858 mov eax, [ebp-4]
0070d254 cmp word ptr [eax+$1a], 0
0070d259 jz loc_70d267
0070d25b 3859 mov ebx, [ebp-4]
0070d25e mov edx, [ebp-4]
0070d261 mov eax, [ebx+$1c]
0070d264 > call dword ptr [ebx+$18]
0070d267 xor eax, eax
0070d269 pop edx
0070d26a pop ecx
0070d26b pop ecx
0070d26c mov fs:[eax], edx
0070d26f push $70d294
0070d274 3861 mov eax, [ebp-4]
0070d277 mov dl, [ebp-5]
0070d27a mov [eax+$8c], dl
0070d280 ret
[...]
thread $11d8:
7741f8da +0e ntdll.dll NtWaitForSingleObject
76cd15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7634118f +3e kernel32.dll WaitForSingleObjectEx
76341143 +0d kernel32.dll WaitForSingleObject
76343368 +10 kernel32.dll BaseThreadInitThunk
thread $11dc:
77420166 +0e ntdll.dll NtWaitForMultipleObjects
76343368 +10 kernel32.dll BaseThreadInitThunk
thread $11f4:
77420166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
76343368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($11c4) at:
739a2713 +24f netbios.dll Netbios
thread $11a8:
7741f8da +0e ntdll.dll NtWaitForSingleObject
76cd15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7634118f +3e kernel32.dll WaitForSingleObjectEx
76341143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
76343368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($11c4) at:
737f4c95 +00 winspool.drv
thread $760:
77421f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76343368 +10 kernel32.dll BaseThreadInitThunk
thread $1638:
77421f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76343368 +10 kernel32.dll BaseThreadInitThunk
thread $17fc:
77421f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76343368 +10 kernel32.dll BaseThreadInitThunk
modules:
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02670000 WINPPLA.DLL C:\Program
Files (x86)\Store
026b0000 BCLW32.dll C:\Program
Files (x86)\Store
04720000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062f0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70f10000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71050000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
710f0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71110000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71430000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
715d0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71620000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71680000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72170000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72190000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72230000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72270000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72420000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72440000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72450000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72c60000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73480000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
734b0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73510000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
737e0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73930000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73940000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73960000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73970000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
739a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
739b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
739c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73a10000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73a60000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73ab0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73d10000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73d30000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73dc0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73e10000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73e40000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73e70000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73eb0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73ed0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73ee0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73ef0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73f50000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73fc0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74160000 version.dll 6.1.7600.16385 C:\Windows\
system32
74170000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74c90000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74ca0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74d00000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74d60000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74d70000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
74ea0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
74eb0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74f60000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75bb0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75c80000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75d30000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d40000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75dd0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75e00000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75f00000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75f40000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
760e0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
760f0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76100000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76110000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76120000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76140000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
761a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76200000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76290000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76330000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76440000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76450000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
765a0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
767e0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76940000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76bf0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76c10000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76cb0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76cc0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76d10000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76dc0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76eb0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76ec0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76ee0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76f80000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
773d0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77400000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0344 svchost.exe 0 0 0
0218 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0520 igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0654 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
03f4 svchost.exe 0 0 0
0564 scpbradserv.exe 0 0 0
041c svchost.exe 0 0 0
0748 core.exe 0 0 0
094c RapportInjService_x64.exe 0 0 0
09e8 fbserver.exe 0 0 0
0b4c WUDFHost.exe 0 0 0
0988 NisSrv.exe 0 0 0
0e84 WmiPrvSE.exe 0 0 0
0eb0 OSPPSVC.EXE 0 0 0
0d04 taskhost.exe 1 26 23 normal
0d3c core.exe 1 9 21 normal
0dd8 sppsvc.exe 0 0 0
02f8 GoogleCrashHandler.exe 0 0 0
03d4 GoogleCrashHandler64.exe 0 0 0
0864 RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0a30 RapportInjService_x64.exe 1 4 3 normal
0720 svchost.exe 0 0 0
0fa8 PresentationFontCache.exe 0 0 0
0dcc dwm.exe 1 20 5 high
0c90 explorer.exe 1 609 394 normal
0a48 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f14 igfxEM.exe 1 14 13 normal
0b10 igfxHK.exe 1 14 13 normal
0890 msseces.exe 1 143 59 normal
065c SearchIndexer.exe 0 0 0
0f08 PrnStatusMX.exe 1 23 20 normal
126c wmpnetwk.exe 0 0 0
11c0 Store.exe 1 3895 719 normal C:\Program Files (x86)\Store
10a4 wuauclt.exe 1 12 6 normal
0d48 splwow64.exe 1 9 4 normal
0770 OIS.EXE 1 117 49 normal
1240 OIS.EXE 1 137 50 normal
1554 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
1740 OIS.EXE 1 107 47 normal
0664 OIS.EXE 1 102 44 normal
0ce8 OIS.EXE 1 139 53 normal
1494 OIS.EXE 1 121 50 normal
14bc chrome.exe 1 28 50 normal
15e4 chrome.exe 1 9 4 normal
06c0 chrome.exe 1 7 7 above normal
12fc chrome.exe 1 4 1 normal
11bc chrome.exe 1 4 1 normal
0868 chrome.exe 1 4 1 idle
0478 chrome.exe 1 4 3 normal
04c0 OIS.EXE 1 122 51 normal
1440 OIS.EXE 1 139 54 normal
12dc OIS.EXE 1 127 56 normal
1550 audiodg.exe 0 0 0
14d4 rundll32.exe 1 116 51 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 04503ff0
ebx = 0bfa3f00
ecx = 000204b0
edx = 044f4601
esi = 0bfa3f00
edi = 0018e368
eip = 0034004e
esp = 0018e0b0
ebp = 0018e0c0
stack dump:
0018e0b0 f7 75 40 00 e4 5b 6f 00 - ac 7c 40 00 c0 bf 65 0d .u@..[o..|@...e.
0018e0c0 d0 e0 18 00 d3 9c 6f 00 - 00 3f fa 01 c0 bf 65 0d ......o..?....e.
0018e0d0 2c e1 18 00 f7 75 40 00 - 47 38 ed 00 34 e1 18 00 ,[email protected]...
0018e0e0 0c 89 40 00 2c e1 18 00 - 00 00 00 00 00 00 00 00 ..@.,...........
0018e0f0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e100 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e110 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e120 00 00 00 00 e0 a0 7a 0a - 10 c2 48 04 b0 e1 18 00 ......z...H.....
0018e130 c9 cf ec 00 18 e5 18 00 - 0c 89 40 00 b0 e1 18 00 ..........@.....
0018e140 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e150 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e160 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e170 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e180 00 00 00 00 00 00 00 00 - 00 00 00 00 00 3f fa 0b .............?..
0018e190 f0 0b 53 04 90 0e 53 04 - 30 11 53 04 30 26 53 04 ..S...S.0.S.0&S.
0018e1a0 50 f4 52 04 90 f9 52 04 - f0 f6 52 04 10 c2 48 04 P.R...R...R...H.
0018e1b0 00 e3 18 00 81 03 53 00 - 00 3f fa 0b c7 33 55 00 ......S..?...3U.
0018e1c0 68 e3 18 00 f6 42 62 00 - 4c 42 62 00 68 e3 18 00 h....Bb.LBb.h...
0018e1d0 f5 3e 55 00 00 3f fa 0b - 28 fe 52 00 68 e3 18 00 .>U..?..(.R.h...
0018e1e0 48 e5 18 00 00 3f fa 0b - f3 00 00 00 05 8b e3 75 H....?.........u
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 708 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $159c:
776bf8da +0e ntdll.dll NtWaitForSingleObject
757415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
759b118f +3e kernel32.dll WaitForSingleObjectEx
759b1143 +0d kernel32.dll WaitForSingleObject
759b3368 +10 kernel32.dll BaseThreadInitThunk
thread $177c:
776c0166 +0e ntdll.dll NtWaitForMultipleObjects
759b3368 +10 kernel32.dll BaseThreadInitThunk
thread $c40:
776bf8da +0e ntdll.dll NtWaitForSingleObject
757415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
759b118f +3e kernel32.dll WaitForSingleObjectEx
759b1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
759b3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1614) at:
72e94c95 +00 winspool.drv
thread $16d4:
776c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
759b3368 +10 kernel32.dll BaseThreadInitThunk
thread $d30:
776c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
759b3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
062a0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063b0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70ef0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71220000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
71240000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
71250000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
712b0000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
71300000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
71310000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71350000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71360000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71470000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
714b0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
716e0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71870000 webio.dll 6.1.7601.23375 C:\Windows\
system32
718c0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71920000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72190000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
721b0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72240000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
724d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72510000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
726c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
726e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
726f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72bf0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
72cf0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72d20000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
72d80000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72e80000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
736c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
736d0000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
737a0000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
73800000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73810000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73820000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73830000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73850000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73860000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73880000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
739e0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73c00000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73c20000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74060000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
740b0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
740e0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74110000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74150000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74170000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74180000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74190000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
741a0000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
741f0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74230000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74240000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
74260000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74400000 version.dll 6.1.7600.16385 C:\Windows\
system32
74410000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74f30000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74f40000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74fd0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
74fe0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75060000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75080000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75090000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
750a0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750b0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
750c0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750d0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750e0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75280000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75340000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75350000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
753f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75540000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75590000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
755d0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75680000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75730000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75780000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
758b0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
759a0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75ab0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75b10000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75ba0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75bd0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75ca0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75e00000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75f30000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75f60000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75f80000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76230000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76240000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76250000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76350000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76360000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
763f0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77040000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
77280000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77670000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
776a0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
02b0 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
0408 svchost.exe 0 0 0
0434 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07fc svchost.exe 0 0 0
0548 scpbradserv.exe 0 0 0
0414 svchost.exe 0 0 0
07e0 core.exe 0 0 0
0918 RapportInjService_x64.exe 0 0 0
09a4 fbserver.exe 0 0 0
0b80 WUDFHost.exe 0 0 0
0350 NisSrv.exe 0 0 0
0e98 WmiPrvSE.exe 0 0 0
0f58 OSPPSVC.EXE 0 0 0
0ed0 taskhost.exe 1 26 22 normal
0eec core.exe 1 9 21 normal
0cac sppsvc.exe 0 0 0
0dd4 GoogleCrashHandler.exe 0 0 0
0ddc GoogleCrashHandler64.exe 0 0 0
0e08 svchost.exe 0 0 0
084c RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
09f0 RapportInjService_x64.exe 1 4 3 normal
05e8 PresentationFontCache.exe 0 0 0
05dc dwm.exe 1 17 4 high
087c explorer.exe 1 427 247 normal
0fa0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0ef4 igfxEM.exe 1 14 14 normal
0b90 igfxHK.exe 1 14 12 normal
1018 msseces.exe 1 143 60 normal
1024 PrnStatusMX.exe 1 23 20 normal
11ec SearchIndexer.exe 0 0 0
1290 wmpnetwk.exe 0 0 0
1194 chrome.exe 1 28 52 normal
1220 chrome.exe 1 9 4 normal
1360 chrome.exe 1 7 7 above normal
108c chrome.exe 1 4 1 normal
17c4 wuauclt.exe 1 12 6 normal
1544 chrome.exe 1 4 1 normal
14bc chrome.exe 1 4 1 idle
0204 chrome.exe 1 4 3 normal
16fc Store.exe 1 817 276 normal C:\Program Files (x86)\Store
0478 splwow64.exe 1 9 3 normal
119c AcroRd32.exe 1 15 17 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader
0768 AcroRd32.exe 1 321 123 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader
11b4 RdrCEF.exe 1 9 23 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
0dbc RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
16e4 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
0770 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
136c audiodg.exe 0 0 0
1534 EXCEL.EXE 1 322 103 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 044c8058
ebx = 00454d6a
ecx = 0044dadc
edx = 0018dff8
esi = 00454d6a
edi = 0aec4980
eip = 00454d6a
esp = 0018e028
ebp = 0018e070
stack dump:
0018e028 6a 4d 45 00 de fa ed 0e - 01 00 00 00 07 00 00 00 jME.............
0018e038 3c e0 18 00 6a 4d 45 00 - 58 80 4c 04 6a 4d 45 00 <...jME.X.L.jME.
0018e048 6a 4d 45 00 80 49 ec 0a - 70 e0 18 00 58 e0 18 00 jME..I..p...X...
0018e058 02 00 00 00 f4 4c 40 00 - 80 49 ec 0a 00 00 00 00 [email protected]......
0018e068 37 4d 40 00 98 22 e2 02 - d0 e0 18 00 6a 4d 45 00 7M@.."......jME.
0018e078 43 d3 52 00 dd 65 61 00 - 9c 02 02 00 0f 00 00 00 C.R..ea.........
0018e088 b0 89 63 0a 68 e3 18 00 - 80 49 ec 0a 00 00 00 00 ..c.h....I......
0018e098 a5 1b 53 00 00 00 00 00 - 68 e3 18 00 80 49 ec 0a ..S.....h....I..
0018e0a8 00 00 00 00 2c 9f 60 00 - 50 f5 e8 0a 50 f5 e8 0a ....,.`.P...P...
0018e0b8 06 b1 60 00 dc e0 18 00 - 0c 89 40 00 d0 e0 18 00 ..`.......@.....
0018e0c8 50 f5 e8 01 80 49 ec 0a - 2c e1 18 00 f7 75 40 00 P....I..,....u@.
0018e0d8 53 38 ed 00 34 e1 18 00 - 0c 89 40 00 2c e1 18 00 S8..4.....@.,...
0018e0e8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0f8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e108 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e118 00 00 00 00 00 00 00 00 - 00 00 00 00 10 f0 6d 0a ..............m.
0018e128 b0 52 3d 04 b0 e1 18 00 - c9 cf ec 00 18 e5 18 00 .R=.............
0018e138 0c 89 40 00 b0 e1 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e148 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e158 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 708 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $159c:
776bf8da +0e ntdll.dll NtWaitForSingleObject
757415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
759b118f +3e kernel32.dll WaitForSingleObjectEx
759b1143 +0d kernel32.dll WaitForSingleObject
759b3368 +10 kernel32.dll BaseThreadInitThunk
thread $177c:
776c0166 +0e ntdll.dll NtWaitForMultipleObjects
759b3368 +10 kernel32.dll BaseThreadInitThunk
thread $c40:
776bf8da +0e ntdll.dll NtWaitForSingleObject
757415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
759b118f +3e kernel32.dll WaitForSingleObjectEx
759b1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
759b3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1614) at:
72e94c95 +00 winspool.drv
thread $16d4:
776c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
759b3368 +10 kernel32.dll BaseThreadInitThunk
thread $d30:
776c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
759b3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
062a0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063b0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70ef0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71220000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
71240000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
71250000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
712b0000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
71300000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
71310000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71350000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71360000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71470000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
714b0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
716e0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71870000 webio.dll 6.1.7601.23375 C:\Windows\
system32
718c0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71920000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72190000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
721b0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72240000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
724d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72510000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
726c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
726e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
726f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72bf0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
72cf0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72d20000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
72d80000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72e80000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
736c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
736d0000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
737a0000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
73800000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73810000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73820000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73830000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73850000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73860000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73880000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
739e0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73c00000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73c20000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74060000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
740b0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
740e0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74110000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74150000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74170000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74180000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74190000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
741a0000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
741f0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74230000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74240000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
74260000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74400000 version.dll 6.1.7600.16385 C:\Windows\
system32
74410000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74f30000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74f40000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74fd0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
74fe0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75060000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75080000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75090000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
750a0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750b0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
750c0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750d0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750e0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75280000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75340000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75350000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
753f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75540000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75590000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
755d0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75680000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75730000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75780000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
758b0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
759a0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75ab0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75b10000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75ba0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75bd0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75ca0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75e00000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75f30000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75f60000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75f80000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76230000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76240000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76250000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76350000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76360000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
763f0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77040000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
77280000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77670000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
776a0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
02b0 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
0408 svchost.exe 0 0 0
0434 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07fc svchost.exe 0 0 0
0548 scpbradserv.exe 0 0 0
0414 svchost.exe 0 0 0
07e0 core.exe 0 0 0
0918 RapportInjService_x64.exe 0 0 0
09a4 fbserver.exe 0 0 0
0b80 WUDFHost.exe 0 0 0
0350 NisSrv.exe 0 0 0
0e98 WmiPrvSE.exe 0 0 0
0f58 OSPPSVC.EXE 0 0 0
0ed0 taskhost.exe 1 26 21 normal
0eec core.exe 1 9 21 normal
0cac sppsvc.exe 0 0 0
0dd4 GoogleCrashHandler.exe 0 0 0
0ddc GoogleCrashHandler64.exe 0 0 0
0e08 svchost.exe 0 0 0
084c RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
09f0 RapportInjService_x64.exe 1 4 3 normal
05e8 PresentationFontCache.exe 0 0 0
05dc dwm.exe 1 17 4 high
087c explorer.exe 1 427 248 normal
0fa0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0ef4 igfxEM.exe 1 14 14 normal
0b90 igfxHK.exe 1 14 12 normal
1018 msseces.exe 1 143 60 normal
1024 PrnStatusMX.exe 1 23 20 normal
11ec SearchIndexer.exe 0 0 0
1290 wmpnetwk.exe 0 0 0
1194 chrome.exe 1 28 52 normal
1220 chrome.exe 1 9 4 normal
1360 chrome.exe 1 7 7 above normal
108c chrome.exe 1 4 1 normal
17c4 wuauclt.exe 1 12 6 normal
1544 chrome.exe 1 4 1 normal
14bc chrome.exe 1 4 1 idle
0204 chrome.exe 1 4 3 normal
16fc Store.exe 1 815 255 normal C:\Program Files (x86)\Store
0478 splwow64.exe 1 9 3 normal
119c AcroRd32.exe 1 15 17 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader
0768 AcroRd32.exe 1 321 123 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader
11b4 RdrCEF.exe 1 9 23 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
0dbc RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
16e4 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
0770 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
136c audiodg.exe 0 0 0
1534 EXCEL.EXE 1 322 103 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a5eadb8
ebx = 00000578
ecx = 00000000
edx = 02722ac8
esi = 0a648140
edi = 0a648140
eip = 0045cf4d
esp = 0018ec34
ebp = 0018ec88
stack dump:
0018ec34 4d cf 45 00 de fa ed 0e - 01 00 00 00 07 00 00 00 M.E.............
0018ec44 48 ec 18 00 4d cf 45 00 - b8 ad 5e 0a 78 05 00 00 H...M.E...^.x...
0018ec54 40 81 64 0a 40 81 64 0a - 88 ec 18 00 64 ec 18 00 @[email protected]...
0018ec64 94 ec 18 00 0c 89 40 00 - 88 ec 18 00 01 42 47 00 [email protected].
0018ec74 00 00 00 00 78 05 00 00 - 00 af 40 00 7c c1 a3 06 ....x.....@.|...
0018ec84 11 57 47 00 a4 ec 18 00 - d6 ce 45 00 92 37 53 00 .WG.......E..7S.
0018ec94 ec ec 18 00 0c 89 40 00 - a4 ec 18 00 40 81 64 0a ......@[email protected].
0018eca4 00 ed 18 00 12 1b 53 00 - 00 73 48 06 40 81 64 0a [email protected].
0018ecb4 40 81 64 0a 01 42 47 00 - 2d fe 54 00 b0 52 3d 04 @.d..BG.-.T..R=.
0018ecc4 09 00 00 00 3d 1b 53 00 - 00 ef 4b 06 11 00 00 00 ....=.S...K.....
0018ecd4 b0 52 3d 04 00 00 00 00 - 2c 9f 60 00 ac 3a 62 00 .R=.....,.`..:b.
0018ece4 f0 21 de 0a 06 b1 60 00 - 0c ed 18 00 0c 89 40 00 .!....`.......@.
0018ecf4 00 ed 18 00 60 76 4c 01 - b0 52 3d 04 34 ed 18 00 ....`vL..R=.4...
0018ed04 f7 75 40 00 2b 49 17 01 - 68 ef 18 00 0c 89 40 00 .u@.+I..h.....@.
0018ed14 34 ed 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 4...............
0018ed24 00 00 00 00 f0 21 de 0a - 00 b2 47 04 a0 41 47 06 .....!....G..AG.
0018ed34 58 ed 18 00 81 03 53 00 - f0 21 de 0a b1 3a 62 00 X.....S..!...:b.
0018ed44 9b 3a 62 00 d4 ee 18 00 - ac 39 62 00 f0 21 de 0a .:b......9b..!..
0018ed54 01 00 00 00 c8 ee 18 00 - b9 07 53 00 11 00 00 00 ..........S.....
0018ed64 11 00 00 00 00 00 00 00 - d4 ee 18 00 f0 21 de 0a .............!..
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 708 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $159c:
776bf8da +0e ntdll.dll NtWaitForSingleObject
757415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
759b118f +3e kernel32.dll WaitForSingleObjectEx
759b1143 +0d kernel32.dll WaitForSingleObject
759b3368 +10 kernel32.dll BaseThreadInitThunk
thread $177c:
776c0166 +0e ntdll.dll NtWaitForMultipleObjects
759b3368 +10 kernel32.dll BaseThreadInitThunk
thread $c40:
776bf8da +0e ntdll.dll NtWaitForSingleObject
757415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
759b118f +3e kernel32.dll WaitForSingleObjectEx
759b1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
759b3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1614) at:
72e94c95 +00 winspool.drv
thread $13a8:
776c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
759b3368 +10 kernel32.dll BaseThreadInitThunk
thread $1184:
776c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
759b3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
062a0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063b0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70ef0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71220000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
71240000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
71250000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
712b0000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
71300000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
71310000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71350000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71360000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71470000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
714b0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
716e0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71870000 webio.dll 6.1.7601.23375 C:\Windows\
system32
718c0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71920000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72190000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
721b0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72240000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
724d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72510000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
726c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
726e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
726f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72bf0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
72cf0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72d20000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
72d80000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72e80000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
736c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
736d0000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
737a0000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
73800000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73810000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73820000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73830000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73850000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73860000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73880000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
739e0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73c00000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73c20000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74060000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
740b0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
740e0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74110000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74150000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74170000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74180000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74190000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
741a0000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
741f0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74230000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74240000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
74260000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74400000 version.dll 6.1.7600.16385 C:\Windows\
system32
74410000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74f30000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74f40000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74fd0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
74fe0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75060000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75080000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75090000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
750a0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750b0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
750c0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750d0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750e0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75280000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75340000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75350000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
753f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75540000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75590000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
755d0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75680000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75730000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75780000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
758b0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
759a0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75ab0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75b10000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75ba0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75bd0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75ca0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75e00000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75f30000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75f60000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75f80000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76230000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76240000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76250000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76350000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76360000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
763f0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77040000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
77280000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77670000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
776a0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
02b0 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
0408 svchost.exe 0 0 0
0434 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07fc svchost.exe 0 0 0
0548 scpbradserv.exe 0 0 0
0414 svchost.exe 0 0 0
07e0 core.exe 0 0 0
0918 RapportInjService_x64.exe 0 0 0
09a4 fbserver.exe 0 0 0
0b80 WUDFHost.exe 0 0 0
0350 NisSrv.exe 0 0 0
0e98 WmiPrvSE.exe 0 0 0
0f58 OSPPSVC.EXE 0 0 0
0ed0 taskhost.exe 1 26 23 normal
0eec core.exe 1 9 21 normal
0cac sppsvc.exe 0 0 0
0dd4 GoogleCrashHandler.exe 0 0 0
0ddc GoogleCrashHandler64.exe 0 0 0
0e08 svchost.exe 0 0 0
084c RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
09f0 RapportInjService_x64.exe 1 4 3 normal
05e8 PresentationFontCache.exe 0 0 0
05dc dwm.exe 1 17 4 high
087c explorer.exe 1 427 244 normal
0fa0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0ef4 igfxEM.exe 1 14 14 normal
0b90 igfxHK.exe 1 14 12 normal
1018 msseces.exe 1 143 60 normal
1024 PrnStatusMX.exe 1 23 20 normal
11ec SearchIndexer.exe 0 0 0
1290 wmpnetwk.exe 0 0 0
1194 chrome.exe 1 28 52 normal
1220 chrome.exe 1 9 4 normal
1360 chrome.exe 1 7 7 above normal
108c chrome.exe 1 4 1 normal
17c4 wuauclt.exe 1 12 6 normal
1544 chrome.exe 1 4 1 normal
14bc chrome.exe 1 4 1 idle
0204 chrome.exe 1 4 3 normal
16fc Store.exe 1 923 284 normal C:\Program Files (x86)\Store
0478 splwow64.exe 1 9 2 normal
119c AcroRd32.exe 1 15 17 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader
0768 AcroRd32.exe 1 321 123 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader
11b4 RdrCEF.exe 1 9 23 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
0dbc RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
16e4 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
0770 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
136c audiodg.exe 0 0 0
1534 EXCEL.EXE 1 322 103 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 05bd9080
ebx = 00000000
ecx = 00000000
edx = 02722ac8
esi = 0446f8f0
edi = 09ff4b3c
eip = 0049064d
esp = 0018ead0
ebp = 0018eb30
stack dump:
0018ead0 4d 06 49 00 de fa ed 0e - 01 00 00 00 07 00 00 00 M.I.............
0018eae0 e4 ea 18 00 4d 06 49 00 - 80 90 bd 05 00 00 00 00 ....M.I.........
0018eaf0 f0 f8 46 04 3c 4b ff 09 - 30 eb 18 00 00 eb 18 00 ..F.<K..0.......
0018eb00 54 eb 18 00 0c 89 40 00 - 30 eb 18 00 54 59 60 00 [email protected]`.
0018eb10 3c 4b ff 09 f0 5a 3d 04 - 3c 4b ff 09 11 00 00 00 <K...Z=.<K......
0018eb20 00 00 00 00 f0 5a 3d 04 - 00 00 00 00 00 00 00 00 .....Z=.........
0018eb30 74 eb 18 00 25 0a 49 00 - 3c 4b ff 09 e5 20 48 00 t...%.I.<K... H.
0018eb40 3c 4b ff 09 f0 5a 3d 04 - 6c ec 18 00 00 00 00 00 <K...Z=.l.......
0018eb50 52 e3 52 00 7c eb 18 00 - 0c 89 40 00 74 eb 18 00 R.R.|[email protected]...
0018eb60 cc 4b ff 09 6c ec 18 00 - 90 ac 47 00 00 00 00 00 .K..l.....G.....
0018eb70 3c 4b ff 09 dc eb 18 00 - 75 ad 48 00 88 eb 18 00 <K......u.H.....
0018eb80 eb 8a 40 00 dc eb 18 00 - 94 eb 18 00 0c 89 40 00 ..@...........@.
0018eb90 dc eb 18 00 e4 eb 18 00 - 0c 89 40 00 dc eb 18 00 ..........@.....
0018eba0 cc 4b ff 09 6c ec 18 00 - f0 5a 3d 04 00 00 00 00 .K..l....Z=.....
0018ebb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ebc0 00 00 00 00 a4 84 48 00 - 04 ec 18 00 21 7c 40 00 ......H.....!|@.
0018ebd0 f0 5a 3d 04 f0 5a 3d 04 - a8 14 40 04 fc eb 18 00 .Z=..Z=...@.....
0018ebe0 3b 73 48 00 04 ec 18 00 - 0c 89 40 00 fc eb 18 00 ;sH.......@.....
0018ebf0 00 00 40 00 a8 14 40 04 - 6c ec 18 00 20 ec 18 00 ..@[email protected]... ...
0018ec00 74 21 48 00 28 ec 18 00 - 0c 89 40 00 20 ec 18 00 t!H.(.....@. ...
disassembling:
[...]
0117486f mov ecx, $1174a14
01174874 mov edx, $1174a24
01174879 mov eax, [$160cbd0]
0117487e mov eax, [eax]
01174880 call -$b5edad ($615ad8) ; Vcl.Forms.TApplication.MessageBox
01174885 1056 jmp loc_1174939
0117488a 1058 mov ecx, [$160c1f0]
01174890 mov eax, [$160cbd0]
01174895 mov eax, [eax]
01174897 mov edx, [$ecc1ac]
0117489d > call -$b5f16a ($615738) ; Vcl.Forms.TApplication.CreateForm
011748a2 1059 mov eax, [$160cdb0]
011748a7 mov eax, [eax]
011748a9 mov eax, [eax+$27c]
011748af mov edx, $1174a9c
011748b4 call -$b1c485 ($658434) ; Data.DB.TDataSet.FieldByName
011748b9 lea edx, [ebp-$18]
011748bc mov ecx, [eax]
011748be call dword ptr [ecx+$80]
011748c4 mov edx, [ebp-$18]
011748c7 mov eax, [$160c1f0]
[...]
thread $33c:
776bf8da +0e ntdll.dll NtWaitForSingleObject
757415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
759b118f +3e kernel32.dll WaitForSingleObjectEx
759b1143 +0d kernel32.dll WaitForSingleObject
759b3368 +10 kernel32.dll BaseThreadInitThunk
thread $db8:
776c0166 +0e ntdll.dll NtWaitForMultipleObjects
759b3368 +10 kernel32.dll BaseThreadInitThunk
thread $830:
776bf8da +0e ntdll.dll NtWaitForSingleObject
757415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
759b118f +3e kernel32.dll WaitForSingleObjectEx
759b1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
759b3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($de4) at:
72e94c95 +00 winspool.drv
thread $1154:
776c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
759b3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00320000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
06300000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06410000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f900000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
70ef0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71250000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71310000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71350000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71470000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
714b0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
716e0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71870000 webio.dll 6.1.7601.23375 C:\Windows\
system32
718c0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71920000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72190000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
721b0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
724d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72510000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
726c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
726e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
726f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72c50000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
72d50000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72d80000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72e80000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
736c0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73820000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73830000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73850000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73860000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73880000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
739e0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73c00000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73c20000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74060000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
740b0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
740e0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74110000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74150000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74170000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74180000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74190000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
741f0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74260000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74400000 version.dll 6.1.7600.16385 C:\Windows\
system32
74410000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74f30000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74f40000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74fd0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
74fe0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75060000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75080000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75090000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
750a0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750b0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
750c0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750d0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750e0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75280000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75340000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75350000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
753f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75540000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75590000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
755d0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75680000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75730000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75780000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
758b0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
759a0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75ab0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75b10000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75ba0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75bd0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75ca0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75e00000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75f30000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75f60000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75f80000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76230000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76240000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76250000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76350000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76360000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
763f0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77040000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
77280000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
776a0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
02b0 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
0408 svchost.exe 0 0 0
0434 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07fc svchost.exe 0 0 0
0548 scpbradserv.exe 0 0 0
0414 svchost.exe 0 0 0
07e0 core.exe 0 0 0
0918 RapportInjService_x64.exe 0 0 0
09a4 fbserver.exe 0 0 0
0b80 WUDFHost.exe 0 0 0
0350 NisSrv.exe 0 0 0
0e98 WmiPrvSE.exe 0 0 0
0f58 OSPPSVC.EXE 0 0 0
0ed0 taskhost.exe 1 26 24 normal
0eec core.exe 1 9 21 normal
0cac sppsvc.exe 0 0 0
0dd4 GoogleCrashHandler.exe 0 0 0
0ddc GoogleCrashHandler64.exe 0 0 0
0e08 svchost.exe 0 0 0
084c RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
09f0 RapportInjService_x64.exe 1 4 3 normal
05e8 PresentationFontCache.exe 0 0 0
05dc dwm.exe 1 17 4 high
087c explorer.exe 1 516 299 normal
0fa0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0ef4 igfxEM.exe 1 14 14 normal
0b90 igfxHK.exe 1 14 12 normal
1018 msseces.exe 1 143 60 normal
1024 PrnStatusMX.exe 1 23 20 normal
11ec SearchIndexer.exe 0 0 0
1290 wmpnetwk.exe 0 0 0
1194 chrome.exe 1 28 50 normal
1220 chrome.exe 1 9 4 normal
1360 chrome.exe 1 7 7 above normal
108c chrome.exe 1 4 1 normal
17c4 wuauclt.exe 1 12 6 normal
1544 chrome.exe 1 4 1 normal
14bc chrome.exe 1 4 1 idle
0204 chrome.exe 1 4 3 normal
0478 splwow64.exe 1 9 3 normal
136c audiodg.exe 0 0 0
1534 EXCEL.EXE 1 375 127 normal
138c Store.exe 1 1245 440 normal C:\Program Files (x86)\Store
0a90 mspaint.exe 1 408 73 normal
1010 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
137c Store.exe 1 332 256 normal C:\Program Files (x86)\Store
1054 OIS.EXE 1 102 43 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0c052b90
ebx = 00003303
ecx = 00000000
edx = 02672ac8
esi = 0018ec8c
edi = 0066c9e4
eip = 0066e902
esp = 0018ec50
ebp = 0018ecb8
stack dump:
0018ec50 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018ec60 64 ec 18 00 02 e9 66 00 - 90 2b 05 0c 03 33 00 00 d.....f..+...3..
0018ec70 8c ec 18 00 e4 c9 66 00 - b8 ec 18 00 80 ec 18 00 ......f.........
0018ec80 00 b2 57 04 0e e9 66 00 - 34 e8 67 00 00 00 00 00 ..W...f.4.g.....
0018ec90 00 b2 57 04 00 00 00 00 - 2f e7 67 00 c4 ec 18 00 ..W...../.g.....
0018eca0 0c 89 40 00 b8 ec 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018ecb0 69 e8 67 01 00 b2 57 04 - e0 ec 18 00 87 e7 67 00 i.g...W.......g.
0018ecc0 a6 4b 67 00 f8 ec 18 00 - 0c 89 40 00 e0 ec 18 00 .Kg.......@.....
0018ecd0 00 b2 57 04 00 00 00 00 - 00 00 00 00 00 b2 57 04 ..W...........W.
0018ece0 0c ed 18 00 4a 91 67 00 - 0f 00 00 00 ac 3a 62 00 ....J.g......:b.
0018ecf0 01 00 00 00 77 72 65 00 - 18 ed 18 00 0c 89 40 00 ....wre.......@.
0018ed00 0c ed 18 00 a0 f8 52 0a - 00 b2 57 04 34 ed 18 00 ......R...W.4...
0018ed10 be 70 65 00 03 5d 17 01 - 68 ef 18 00 0c 89 40 00 .pe..]..h.....@.
0018ed20 34 ed 18 00 00 00 00 00 - a0 f8 52 0a 00 b2 57 04 4.........R...W.
0018ed30 a0 b9 49 06 58 ed 18 00 - 81 03 53 00 a0 f8 52 0a ..I.X.....S...R.
0018ed40 b1 3a 62 00 9b 3a 62 00 - d4 ee 18 00 ac 39 62 00 .:b..:b......9b.
0018ed50 a0 f8 52 0a 01 00 00 00 - c8 ee 18 00 b9 07 53 00 ..R...........S.
0018ed60 0f 00 00 00 18 00 00 00 - 00 00 00 00 d4 ee 18 00 ................
0018ed70 a0 f8 52 0a 35 08 53 00 - 18 00 0f 00 d4 ee 18 00 ..R.5.S.........
0018ed80 e2 04 19 00 01 ee 18 00 - c0 e7 52 00 50 00 00 00 ..........R.P...
disassembling:
[...]
01175cd8 push $1175f48
01175cdd lea eax, [ebp-$10]
01175ce0 mov edx, 3
01175ce5 call -$d6b53a ($40a7b0) ; System.@UStrCatN
01175cea mov edx, [ebp-$10]
01175ced mov eax, [ebp-8]
01175cf0 mov eax, [eax+$250]
01175cf6 mov ecx, [eax]
01175cf8 call dword ptr [ecx+$38]
01175cfb 1151 mov eax, [ebp-8]
01175cfe > call -$b1ec4f ($6570b4) ; Data.DB.TDataSet.Open
01175d03 1153 mov eax, [ebp-4]
01175d06 mov eax, [eax+$598]
01175d0c xor edx, edx
01175d0e mov [eax+$c], edx
01175d11 1154 mov ecx, [$160c36c]
01175d17 mov eax, [$160cbd0]
01175d1c mov eax, [eax]
01175d1e mov edx, [$eebab4]
01175d24 call -$b605f1 ($615738) ; Vcl.Forms.TApplication.CreateForm
01175d29 1155 mov eax, [ebp-4]
[...]
thread $11fc:
777bf8da +0e ntdll.dll NtWaitForSingleObject
750f15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7514118f +3e kernel32.dll WaitForSingleObjectEx
75141143 +0d kernel32.dll WaitForSingleObject
75143368 +10 kernel32.dll BaseThreadInitThunk
thread $11d4:
777c0166 +0e ntdll.dll NtWaitForMultipleObjects
75143368 +10 kernel32.dll BaseThreadInitThunk
thread $e00:
777c0166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
75143368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($fbc) at:
72f92713 +24f netbios.dll Netbios
thread $474:
777bf8da +0e ntdll.dll NtWaitForSingleObject
750f15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7514118f +3e kernel32.dll WaitForSingleObjectEx
75141143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
75143368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($fbc) at:
72b64c95 +00 winspool.drv
thread $174:
777c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75143368 +10 kernel32.dll BaseThreadInitThunk
thread $d64:
777c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75143368 +10 kernel32.dll BaseThreadInitThunk
thread $1370:
777c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75143368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
003c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
062a0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063d0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70ee0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
70fe0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
71410000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71750000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71790000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
717b0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
717e0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71970000 webio.dll 6.1.7601.23375 C:\Windows\
system32
719c0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71a20000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72510000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72530000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72610000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
727c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
727e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
727f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72a50000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72b50000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
72f90000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
72fa0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
737b0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73810000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73920000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73930000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73950000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73960000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
739e0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73c40000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73c60000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73ea0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73ef0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74150000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
741b0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
741e0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74210000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74250000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74270000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74280000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74290000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
742f0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74360000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74500000 version.dll 6.1.7600.16385 C:\Windows\
system32
74510000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75030000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75040000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
750d0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750e0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75130000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75240000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
752a0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75330000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75570000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
755d0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
755e0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75660000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75670000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75750000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75770000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75820000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75830000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75930000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75970000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75990000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
759a0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
759b0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
759c0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
759d0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
759e0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76630000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76640000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76770000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76840000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76870000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
769c0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
769e0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76ad0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76d80000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76d90000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76f30000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76fe0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77010000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
770a0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77200000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77300000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
77770000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
777a0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0248 wininit.exe 0 0 0
0250 csrss.exe 1 0 0
0280 winlogon.exe 1 0 0
02ac services.exe 0 0 0
02b8 lsass.exe 0 0 0
02c0 lsm.exe 0 0 0
0324 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
02a4 svchost.exe 0 0 0
0334 svchost.exe 0 0 0
0254 svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0528 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0634 spoolsv.exe 0 0 0
063c taskeng.exe 0 0 0
0660 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
0760 fbguard.exe 0 0 0
0784 svchost.exe 0 0 0
079c NetExpressUpdater.exe 0 0 0
0444 svchost.exe 0 0 0
0564 scpbradserv.exe 0 0 0
00bc core.exe 0 0 0
0960 RapportInjService_x64.exe 0 0 0
0a00 fbserver.exe 0 0 0
0b98 WUDFHost.exe 0 0 0
0860 NisSrv.exe 0 0 0
0ec4 WmiPrvSE.exe 0 0 0
0ef0 OSPPSVC.EXE 0 0 0
0fc4 taskhost.exe 1 26 23 normal
0fd8 core.exe 1 9 21 normal
0924 sppsvc.exe 0 0 0
0e60 GoogleCrashHandler.exe 0 0 0
0e68 GoogleCrashHandler64.exe 0 0 0
0f04 RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0c38 RapportInjService_x64.exe 1 4 3 normal
0e14 svchost.exe 0 0 0
0fcc SearchIndexer.exe 0 0 0
0a8c PresentationFontCache.exe 0 0 0
0af8 dwm.exe 1 17 4 high
0dd0 explorer.exe 1 665 395 normal
033c igfxEM.exe 1 14 13 normal
0f5c igfxHK.exe 1 14 12 normal
0e88 msseces.exe 1 143 59 normal
0da4 PrnStatusMX.exe 1 23 20 normal
1218 wmpnetwk.exe 0 0 0
1260 wuauclt.exe 1 12 5 normal
10d8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
1164 Store.exe 1 863 381 normal C:\Program Files (x86)\Store
114c OIS.EXE 1 102 44 normal
119c DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0ed8 splwow64.exe 1 9 3 normal
1048 OIS.EXE 1 105 45 normal
12f8 chrome.exe 1 25 47 normal
06d0 chrome.exe 1 9 4 normal
134c chrome.exe 1 7 7 above normal
0d70 chrome.exe 1 4 1 normal
030c chrome.exe 1 4 1 normal
105c chrome.exe 1 4 1 idle
1154 chrome.exe 1 4 3 normal
0f84 AcroRd32.exe 1 16 16 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader
16e8 AcroRd32.exe 1 352 121 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader
1568 RdrCEF.exe 1 9 22 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
15b8 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
17bc slui.exe 1 43 31 normal
0538 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
13c8 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0be15790
ebx = 0000280f
ecx = 00000000
edx = 02712ac8
esi = 00000000
edi = 0018ddc0
eip = 0066e902
esp = 0018d7a4
ebp = 0018d80c
stack dump:
0018d7a4 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018d7b4 b8 d7 18 00 02 e9 66 00 - 90 57 e1 0b 0f 28 00 00 ......f..W...(..
0018d7c4 00 00 00 00 c0 dd 18 00 - 0c d8 18 00 d4 d7 18 00 ................
0018d7d4 e0 c9 18 0b 0e e9 66 00 - 34 e8 67 00 00 00 00 00 ......f.4.g.....
0018d7e4 50 bf 88 06 e4 c9 66 00 - 2f e7 67 00 14 d8 18 00 P.....f./.g.....
0018d7f4 0c 89 40 00 0c d8 18 00 - e4 c9 66 00 00 00 00 00 [email protected].....
0018d804 30 d8 18 00 e0 c9 18 0b - 28 d8 18 00 c5 e7 67 00 0.......(.....g.
0018d814 30 d8 18 00 0c 89 40 00 - 28 d8 18 00 50 bf 88 06 0.....@.(...P...
0018d824 e0 c9 18 0b b4 db 18 00 - 57 79 ef 00 cc db 18 00 ........Wy......
0018d834 0c 89 40 00 b4 db 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018d844 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d854 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d864 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d874 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d884 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d894 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d8a4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d8b4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d8c4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d8d4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00ef7927 push eax
00ef7928 lea edx, [ebp-$370]
00ef792e mov eax, [$160c890]
00ef7933 mov eax, [eax]
00ef7935 call -$aa497a ($452fc0) ; System.SysUtils.IntToStr
00ef793a mov eax, [ebp-$370]
00ef7940 mov ecx, $efaa30
00ef7945 mov edx, $efaa5c
00ef794a call +$30db59 ($12054a8) ; UnitMonitor.GravaMonitor
00ef794f 1559 mov eax, [ebp-$2c]
00ef7952 > call -$8791cf ($67e788) ; Bde.DBTables.TQuery.ExecSQL
00ef7957 1561 mov eax, [$160cdb0]
00ef795c mov eax, [eax]
00ef795e mov eax, [eax+$27c]
00ef7964 mov [ebp-$30], eax
00ef7967 1563 mov eax, [ebp-$30]
00ef796a call -$8a08af ($6570c0) ; Data.DB.TDataSet.Close
00ef796f 1564 mov eax, [ebp-$30]
00ef7972 mov eax, [eax+$250]
00ef7978 mov edx, [eax]
00ef797a call dword ptr [edx+$44]
[...]
thread $11fc:
777bf8da +0e ntdll.dll NtWaitForSingleObject
750f15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7514118f +3e kernel32.dll WaitForSingleObjectEx
75141143 +0d kernel32.dll WaitForSingleObject
75143368 +10 kernel32.dll BaseThreadInitThunk
thread $11d4:
777c0166 +0e ntdll.dll NtWaitForMultipleObjects
75143368 +10 kernel32.dll BaseThreadInitThunk
thread $e00:
777c0166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
75143368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($fbc) at:
72f92713 +24f netbios.dll Netbios
thread $474:
777bf8da +0e ntdll.dll NtWaitForSingleObject
750f15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7514118f +3e kernel32.dll WaitForSingleObjectEx
75141143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
75143368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($fbc) at:
72b64c95 +00 winspool.drv
thread $174:
777c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75143368 +10 kernel32.dll BaseThreadInitThunk
thread $d64:
777c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75143368 +10 kernel32.dll BaseThreadInitThunk
thread $1370:
777c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75143368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
003c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
062a0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063d0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70ee0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
70fe0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
71410000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71750000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71790000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
717b0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
717e0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71970000 webio.dll 6.1.7601.23375 C:\Windows\
system32
719c0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71a20000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72510000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72530000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72610000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
727c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
727e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
727f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72a50000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72b50000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
72f90000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
72fa0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
737b0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73810000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73920000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73930000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73950000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73960000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
739e0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73c40000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73c60000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73ea0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73ef0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74150000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
741b0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
741e0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74210000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74250000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74270000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74280000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74290000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
742f0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74360000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74500000 version.dll 6.1.7600.16385 C:\Windows\
system32
74510000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75030000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75040000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
750d0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750e0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75130000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75240000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
752a0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75330000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75570000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
755d0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
755e0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75660000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75670000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75750000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75770000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75820000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75830000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75930000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75970000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75990000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
759a0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
759b0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
759c0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
759d0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
759e0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76630000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76640000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76770000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76840000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76870000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
769c0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
769e0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76ad0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76d80000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76d90000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76f30000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76fe0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77010000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
770a0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77200000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77300000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
77770000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
777a0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0248 wininit.exe 0 0 0
0250 csrss.exe 1 0 0
0280 winlogon.exe 1 0 0
02ac services.exe 0 0 0
02b8 lsass.exe 0 0 0
02c0 lsm.exe 0 0 0
0324 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
02a4 svchost.exe 0 0 0
0334 svchost.exe 0 0 0
0254 svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0528 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0634 spoolsv.exe 0 0 0
063c taskeng.exe 0 0 0
0660 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
0760 fbguard.exe 0 0 0
0784 svchost.exe 0 0 0
079c NetExpressUpdater.exe 0 0 0
0444 svchost.exe 0 0 0
0564 scpbradserv.exe 0 0 0
00bc core.exe 0 0 0
0960 RapportInjService_x64.exe 0 0 0
0a00 fbserver.exe 0 0 0
0b98 WUDFHost.exe 0 0 0
0860 NisSrv.exe 0 0 0
0ec4 WmiPrvSE.exe 0 0 0
0ef0 OSPPSVC.EXE 0 0 0
0fc4 taskhost.exe 1 26 23 normal
0fd8 core.exe 1 9 21 normal
0924 sppsvc.exe 0 0 0
0e60 GoogleCrashHandler.exe 0 0 0
0e68 GoogleCrashHandler64.exe 0 0 0
0f04 RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0c38 RapportInjService_x64.exe 1 4 3 normal
0e14 svchost.exe 0 0 0
0fcc SearchIndexer.exe 0 0 0
0a8c PresentationFontCache.exe 0 0 0
0af8 dwm.exe 1 17 4 high
0dd0 explorer.exe 1 665 400 normal
033c igfxEM.exe 1 14 13 normal
0f5c igfxHK.exe 1 14 12 normal
0e88 msseces.exe 1 143 59 normal
0da4 PrnStatusMX.exe 1 23 20 normal
1218 wmpnetwk.exe 0 0 0
1260 wuauclt.exe 1 12 5 normal
10d8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
1164 Store.exe 1 889 427 normal C:\Program Files (x86)\Store
114c OIS.EXE 1 102 44 normal
119c DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0ed8 splwow64.exe 1 9 3 normal
1048 OIS.EXE 1 105 45 normal
12f8 chrome.exe 1 25 47 normal
06d0 chrome.exe 1 9 4 normal
134c chrome.exe 1 7 7 above normal
0d70 chrome.exe 1 4 1 normal
030c chrome.exe 1 4 1 normal
105c chrome.exe 1 4 1 idle
1154 chrome.exe 1 4 3 normal
0f84 AcroRd32.exe 1 16 16 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader
16e8 AcroRd32.exe 1 352 121 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader
1568 RdrCEF.exe 1 9 22 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
15b8 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
17bc slui.exe 1 43 31 normal
0538 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
13c8 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0b139be0
ebx = 00442664
ecx = 00000000
edx = 02712ac8
esi = 0018d4dc
edi = 00000000
eip = 00451aee
esp = 0018d498
ebp = 0018dbc4
stack dump:
0018d498 ee 1a 45 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..E.............
0018d4a8 ac d4 18 00 ee 1a 45 00 - e0 9b 13 0b 64 26 44 00 ......E.....d&D.
0018d4b8 dc d4 18 00 00 00 00 00 - c4 db 18 00 c8 d4 18 00 ................
0018d4c8 c0 dd 18 00 00 00 00 00 - 00 00 00 00 ed 31 45 00 .............1E.
0018d4d8 01 00 00 00 00 00 00 00 - 11 bf 88 06 50 bf 88 06 ............P...
0018d4e8 50 bf 88 06 e1 e8 16 01 - cc db 18 00 0c 89 40 00 P.............@.
0018d4f8 c4 db 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d508 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d518 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d528 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d538 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d548 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d558 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d568 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d578 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d588 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d598 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d5a8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d5b8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d5c8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
0116e8ad mov edx, $1171488
0116e8b2 call -$b16483 ($658434) ; Data.DB.TDataSet.FieldByName
0116e8b7 lea edx, [ebp-$5dc]
0116e8bd mov ecx, [eax]
0116e8bf call dword ptr [ecx+$80]
0116e8c5 mov edx, [ebp-$5dc]
0116e8cb mov eax, [$160d150]
0116e8d0 call -$d651a1 ($409734) ; System.@UStrAsg
0116e8d5 640 mov eax, [$160d150]
0116e8da mov eax, [eax]
0116e8dc > call -$d1b725 ($4531bc) ; System.SysUtils.StrToInt
0116e8e1 mov edx, eax
0116e8e3 mov eax, [$160c36c]
0116e8e8 mov eax, [eax]
0116e8ea mov eax, [eax+$4cc]
0116e8f0 mov ecx, [eax]
0116e8f2 call dword ptr [ecx+$fc]
0116e8f8 641 mov eax, [$160cdb0]
0116e8fd mov eax, [eax]
0116e8ff mov eax, [eax+$27c]
0116e905 mov edx, $11714ac
[...]
thread $1164:
7718f8da +0e ntdll.dll NtWaitForSingleObject
74e015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7511118f +3e kernel32.dll WaitForSingleObjectEx
75111143 +0d kernel32.dll WaitForSingleObject
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $1190:
77190166 +0e ntdll.dll NtWaitForMultipleObjects
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $1008:
77190166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
75113368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1130) at:
73332713 +24f netbios.dll Netbios
thread $1120:
7718f8da +0e ntdll.dll NtWaitForSingleObject
74e015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7511118f +3e kernel32.dll WaitForSingleObjectEx
75111143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
75113368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1130) at:
734d4c95 +00 winspool.drv
thread $19c4:
77191f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $16a0:
77191f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75113368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
062c0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063f0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06ba0000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
705a0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70d10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70d70000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70dc0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70e00000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70e80000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
711b0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71340000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71390000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
713f0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71c60000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71c80000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71fa0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71fe0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72190000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
721b0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
721c0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72540000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
72e40000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
731b0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
732b0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73300000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73330000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73340000 security.dll 6.1.7600.16385 C:\Windows\
system32
73350000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73360000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
733c0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
734c0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73710000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73720000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73740000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73750000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73b30000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73b80000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73bb0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73be0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73c40000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73c50000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73c60000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73cc0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73d30000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73ed0000 version.dll 6.1.7600.16385 C:\Windows\
system32
73ee0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74a00000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74a10000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74a70000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
74b40000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
74be0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
74c70000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74cd0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
74d80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74d90000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74de0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74df0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74e40000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
74f10000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
74f90000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75030000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75040000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
750d0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
750e0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750f0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75100000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75210000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75240000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75250000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
752d0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75310000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75320000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75470000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75570000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
757b0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75950000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75ab0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75ba0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75cd0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75d00000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75fb0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75fd0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76c20000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c30000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c40000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76c60000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76cc0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77170000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
03f0 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
0748 svchost.exe 0 0 0
0768 fbguard.exe 0 0 0
0794 svchost.exe 0 0 0
07a8 NetExpressUpdater.exe 0 0 0
04b8 svchost.exe 0 0 0
0680 scpbradserv.exe 0 0 0
0744 svchost.exe 0 0 0
0818 core.exe 0 0 0
096c RapportInjService_x64.exe 0 0 0
0a00 fbserver.exe 0 0 0
0b80 WUDFHost.exe 0 0 0
0bec WmiPrvSE.exe 0 0 0
041c OSPPSVC.EXE 0 0 0
0bdc NisSrv.exe 0 0 0
095c taskhost.exe 1 26 22 normal
0c14 core.exe 1 9 21 normal
0cb8 sppsvc.exe 0 0 0
0f94 PresentationFontCache.exe 0 0 0
0fa8 dwm.exe 1 17 4 high
0fb4 explorer.exe 1 477 283 normal
0c44 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0700 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c98 igfxEM.exe 1 14 14 normal
0c94 igfxHK.exe 1 14 13 normal
085c msseces.exe 1 143 60 normal
08f4 RapportInjService_x64.exe 1 4 3 normal
0ddc PrnStatusMX.exe 1 23 20 normal
11b8 SearchIndexer.exe 0 0 0
11c4 GoogleCrashHandler.exe 0 0 0
11f8 GoogleCrashHandler64.exe 0 0 0
1278 wmpnetwk.exe 0 0 0
12f4 svchost.exe 0 0 0
1230 Store.exe 1 2086 461 normal C:\Program Files (x86)\Store
0640 wuauclt.exe 1 12 7 normal
05c4 splwow64.exe 1 9 4 normal
13a8 chrome.exe 1 77 52 normal
1b5c chrome.exe 1 9 4 normal
1680 chrome.exe 1 12 6 above normal
18f4 chrome.exe 1 4 1 normal
161c chrome.exe 1 4 1 idle
0a10 chrome.exe 1 4 3 normal
03bc OIS.EXE 1 139 54 normal
1488 chrome.exe 1 4 1 idle
158c chrome.exe 1 4 1 idle
1220 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0754 Store.exe 1 128 125 normal C:\Program Files (x86)\Store
193c Store.exe 1 91 69 normal C:\Program Files (x86)\Store
0eb8 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0b4dd8d0
ebx = 09fd1d00
ecx = 000204b0
edx = 054dd801
esi = 0052db9c
edi = 0a474940
eip = 0034005f
esp = 0018d578
ebp = 04443910
stack dump:
0018d578 f7 75 40 00 28 d3 52 00 - 84 00 00 00 00 00 00 00 .u@.(.R.........
0018d588 9e 00 00 00 16 00 00 00 - 40 49 47 0a 40 49 47 0a ........@IG.@IG.
0018d598 01 42 47 00 74 98 53 00 - 10 39 44 04 05 00 00 00 .BG.t.S..9D.....
0018d5a8 3d 1b 53 00 00 53 fd 09 - 00 00 00 00 15 00 00 00 =.S..S..........
0018d5b8 01 42 47 00 8f 4b 59 00 - 08 d6 18 00 10 39 44 04 .BG..KY......9D.
0018d5c8 f0 c5 3c 0a 04 00 00 00 - 3d 1b 53 00 00 77 49 06 ..<.....=.S..wI.
0018d5d8 00 00 00 00 f0 c5 3c 0a - 00 00 00 00 2c 9f 60 00 ......<.....,.`.
0018d5e8 f0 c5 3c 0a 0c d8 18 00 - 06 b1 60 00 dc d7 18 00 ..<.......`.....
0018d5f8 0c 89 40 00 08 d6 18 00 - 46 00 00 01 f0 c5 3c 0a [email protected].....<.
0018d608 3c d7 18 00 f7 75 40 00 - f1 05 61 00 28 fe 52 00 <[email protected].(.R.
0018d618 00 00 00 00 28 0e 1e 06 - 0c d8 18 00 34 ad 50 00 ....(.......4.P.
0018d628 3c ad 50 00 48 33 1d 77 - e8 9f 51 04 f8 e9 3e 77 <.P.H3.w..Q...>w
0018d638 40 e5 18 00 f2 3d 53 00 - ed 88 40 00 00 00 00 00 @....=S...@.....
0018d648 b1 75 40 00 58 80 52 04 - 7c db 18 00 58 d6 18 00 [email protected].|...X...
0018d658 88 d6 18 00 0c 89 40 00 - 94 d6 18 00 94 d6 18 00 ......@.........
0018d668 00 00 00 00 00 00 00 00 - 00 00 00 00 c9 34 1d 77 .............4.w
0018d678 7c db 18 00 18 e5 18 00 - 8c d7 18 00 80 d7 18 00 |...............
0018d688 18 e5 18 00 04 35 1d 77 - 18 e5 18 00 5c da 18 00 .....5.w....\...
0018d698 9b 34 1d 77 7c db 18 00 - 18 e5 18 00 8c d7 18 00 .4.w|...........
0018d6a8 80 d7 18 00 f3 3d 53 00 - 01 00 00 00 7c db 18 00 .....=S.....|...
disassembling:
004075a0 public System.TObject.FreeInstance: ; function entry point
004075a0 708 push ebx
004075a1 mov ebx, eax
004075a3 mov eax, ebx
004075a5 call +$a6 ($407650) ; System.TObject.CleanupInstance
004075aa mov eax, ebx
004075ac call -$29fd ($404bb4) ; System.@FreeMem
004075b1 > pop ebx
004075b2 ret
thread $1164:
7718f8da +0e ntdll.dll NtWaitForSingleObject
74e015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7511118f +3e kernel32.dll WaitForSingleObjectEx
75111143 +0d kernel32.dll WaitForSingleObject
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $1190:
77190166 +0e ntdll.dll NtWaitForMultipleObjects
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $1008:
77190166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
75113368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1130) at:
73332713 +24f netbios.dll Netbios
thread $1120:
7718f8da +0e ntdll.dll NtWaitForSingleObject
74e015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7511118f +3e kernel32.dll WaitForSingleObjectEx
75111143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
75113368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1130) at:
734d4c95 +00 winspool.drv
thread $19c4:
77191f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $16a0:
77191f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75113368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
062c0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063f0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06ba0000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
705a0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70d10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70d70000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70dc0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70e00000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70e80000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
711b0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71340000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71390000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
713f0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71c60000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71c80000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71fa0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71fe0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72190000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
721b0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
721c0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72540000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
72e40000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
731b0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
732b0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73300000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73330000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73340000 security.dll 6.1.7600.16385 C:\Windows\
system32
73350000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73360000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
733c0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
734c0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73710000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73720000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73740000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73750000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73b30000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73b80000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73bb0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73be0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73c40000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73c50000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73c60000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73cc0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73d30000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73ed0000 version.dll 6.1.7600.16385 C:\Windows\
system32
73ee0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74a00000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74a10000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74a70000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
74b40000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
74be0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
74c70000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74cd0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
74d80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74d90000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74de0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74df0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74e40000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
74f10000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
74f90000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75030000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75040000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
750d0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
750e0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750f0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75100000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75210000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75240000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75250000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
752d0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75310000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75320000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75470000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75570000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
757b0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75950000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75ab0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75ba0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75cd0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75d00000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75fb0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75fd0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76c20000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c30000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c40000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76c60000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76cc0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77140000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77170000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
03f0 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
0748 svchost.exe 0 0 0
0768 fbguard.exe 0 0 0
0794 svchost.exe 0 0 0
07a8 NetExpressUpdater.exe 0 0 0
04b8 svchost.exe 0 0 0
0680 scpbradserv.exe 0 0 0
0744 svchost.exe 0 0 0
0818 core.exe 0 0 0
096c RapportInjService_x64.exe 0 0 0
0a00 fbserver.exe 0 0 0
0b80 WUDFHost.exe 0 0 0
0bec WmiPrvSE.exe 0 0 0
041c OSPPSVC.EXE 0 0 0
0bdc NisSrv.exe 0 0 0
095c taskhost.exe 1 26 23 normal
0c14 core.exe 1 9 21 normal
0cb8 sppsvc.exe 0 0 0
0f94 PresentationFontCache.exe 0 0 0
0fa8 dwm.exe 1 17 4 high
0fb4 explorer.exe 1 465 280 normal
0c44 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0700 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c98 igfxEM.exe 1 14 14 normal
0c94 igfxHK.exe 1 14 13 normal
085c msseces.exe 1 143 60 normal
08f4 RapportInjService_x64.exe 1 4 3 normal
0ddc PrnStatusMX.exe 1 23 20 normal
11b8 SearchIndexer.exe 0 0 0
11c4 GoogleCrashHandler.exe 0 0 0
11f8 GoogleCrashHandler64.exe 0 0 0
1278 wmpnetwk.exe 0 0 0
12f4 svchost.exe 0 0 0
1230 Store.exe 1 2086 462 normal C:\Program Files (x86)\Store
0640 wuauclt.exe 1 12 7 normal
05c4 splwow64.exe 1 9 4 normal
13a8 chrome.exe 1 77 52 normal
1b5c chrome.exe 1 9 4 normal
1680 chrome.exe 1 12 6 above normal
18f4 chrome.exe 1 4 1 normal
161c chrome.exe 1 4 1 idle
0a10 chrome.exe 1 4 3 normal
03bc OIS.EXE 1 139 54 normal
1488 chrome.exe 1 4 1 idle
158c chrome.exe 1 4 1 idle
1220 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0754 Store.exe 1 128 125 normal C:\Program Files (x86)\Store
193c Store.exe 1 91 69 normal C:\Program Files (x86)\Store
0eb8 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 04528058
ebx = 004075b1
ecx = 0044dadc
edx = 0018e054
esi = 004075b1
edi = 0018e368
eip = 004075b1
esp = 0018e084
ebp = 0018e0cc
stack dump:
0018e084 b1 75 40 00 de fa ed 0e - 01 00 00 00 07 00 00 00 .u@.............
0018e094 98 e0 18 00 b1 75 40 00 - 58 80 52 04 b1 75 40 00 [email protected]@.
0018e0a4 b1 75 40 00 68 e3 18 00 - cc e0 18 00 b4 e0 18 00 [email protected]...........
0018e0b4 02 00 00 00 f4 4c 40 00 - c0 67 3d 0a b0 8c 4e 0a [email protected]=...N.
0018e0c4 37 4d 40 00 b0 8c 4e 02 - ec e0 18 00 b1 75 40 00 [email protected]@.
0018e0d4 b0 8c 4e 0a 5c 76 4d 00 - c0 67 3d 0a 35 b1 60 00 ..N.\vM..g=.5.`.
0018e0e4 c0 67 3d 01 b0 8c 4e 0a - b0 e1 18 00 f7 75 40 00 .g=...N......u@.
0018e0f4 10 4e ed 00 18 e5 18 00 - 0c 89 40 00 b0 e1 18 00 .N........@.....
0018e104 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e114 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e124 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e134 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e144 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e154 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e164 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e174 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e184 00 00 00 00 c0 67 3d 0a - c0 86 e1 0a 20 7f 4e 04 .....g=..... .N.
0018e194 c0 81 4e 04 60 84 4e 04 - 60 99 4e 04 80 67 4e 04 ..N.`.N.`.N..gN.
0018e1a4 c0 6c 4e 04 20 6a 4e 04 - d0 77 43 04 00 e3 18 00 .lN. jN..wC.....
0018e1b4 81 03 53 00 c0 67 3d 0a - c7 33 55 00 68 e3 18 00 ..S..g=..3U.h...
disassembling:
004075a0 public System.TObject.FreeInstance: ; function entry point
004075a0 708 push ebx
004075a1 mov ebx, eax
004075a3 mov eax, ebx
004075a5 call +$a6 ($407650) ; System.TObject.CleanupInstance
004075aa mov eax, ebx
004075ac call -$29fd ($404bb4) ; System.@FreeMem
004075b1 > pop ebx
004075b2 ret
thread $1164:
7718f8da +0e ntdll.dll NtWaitForSingleObject
74e015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7511118f +3e kernel32.dll WaitForSingleObjectEx
75111143 +0d kernel32.dll WaitForSingleObject
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $1190:
77190166 +0e ntdll.dll NtWaitForMultipleObjects
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $1008:
77190166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
75113368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1130) at:
73332713 +24f netbios.dll Netbios
thread $1120:
7718f8da +0e ntdll.dll NtWaitForSingleObject
74e015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7511118f +3e kernel32.dll WaitForSingleObjectEx
75111143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
75113368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1130) at:
734d4c95 +00 winspool.drv
thread $19c4:
77191f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $16a0:
77191f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75113368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
062c0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063f0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06ba0000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
705a0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70d10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70d70000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70dc0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70e00000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70e80000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
711b0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71340000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71390000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
713f0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71c60000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71c80000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71fa0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71fe0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72190000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
721b0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
721c0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72540000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
72e40000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
731b0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
732b0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73300000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73330000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73340000 security.dll 6.1.7600.16385 C:\Windows\
system32
73350000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73360000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
733c0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
734c0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73710000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73720000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73740000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73750000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73b30000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73b80000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73bb0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73be0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73c40000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73c50000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73c60000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73cc0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73d30000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73ed0000 version.dll 6.1.7600.16385 C:\Windows\
system32
73ee0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74a00000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74a10000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74a70000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
74b40000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
74be0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
74c70000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74cd0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
74d80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74d90000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74de0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74df0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74e40000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
74f10000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
74f90000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75030000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75040000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
750d0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
750e0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750f0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75100000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75210000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75240000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75250000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
752d0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75310000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75320000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75470000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75570000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
757b0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75950000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75ab0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75ba0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75cd0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75d00000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75fb0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75fd0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76c20000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c30000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c40000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76c60000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76cc0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77140000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77170000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
03f0 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
0748 svchost.exe 0 0 0
0768 fbguard.exe 0 0 0
0794 svchost.exe 0 0 0
07a8 NetExpressUpdater.exe 0 0 0
04b8 svchost.exe 0 0 0
0680 scpbradserv.exe 0 0 0
0744 svchost.exe 0 0 0
0818 core.exe 0 0 0
096c RapportInjService_x64.exe 0 0 0
0a00 fbserver.exe 0 0 0
0b80 WUDFHost.exe 0 0 0
0bec WmiPrvSE.exe 0 0 0
041c OSPPSVC.EXE 0 0 0
0bdc NisSrv.exe 0 0 0
095c taskhost.exe 1 26 23 normal
0c14 core.exe 1 9 21 normal
0cb8 sppsvc.exe 0 0 0
0f94 PresentationFontCache.exe 0 0 0
0fa8 dwm.exe 1 17 4 high
0fb4 explorer.exe 1 465 279 normal
0c44 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0700 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c98 igfxEM.exe 1 14 14 normal
0c94 igfxHK.exe 1 14 13 normal
085c msseces.exe 1 143 60 normal
08f4 RapportInjService_x64.exe 1 4 3 normal
0ddc PrnStatusMX.exe 1 23 20 normal
11b8 SearchIndexer.exe 0 0 0
11c4 GoogleCrashHandler.exe 0 0 0
11f8 GoogleCrashHandler64.exe 0 0 0
1278 wmpnetwk.exe 0 0 0
12f4 svchost.exe 0 0 0
1230 Store.exe 1 2084 442 normal C:\Program Files (x86)\Store
0640 wuauclt.exe 1 12 7 normal
05c4 splwow64.exe 1 9 4 normal
13a8 chrome.exe 1 77 52 normal
1b5c chrome.exe 1 9 4 normal
1680 chrome.exe 1 12 6 above normal
18f4 chrome.exe 1 4 1 normal
161c chrome.exe 1 4 1 idle
0a10 chrome.exe 1 4 3 normal
03bc OIS.EXE 1 139 54 normal
1488 chrome.exe 1 4 1 idle
158c chrome.exe 1 4 1 idle
1220 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0754 Store.exe 1 128 125 normal C:\Program Files (x86)\Store
193c Store.exe 1 91 69 normal C:\Program Files (x86)\Store
0eb8 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0ae48db8
ebx = 00000578
ecx = 00000000
edx = 02702ac8
esi = 0a4b7570
edi = 0a4b7570
eip = 0045cf4d
esp = 0018ec34
ebp = 0018ec88
stack dump:
0018ec34 4d cf 45 00 de fa ed 0e - 01 00 00 00 07 00 00 00 M.E.............
0018ec44 48 ec 18 00 4d cf 45 00 - b8 8d e4 0a 78 05 00 00 H...M.E.....x...
0018ec54 70 75 4b 0a 70 75 4b 0a - 88 ec 18 00 64 ec 18 00 puK.puK.....d...
0018ec64 94 ec 18 00 0c 89 40 00 - 88 ec 18 00 01 42 47 00 [email protected].
0018ec74 00 00 00 00 78 05 00 00 - 00 af 40 00 7c 0c c5 0b ....x.....@.|...
0018ec84 11 57 47 00 a4 ec 18 00 - d6 ce 45 00 92 37 53 00 .WG.......E..7S.
0018ec94 ec ec 18 00 0c 89 40 00 - a4 ec 18 00 70 75 4b 0a [email protected].
0018eca4 00 ed 18 00 12 1b 53 00 - 00 89 9b 0b 70 75 4b 0a ......S.....puK.
0018ecb4 70 75 4b 0a 01 42 47 00 - 2d fe 54 00 d0 77 43 04 puK..BG.-.T..wC.
0018ecc4 09 00 00 00 3d 1b 53 00 - 00 33 55 04 09 00 00 00 ....=.S..3U.....
0018ecd4 d0 77 43 04 00 00 00 00 - 2c 9f 60 00 ac 3a 62 00 .wC.....,.`..:b.
0018ece4 80 09 47 0a 06 b1 60 00 - 0c ed 18 00 0c 89 40 00 ..G...`.......@.
0018ecf4 00 ed 18 00 10 d8 7e 01 - d0 77 43 04 34 ed 18 00 ......~..wC.4...
0018ed04 f7 75 40 00 2b 49 17 01 - 68 ef 18 00 0c 89 40 00 .u@.+I..h.....@.
0018ed14 34 ed 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 4...............
0018ed24 00 00 00 00 80 09 47 0a - 60 99 4e 04 d0 2c 44 06 ......G.`.N..,D.
0018ed34 58 ed 18 00 81 03 53 00 - 80 09 47 0a b1 3a 62 00 X.....S...G..:b.
0018ed44 9b 3a 62 00 d4 ee 18 00 - ac 39 62 00 80 09 47 0a .:b......9b...G.
0018ed54 01 00 00 00 c8 ee 18 00 - b9 07 53 00 09 00 00 00 ..........S.....
0018ed64 0e 00 00 00 00 00 00 00 - d4 ee 18 00 80 09 47 0a ..............G.
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 708 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $1164:
7718f8da +0e ntdll.dll NtWaitForSingleObject
74e015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7511118f +3e kernel32.dll WaitForSingleObjectEx
75111143 +0d kernel32.dll WaitForSingleObject
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $1190:
77190166 +0e ntdll.dll NtWaitForMultipleObjects
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $1008:
77190166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
75113368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1130) at:
73332713 +24f netbios.dll Netbios
thread $1120:
7718f8da +0e ntdll.dll NtWaitForSingleObject
74e015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7511118f +3e kernel32.dll WaitForSingleObjectEx
75111143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
75113368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1130) at:
734d4c95 +00 winspool.drv
thread $19c4:
77191f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $16a0:
77191f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75113368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
062c0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063f0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06ba0000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
705a0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70d10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70d70000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70dc0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70e00000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70e80000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
711b0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71340000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71390000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
713f0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71c60000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71c80000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71fa0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71fe0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72190000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
721b0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
721c0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72540000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
72e40000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
731b0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
732b0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73300000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73330000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73340000 security.dll 6.1.7600.16385 C:\Windows\
system32
73350000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73360000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
733c0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
734c0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73710000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73720000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73740000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73750000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73b30000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73b80000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73bb0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73be0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73c40000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73c50000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73c60000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73cc0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73d30000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73ed0000 version.dll 6.1.7600.16385 C:\Windows\
system32
73ee0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74a00000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74a10000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74a70000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
74b40000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
74be0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
74c70000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74cd0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
74d80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74d90000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74de0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74df0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74e40000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
74f10000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
74f90000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75030000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75040000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
750d0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
750e0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750f0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75100000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75210000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75240000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75250000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
752d0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75310000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75320000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75470000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75570000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
757b0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75950000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75ab0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75ba0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75cd0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75d00000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75fb0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75fd0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76c20000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c30000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c40000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76c60000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76cc0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77140000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77170000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
03f0 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
0748 svchost.exe 0 0 0
0768 fbguard.exe 0 0 0
0794 svchost.exe 0 0 0
07a8 NetExpressUpdater.exe 0 0 0
04b8 svchost.exe 0 0 0
0680 scpbradserv.exe 0 0 0
0744 svchost.exe 0 0 0
0818 core.exe 0 0 0
096c RapportInjService_x64.exe 0 0 0
0a00 fbserver.exe 0 0 0
0b80 WUDFHost.exe 0 0 0
0bec WmiPrvSE.exe 0 0 0
041c OSPPSVC.EXE 0 0 0
0bdc NisSrv.exe 0 0 0
095c taskhost.exe 1 26 23 normal
0c14 core.exe 1 9 21 normal
0cb8 sppsvc.exe 0 0 0
0f94 PresentationFontCache.exe 0 0 0
0fa8 dwm.exe 1 17 4 high
0fb4 explorer.exe 1 465 278 normal
0c44 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0700 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c98 igfxEM.exe 1 14 14 normal
0c94 igfxHK.exe 1 14 13 normal
085c msseces.exe 1 143 60 normal
08f4 RapportInjService_x64.exe 1 4 3 normal
0ddc PrnStatusMX.exe 1 23 20 normal
11b8 SearchIndexer.exe 0 0 0
11c4 GoogleCrashHandler.exe 0 0 0
11f8 GoogleCrashHandler64.exe 0 0 0
1278 wmpnetwk.exe 0 0 0
12f4 svchost.exe 0 0 0
1230 Store.exe 1 2084 444 normal C:\Program Files (x86)\Store
0640 wuauclt.exe 1 12 7 normal
05c4 splwow64.exe 1 9 4 normal
13a8 chrome.exe 1 77 52 normal
1b5c chrome.exe 1 9 4 normal
1680 chrome.exe 1 12 6 above normal
18f4 chrome.exe 1 4 1 normal
161c chrome.exe 1 4 1 idle
0a10 chrome.exe 1 4 3 normal
03bc OIS.EXE 1 139 54 normal
1488 chrome.exe 1 4 1 idle
158c chrome.exe 1 4 1 idle
1220 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0754 Store.exe 1 128 125 normal C:\Program Files (x86)\Store
193c Store.exe 1 91 69 normal C:\Program Files (x86)\Store
0eb8 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 05ebdad0
ebx = 00000000
ecx = 00000000
edx = 02702ac8
esi = 044de050
edi = 0a43604c
eip = 0049064d
esp = 0018ead0
ebp = 0018eb30
stack dump:
0018ead0 4d 06 49 00 de fa ed 0e - 01 00 00 00 07 00 00 00 M.I.............
0018eae0 e4 ea 18 00 4d 06 49 00 - d0 da eb 05 00 00 00 00 ....M.I.........
0018eaf0 50 e0 4d 04 4c 60 43 0a - 30 eb 18 00 00 eb 18 00 P.M.L`C.0.......
0018eb00 54 eb 18 00 0c 89 40 00 - 30 eb 18 00 54 59 60 00 [email protected]`.
0018eb10 4c 60 43 0a 30 84 43 04 - 4c 60 43 0a 11 00 00 00 L`C.0.C.L`C.....
0018eb20 00 00 00 00 30 84 43 04 - 00 00 00 00 00 00 00 00 ....0.C.........
0018eb30 74 eb 18 00 25 0a 49 00 - 4c 60 43 0a e5 20 48 00 t...%.I.L`C.. H.
0018eb40 4c 60 43 0a 30 84 43 04 - 6c ec 18 00 00 00 00 00 L`C.0.C.l.......
0018eb50 52 e3 52 00 7c eb 18 00 - 0c 89 40 00 74 eb 18 00 R.R.|[email protected]...
0018eb60 3c cb 42 0a 6c ec 18 00 - 90 ac 47 00 00 00 00 00 <.B.l.....G.....
0018eb70 4c 60 43 0a dc eb 18 00 - 75 ad 48 00 88 eb 18 00 L`C.....u.H.....
0018eb80 eb 8a 40 00 dc eb 18 00 - 94 eb 18 00 0c 89 40 00 ..@...........@.
0018eb90 dc eb 18 00 e4 eb 18 00 - 0c 89 40 00 dc eb 18 00 ..........@.....
0018eba0 3c cb 42 0a 6c ec 18 00 - 30 84 43 04 00 00 00 00 <.B.l...0.C.....
0018ebb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ebc0 00 00 00 00 a4 84 48 00 - 04 ec 18 00 21 7c 40 00 ......H.....!|@.
0018ebd0 30 84 43 04 30 84 43 04 - c0 76 4e 0b fc eb 18 00 0.C.0.C..vN.....
0018ebe0 3b 73 48 00 04 ec 18 00 - 0c 89 40 00 fc eb 18 00 ;sH.......@.....
0018ebf0 00 00 40 00 c0 76 4e 0b - 6c ec 18 00 20 ec 18 00 [email protected]... ...
0018ec00 74 21 48 00 28 ec 18 00 - 0c 89 40 00 20 ec 18 00 t!H.(.....@. ...
disassembling:
[...]
0117486f mov ecx, $1174a14
01174874 mov edx, $1174a24
01174879 mov eax, [$160cbd0]
0117487e mov eax, [eax]
01174880 call -$b5edad ($615ad8) ; Vcl.Forms.TApplication.MessageBox
01174885 1056 jmp loc_1174939
0117488a 1058 mov ecx, [$160c1f0]
01174890 mov eax, [$160cbd0]
01174895 mov eax, [eax]
01174897 mov edx, [$ecc1ac]
0117489d > call -$b5f16a ($615738) ; Vcl.Forms.TApplication.CreateForm
011748a2 1059 mov eax, [$160cdb0]
011748a7 mov eax, [eax]
011748a9 mov eax, [eax+$27c]
011748af mov edx, $1174a9c
011748b4 call -$b1c485 ($658434) ; Data.DB.TDataSet.FieldByName
011748b9 lea edx, [ebp-$18]
011748bc mov ecx, [eax]
011748be call dword ptr [ecx+$80]
011748c4 mov edx, [ebp-$18]
011748c7 mov eax, [$160c1f0]
[...]
thread $1164:
7718f8da +0e ntdll.dll NtWaitForSingleObject
74e015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7511118f +3e kernel32.dll WaitForSingleObjectEx
75111143 +0d kernel32.dll WaitForSingleObject
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $1190:
77190166 +0e ntdll.dll NtWaitForMultipleObjects
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $1008:
77190166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
75113368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1130) at:
73332713 +24f netbios.dll Netbios
thread $1120:
7718f8da +0e ntdll.dll NtWaitForSingleObject
74e015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7511118f +3e kernel32.dll WaitForSingleObjectEx
75111143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
75113368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1130) at:
734d4c95 +00 winspool.drv
thread $19c4:
77191f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $16a0:
77191f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75113368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
062c0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063f0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06ba0000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
705a0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70d10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70d70000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70dc0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70e00000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70e80000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
711b0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71340000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71390000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
713f0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71c60000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71c80000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71fa0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71fe0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72190000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
721b0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
721c0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72540000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
72e40000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
731b0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
732b0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73300000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73330000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73340000 security.dll 6.1.7600.16385 C:\Windows\
system32
73350000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73360000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
733c0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
734c0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73710000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73720000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73740000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73750000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73b30000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73b80000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73bb0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73be0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73c40000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73c50000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73c60000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73cc0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73d30000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73ed0000 version.dll 6.1.7600.16385 C:\Windows\
system32
73ee0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74a00000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74a10000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74a70000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
74b40000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
74be0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
74c70000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74cd0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
74d80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74d90000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74de0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74df0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74e40000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
74f10000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
74f90000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75030000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75040000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
750d0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
750e0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750f0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75100000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75210000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75240000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75250000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
752d0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75310000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75320000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75470000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75570000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
757b0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75950000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75ab0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75ba0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75cd0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75d00000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75fb0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75fd0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76c20000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c30000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c40000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76c60000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76cc0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77140000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77170000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
03f0 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
0748 svchost.exe 0 0 0
0768 fbguard.exe 0 0 0
0794 svchost.exe 0 0 0
07a8 NetExpressUpdater.exe 0 0 0
04b8 svchost.exe 0 0 0
0680 scpbradserv.exe 0 0 0
0744 svchost.exe 0 0 0
0818 core.exe 0 0 0
096c RapportInjService_x64.exe 0 0 0
0a00 fbserver.exe 0 0 0
0b80 WUDFHost.exe 0 0 0
0bec WmiPrvSE.exe 0 0 0
041c OSPPSVC.EXE 0 0 0
0bdc NisSrv.exe 0 0 0
095c taskhost.exe 1 26 24 normal
0c14 core.exe 1 9 21 normal
0cb8 sppsvc.exe 0 0 0
0f94 PresentationFontCache.exe 0 0 0
0fa8 dwm.exe 1 17 4 high
0fb4 explorer.exe 1 465 280 normal
0c44 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0700 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c98 igfxEM.exe 1 14 14 normal
0c94 igfxHK.exe 1 14 13 normal
085c msseces.exe 1 143 60 normal
08f4 RapportInjService_x64.exe 1 4 3 normal
0ddc PrnStatusMX.exe 1 23 20 normal
11b8 SearchIndexer.exe 0 0 0
11c4 GoogleCrashHandler.exe 0 0 0
11f8 GoogleCrashHandler64.exe 0 0 0
1278 wmpnetwk.exe 0 0 0
12f4 svchost.exe 0 0 0
1230 Store.exe 1 2059 331 normal C:\Program Files (x86)\Store
0640 wuauclt.exe 1 12 7 normal
05c4 splwow64.exe 1 9 4 normal
13a8 chrome.exe 1 77 52 normal
1b5c chrome.exe 1 9 4 normal
1680 chrome.exe 1 12 6 above normal
18f4 chrome.exe 1 4 1 normal
161c chrome.exe 1 4 1 idle
0a10 chrome.exe 1 4 3 normal
03bc OIS.EXE 1 139 54 normal
1488 chrome.exe 1 4 1 idle
158c chrome.exe 1 4 1 idle
1220 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0754 Store.exe 1 128 127 normal C:\Program Files (x86)\Store
193c Store.exe 1 91 69 normal C:\Program Files (x86)\Store
0eb8 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0dfd5740
ebx = 00474201
ecx = 000204b0
edx = 00474201
esi = 0a474940
edi = 057fb300
eip = 0034003d
esp = 0018febc
ebp = 0018ff40
stack dump:
0018febc f7 75 40 00 69 98 53 00 - 40 49 47 0a f0 c5 3c 0a [email protected].@IG...<.
0018fecc 56 03 49 00 f0 c5 3c 0a - f0 c5 3c 0a 00 64 51 05 V.I...<...<..dQ.
0018fedc 9c 00 49 00 f0 c5 3c 0a - 00 00 00 00 79 d3 52 00 ..I...<.....y.R.
0018feec 98 cc 51 05 5c 76 4d 00 - 01 cc 51 05 cc 3c 48 00 ..Q.\vM...Q..<H.
0018fefc 50 5b 45 06 f0 c5 3c 0a - 00 00 00 00 a5 1b 53 00 P[E...<.......S.
0018ff0c 00 00 00 00 f8 a1 51 04 - f0 c5 3c 0a 00 00 00 00 ......Q...<.....
0018ff1c 2c 9f 60 00 f0 c5 3c 0a - 50 e0 4d 04 06 b1 60 00 ,.`...<.P.M...`.
0018ff2c 78 ff 18 00 0c 89 40 00 - 40 ff 18 00 f8 a1 51 01 x.....@[email protected].
0018ff3c f0 c5 3c 0a 88 ff 18 00 - 56 03 49 00 54 e0 60 01 ..<.....V.I.T.`.
0018ff4c 18 0b 61 01 c8 8c 60 00 - 02 8d 60 00 0c 1e 45 00 ..a...`...`...E.
0018ff5c e4 1d 45 00 af 90 40 00 - 88 ff 18 00 00 00 00 00 ..E...@.........
0018ff6c 00 00 00 00 00 e0 fd 7e - 29 21 5e 01 c4 ff 18 00 .......~)!^.....
0018ff7c dc 8b 40 00 88 ff 18 00 - 00 00 00 00 94 ff 18 00 ..@.............
0018ff8c 6a 33 11 75 00 e0 fd 7e - d4 ff 18 00 f2 98 1a 77 j3.u...~.......w
0018ff9c 00 e0 fd 7e 58 c0 3e 77 - 00 00 00 00 00 00 00 00 ...~X.>w........
0018ffac 00 e0 fd 7e 00 00 00 00 - b9 6c fc 76 00 00 00 00 ...~.....l.v....
0018ffbc a0 ff 18 00 00 00 00 00 - ff ff ff ff 45 58 1e 77 ............EX.w
0018ffcc ac f9 3f 00 00 00 00 00 - ec ff 18 00 c5 98 1a 77 ..?............w
0018ffdc 70 20 5e 01 00 e0 fd 7e - 00 00 00 00 00 00 00 00 p ^....~........
0018ffec 00 00 00 00 00 00 00 00 - 70 20 5e 01 00 e0 fd 7e ........p ^....~
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 708 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $19ec:
7718f8da +0e ntdll.dll NtWaitForSingleObject
74e015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7511118f +3e kernel32.dll WaitForSingleObjectEx
75111143 +0d kernel32.dll WaitForSingleObject
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $1440:
77190166 +0e ntdll.dll NtWaitForMultipleObjects
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $170c:
7718f8da +0e ntdll.dll NtWaitForSingleObject
74e015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7511118f +3e kernel32.dll WaitForSingleObjectEx
75111143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
75113368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1a2c) at:
73474c95 +00 winspool.drv
thread $1ae0:
77191f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $18d4:
77191f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $15d0:
77191f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75113368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00340000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
062d0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06ba0000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
705a0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70810000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
70d10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70d70000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70dc0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70e00000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70e80000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
711b0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71340000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71390000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
713f0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71c60000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71c80000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71fa0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71fe0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72190000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
721b0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
721c0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72540000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
72e40000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
732b0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73330000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73360000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73460000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
734c0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73710000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73720000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73740000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73750000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73ad0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73ae0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73b30000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73b80000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73bb0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73be0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73c40000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73c50000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73c60000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73cc0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73d30000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73ed0000 version.dll 6.1.7600.16385 C:\Windows\
system32
73ee0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74a00000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74a10000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74a70000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
74b40000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
74be0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
74c70000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74cd0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
74d80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74d90000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74de0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74df0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74e40000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
74f10000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
74f90000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75030000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75040000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
750d0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
750e0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750f0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75100000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75210000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75240000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75250000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
752d0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75310000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75320000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75470000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75570000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
757b0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75950000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75ab0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75ba0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75cd0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75d00000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75fb0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75fd0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76c20000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c30000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c40000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76c60000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76cc0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77140000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77170000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
03f0 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
0748 svchost.exe 0 0 0
0768 fbguard.exe 0 0 0
0794 svchost.exe 0 0 0
07a8 NetExpressUpdater.exe 0 0 0
04b8 svchost.exe 0 0 0
0680 scpbradserv.exe 0 0 0
0744 svchost.exe 0 0 0
0818 core.exe 0 0 0
096c RapportInjService_x64.exe 0 0 0
0a00 fbserver.exe 0 0 0
0b80 WUDFHost.exe 0 0 0
0bec WmiPrvSE.exe 0 0 0
041c OSPPSVC.EXE 0 0 0
0bdc NisSrv.exe 0 0 0
095c taskhost.exe 1 26 23 normal
0c14 core.exe 1 9 21 normal
0cb8 sppsvc.exe 0 0 0
0f94 PresentationFontCache.exe 0 0 0
0fa8 dwm.exe 1 17 4 high
0fb4 explorer.exe 1 471 403 normal
0c44 RapportService.exe 1 14 18 normal C:\Program Files (x86)\Trusteer\
Rapport\bin
0700 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\scpbrad
0c98 igfxEM.exe 1 14 14 normal
0c94 igfxHK.exe 1 14 13 normal
085c msseces.exe 1 143 60 normal
08f4 RapportInjService_x64.exe 1 4 3 normal
0ddc PrnStatusMX.exe 1 23 20 normal
11b8 SearchIndexer.exe 0 0 0
11c4 GoogleCrashHandler.exe 0 0 0
11f8 GoogleCrashHandler64.exe 0 0 0
1278 wmpnetwk.exe 0 0 0
12f4 svchost.exe 0 0 0
0640 wuauclt.exe 1 12 6 normal
1220 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1124 Store.exe 1 4082 903 normal C:\Program Files (x86)\Store
1b88 splwow64.exe 1 9 5 normal
07f4 OIS.EXE 1 111 80 normal
1340 OIS.EXE 1 130 48 normal
1918 OIS.EXE 1 109 44 normal
167c RdrCEF.exe 1 9 19 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
193c RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
102c audiodg.exe 0 0 0
1310 WmiPrvSE.exe 0 0 0
1580 VSSVC.exe 0 0 0
1900 svchost.exe 0 0 0
1600 rundll32.exe 1 116 52 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 046134c0
ebx = 0a7a5b20
ecx = 00000000
edx = 04604701
esi = 0a7a5b20
edi = 0018e368
eip = 004075f4
esp = 0018e0b4
ebp = 0018e0c0
stack dump:
0018e0b4 e4 5b 6f 00 ac 7c 40 00 - d0 c6 d2 0c d0 e0 18 00 .[o..|@.........
0018e0c4 d3 9c 6f 00 20 5b 7a 01 - d0 c6 d2 0c 2c e1 18 00 ..o. [z.....,...
0018e0d4 f7 75 40 00 47 38 ed 00 - 34 e1 18 00 0c 89 40 00 [email protected].....@.
0018e0e4 2c e1 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ,...............
0018e0f4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e104 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e114 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e124 c0 90 77 0a b0 d6 59 04 - b0 e1 18 00 c9 cf ec 00 ..w...Y.........
0018e134 18 e5 18 00 0c 89 40 00 - b0 e1 18 00 00 00 00 00 ......@.........
0018e144 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e154 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e164 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e174 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e184 00 00 00 00 00 00 00 00 - 20 5b 7a 0a 20 7f 64 04 ........ [z. .d.
0018e194 c0 81 64 04 60 84 64 04 - 60 99 64 04 80 67 64 04 ..d.`.d.`.d..gd.
0018e1a4 c0 6c 64 04 20 6a 64 04 - b0 d6 59 04 00 e3 18 00 .ld. jd...Y.....
0018e1b4 81 03 53 00 20 5b 7a 0a - c7 33 55 00 68 e3 18 00 ..S. [z..3U.h...
0018e1c4 f6 42 62 00 4c 42 62 00 - 68 e3 18 00 f5 3e 55 00 .Bb.LBb.h....>U.
0018e1d4 20 5b 7a 0a 28 fe 52 00 - 68 e3 18 00 48 e5 18 00 [z.(.R.h...H...
0018e1e4 20 5b 7a 0a f3 00 00 00 - 05 8b 4a 75 68 74 48 75 [z.......JuhtHu
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 708 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $19ec:
7718f8da +0e ntdll.dll NtWaitForSingleObject
74e015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7511118f +3e kernel32.dll WaitForSingleObjectEx
75111143 +0d kernel32.dll WaitForSingleObject
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $1440:
77190166 +0e ntdll.dll NtWaitForMultipleObjects
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $170c:
7718f8da +0e ntdll.dll NtWaitForSingleObject
74e015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7511118f +3e kernel32.dll WaitForSingleObjectEx
75111143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
75113368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1a2c) at:
73474c95 +00 winspool.drv
thread $19b0:
77191f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75113368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00340000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
062d0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06ba0000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
705a0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70810000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
70d10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70d70000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70dc0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70e00000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70e80000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
711b0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71340000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71390000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
713f0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71c60000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71c80000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71fa0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71fe0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72190000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
721b0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
721c0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72540000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
72e40000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
732b0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73330000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73360000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73460000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
734c0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73710000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73720000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73740000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73750000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73ad0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73ae0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73b30000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73b80000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73bb0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73be0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73c40000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73c50000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73c60000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73cc0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73d30000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73ed0000 version.dll 6.1.7600.16385 C:\Windows\
system32
73ee0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74a00000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74a10000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74a70000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
74b40000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
74be0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
74c70000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74cd0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
74d80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74d90000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74de0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74df0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74e40000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
74f10000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
74f90000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75030000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75040000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
750d0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
750e0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750f0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75100000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75210000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75240000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75250000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
752d0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75310000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75320000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75470000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75570000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
757b0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75950000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75ab0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75ba0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75cd0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75d00000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75fb0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75fd0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76c20000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c30000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c40000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76c60000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76cc0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77140000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77170000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
03f0 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
0748 svchost.exe 0 0 0
0768 fbguard.exe 0 0 0
0794 svchost.exe 0 0 0
07a8 NetExpressUpdater.exe 0 0 0
04b8 svchost.exe 0 0 0
0680 scpbradserv.exe 0 0 0
0744 svchost.exe 0 0 0
0818 core.exe 0 0 0
096c RapportInjService_x64.exe 0 0 0
0a00 fbserver.exe 0 0 0
0b80 WUDFHost.exe 0 0 0
0bec WmiPrvSE.exe 0 0 0
041c OSPPSVC.EXE 0 0 0
0bdc NisSrv.exe 0 0 0
095c taskhost.exe 1 26 24 normal
0c14 core.exe 1 9 21 normal
0cb8 sppsvc.exe 0 0 0
0f94 PresentationFontCache.exe 0 0 0
0fa8 dwm.exe 1 17 4 high
0fb4 explorer.exe 1 469 420 normal
0c44 RapportService.exe 1 14 18 normal C:\Program Files (x86)\Trusteer\
Rapport\bin
0700 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\scpbrad
0c98 igfxEM.exe 1 14 14 normal
0c94 igfxHK.exe 1 14 13 normal
085c msseces.exe 1 143 60 normal
08f4 RapportInjService_x64.exe 1 4 3 normal
0ddc PrnStatusMX.exe 1 23 20 normal
11b8 SearchIndexer.exe 0 0 0
11c4 GoogleCrashHandler.exe 0 0 0
11f8 GoogleCrashHandler64.exe 0 0 0
1278 wmpnetwk.exe 0 0 0
12f4 svchost.exe 0 0 0
0640 wuauclt.exe 1 12 6 normal
1220 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1124 Store.exe 1 4990 762 normal C:\Program Files (x86)\Store
1b88 splwow64.exe 1 9 2 normal
07f4 OIS.EXE 1 111 80 normal
1340 OIS.EXE 1 130 48 normal
1918 OIS.EXE 1 109 45 normal
167c RdrCEF.exe 1 9 19 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
193c RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
1274 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0018fe18
ebx = 004075b1
ecx = 00000007
edx = 00000000
esi = 004075b1
edi = 0da9d5e0
eip = 74dfc54f
esp = 0018fe18
ebp = 0018fe68
stack dump:
0018fe18 de fa ed 0e 01 00 00 00 - 00 00 00 00 4f c5 df 74 ............O..t
0018fe28 07 00 00 00 b1 75 40 00 - 58 80 68 04 b1 75 40 00 [email protected]@.
0018fe38 b1 75 40 00 e0 d5 a9 0d - b4 fe 18 00 9c fe 18 00 .u@.............
0018fe48 df 60 4d 00 e0 d5 a9 0d - b1 75 40 00 b4 fe 18 00 .`M......u@.....
0018fe58 6c fe 18 00 b1 75 40 00 - 3c fe 18 00 dc da 44 00 l....u@.<.....D.
0018fe68 b4 fe 18 00 b1 75 40 00 - de fa ed 0e 01 00 00 00 .....u@.........
0018fe78 07 00 00 00 80 fe 18 00 - b1 75 40 00 58 80 68 04 [email protected].
0018fe88 b1 75 40 00 b1 75 40 00 - e0 d5 a9 0d b4 fe 18 00 [email protected]@.........
0018fe98 9c fe 18 00 02 00 00 00 - f4 4c 40 00 b0 c7 fe 05 .........L@.....
0018fea8 e0 d5 a9 0d 37 4d 40 00 - e0 d5 a9 02 e0 fe 18 00 ....7M@.........
0018feb8 b1 75 40 00 e0 d5 a9 0d - 5c 76 4d 00 02 00 00 00 .u@.....\vM.....
0018fec8 1b 67 48 00 d0 c6 d2 0c - b0 c7 fe 05 02 00 00 00 .gH.............
0018fed8 24 ae 50 01 00 00 00 00 - f4 fe 18 00 f7 75 40 00 $.P..........u@.
0018fee8 68 5b 6f 00 ac 7c 40 00 - d0 c6 d2 0c 04 ff 18 00 h[o..|@.........
0018fef8 d3 9c 6f 00 e9 2d 53 01 - d0 c6 d2 0c 40 ff 18 00 ..o..-S.....@...
0018ff08 3d 1b 53 00 00 39 c4 0b - f8 a1 67 04 b0 c7 fe 05 =.S..9....g.....
0018ff18 00 00 00 00 2c 9f 60 00 - b0 c7 fe 05 50 e0 63 04 ....,.`.....P.c.
0018ff28 06 b1 60 00 78 ff 18 00 - 0c 89 40 00 40 ff 18 00 ..`.x.....@.@...
0018ff38 f8 a1 67 01 b0 c7 fe 05 - 88 ff 18 00 56 03 49 00 ..g.........V.I.
0018ff48 54 e0 60 01 18 0b 61 01 - c8 8c 60 00 02 8d 60 00 T.`...a...`...`.
disassembling:
004075a0 public System.TObject.FreeInstance: ; function entry point
004075a0 708 push ebx
004075a1 mov ebx, eax
004075a3 mov eax, ebx
004075a5 call +$a6 ($407650) ; System.TObject.CleanupInstance
004075aa mov eax, ebx
004075ac call -$29fd ($404bb4) ; System.@FreeMem
004075b1 > pop ebx
004075b2 ret
thread $cc4:
77d5f8da +0e ntdll.dll NtWaitForSingleObject
772215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7637118f +3e kernel32.dll WaitForSingleObjectEx
76371143 +0d kernel32.dll WaitForSingleObject
76373368 +10 kernel32.dll BaseThreadInitThunk
thread $e28:
77d60166 +0e ntdll.dll NtWaitForMultipleObjects
76373368 +10 kernel32.dll BaseThreadInitThunk
thread $10bc:
77d60166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
76373368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($12c4) at:
72ff2713 +24f netbios.dll Netbios
thread $648:
77d5f8da +0e ntdll.dll NtWaitForSingleObject
772215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7637118f +3e kernel32.dll WaitForSingleObjectEx
76371143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
76373368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($12c4) at:
73254c95 +00 winspool.drv
thread $1658:
77d61f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76373368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00300000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
063d0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
064d0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
700e0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
71730000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71770000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71790000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71b30000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71d90000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71de0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71e40000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71e80000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
72830000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72850000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72b70000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72bb0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72d60000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72d80000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72d90000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72ff0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73000000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73240000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
739f0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73a00000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73ae0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73af0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73b10000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73b20000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73f00000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73f50000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73f90000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
741e0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74200000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74350000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
743c0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
74700000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74750000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74780000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
747b0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
747f0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74810000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74820000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74830000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74890000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74900000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74aa0000 version.dll 6.1.7600.16385 C:\Windows\
system32
74ab0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
755d0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
755e0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75640000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
757e0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75890000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
758a0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
758b0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
759a0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75a40000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75a50000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75a80000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75a90000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75ae0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75af0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75b30000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75c00000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75d30000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d40000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75ff0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76090000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
760f0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76100000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76250000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76260000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76360000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76470000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
764f0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76510000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
765c0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77210000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77260000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
772f0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77340000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77360000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
773c0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77580000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77590000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
775a0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
77640000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
776d0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
77910000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77d10000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77d40000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
032c svchost.exe 0 0 0
0378 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
00a8 RapportMgmtService.exe 0 0 0
02b0 svchost.exe 0 0 0
0368 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
04ac svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0630 spoolsv.exe 0 0 0
0638 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06e8 armsvc.exe 0 0 0
0700 atkexComSvc.exe 0 0 0
0740 svchost.exe 0 0 0
0764 fbguard.exe 0 0 0
0788 svchost.exe 0 0 0
079c NetExpressUpdater.exe 0 0 0
04c0 svchost.exe 0 0 0
0670 scpbradserv.exe 0 0 0
070c svchost.exe 0 0 0
0810 core.exe 0 0 0
0964 RapportInjService_x64.exe 0 0 0
0a14 fbserver.exe 0 0 0
0b20 WUDFHost.exe 0 0 0
0bb8 NisSrv.exe 0 0 0
0e6c taskhost.exe 1 26 24 normal
0e8c core.exe 1 9 21 normal
0fa8 sppsvc.exe 0 0 0
0d40 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0d80 RapportInjService_x64.exe 1 4 3 normal
0e1c svchost.exe 0 0 0
0c50 GoogleCrashHandler.exe 0 0 0
0d70 GoogleCrashHandler64.exe 0 0 0
0174 WmiPrvSE.exe 0 0 0
0fa4 OSPPSVC.EXE 0 0 0
0878 PresentationFontCache.exe 0 0 0
084c dwm.exe 1 17 4 high
07f0 explorer.exe 1 434 240 normal
0fe4 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
082c igfxEM.exe 1 14 13 normal
0580 igfxHK.exe 1 14 12 normal
0be4 msseces.exe 1 143 60 normal
0ed0 PrnStatusMX.exe 1 23 20 normal
117c SearchIndexer.exe 0 0 0
11ac wuauclt.exe 1 12 6 normal
1258 wmpnetwk.exe 0 0 0
12c0 Store.exe 1 639 379 normal C:\Program Files (x86)\Store
1230 chrome.exe 1 26 47 normal
1218 chrome.exe 1 9 4 normal
1094 chrome.exe 1 7 6 above normal
1184 chrome.exe 1 4 1 normal
1250 chrome.exe 1 4 1 normal
16d4 chrome.exe 1 4 1 idle
1a40 chrome.exe 1 4 3 normal
18e4 splwow64.exe 1 9 2 normal
1560 OIS.EXE 1 102 44 normal
18d8 svchost.exe 0 0 0
1834 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 062ba360
ebx = 00003303
ecx = 00000000
edx = 02652ac8
esi = 0018d170
edi = 0066c9e4
eip = 0066e902
esp = 0018d134
ebp = 0018d19c
stack dump:
0018d134 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018d144 48 d1 18 00 02 e9 66 00 - 60 a3 2b 06 03 33 00 00 H.....f.`.+..3..
0018d154 70 d1 18 00 e4 c9 66 00 - 9c d1 18 00 64 d1 18 00 p.....f.....d...
0018d164 20 d2 65 06 0e e9 66 00 - 34 e8 67 00 00 00 00 00 .e...f.4.g.....
0018d174 20 d2 65 06 00 00 00 00 - 2f e7 67 00 a8 d1 18 00 .e...../.g.....
0018d184 0c 89 40 00 9c d1 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018d194 69 e8 67 01 20 d2 65 06 - c4 d1 18 00 87 e7 67 00 i.g. .e.......g.
0018d1a4 a6 4b 67 00 dc d1 18 00 - 0c 89 40 00 c4 d1 18 00 .Kg.......@.....
0018d1b4 20 d2 65 06 00 00 00 00 - 00 00 00 00 20 d2 65 06 .e......... .e.
0018d1c4 f0 d1 18 00 4a 91 67 00 - b4 d7 18 00 80 a2 27 06 ....J.g.......'.
0018d1d4 01 00 00 00 77 72 65 00 - fc d1 18 00 0c 89 40 00 ....wre.......@.
0018d1e4 f0 d1 18 00 80 a2 27 06 - 20 d2 65 06 c0 d2 18 00 ......'. .e.....
0018d1f4 be 70 65 00 88 ba 16 01 - c8 d2 18 00 0c 89 40 00 .pe...........@.
0018d204 c0 d2 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d214 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d224 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d234 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d244 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d254 00 00 00 00 00 00 00 00 - e0 79 e5 40 a0 b9 5e 06 .........y.@..^.
0018d264 00 00 00 00 fa a4 4f fa - 7f 7e e5 40 00 00 00 00 ......O..~.@....
disassembling:
[...]
0116ba5f mov eax, [ebp-$18]
0116ba62 mov eax, [eax+$250]
0116ba68 mov ecx, [eax]
0116ba6a call dword ptr [ecx+$38]
0116ba6d 425 mov edx, $116cac0
0116ba72 mov eax, [ebp-$18]
0116ba75 mov eax, [eax+$250]
0116ba7b mov ecx, [eax]
0116ba7d call dword ptr [ecx+$38]
0116ba80 427 mov eax, [ebp-$18]
0116ba83 > call -$b149d4 ($6570b4) ; Data.DB.TDataSet.Open
0116ba88 428 mov eax, [ebp-$18]
0116ba8b call -$b12114 ($65997c) ; Data.DB.TDataSet.First
0116ba90 429 mov eax, [ebp-$18]
0116ba93 cmp byte ptr [eax+$a9], 0
0116ba9a jz loc_116baa8
0116ba9c mov eax, [ebp-$18]
0116ba9f cmp byte ptr [eax+$a8], 0
0116baa6 jnz loc_116bab7
0116baa8 431 mov eax, [ebp-4]
0116baab call +$32fe8 ($119ea98) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $cc4:
77d5f8da +0e ntdll.dll NtWaitForSingleObject
772215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7637118f +3e kernel32.dll WaitForSingleObjectEx
76371143 +0d kernel32.dll WaitForSingleObject
76373368 +10 kernel32.dll BaseThreadInitThunk
thread $e28:
77d60166 +0e ntdll.dll NtWaitForMultipleObjects
76373368 +10 kernel32.dll BaseThreadInitThunk
thread $10bc:
77d60166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
76373368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($12c4) at:
72ff2713 +24f netbios.dll Netbios
thread $648:
77d5f8da +0e ntdll.dll NtWaitForSingleObject
772215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7637118f +3e kernel32.dll WaitForSingleObjectEx
76371143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
76373368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($12c4) at:
73254c95 +00 winspool.drv
thread $1748:
77d61f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76373368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00300000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
063d0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
064d0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
700e0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
71730000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71770000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71790000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71b30000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71d90000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71de0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71e40000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71e80000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
72830000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72850000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72b70000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72bb0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72d60000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72d80000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72d90000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72ff0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73000000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73240000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
739f0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73a00000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73ae0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73af0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73b10000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73b20000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73f00000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73f50000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73f90000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
741e0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74200000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74350000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
743c0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
74700000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74750000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74780000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
747b0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
747f0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74810000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74820000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74830000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74890000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74900000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74aa0000 version.dll 6.1.7600.16385 C:\Windows\
system32
74ab0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
755d0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
755e0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75640000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
757e0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75890000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
758a0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
758b0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
759a0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75a40000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75a50000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75a80000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75a90000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75ae0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75af0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75b30000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75c00000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75d30000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d40000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75ff0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76090000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
760f0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76100000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76250000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76260000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76360000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76470000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
764f0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76510000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
765c0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77210000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77260000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
772f0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77340000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77360000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
773c0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77580000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77590000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
775a0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
77640000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
776d0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
77910000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77d10000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77d40000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
032c svchost.exe 0 0 0
0378 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
00a8 RapportMgmtService.exe 0 0 0
02b0 svchost.exe 0 0 0
0368 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
04ac svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0630 spoolsv.exe 0 0 0
0638 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06e8 armsvc.exe 0 0 0
0700 atkexComSvc.exe 0 0 0
0740 svchost.exe 0 0 0
0764 fbguard.exe 0 0 0
0788 svchost.exe 0 0 0
079c NetExpressUpdater.exe 0 0 0
04c0 svchost.exe 0 0 0
0670 scpbradserv.exe 0 0 0
070c svchost.exe 0 0 0
0810 core.exe 0 0 0
0964 RapportInjService_x64.exe 0 0 0
0a14 fbserver.exe 0 0 0
0b20 WUDFHost.exe 0 0 0
0bb8 NisSrv.exe 0 0 0
0e6c taskhost.exe 1 26 22 normal
0e8c core.exe 1 9 21 normal
0fa8 sppsvc.exe 0 0 0
0d40 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0d80 RapportInjService_x64.exe 1 4 3 normal
0e1c svchost.exe 0 0 0
0c50 GoogleCrashHandler.exe 0 0 0
0d70 GoogleCrashHandler64.exe 0 0 0
0174 WmiPrvSE.exe 0 0 0
0fa4 OSPPSVC.EXE 0 0 0
0878 PresentationFontCache.exe 0 0 0
084c dwm.exe 1 17 4 high
07f0 explorer.exe 1 541 320 normal
0fe4 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
082c igfxEM.exe 1 14 13 normal
0580 igfxHK.exe 1 14 12 normal
0be4 msseces.exe 1 143 60 normal
0ed0 PrnStatusMX.exe 1 23 20 normal
117c SearchIndexer.exe 0 0 0
11ac wuauclt.exe 1 12 6 normal
1258 wmpnetwk.exe 0 0 0
12c0 Store.exe 1 1535 287 normal C:\Program Files (x86)\Store
1230 chrome.exe 1 74 50 normal
1218 chrome.exe 1 9 4 normal
1094 chrome.exe 1 7 6 above normal
1184 chrome.exe 1 4 1 normal
1250 chrome.exe 1 4 1 normal
16d4 chrome.exe 1 4 1 idle
1a40 chrome.exe 1 4 3 normal
18e4 splwow64.exe 1 9 2 normal
1560 OIS.EXE 1 102 44 normal
1750 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1b18 OIS.EXE 1 102 44 normal
18bc OIS.EXE 1 131 50 normal
13e4 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 05d590e0
ebx = 00003303
ecx = 00000000
edx = 02652ac8
esi = 0018e858
edi = 0066c9e4
eip = 0066e902
esp = 0018e81c
ebp = 0018e884
stack dump:
0018e81c 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018e82c 30 e8 18 00 02 e9 66 00 - e0 90 d5 05 03 33 00 00 0.....f......3..
0018e83c 58 e8 18 00 e4 c9 66 00 - 84 e8 18 00 4c e8 18 00 X.....f.....L...
0018e84c 00 9d 41 04 0e e9 66 00 - 34 e8 67 00 00 00 00 00 ..A...f.4.g.....
0018e85c 00 9d 41 04 00 00 00 00 - 2f e7 67 00 90 e8 18 00 ..A...../.g.....
0018e86c 0c 89 40 00 84 e8 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e87c 69 e8 67 01 00 9d 41 04 - ac e8 18 00 87 e7 67 00 i.g...A.......g.
0018e88c a6 4b 67 00 c4 e8 18 00 - 0c 89 40 00 ac e8 18 00 .Kg.......@.....
0018e89c 00 9d 41 04 00 00 00 00 - 00 00 00 00 00 9d 41 04 ..A...........A.
0018e8ac d8 e8 18 00 4a 91 67 00 - 00 00 00 00 cc 5b 53 00 ....J.g......[S.
0018e8bc 01 00 00 00 77 72 65 00 - e4 e8 18 00 0c 89 40 00 ....wre.......@.
0018e8cc d8 e8 18 00 40 d5 6e 06 - 00 9d 41 04 18 e9 18 00 [email protected].....
0018e8dc be 70 65 00 70 cd 16 01 - 30 e9 18 00 0c 89 40 00 .pe.p...0.....@.
0018e8ec 18 e9 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e8fc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e90c 40 d5 6e 06 00 9d 41 04 - a0 b9 5e 06 5c e9 18 00 @.n...A...^.\...
0018e91c e7 5b 53 00 0c eb 18 00 - 9a 68 53 00 0c eb 18 00 .[S......hS.....
0018e92c b3 f7 54 00 3c e9 18 00 - eb 8a 40 00 5c e9 18 00 ..T.<.....@.\...
0018e93c dc ea 18 00 0c 89 40 00 - 5c e9 18 00 00 00 00 00 ......@.\.......
0018e94c 40 d5 6e 06 0c eb 18 00 - 00 00 00 00 40 d5 6e 06 @[email protected].
disassembling:
[...]
0116cd45 push $116ced4
0116cd4a lea eax, [ebp-$20]
0116cd4d mov edx, 3
0116cd52 call -$d625a7 ($40a7b0) ; System.@UStrCatN
0116cd57 mov edx, [ebp-$20]
0116cd5a mov eax, [ebp-8]
0116cd5d mov eax, [eax+$250]
0116cd63 mov ecx, [eax]
0116cd65 call dword ptr [ecx+$38]
0116cd68 463 mov eax, [ebp-8]
0116cd6b > call -$b15cbc ($6570b4) ; Data.DB.TDataSet.Open
0116cd70 464 mov eax, [ebp-8]
0116cd73 cmp byte ptr [eax+$a8], 0
0116cd7a jz loc_116cd9d
0116cd7c mov eax, [ebp-8]
0116cd7f cmp byte ptr [eax+$a9], 0
0116cd86 jz loc_116cd9d
0116cd88 465 mov edx, $116cee8
0116cd8d mov eax, [ebp-4]
0116cd90 mov eax, [eax+$4f4]
0116cd96 call -$c3e843 ($52e558) ; Vcl.Controls.TControl.SetText
[...]
thread $d48:
7783f8da +0e ntdll.dll NtWaitForSingleObject
771715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7703118f +3e kernel32.dll WaitForSingleObjectEx
77031143 +0d kernel32.dll WaitForSingleObject
77033368 +10 kernel32.dll BaseThreadInitThunk
thread $1610:
77840166 +0e ntdll.dll NtWaitForMultipleObjects
77033368 +10 kernel32.dll BaseThreadInitThunk
thread $17f4:
7783f8da +0e ntdll.dll NtWaitForSingleObject
771715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7703118f +3e kernel32.dll WaitForSingleObjectEx
77031143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
77033368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($b50) at:
73274c95 +00 winspool.drv
thread $1738:
77841f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
77033368 +10 kernel32.dll BaseThreadInitThunk
modules:
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02670000 WINPPLA.DLL C:\Program
Files (x86)\Store
026b0000 BCLW32.dll C:\Program
Files (x86)\Store
04680000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063d0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71430000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
716d0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71950000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71970000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
719b0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71c90000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71ce0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71d40000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72590000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
725b0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72650000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72690000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72840000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72860000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72870000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72c80000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73100000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73160000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73260000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
732c0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73700000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73890000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73980000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
739a0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
739b0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
739d0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
739e0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73a00000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73c30000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73f00000 security.dll 6.1.7600.16385 C:\Windows\
system32
73f10000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
741d0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74230000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74260000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74290000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
742d0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
742f0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74300000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74310000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74370000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
743e0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74580000 version.dll 6.1.7600.16385 C:\Windows\
system32
74590000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
750b0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
750c0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75120000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75d70000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75e10000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75e20000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75e50000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75ec0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76100000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
763b0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
764b0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76550000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
765e0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
765f0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
766e0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76700000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76720000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76760000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76830000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
769d0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76a00000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76b30000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76b50000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76b60000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76c00000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76c20000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76cd0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76d90000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76e10000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76f70000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77020000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
77130000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77140000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77150000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77160000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
771b0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77200000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77260000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
773b0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
773c0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
777f0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77820000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03cc MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
0304 svchost.exe 0 0 0
0208 svchost.exe 0 0 0
042c svchost.exe 0 0 0
0498 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0550 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0654 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
0530 scpbradserv.exe 0 0 0
06c4 svchost.exe 0 0 0
0750 core.exe 0 0 0
0928 RapportInjService_x64.exe 0 0 0
09e0 fbserver.exe 0 0 0
0af4 WUDFHost.exe 0 0 0
05ec NisSrv.exe 0 0 0
0c50 WmiPrvSE.exe 0 0 0
0c7c OSPPSVC.EXE 0 0 0
0e84 taskhost.exe 1 26 22 normal
0ea4 core.exe 1 9 22 normal
0f68 sppsvc.exe 0 0 0
0500 GoogleCrashHandler.exe 0 0 0
05c8 GoogleCrashHandler64.exe 0 0 0
0a08 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0a80 PresentationFontCache.exe 0 0 0
0d2c dwm.exe 1 17 4 high
0d38 explorer.exe 1 471 310 normal
0d78 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0d8c RapportInjService_x64.exe 1 4 3 normal
0e20 igfxEM.exe 1 14 13 normal
0e50 igfxHK.exe 1 14 12 normal
0dec svchost.exe 0 0 0
0eb8 msseces.exe 1 143 59 normal
0230 PrnStatusMX.exe 1 23 20 normal
1030 SearchIndexer.exe 0 0 0
1208 wmpnetwk.exe 0 0 0
1280 wuauclt.exe 1 12 6 normal
1740 OIS.EXE 1 130 48 normal
0600 OIS.EXE 1 102 43 normal
166c DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
0ed8 chrome.exe 1 74 50 normal
12c4 chrome.exe 1 9 4 normal
1278 chrome.exe 1 7 6 above normal
1218 chrome.exe 1 4 1 normal
09b0 chrome.exe 1 4 1 normal
09d4 chrome.exe 1 4 1 idle
11ec chrome.exe 1 4 3 normal
17cc Store.exe 1 599 199 normal C:\Program Files (x86)\Store
16d8 splwow64.exe 1 9 3 normal
0e7c audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0ac137c8
ebx = 00003303
ecx = 00000000
edx = 00262ac8
esi = 0018e3c8
edi = 0066c9e4
eip = 0066e902
esp = 0018e38c
ebp = 0018e3f4
stack dump:
0018e38c 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018e39c a0 e3 18 00 02 e9 66 00 - c8 37 c1 0a 03 33 00 00 ......f..7...3..
0018e3ac c8 e3 18 00 e4 c9 66 00 - f4 e3 18 00 bc e3 18 00 ......f.........
0018e3bc 30 11 43 04 0e e9 66 00 - 34 e8 67 00 00 00 00 00 0.C...f.4.g.....
0018e3cc 30 11 43 04 00 00 00 00 - 2f e7 67 00 00 e4 18 00 0.C...../.g.....
0018e3dc 0c 89 40 00 f4 e3 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e3ec 69 e8 67 01 30 11 43 04 - 1c e4 18 00 87 e7 67 00 i.g.0.C.......g.
0018e3fc a6 4b 67 00 34 e4 18 00 - 0c 89 40 00 1c e4 18 00 .Kg.4.....@.....
0018e40c 30 11 43 04 00 00 00 00 - 00 00 00 00 30 11 43 04 0.C.........0.C.
0018e41c 48 e4 18 00 4a 91 67 00 - 00 00 00 00 cc 5b 53 00 H...J.g......[S.
0018e42c 01 00 00 00 77 72 65 00 - 54 e4 18 00 0c 89 40 00 ....wre.T.....@.
0018e43c 48 e4 18 00 40 d5 5e 06 - 30 11 43 04 88 e4 18 00 H...@.^.0.C.....
0018e44c be 70 65 00 70 cd 16 01 - a0 e4 18 00 0c 89 40 00 .pe.p.........@.
0018e45c 88 e4 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e46c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e47c 40 d5 5e 06 30 11 43 04 - d0 2c 4f 06 cc e4 18 00 @.^.0.C..,O.....
0018e48c e7 5b 53 00 7c e6 18 00 - 9a 68 53 00 7c e6 18 00 .[S.|....hS.|...
0018e49c b3 f7 54 00 ac e4 18 00 - eb 8a 40 00 cc e4 18 00 ..T.......@.....
0018e4ac 4c e6 18 00 0c 89 40 00 - cc e4 18 00 00 00 00 00 L.....@.........
0018e4bc 40 d5 5e 06 7c e6 18 00 - 00 00 00 00 40 d5 5e 06 @.^.|.......@.^.
disassembling:
[...]
0116cd45 push $116ced4
0116cd4a lea eax, [ebp-$20]
0116cd4d mov edx, 3
0116cd52 call -$d625a7 ($40a7b0) ; System.@UStrCatN
0116cd57 mov edx, [ebp-$20]
0116cd5a mov eax, [ebp-8]
0116cd5d mov eax, [eax+$250]
0116cd63 mov ecx, [eax]
0116cd65 call dword ptr [ecx+$38]
0116cd68 463 mov eax, [ebp-8]
0116cd6b > call -$b15cbc ($6570b4) ; Data.DB.TDataSet.Open
0116cd70 464 mov eax, [ebp-8]
0116cd73 cmp byte ptr [eax+$a8], 0
0116cd7a jz loc_116cd9d
0116cd7c mov eax, [ebp-8]
0116cd7f cmp byte ptr [eax+$a9], 0
0116cd86 jz loc_116cd9d
0116cd88 465 mov edx, $116cee8
0116cd8d mov eax, [ebp-4]
0116cd90 mov eax, [eax+$4f4]
0116cd96 call -$c3e843 ($52e558) ; Vcl.Controls.TControl.SetText
[...]
thread $11d0:
777c0166 +0e ntdll.dll NtWaitForMultipleObjects
77003368 +10 kernel32.dll BaseThreadInitThunk
thread $1264:
777c0166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
77003368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($bd4) at:
72c22713 +24f netbios.dll Netbios
thread $13d0:
777bf8da +0e ntdll.dll NtWaitForSingleObject
754915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7700118f +3e kernel32.dll WaitForSingleObjectEx
77001143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
77003368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($bd4) at:
72da4c95 +00 winspool.drv
thread $1740:
777c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
77003368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00390000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
06280000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70f80000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70fa0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
711e0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71220000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
71240000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71280000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
712b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
712e0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71440000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
71480000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
714e0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71890000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71a20000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71a70000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71ad0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
725c0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
725e0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72680000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
726c0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72870000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72890000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
728a0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72ac0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
72b40000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
72c20000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
72c30000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
72c90000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72d90000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73970000 security.dll 6.1.7600.16385 C:\Windows\
system32
73980000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
739d0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73aa0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73d20000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73d50000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73ef0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74160000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
741b0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
741e0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74210000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74250000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74270000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74280000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74290000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
742f0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74360000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74500000 version.dll 6.1.7600.16385 C:\Windows\
system32
74510000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75030000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75040000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
750a0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750b0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
751b0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75200000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
752c0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75300000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75330000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
753e0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75440000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75480000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
754d0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
754e0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75500000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
755a0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
761f0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76280000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
762e0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
762f0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76490000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76560000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76570000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
765f0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76720000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
767b0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76910000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76920000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76930000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76940000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76a30000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76a50000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76d00000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76db0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76f00000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76fa0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76fc0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76fd0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76fe0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ff0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
77160000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
77770000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
777a0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
009c RapportMgmtService.exe 0 0 0
02b0 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0790 NetExpressUpdater.exe 0 0 0
07fc svchost.exe 0 0 0
0550 scpbradserv.exe 0 0 0
0808 core.exe 0 0 0
0938 RapportInjService_x64.exe 0 0 0
0a08 fbserver.exe 0 0 0
0b58 WUDFHost.exe 0 0 0
05c8 NisSrv.exe 0 0 0
0e90 WmiPrvSE.exe 0 0 0
0ebc OSPPSVC.EXE 0 0 0
0e78 svchost.exe 0 0 0
0ff8 sppsvc.exe 0 0 0
0978 GoogleCrashHandler.exe 0 0 0
0a70 GoogleCrashHandler64.exe 0 0 0
0b60 SearchIndexer.exe 0 0 0
0fd4 taskhost.exe 1 26 24 normal
0fa4 core.exe 1 9 21 normal
0994 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0fc8 RapportInjService_x64.exe 1 4 3 normal
04ac PresentationFontCache.exe 0 0 0
0198 dwm.exe 1 18 4 high
0144 explorer.exe 1 445 298 normal
057c scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0df4 igfxEM.exe 1 14 13 normal
0cd8 igfxHK.exe 1 14 12 normal
0ee8 msseces.exe 1 143 60 normal
0c9c PrnStatusMX.exe 1 23 20 normal
1238 wmpnetwk.exe 0 0 0
13ac wuauclt.exe 1 12 6 normal
0d70 Store.exe 1 2953 758 normal C:\Program Files (x86)\Store
0dfc splwow64.exe 1 9 2 normal
1160 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1324 chrome.exe 1 80 53 normal
1024 chrome.exe 1 9 4 normal
0f8c chrome.exe 1 9 7 above normal
04e4 chrome.exe 1 4 1 normal
1038 chrome.exe 1 4 1 normal
12c0 chrome.exe 1 4 1 idle
1138 chrome.exe 1 4 3 normal
138c OUTLOOK.EXE 1 329 211 normal
0f94 audiodg.exe 0 0 0
12ec GoogleUpdate.exe 0 0 0
0f10 GoogleUpdate.exe 0 0 0
0804 WmiPrvSE.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0dacd700
ebx = 00003303
ecx = 00000000
edx = 026e2ac8
esi = 0018ec80
edi = 0066c9e4
eip = 0066e902
esp = 0018ec44
ebp = 0018ecac
stack dump:
0018ec44 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018ec54 58 ec 18 00 02 e9 66 00 - 00 d7 ac 0d 03 33 00 00 X.....f......3..
0018ec64 80 ec 18 00 e4 c9 66 00 - ac ec 18 00 74 ec 18 00 ......f.....t...
0018ec74 60 99 43 04 0e e9 66 00 - 34 e8 67 00 00 00 00 00 `.C...f.4.g.....
0018ec84 60 99 43 04 00 00 00 00 - 2f e7 67 00 b8 ec 18 00 `.C...../.g.....
0018ec94 0c 89 40 00 ac ec 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018eca4 69 e8 67 01 60 99 43 04 - d4 ec 18 00 87 e7 67 00 i.g.`.C.......g.
0018ecb4 a6 4b 67 00 ec ec 18 00 - 0c 89 40 00 d4 ec 18 00 .Kg.......@.....
0018ecc4 60 99 43 04 00 00 00 00 - 00 00 00 00 60 99 43 04 `.C.........`.C.
0018ecd4 00 ed 18 00 4a 91 67 00 - 04 00 00 00 ac 3a 62 00 ....J.g......:b.
0018ece4 01 00 00 00 77 72 65 00 - 0c ed 18 00 0c 89 40 00 ....wre.......@.
0018ecf4 00 ed 18 00 b0 30 45 04 - 60 99 43 04 34 ed 18 00 .....0E.`.C.4...
0018ed04 be 70 65 00 3c 48 17 01 - 68 ef 18 00 0c 89 40 00 .pe.<H..h.....@.
0018ed14 34 ed 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 4...............
0018ed24 00 00 00 00 b0 30 45 04 - 60 99 43 04 30 94 1c 05 .....0E.`.C.0...
0018ed34 58 ed 18 00 81 03 53 00 - b0 30 45 04 b1 3a 62 00 X.....S..0E..:b.
0018ed44 9b 3a 62 00 d4 ee 18 00 - ac 39 62 00 b0 30 45 04 .:b......9b..0E.
0018ed54 01 00 00 00 c8 ee 18 00 - b9 07 53 00 04 00 00 00 ..........S.....
0018ed64 11 00 00 00 00 00 00 00 - d4 ee 18 00 b0 30 45 04 .............0E.
0018ed74 35 08 53 00 11 00 04 00 - d4 ee 18 00 24 02 0c 00 5.S.........$...
disassembling:
[...]
01174811 push $11749d8
01174816 lea eax, [ebp-$10]
01174819 mov edx, 3
0117481e call -$d6a073 ($40a7b0) ; System.@UStrCatN
01174823 mov edx, [ebp-$10]
01174826 mov eax, [ebp-8]
01174829 mov eax, [eax+$250]
0117482f mov ecx, [eax]
01174831 call dword ptr [ecx+$38]
01174834 1051 mov eax, [ebp-8]
01174837 > call -$b1d788 ($6570b4) ; Data.DB.TDataSet.Open
0117483c 1053 mov eax, [$160cdb0]
01174841 mov eax, [eax]
01174843 mov eax, [eax+$27c]
01174849 mov edx, $11749ec
0117484e call -$b1c41f ($658434) ; Data.DB.TDataSet.FieldByName
01174853 lea edx, [ebp-$14]
01174856 mov ecx, [eax]
01174858 call dword ptr [ecx+$80]
0117485e mov eax, [ebp-$14]
01174861 mov edx, $1174a10
[...]
thread $11ac:
777bf8da +0e ntdll.dll NtWaitForSingleObject
754915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7700118f +3e kernel32.dll WaitForSingleObjectEx
77001143 +0d kernel32.dll WaitForSingleObject
77003368 +10 kernel32.dll BaseThreadInitThunk
thread $11d0:
777c0166 +0e ntdll.dll NtWaitForMultipleObjects
77003368 +10 kernel32.dll BaseThreadInitThunk
thread $1264:
777c0166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
77003368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($bd4) at:
72c22713 +24f netbios.dll Netbios
thread $13d0:
777bf8da +0e ntdll.dll NtWaitForSingleObject
754915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7700118f +3e kernel32.dll WaitForSingleObjectEx
77001143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
77003368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($bd4) at:
72da4c95 +00 winspool.drv
thread $1114:
777c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
77003368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00390000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
06280000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70f80000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70fa0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
711e0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71220000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
71240000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71280000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
712b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
712e0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71440000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
71480000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
714e0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71890000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71a20000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71a70000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71ad0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
725c0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
725e0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72680000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
726c0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72870000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72890000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
728a0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72ac0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
72b40000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
72c20000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
72c30000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
72c90000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72d90000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73970000 security.dll 6.1.7600.16385 C:\Windows\
system32
73980000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
739d0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73aa0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73d20000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73d50000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73ef0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74160000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
741b0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
741e0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74210000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74250000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74270000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74280000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74290000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
742f0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74360000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74500000 version.dll 6.1.7600.16385 C:\Windows\
system32
74510000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75030000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75040000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
750a0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750b0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
751b0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75200000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
752c0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75300000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75330000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
753e0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75440000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75480000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
754d0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
754e0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75500000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
755a0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
761f0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76280000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
762e0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
762f0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76490000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76560000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76570000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
765f0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76720000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
767b0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76910000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76920000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76930000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76940000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76a30000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76a50000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76d00000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76db0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76f00000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76fa0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76fc0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76fd0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76fe0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ff0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
77160000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
77770000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
777a0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
009c RapportMgmtService.exe 0 0 0
02b0 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0790 NetExpressUpdater.exe 0 0 0
07fc svchost.exe 0 0 0
0550 scpbradserv.exe 0 0 0
0808 core.exe 0 0 0
0938 RapportInjService_x64.exe 0 0 0
0a08 fbserver.exe 0 0 0
0b58 WUDFHost.exe 0 0 0
05c8 NisSrv.exe 0 0 0
0e90 WmiPrvSE.exe 0 0 0
0ebc OSPPSVC.EXE 0 0 0
0e78 svchost.exe 0 0 0
0ff8 sppsvc.exe 0 0 0
0978 GoogleCrashHandler.exe 0 0 0
0a70 GoogleCrashHandler64.exe 0 0 0
0b60 SearchIndexer.exe 0 0 0
0fd4 taskhost.exe 1 26 23 normal
0fa4 core.exe 1 9 21 normal
0994 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0fc8 RapportInjService_x64.exe 1 4 3 normal
04ac PresentationFontCache.exe 0 0 0
0198 dwm.exe 1 18 4 high
0144 explorer.exe 1 455 304 normal
057c scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0df4 igfxEM.exe 1 14 13 normal
0cd8 igfxHK.exe 1 14 12 normal
0ee8 msseces.exe 1 143 60 normal
0c9c PrnStatusMX.exe 1 23 20 normal
1238 wmpnetwk.exe 0 0 0
13ac wuauclt.exe 1 12 6 normal
0d70 Store.exe 1 3162 822 normal C:\Program Files (x86)\Store
0dfc splwow64.exe 1 9 4 normal
1160 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1324 chrome.exe 1 80 54 normal
1024 chrome.exe 1 9 4 normal
0f8c chrome.exe 1 9 7 above normal
04e4 chrome.exe 1 4 1 normal
1038 chrome.exe 1 4 1 normal
12c0 chrome.exe 1 4 1 idle
1138 chrome.exe 1 4 3 normal
138c OUTLOOK.EXE 1 329 214 normal
0f94 audiodg.exe 0 0 0
0444 OIS.EXE 1 102 39 normal
14a4 rundll32.exe 1 116 46 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 0a721dc0
ecx = 00705ab8
edx = 0018df01
esi = 00593a80
edi = 0018de5c
eip = 0070c5fe
esp = 0018dc90
ebp = 0018dc98
stack dump:
0018dc90 ac 7c 40 00 00 49 0d 05 - b8 dc 18 00 fd bf 70 00 .|@..I........p.
0018dca0 00 00 00 00 d0 01 00 01 - 06 00 00 00 80 3a 59 00 .............:Y.
0018dcb0 b0 d6 38 01 00 49 0d 05 - d8 dc 18 00 f7 75 40 00 ..8..I.......u@.
0018dcc0 f4 71 6f 00 41 72 6f 00 - 0f 00 00 00 10 48 0d 05 .qo.Aro......H..
0018dcd0 d0 2d 39 04 b0 d6 38 04 - ec dc 18 00 a8 f5 6f 00 .-9...8.......o.
0018dce0 c0 1d 72 0a c0 1d 72 0a - 30 cc 43 06 50 de 18 00 ..r...r.0.C.P...
0018dcf0 81 03 53 00 c0 1d 72 0a - 85 3a 59 00 2a 08 53 00 ..S...r..:Y.*.S.
0018dd00 0e 00 07 00 0e 00 00 00 - 07 00 00 00 00 00 00 00 ................
0018dd10 00 00 00 00 21 00 00 00 - 16 00 00 00 0e 00 07 00 ....!...........
0018dd20 c0 1d 72 0a 5c de 18 00 - 28 fe 52 00 0e 00 07 00 ..r.\...(.R.....
0018dd30 58 df 18 00 c0 1d 72 0a - c0 1d 72 0a c7 01 00 00 X.....r...r.....
0018dd40 07 00 00 00 00 00 00 00 - c4 dd 18 00 1f b0 5e 72 ..............^r
0018dd50 90 80 cb 05 8e 07 03 00 - 02 02 00 00 0f 00 00 00 ................
0018dd60 c7 01 07 00 00 00 00 00 - bb 80 5e 72 8e 81 5e 72 ..........^r..^r
0018dd70 00 00 00 00 c7 01 07 00 - 8e 07 03 00 00 00 00 00 ................
0018dd80 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd90 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dda0 bb 80 5e 72 01 00 00 00 - 40 de 18 00 00 00 00 00 ..^r....@.......
0018ddb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ddc0 46 d9 f7 95 f0 dd 18 00 - fa 62 0c 75 8e 07 03 00 F........b.u....
disassembling:
0070c5ec public QRPrntr.TQRPrinter.GetUseStandardPrinter: ; function entry
point
0070c5ec 3461 push ebp
0070c5ed mov ebp, esp
0070c5ef add esp, -8
0070c5f2 mov [ebp-4], eax
0070c5f5 3462 mov eax, [ebp-4]
0070c5f8 mov eax, [eax+$b8]
0070c5fe > mov al, [eax+$22]
0070c601 mov [ebp-5], al
0070c604 3463 mov al, [ebp-5]
0070c607 pop ecx
0070c608 pop ecx
0070c609 pop ebp
0070c60a ret
thread $11ac:
777bf8da +0e ntdll.dll NtWaitForSingleObject
754915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7700118f +3e kernel32.dll WaitForSingleObjectEx
77001143 +0d kernel32.dll WaitForSingleObject
77003368 +10 kernel32.dll BaseThreadInitThunk
thread $11d0:
777c0166 +0e ntdll.dll NtWaitForMultipleObjects
77003368 +10 kernel32.dll BaseThreadInitThunk
thread $1264:
777c0166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
77003368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($bd4) at:
72c22713 +24f netbios.dll Netbios
thread $13d0:
777bf8da +0e ntdll.dll NtWaitForSingleObject
754915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7700118f +3e kernel32.dll WaitForSingleObjectEx
77001143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
77003368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($bd4) at:
72da4c95 +00 winspool.drv
thread $111c:
777c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
77003368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00390000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
06280000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70f80000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70fa0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
711e0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71220000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
71240000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71280000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
712b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
712e0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71440000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
71480000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
714e0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71890000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71a20000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71a70000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71ad0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
725c0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
725e0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72680000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
726c0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72870000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72890000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
728a0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72ac0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
72b40000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
72c20000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
72c30000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
72c90000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72d90000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73970000 security.dll 6.1.7600.16385 C:\Windows\
system32
73980000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
739d0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73aa0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73d20000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73d50000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73ef0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74160000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
741b0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
741e0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74210000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74250000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74270000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74280000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74290000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
742f0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74360000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74500000 version.dll 6.1.7600.16385 C:\Windows\
system32
74510000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75030000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75040000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
750a0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750b0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
751b0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75200000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
752c0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75300000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75330000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
753e0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75440000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75480000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
754d0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
754e0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75500000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
755a0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
761f0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76280000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
762e0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
762f0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76490000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76560000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76570000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
765f0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76720000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
767b0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76910000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76920000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76930000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76940000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76a30000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76a50000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76d00000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76db0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76f00000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76fa0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76fc0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76fd0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76fe0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ff0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
77160000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
77770000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
777a0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
009c RapportMgmtService.exe 0 0 0
02b0 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0790 NetExpressUpdater.exe 0 0 0
07fc svchost.exe 0 0 0
0550 scpbradserv.exe 0 0 0
0808 core.exe 0 0 0
0938 RapportInjService_x64.exe 0 0 0
0a08 fbserver.exe 0 0 0
0b58 WUDFHost.exe 0 0 0
05c8 NisSrv.exe 0 0 0
0e90 WmiPrvSE.exe 0 0 0
0ebc OSPPSVC.EXE 0 0 0
0e78 svchost.exe 0 0 0
0ff8 sppsvc.exe 0 0 0
0978 GoogleCrashHandler.exe 0 0 0
0a70 GoogleCrashHandler64.exe 0 0 0
0b60 SearchIndexer.exe 0 0 0
0fd4 taskhost.exe 1 26 20 normal
0fa4 core.exe 1 9 21 normal
0994 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0fc8 RapportInjService_x64.exe 1 4 3 normal
04ac PresentationFontCache.exe 0 0 0
0198 dwm.exe 1 18 4 high
0144 explorer.exe 1 451 303 normal
057c scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0df4 igfxEM.exe 1 14 13 normal
0cd8 igfxHK.exe 1 14 12 normal
0ee8 msseces.exe 1 143 60 normal
0c9c PrnStatusMX.exe 1 23 20 normal
1238 wmpnetwk.exe 0 0 0
13ac wuauclt.exe 1 12 6 normal
0d70 Store.exe 1 3162 823 normal C:\Program Files (x86)\Store
0dfc splwow64.exe 1 9 2 normal
1160 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1324 chrome.exe 1 80 54 normal
1024 chrome.exe 1 9 4 normal
0f8c chrome.exe 1 9 7 above normal
04e4 chrome.exe 1 4 1 normal
1038 chrome.exe 1 4 1 normal
12c0 chrome.exe 1 4 1 idle
1138 chrome.exe 1 4 3 normal
138c OUTLOOK.EXE 1 329 213 normal
0444 OIS.EXE 1 102 45 normal
0cb4 slui.exe 1 15 9 normal
0568 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 002b0020
ebx = 050d48ff
ecx = 006f73dc
edx = 050d4900
esi = 0438d6b0
edi = 00000000
eip = 00660038
esp = 0018cc88
ebp = 0018cca4
stack dump:
0018cc88 67 d2 70 00 34 ce 18 00 - 0c 89 40 00 a4 cc 18 00 g.p.4.....@.....
0018cc98 64 ce 18 00 18 2f 41 00 - 00 49 0d 05 d4 cc 18 00 d..../A..I......
0018cca8 2c 74 6f 00 64 ce 18 00 - b0 d6 38 04 e0 cd 18 00 ,to.d.....8.....
0018ccb8 28 fe 52 00 00 00 00 00 - c8 0f 8f 06 b0 d6 38 04 (.R...........8.
0018ccc8 b0 d6 38 04 7c ce 18 00 - 28 fe 52 00 01 00 00 00 ..8.|...(.R.....
0018ccd8 c8 0f 8f 06 b0 d6 38 04 - 9c cc 18 00 01 00 00 00 ......8.........
0018cce8 18 cf 18 00 b6 a6 12 75 - 36 69 e3 e0 fe ff ff ff .......u6i......
0018ccf8 51 6d 0c 75 3f 0d 0d 75 - 00 00 00 00 18 2f 41 00 Qm.u?..u...../A.
0018cd08 5e 07 18 00 30 00 00 00 - 23 19 0a eb 01 00 00 00 ^...0...#.......
0018cd18 00 00 00 00 00 00 00 00 - 30 00 00 00 b0 d6 38 04 ........0.....8.
0018cd28 04 c4 6e 00 00 00 00 00 - 50 cd 18 00 65 0d 0d 75 ..n.....P...e..u
0018cd38 18 2f 41 00 5e 07 18 00 - 30 00 00 00 23 19 0a eb ./A.^...0...#...
0018cd48 01 00 00 00 00 00 00 00 - a4 ce 18 00 85 48 53 00 .............HS.
0018cd58 18 2f 41 00 5e 07 18 00 - 30 00 00 00 23 19 0a eb ./A.^...0...#...
0018cd68 01 00 00 00 a4 ce 18 00 - b0 d6 38 04 b0 d6 38 04 ..........8...8.
0018cd78 fc ce 18 00 28 fe 52 00 - b0 d6 38 04 b0 d6 38 04 ....(.R...8...8.
0018cd88 b0 d6 38 04 ef 47 7d 77 - 01 00 00 00 00 00 40 00 ..8..G}w......@.
0018cd98 00 00 00 00 00 00 00 00 - a4 cd 18 00 c6 c9 f7 95 ................
0018cda8 5c ce 18 00 44 aa 0c 75 - 00 00 01 00 14 ce 18 00 \...D..u........
0018cdb8 00 00 00 00 00 00 00 46 - 2f 01 00 00 b2 00 00 00 .......F/.......
disassembling:
[...]
0070d240 cmp byte ptr [eax+$8d], 1
0070d247 jnz loc_70d251
0070d249 mov eax, [ebp-4]
0070d24c call -$341 ($70cf10) ; QRPrntr.TQRPrinter.Cancel
0070d251 3858 mov eax, [ebp-4]
0070d254 cmp word ptr [eax+$1a], 0
0070d259 jz loc_70d267
0070d25b 3859 mov ebx, [ebp-4]
0070d25e mov edx, [ebp-4]
0070d261 mov eax, [ebx+$1c]
0070d264 > call dword ptr [ebx+$18]
0070d267 xor eax, eax
0070d269 pop edx
0070d26a pop ecx
0070d26b pop ecx
0070d26c mov fs:[eax], edx
0070d26f push $70d294
0070d274 3861 mov eax, [ebp-4]
0070d277 mov dl, [ebp-5]
0070d27a mov [eax+$8c], dl
0070d280 ret
[...]
thread $1360:
77ddf8da +0e ntdll.dll NtWaitForSingleObject
770715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
774e118f +3e kernel32.dll WaitForSingleObjectEx
774e1143 +0d kernel32.dll WaitForSingleObject
774e3368 +10 kernel32.dll BaseThreadInitThunk
thread $bd0:
77de0166 +0e ntdll.dll NtWaitForMultipleObjects
774e3368 +10 kernel32.dll BaseThreadInitThunk
thread $139c:
77de0166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
774e3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($135c) at:
736f2713 +24f netbios.dll Netbios
thread $1274:
77ddf8da +0e ntdll.dll NtWaitForSingleObject
770715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
774e118f +3e kernel32.dll WaitForSingleObjectEx
774e1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
774e3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($135c) at:
73884c95 +00 winspool.drv
thread $fb0:
77de1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
774e3368 +10 kernel32.dll BaseThreadInitThunk
thread $568:
77de1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
774e3368 +10 kernel32.dll BaseThreadInitThunk
thread $160:
77de1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
774e3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
062c0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06370000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
715d0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
71860000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
718a0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
718c0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71c60000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71cc0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71d10000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71f70000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71ff0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
72700000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72980000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72ca0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72ce0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72e90000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72eb0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72ec0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
730a0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
730b0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
730d0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
730e0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73590000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73670000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
736c0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
736f0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73700000 security.dll 6.1.7600.16385 C:\Windows\
system32
73710000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73770000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73870000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73b40000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73c40000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73d20000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74280000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
74340000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
743b0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
743d0000 slc.dll 6.1.7600.16385 C:\Windows\
system32
74780000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
747d0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74800000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74830000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74870000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74890000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
748a0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
748b0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74910000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74980000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74b20000 version.dll 6.1.7600.16385 C:\Windows\
system32
74b30000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75650000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75660000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
756c0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
756e0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75700000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75720000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75960000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75a10000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75a20000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75a70000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75a80000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75b20000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75b90000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75bc0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75bd0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75c00000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75eb0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76b00000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76c00000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c10000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76d60000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76e90000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ef0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76f00000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77060000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
770b0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
770c0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
771b0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
77240000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77250000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77260000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77270000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
773a0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77430000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
774d0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
775e0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77780000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77830000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
778b0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
778c0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77d90000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77dc0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
00a4 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0300 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
041c svchost.exe 0 0 0
0494 svchost.exe 0 0 0
0508 igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d0 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
072c svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
07a8 NetExpressUpdater.exe 0 0 0
03f0 svchost.exe 0 0 0
0544 scpbradserv.exe 0 0 0
067c svchost.exe 0 0 0
00bc core.exe 0 0 0
0888 RapportInjService_x64.exe 0 0 0
09d0 fbserver.exe 0 0 0
0b7c WUDFHost.exe 0 0 0
05e4 NisSrv.exe 0 0 0
0c08 taskhost.exe 1 26 23 normal
0c28 core.exe 1 9 21 normal
0ce4 sppsvc.exe 0 0 0
0c20 RapportService.exe 1 14 18 normal C:\Program Files (x86)\Trusteer\
Rapport\bin
0da4 PresentationFontCache.exe 0 0 0
0e10 dwm.exe 1 18 4 high
0ea4 explorer.exe 1 470 333 normal
08f8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\scpbrad
0e00 RapportInjService_x64.exe 1 4 3 normal
0ee0 msseces.exe 1 143 59 normal
0f54 PrnStatusMX.exe 1 23 19 normal
0170 igfxEM.exe 1 14 14 normal
0204 igfxHK.exe 1 14 13 normal
0fb8 GoogleCrashHandler.exe 0 0 0
0fb4 GoogleCrashHandler64.exe 0 0 0
10e4 svchost.exe 0 0 0
1124 SearchIndexer.exe 0 0 0
11a8 wmpnetwk.exe 0 0 0
0eb4 WmiPrvSE.exe 0 0 0
132c OSPPSVC.EXE 0 0 0
134c Store.exe 1 2630 820 normal C:\Program Files (x86)\Store
1030 wuauclt.exe 1 12 6 normal
0714 splwow64.exe 1 9 4 normal
13a0 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
170c audiodg.exe 0 0 0
04f8 rundll32.exe 1 116 52 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 0a462000
ecx = 043c1350
edx = 043bf170
esi = 00593a80
edi = 0018de5c
eip = 006ff5b1
esp = 0018dce0
ebp = 0018dcec
stack dump:
0018dce0 00 20 46 0a 00 20 46 0a - 20 1b 4b 06 50 de 18 00 . F.. F. .K.P...
0018dcf0 81 03 53 00 00 20 46 0a - 85 3a 59 00 2a 08 53 00 ..S.. F..:Y.*.S.
0018dd00 1a 00 0d 00 1a 00 00 00 - 0d 00 00 00 00 00 00 00 ................
0018dd10 00 00 00 00 21 00 00 00 - 16 00 00 00 1a 00 0d 00 ....!...........
0018dd20 00 20 46 0a 5c de 18 00 - 28 fe 52 00 1a 00 0d 00 . F.\...(.R.....
0018dd30 58 df 18 00 00 20 46 0a - 00 20 46 0a d3 01 00 00 X.... F.. F.....
0018dd40 0d 00 00 00 00 00 00 00 - c4 dd 18 00 1f b0 98 72 ...............r
0018dd50 58 2e 90 0a de 02 43 00 - 02 02 00 00 0f 00 00 00 X.....C.........
0018dd60 d3 01 0d 00 00 00 00 00 - bb 80 98 72 8e 81 98 72 ...........r...r
0018dd70 10 35 3c 04 d3 01 0d 00 - de 02 43 00 00 00 00 00 .5<.......C.....
0018dd80 10 35 3c 04 00 00 00 00 - 00 00 00 00 00 00 00 00 .5<.............
0018dd90 00 00 00 00 00 00 00 01 - 00 00 00 00 00 00 00 00 ................
0018dda0 bb 80 98 72 01 00 00 00 - 40 de 18 00 00 00 00 00 ...r....@.......
0018ddb0 00 00 01 00 00 00 00 01 - 07 00 00 00 00 00 00 00 ................
0018ddc0 be 3e d5 c9 f0 dd 18 00 - fa 62 b1 76 de 02 43 00 .>.......b.v..C.
0018ddd0 02 02 00 00 00 00 00 00 - d3 01 0d 00 bb 80 98 72 ...............r
0018dde0 cd ab ba dc 00 00 00 00 - 00 00 00 00 08 de 18 00 ................
0018ddf0 63 fa 52 00 00 20 46 0a - 0a b0 00 00 00 00 00 00 c.R.. F.........
0018de00 1a 00 0d 00 01 00 00 00 - 3c de 18 00 d5 3e 53 00 ........<....>S.
0018de10 1a 00 0d 00 10 35 3c 04 - 00 00 00 00 00 00 00 00 .....5<.........
disassembling:
[...]
006ff58a test al, al
006ff58c jnz loc_6ff59e
006ff58e 402 mov eax, [ebp-4]
006ff591 mov eax, [eax+$460]
006ff597 call +$eb20 ($70e0bc) ; QRPrntr.TQRPrinter.Print
006ff59c jmp loc_6ff5d3
006ff59e 405 mov eax, [$16148d8]
006ff5a3 call -$84ac ($6f70fc) ; QuickRpt.TCustomQuickRep.Print
006ff5a8 407 mov eax, [ebp-4]
006ff5ab mov eax, [eax+$3cc]
006ff5b1 > cmp dword ptr [eax+$2b8], 0
006ff5b8 jnz loc_6ff5d3
006ff5ba 409 mov eax, [$16148d8]
006ff5bf mov edx, [eax+$36c]
006ff5c5 mov eax, [ebp-4]
006ff5c8 mov eax, [eax+$3cc]
006ff5ce call +$a6f5 ($709cc8) ; QRPrntr.TQRPreview.SetQRPrinter
006ff5d3 412 pop ebx
006ff5d4 pop ecx
006ff5d5 pop ecx
006ff5d6 pop ebp
[...]
thread $1360:
77ddf8da +0e ntdll.dll NtWaitForSingleObject
770715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
774e118f +3e kernel32.dll WaitForSingleObjectEx
774e1143 +0d kernel32.dll WaitForSingleObject
774e3368 +10 kernel32.dll BaseThreadInitThunk
thread $bd0:
77de0166 +0e ntdll.dll NtWaitForMultipleObjects
774e3368 +10 kernel32.dll BaseThreadInitThunk
thread $139c:
77de0166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
774e3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($135c) at:
736f2713 +24f netbios.dll Netbios
thread $1274:
77ddf8da +0e ntdll.dll NtWaitForSingleObject
770715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
774e118f +3e kernel32.dll WaitForSingleObjectEx
774e1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
774e3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($135c) at:
73884c95 +00 winspool.drv
thread $30c:
77de1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
774e3368 +10 kernel32.dll BaseThreadInitThunk
thread $1564:
77de1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
774e3368 +10 kernel32.dll BaseThreadInitThunk
thread $149c:
77de1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
774e3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
062c0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06370000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
715d0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
71860000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
718a0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
718c0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71c60000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71cc0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71d10000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71f70000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71ff0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
72700000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72980000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72ca0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72ce0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72e90000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72eb0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72ec0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
730a0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
730b0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
730d0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
730e0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73590000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73670000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
736c0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
736f0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73700000 security.dll 6.1.7600.16385 C:\Windows\
system32
73710000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73770000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73870000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73b40000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73c40000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73d20000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74280000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
74340000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
743b0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
743d0000 slc.dll 6.1.7600.16385 C:\Windows\
system32
74780000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
747d0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74800000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74830000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74870000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74890000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
748a0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
748b0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74910000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74980000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74b20000 version.dll 6.1.7600.16385 C:\Windows\
system32
74b30000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75650000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75660000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
756c0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
756e0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75700000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75720000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75960000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75a10000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75a20000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75a70000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75a80000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75b20000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75b80000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75b90000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75bc0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75bd0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75c00000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75eb0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76b00000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76c00000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c10000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76d60000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76e90000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ef0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76f00000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77060000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
770b0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
770c0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
771b0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
77240000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77250000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77260000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77270000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
773a0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77430000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
774d0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
775e0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77780000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77830000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
778b0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
778c0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77d90000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77dc0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
00a4 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0300 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
041c svchost.exe 0 0 0
0494 svchost.exe 0 0 0
0508 igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d0 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
072c svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
07a8 NetExpressUpdater.exe 0 0 0
03f0 svchost.exe 0 0 0
0544 scpbradserv.exe 0 0 0
067c svchost.exe 0 0 0
00bc core.exe 0 0 0
0888 RapportInjService_x64.exe 0 0 0
09d0 fbserver.exe 0 0 0
0b7c WUDFHost.exe 0 0 0
05e4 NisSrv.exe 0 0 0
0c08 taskhost.exe 1 26 23 normal
0c28 core.exe 1 9 21 normal
0ce4 sppsvc.exe 0 0 0
0c20 RapportService.exe 1 14 18 normal C:\Program Files (x86)\Trusteer\
Rapport\bin
0da4 PresentationFontCache.exe 0 0 0
0e10 dwm.exe 1 18 4 high
0ea4 explorer.exe 1 458 371 normal
08f8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\scpbrad
0e00 RapportInjService_x64.exe 1 4 3 normal
0ee0 msseces.exe 1 143 59 normal
0f54 PrnStatusMX.exe 1 23 19 normal
0170 igfxEM.exe 1 14 14 normal
0204 igfxHK.exe 1 14 13 normal
0fb8 GoogleCrashHandler.exe 0 0 0
0fb4 GoogleCrashHandler64.exe 0 0 0
10e4 svchost.exe 0 0 0
1124 SearchIndexer.exe 0 0 0
11a8 wmpnetwk.exe 0 0 0
0eb4 WmiPrvSE.exe 0 0 0
132c OSPPSVC.EXE 0 0 0
134c Store.exe 1 5010 1545 normal C:\Program Files (x86)\Store
1030 wuauclt.exe 1 12 6 normal
0714 splwow64.exe 1 9 4 normal
13a0 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
170c audiodg.exe 0 0 0
160c rundll32.exe 1 116 52 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0f8f1c58
ebx = 00003303
ecx = 00000000
edx = 02742ac8
esi = 0018dae8
edi = 0066c9e4
eip = 0066e902
esp = 0018daac
ebp = 0018db14
stack dump:
0018daac 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018dabc c0 da 18 00 02 e9 66 00 - 58 1c 8f 0f 03 33 00 00 ......f.X....3..
0018dacc e8 da 18 00 e4 c9 66 00 - 14 db 18 00 dc da 18 00 ......f.........
0018dadc 80 ae 50 06 0e e9 66 00 - 34 e8 67 00 00 00 00 00 ..P...f.4.g.....
0018daec 80 ae 50 06 00 00 00 00 - 2f e7 67 00 20 db 18 00 ..P...../.g. ...
0018dafc 0c 89 40 00 14 db 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018db0c 69 e8 67 01 80 ae 50 06 - 3c db 18 00 87 e7 67 00 i.g...P.<.....g.
0018db1c a6 4b 67 00 54 db 18 00 - 0c 89 40 00 3c db 18 00 .Kg.T.....@.<...
0018db2c 80 ae 50 06 00 00 00 00 - 00 00 00 00 80 ae 50 06 ..P...........P.
0018db3c 68 db 18 00 4a 91 67 00 - 00 00 00 00 cc 5b 53 00 h...J.g......[S.
0018db4c 01 00 00 00 77 72 65 00 - 74 db 18 00 0c 89 40 00 ....wre.t.....@.
0018db5c 68 db 18 00 90 07 96 0a - 80 ae 50 06 d8 e0 18 00 h.........P.....
0018db6c be 70 65 00 f2 ff f0 00 - e0 e0 18 00 0c 89 40 00 .pe...........@.
0018db7c d8 e0 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dbac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dbbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dbcc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dbdc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00f0ffc1 push $f1121c
00f0ffc6 lea eax, [ebp-$4bc]
00f0ffcc mov edx, 3
00f0ffd1 call -$b05826 ($40a7b0) ; System.@UStrCatN
00f0ffd6 mov edx, [ebp-$4bc]
00f0ffdc mov eax, [ebp-$34]
00f0ffdf mov eax, [eax+$250]
00f0ffe5 mov ecx, [eax]
00f0ffe7 call dword ptr [ecx+$38]
00f0ffea 4108 mov eax, [ebp-$34]
00f0ffed > call -$8b8f3e ($6570b4) ; Data.DB.TDataSet.Open
00f0fff2 4110 mov eax, [$160cdb0]
00f0fff7 mov eax, [eax]
00f0fff9 mov eax, [eax+$1710]
00f0ffff cmp byte ptr [eax+$a9], 0
00f10006 jz loc_f105c2
00f1000c mov eax, [$160cdb0]
00f10011 mov eax, [eax]
00f10013 mov eax, [eax+$1710]
00f10019 cmp byte ptr [eax+$a8], 0
00f10020 jz loc_f105c2
[...]
thread $11d0:
77b4f8da +0e ntdll.dll NtWaitForSingleObject
776f15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
773e118f +3e kernel32.dll WaitForSingleObjectEx
773e1143 +0d kernel32.dll WaitForSingleObject
773e3368 +10 kernel32.dll BaseThreadInitThunk
thread $11d4:
77b50166 +0e ntdll.dll NtWaitForMultipleObjects
773e3368 +10 kernel32.dll BaseThreadInitThunk
thread $12a8:
77b50166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
773e3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1064) at:
73402713 +24f netbios.dll Netbios
thread $163c:
77b4f8da +0e ntdll.dll NtWaitForSingleObject
776f15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
773e118f +3e kernel32.dll WaitForSingleObjectEx
773e1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
773e3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1064) at:
73584c95 +00 winspool.drv
thread $1360:
77b51f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
773e3368 +10 kernel32.dll BaseThreadInitThunk
thread $10a4:
77b51f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
773e3368 +10 kernel32.dll BaseThreadInitThunk
thread $41c:
77b51f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
773e3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00310000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
05500000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
062c0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063d0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70d10000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70d90000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70da0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
711b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
711c0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
715c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71600000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71770000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
717e0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71860000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
719b0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71c30000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71db0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71e00000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71e60000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
726d0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
726f0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a10000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a50000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c00000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c20000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c30000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
733d0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73400000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73410000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73470000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73570000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
736c0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73ba0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73bb0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73d60000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
744f0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74540000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74570000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
745a0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
745e0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74600000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74610000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74620000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74680000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
746f0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74890000 version.dll 6.1.7600.16385 C:\Windows\
system32
748a0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
753c0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75430000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75440000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
754d0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76120000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76160000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76200000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
762f0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76370000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76510000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76750000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76760000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76810000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76820000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76830000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
768e0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
768f0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76a70000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76b40000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76c70000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76c90000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76cc0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76cd0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76d70000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76ec0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ed0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76ee0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76f00000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76f10000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76f70000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76f80000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76fd0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77280000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
772a0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
773a0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
773d0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
774e0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77570000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
776d0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
776e0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77b00000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77b30000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0308 svchost.exe 0 0 0
0408 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
0470 audiodg.exe 0 0 0
0498 svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
061c spoolsv.exe 0 0 0
0624 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
072c svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0774 svchost.exe 0 0 0
0788 NetExpressUpdater.exe 0 0 0
0468 svchost.exe 0 0 0
0554 scpbradserv.exe 0 0 0
0694 svchost.exe 0 0 0
07dc core.exe 0 0 0
0948 RapportInjService_x64.exe 0 0 0
09f0 fbserver.exe 0 0 0
0b54 WUDFHost.exe 0 0 0
06b8 NisSrv.exe 0 0 0
0e30 WmiPrvSE.exe 0 0 0
0e5c OSPPSVC.EXE 0 0 0
0edc svchost.exe 0 0 0
037c sppsvc.exe 0 0 0
0508 GoogleCrashHandler.exe 0 0 0
0ff4 GoogleCrashHandler64.exe 0 0 0
0588 SearchIndexer.exe 0 0 0
0324 taskhost.exe 1 26 23 normal
08d0 core.exe 1 9 21 normal
02f4 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0fbc RapportInjService_x64.exe 1 4 3 normal
075c PresentationFontCache.exe 0 0 0
009c dwm.exe 1 17 4 high
0bb8 explorer.exe 1 385 223 normal
0dd0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f88 igfxEM.exe 1 14 13 normal
0b80 igfxHK.exe 1 14 12 normal
1038 msseces.exe 1 143 60 normal
1044 PrnStatusMX.exe 1 23 20 normal
127c wmpnetwk.exe 0 0 0
13d8 TrustedInstaller.exe 0 0 0
1134 Store.exe 1 190 202 normal C:\Program Files (x86)\Store
1324 wuauclt.exe 1 12 7 normal
1078 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
132c chrome.exe 1 27 55 normal
0764 chrome.exe 1 9 4 normal
12e8 chrome.exe 1 7 6 above normal
12ec chrome.exe 1 4 1 normal
1220 chrome.exe 1 4 1 normal
1598 chrome.exe 1 4 1 idle
16e8 WmiPrvSE.exe 0 0 0
1544 chrome.exe 1 4 3 normal
09e8 splwow64.exe 1 9 2 normal
138c slui.exe 1 40 30 normal
1160 taskeng.exe 1 9 3 normal
0738 svchost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 064fad50
ebx = 00003303
ecx = 00000000
edx = 02662ac8
esi = 0018ebe4
edi = 0066c9e4
eip = 0066e902
esp = 0018eba8
ebp = 0018ec10
stack dump:
0018eba8 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018ebb8 bc eb 18 00 02 e9 66 00 - 50 ad 4f 06 03 33 00 00 ......f.P.O..3..
0018ebc8 e4 eb 18 00 e4 c9 66 00 - 10 ec 18 00 d8 eb 18 00 ......f.........
0018ebd8 50 50 50 06 0e e9 66 00 - 34 e8 67 00 00 00 00 00 PPP...f.4.g.....
0018ebe8 50 50 50 06 00 00 00 00 - 2f e7 67 00 1c ec 18 00 PPP...../.g.....
0018ebf8 0c 89 40 00 10 ec 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018ec08 69 e8 67 01 50 50 50 06 - 38 ec 18 00 87 e7 67 00 i.g.PPP.8.....g.
0018ec18 a6 4b 67 00 50 ec 18 00 - 0c 89 40 00 38 ec 18 00 [email protected]...
0018ec28 50 50 50 06 00 00 00 00 - 00 00 00 00 50 50 50 06 PPP.........PPP.
0018ec38 64 ec 18 00 4a 91 67 00 - 08 00 00 00 ac 3a 62 00 d...J.g......:b.
0018ec48 01 00 00 00 77 72 65 00 - 70 ec 18 00 0c 89 40 00 ....wre.p.....@.
0018ec58 64 ec 18 00 80 eb 3f 0a - 50 50 50 06 34 ed 18 00 d.....?.PPP.4...
0018ec68 be 70 65 00 88 ba 16 01 - 68 ef 18 00 0c 89 40 00 .pe.....h.....@.
0018ec78 34 ed 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 4...............
0018ec88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ec98 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eca8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ecb8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ecc8 00 00 00 00 00 00 00 00 - 80 79 e5 40 80 eb 3f 0a .........y.@..?.
0018ecd8 00 00 00 00 fa a4 4f fa - 5f 7f e5 40 00 00 00 00 ......O._..@....
disassembling:
[...]
0116ba5f mov eax, [ebp-$18]
0116ba62 mov eax, [eax+$250]
0116ba68 mov ecx, [eax]
0116ba6a call dword ptr [ecx+$38]
0116ba6d 425 mov edx, $116cac0
0116ba72 mov eax, [ebp-$18]
0116ba75 mov eax, [eax+$250]
0116ba7b mov ecx, [eax]
0116ba7d call dword ptr [ecx+$38]
0116ba80 427 mov eax, [ebp-$18]
0116ba83 > call -$b149d4 ($6570b4) ; Data.DB.TDataSet.Open
0116ba88 428 mov eax, [ebp-$18]
0116ba8b call -$b12114 ($65997c) ; Data.DB.TDataSet.First
0116ba90 429 mov eax, [ebp-$18]
0116ba93 cmp byte ptr [eax+$a9], 0
0116ba9a jz loc_116baa8
0116ba9c mov eax, [ebp-$18]
0116ba9f cmp byte ptr [eax+$a8], 0
0116baa6 jnz loc_116bab7
0116baa8 431 mov eax, [ebp-4]
0116baab call +$32fe8 ($119ea98) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $11d0:
77b4f8da +0e ntdll.dll NtWaitForSingleObject
776f15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
773e118f +3e kernel32.dll WaitForSingleObjectEx
773e1143 +0d kernel32.dll WaitForSingleObject
773e3368 +10 kernel32.dll BaseThreadInitThunk
thread $11d4:
77b50166 +0e ntdll.dll NtWaitForMultipleObjects
773e3368 +10 kernel32.dll BaseThreadInitThunk
thread $12a8:
77b50166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
773e3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1064) at:
73402713 +24f netbios.dll Netbios
thread $163c:
77b4f8da +0e ntdll.dll NtWaitForSingleObject
776f15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
773e118f +3e kernel32.dll WaitForSingleObjectEx
773e1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
773e3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1064) at:
73584c95 +00 winspool.drv
thread $1580:
77b51f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
773e3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00310000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
05500000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
062c0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063d0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70d10000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70d90000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70da0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
711b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
711c0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
715c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71600000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71770000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
717e0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71860000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
719b0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71c30000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71db0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71e00000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71e60000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
726d0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
726f0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a10000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a50000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c00000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c20000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c30000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
730f0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73170000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
733d0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73400000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73410000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73470000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73570000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
736c0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73ba0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73bb0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73d60000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73f70000 slc.dll 6.1.7600.16385 C:\Windows\
system32
744f0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74540000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74570000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
745a0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
745e0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74600000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74610000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74620000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74680000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
746f0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74890000 version.dll 6.1.7600.16385 C:\Windows\
system32
748a0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
753c0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75430000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75440000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
754d0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76120000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76160000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76200000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
762f0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76370000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76510000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76750000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76760000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76810000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76820000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76830000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
768e0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
768f0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76a70000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76b40000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76c70000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76c90000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76cc0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76cd0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76d70000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76ec0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ed0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76ee0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76f00000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76f10000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76f70000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76f80000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76fd0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77280000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
772a0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
773a0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
773d0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
774e0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77570000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
776d0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
776e0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77b00000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77b30000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0308 svchost.exe 0 0 0
0408 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
0498 svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
061c spoolsv.exe 0 0 0
0624 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
072c svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0774 svchost.exe 0 0 0
0788 NetExpressUpdater.exe 0 0 0
0468 svchost.exe 0 0 0
0554 scpbradserv.exe 0 0 0
0694 svchost.exe 0 0 0
07dc core.exe 0 0 0
0948 RapportInjService_x64.exe 0 0 0
09f0 fbserver.exe 0 0 0
0b54 WUDFHost.exe 0 0 0
06b8 NisSrv.exe 0 0 0
0e30 WmiPrvSE.exe 0 0 0
0e5c OSPPSVC.EXE 0 0 0
0edc svchost.exe 0 0 0
037c sppsvc.exe 0 0 0
0508 GoogleCrashHandler.exe 0 0 0
0ff4 GoogleCrashHandler64.exe 0 0 0
0588 SearchIndexer.exe 0 0 0
0324 taskhost.exe 1 26 23 normal
08d0 core.exe 1 9 22 normal
02f4 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0fbc RapportInjService_x64.exe 1 4 3 normal
075c PresentationFontCache.exe 0 0 0
009c dwm.exe 1 17 4 high
0bb8 explorer.exe 1 423 270 normal
0dd0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f88 igfxEM.exe 1 14 13 normal
0b80 igfxHK.exe 1 14 12 normal
1038 msseces.exe 1 143 60 normal
1044 PrnStatusMX.exe 1 23 20 normal
127c wmpnetwk.exe 0 0 0
1134 Store.exe 1 1636 391 normal C:\Program Files (x86)\Store
1324 wuauclt.exe 1 12 7 normal
1078 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
132c chrome.exe 1 77 57 normal
0764 chrome.exe 1 9 4 normal
12e8 chrome.exe 1 8 6 above normal
12ec chrome.exe 1 4 1 normal
1220 chrome.exe 1 4 1 normal
1544 chrome.exe 1 4 3 normal
09e8 splwow64.exe 1 9 3 normal
138c slui.exe 1 43 31 normal
0cf4 chrome.exe 1 4 1 idle
0638 chrome.exe 1 4 1 idle
1158 chrome.exe 1 4 1 idle
1784 chrome.exe 1 4 1 idle
1240 chrome.exe 1 4 1 idle
1208 chrome.exe 1 4 1 idle
176c OIS.EXE 1 102 44 normal
159c chrome.exe 1 4 1 idle
0c68 chrome.exe 1 4 1 idle
06b4 chrome.exe 1 4 1 idle
15a0 chrome.exe 1 4 1 idle
0f10 audiodg.exe 0 0 0
0db4 rundll32.exe 1 116 53 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0000000b
ebx = 0a403e00
ecx = 044ef590
edx = 044ee670
esi = 00593a80
edi = 0018de5c
eip = 006ff5b1
esp = 0018dce0
ebp = 0018dcec
stack dump:
0018dce0 00 3e 40 0a 00 3e 40 0a - d0 61 4c 06 50 de 18 00 .>@..>@..aL.P...
0018dcf0 81 03 53 00 00 3e 40 0a - 85 3a 59 00 2a 08 53 00 ..S..>@..:Y.*.S.
0018dd00 16 00 06 00 16 00 00 00 - 06 00 00 00 00 00 00 00 ................
0018dd10 00 00 00 00 21 00 00 00 - 16 00 00 00 16 00 06 00 ....!...........
0018dd20 00 3e 40 0a 5c de 18 00 - 28 fe 52 00 16 00 06 00 .>@.\...(.R.....
0018dd30 58 df 18 00 00 3e 40 0a - 00 3e 40 0a cf 01 00 00 X....>@..>@.....
0018dd40 06 00 00 00 00 00 00 00 - c4 dd 18 00 1f b0 6f 72 ..............or
0018dd50 b8 90 6c 02 a8 04 0a 00 - 02 02 00 00 0f 00 00 00 ..l.............
0018dd60 cf 01 06 00 00 00 00 00 - bb 80 6f 72 8e 81 6f 72 ..........or..or
0018dd70 00 00 00 00 cf 01 06 00 - a8 04 0a 00 00 00 00 00 ................
0018dd80 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd90 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dda0 bb 80 6f 72 01 00 00 00 - 40 de 18 00 00 00 00 00 ..or....@.......
0018ddb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ddc0 f9 bc e9 d5 f0 dd 18 00 - fa 62 2b 77 a8 04 0a 00 .........b+w....
0018ddd0 02 02 00 00 00 00 00 00 - cf 01 06 00 bb 80 6f 72 ..............or
0018dde0 cd ab ba dc 00 00 00 00 - 00 00 00 00 08 de 18 00 ................
0018ddf0 63 fa 52 00 00 3e 40 0a - 0a b0 00 00 00 00 00 00 c.R..>@.........
0018de00 16 00 06 00 01 00 00 00 - 3c de 18 00 d5 3e 53 00 ........<....>S.
0018de10 16 00 06 00 d0 f1 4e 04 - 00 00 00 00 00 00 00 00 ......N.........
disassembling:
[...]
006ff58a test al, al
006ff58c jnz loc_6ff59e
006ff58e 402 mov eax, [ebp-4]
006ff591 mov eax, [eax+$460]
006ff597 call +$eb20 ($70e0bc) ; QRPrntr.TQRPrinter.Print
006ff59c jmp loc_6ff5d3
006ff59e 405 mov eax, [$16148d8]
006ff5a3 call -$84ac ($6f70fc) ; QuickRpt.TCustomQuickRep.Print
006ff5a8 407 mov eax, [ebp-4]
006ff5ab mov eax, [eax+$3cc]
006ff5b1 > cmp dword ptr [eax+$2b8], 0
006ff5b8 jnz loc_6ff5d3
006ff5ba 409 mov eax, [$16148d8]
006ff5bf mov edx, [eax+$36c]
006ff5c5 mov eax, [ebp-4]
006ff5c8 mov eax, [eax+$3cc]
006ff5ce call +$a6f5 ($709cc8) ; QRPrntr.TQRPreview.SetQRPrinter
006ff5d3 412 pop ebx
006ff5d4 pop ecx
006ff5d5 pop ecx
006ff5d6 pop ebp
[...]
thread $10a4:
77b50166 +0e ntdll.dll NtWaitForMultipleObjects
773e3368 +10 kernel32.dll BaseThreadInitThunk
thread $c34:
77b51f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
773e3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
042b0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
054a0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
06300000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70d10000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70d90000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70da0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
711b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
711c0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
715c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71600000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71770000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
717e0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71860000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
719b0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71c30000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71db0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71e00000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71e60000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
726d0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
726f0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a10000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a50000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c00000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c20000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c30000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
733d0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73410000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73470000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73570000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
736c0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73ba0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73bb0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73d60000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74540000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74570000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
745a0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
745e0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74600000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74610000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74620000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74680000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
746f0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74890000 version.dll 6.1.7600.16385 C:\Windows\
system32
748a0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
753c0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75430000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75440000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
754d0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76120000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76160000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76200000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
762f0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76370000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76510000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76750000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76760000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76810000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76820000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76830000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
768e0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
768f0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76a70000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76b40000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76c70000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76c90000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76cc0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76cd0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76d70000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76ec0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ed0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76ee0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76f00000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76f10000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76f70000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76f80000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76fd0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77280000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
772a0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
773a0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
773d0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
774e0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77570000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
776d0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
776e0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77b00000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77b30000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0308 svchost.exe 0 0 0
0408 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
0498 svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
061c spoolsv.exe 0 0 0
0624 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
072c svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0774 svchost.exe 0 0 0
0788 NetExpressUpdater.exe 0 0 0
0468 svchost.exe 0 0 0
0554 scpbradserv.exe 0 0 0
0694 svchost.exe 0 0 0
07dc core.exe 0 0 0
0948 RapportInjService_x64.exe 0 0 0
09f0 fbserver.exe 0 0 0
0b54 WUDFHost.exe 0 0 0
06b8 NisSrv.exe 0 0 0
0e30 WmiPrvSE.exe 0 0 0
0e5c OSPPSVC.EXE 0 0 0
0edc svchost.exe 0 0 0
037c sppsvc.exe 0 0 0
0508 GoogleCrashHandler.exe 0 0 0
0ff4 GoogleCrashHandler64.exe 0 0 0
0588 SearchIndexer.exe 0 0 0
0324 taskhost.exe 1 26 23 normal
08d0 core.exe 1 9 22 normal
02f4 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0fbc RapportInjService_x64.exe 1 4 3 normal
075c PresentationFontCache.exe 0 0 0
009c dwm.exe 1 19 4 high
0bb8 explorer.exe 1 496 302 normal
0dd0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f88 igfxEM.exe 1 14 13 normal
0b80 igfxHK.exe 1 14 12 normal
1038 msseces.exe 1 143 60 normal
1044 PrnStatusMX.exe 1 23 20 normal
127c wmpnetwk.exe 0 0 0
1134 Store.exe 1 2157 351 normal C:\Program Files (x86)\Store
1324 wuauclt.exe 1 12 6 normal
1078 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
132c chrome.exe 1 82 69 normal
0764 chrome.exe 1 9 4 normal
12e8 chrome.exe 1 8 7 above normal
12ec chrome.exe 1 4 1 normal
1220 chrome.exe 1 4 1 normal
1544 chrome.exe 1 4 3 normal
09e8 splwow64.exe 1 9 3 normal
0cf4 chrome.exe 1 4 1 idle
0638 chrome.exe 1 4 1 idle
1158 chrome.exe 1 4 1 idle
1784 chrome.exe 1 4 1 idle
1240 chrome.exe 1 4 1 idle
1208 chrome.exe 1 4 1 idle
176c OIS.EXE 1 102 43 normal
159c chrome.exe 1 4 1 idle
0c68 chrome.exe 1 4 1 idle
06b4 chrome.exe 1 4 1 idle
151c Store.exe 1 137 134 normal C:\Program Files (x86)\Store
1b58 audiodg.exe 0 0 0
18a4 OIS.EXE 1 142 106 normal
1a40 chrome.exe 1 4 1 idle
1414 chrome.exe 1 4 1 idle
0b78 chrome.exe 1 4 1 idle
1b14 chrome.exe 1 4 1 idle
18bc chrome.exe 1 4 1 idle
05b0 chrome.exe 1 4 1 idle
19b8 chrome.exe 1 4 1 idle
1b7c chrome.exe 1 4 1 idle
0548 chrome.exe 1 4 1 idle
19d4 chrome.exe 1 4 1 idle
0dc0 chrome.exe 1 4 1 idle
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 064cb868
ebx = 00003303
ecx = 00000000
edx = 02702ac8
esi = 0018f2b8
edi = 0066c9e4
eip = 0066e902
esp = 0018f27c
ebp = 0018f2e4
stack dump:
0018f27c 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018f28c 90 f2 18 00 02 e9 66 00 - 68 b8 4c 06 03 33 00 00 ......f.h.L..3..
0018f29c b8 f2 18 00 e4 c9 66 00 - e4 f2 18 00 ac f2 18 00 ......f.........
0018f2ac 30 6d 4d 06 0e e9 66 00 - 34 e8 67 00 00 00 00 00 0mM...f.4.g.....
0018f2bc 30 6d 4d 06 00 00 00 00 - 2f e7 67 00 f0 f2 18 00 0mM...../.g.....
0018f2cc 0c 89 40 00 e4 f2 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018f2dc 69 e8 67 01 30 6d 4d 06 - 0c f3 18 00 87 e7 67 00 i.g.0mM.......g.
0018f2ec a6 4b 67 00 24 f3 18 00 - 0c 89 40 00 0c f3 18 00 .Kg.$.....@.....
0018f2fc 30 6d 4d 06 00 00 00 00 - 00 00 00 00 30 6d 4d 06 0mM.........0mM.
0018f30c 38 f3 18 00 4a 91 67 00 - 00 00 00 00 d0 98 5b 00 8...J.g.......[.
0018f31c 01 00 00 00 77 72 65 00 - 44 f3 18 00 0c 89 40 00 ....wre.D.....@.
0018f32c 38 f3 18 00 20 90 4d 06 - 30 6d 4d 06 98 f3 18 00 8... .M.0mM.....
0018f33c be 70 65 00 f8 5e 5b 01 - 50 f3 18 00 64 89 40 00 .pe..^[.P...d.@.
0018f34c 98 f3 18 00 a8 f3 18 00 - 0c 89 40 00 98 f3 18 00 ..........@.....
0018f35c 00 00 00 00 d0 98 5b 00 - 20 90 4d 06 00 00 00 00 ......[. .M.....
0018f36c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f37c 00 00 00 00 20 90 4d 06 - 01 00 00 00 00 00 00 00 .... .M.........
0018f38c 00 00 00 00 30 6d 4d 06 - 40 86 2d 0a c4 f3 18 00 [email protected].....
0018f39c e2 98 5b 00 cc f3 18 00 - c8 97 5b 00 70 f4 18 00 ..[.......[.p...
0018f3ac dc 86 40 00 c4 f3 18 00 - 00 00 00 00 fd 0c 0e 04 ..@.............
disassembling:
[...]
015b5ecf 884 mov eax, [ebp-8]
015b5ed2 mov eax, [eax+$250]
015b5ed8 mov edx, [eax]
015b5eda call dword ptr [edx+$44]
015b5edd 885 mov eax, [ebp-8]
015b5ee0 mov eax, [eax+$250]
015b5ee6 mov edx, $15b60c0
015b5eeb mov ecx, [eax]
015b5eed call dword ptr [ecx+$38]
015b5ef0 886 mov eax, [ebp-8]
015b5ef3 > call -$f5ee44 ($6570b4) ; Data.DB.TDataSet.Open
015b5ef8 xor eax, eax
015b5efa pop edx
015b5efb pop ecx
015b5efc pop ecx
015b5efd mov fs:[eax], edx
015b5f00 jmp loc_15b608b
015b5f05 jmp -$11ad932 ($4085d8) ; System.@HandleAnyException
015b5f0a 890 mov eax, [$160cdb0]
015b5f0f mov eax, [eax]
015b5f11 mov eax, [eax+$60]
[...]
thread $1108:
77d0f8da +0e ntdll.dll NtWaitForSingleObject
777b15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
759c118f +3e kernel32.dll WaitForSingleObjectEx
759c1143 +0d kernel32.dll WaitForSingleObject
759c3368 +10 kernel32.dll BaseThreadInitThunk
thread $1050:
77d10166 +0e ntdll.dll NtWaitForMultipleObjects
759c3368 +10 kernel32.dll BaseThreadInitThunk
thread $105c:
77d11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
759c3368 +10 kernel32.dll BaseThreadInitThunk
thread $1078:
77d10166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
759c3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1148) at:
73432713 +24f netbios.dll Netbios
modules:
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02670000 WINPPLA.DLL C:\Program
Files (x86)\Store
026b0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
026e0000 BCLW32.dll C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063f0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
719a0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71bf0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71d70000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71e10000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71f30000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
72210000 webio.dll 6.1.7601.23375 C:\Windows\
system32
72260000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
722c0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72b10000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72b30000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72bd0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72c10000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72dc0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72de0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72df0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73050000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73060000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73080000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73090000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
733a0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
733f0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73400000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73430000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73440000 security.dll 6.1.7600.16385 C:\Windows\
system32
73540000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
735a0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
736a0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73a50000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73cb0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73cc0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73ce0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
745a0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
74700000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74730000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74760000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
747a0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
747c0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
747d0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
747e0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74840000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
748b0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74a50000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a60000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75580000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75590000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
755f0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75600000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
758b0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75960000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
759b0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75ac0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75b50000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75c00000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75c10000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75c20000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75c50000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75c60000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75c70000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75c80000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75e20000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75f20000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76160000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
761a0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
761c0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
761d0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76280000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
763e0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
763f0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76470000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76560000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76580000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76610000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
766a0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
766b0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77300000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77360000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
77400000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77530000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
775d0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77720000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77730000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77790000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
777a0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77820000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
77cc0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77cf0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c4 lsass.exe 0 0 0
02cc lsm.exe 0 0 0
032c svchost.exe 0 0 0
0378 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
009c RapportMgmtService.exe 0 0 0
02b0 svchost.exe 0 0 0
0368 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0434 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0528 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
063c spoolsv.exe 0 0 0
0644 taskeng.exe 0 0 0
0668 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
0700 atkexComSvc.exe 0 0 0
0744 svchost.exe 0 0 0
0768 fbguard.exe 0 0 0
0790 svchost.exe 0 0 0
07a8 NetExpressUpdater.exe 0 0 0
0470 svchost.exe 0 0 0
05a0 scpbradserv.exe 0 0 0
0520 svchost.exe 0 0 0
0740 core.exe 0 0 0
0968 RapportInjService_x64.exe 0 0 0
0998 fbserver.exe 0 0 0
0b20 WUDFHost.exe 0 0 0
0bfc taskhost.exe 1 26 24 normal
0604 core.exe 1 9 21 normal
0c30 sppsvc.exe 0 0 0
0d94 NisSrv.exe 0 0 0
0f48 RapportService.exe 1 14 17 normal C:\Program Files (x86)\Trusteer\
Rapport\bin
0e98 PresentationFontCache.exe 0 0 0
016c dwm.exe 1 16 4 high
0164 explorer.exe 1 378 217 normal
0bd4 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\scpbrad
0c74 RapportInjService_x64.exe 1 4 3 normal
0904 igfxEM.exe 1 14 13 normal
0ddc igfxHK.exe 1 14 12 normal
0f34 msseces.exe 1 143 59 normal
0c60 PrnStatusMX.exe 1 23 19 normal
10b0 GoogleCrashHandler.exe 0 0 0
10bc GoogleCrashHandler64.exe 0 0 0
1198 SearchIndexer.exe 0 0 0
1214 svchost.exe 0 0 0
121c WmiPrvSE.exe 0 0 0
1278 OSPPSVC.EXE 0 0 0
100c wuauclt.exe 1 12 6 normal
113c Store.exe 1 207 202 normal C:\Program Files (x86)\Store
06ec audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a6b6b10
ebx = 00003303
ecx = 00000000
edx = 00282ac8
esi = 0018ee84
edi = 0066c9e4
eip = 0066e902
esp = 0018ee48
ebp = 0018eeb0
stack dump:
0018ee48 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018ee58 5c ee 18 00 02 e9 66 00 - 10 6b 6b 0a 03 33 00 00 \.....f..kk..3..
0018ee68 84 ee 18 00 e4 c9 66 00 - b0 ee 18 00 78 ee 18 00 ......f.....x...
0018ee78 00 ef 4a 06 0e e9 66 00 - 34 e8 67 00 00 00 00 00 ..J...f.4.g.....
0018ee88 00 ef 4a 06 00 00 00 00 - 2f e7 67 00 bc ee 18 00 ..J...../.g.....
0018ee98 0c 89 40 00 b0 ee 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018eea8 69 e8 67 01 00 ef 4a 06 - d8 ee 18 00 87 e7 67 00 i.g...J.......g.
0018eeb8 a6 4b 67 00 f0 ee 18 00 - 0c 89 40 00 d8 ee 18 00 .Kg.......@.....
0018eec8 00 ef 4a 06 00 00 00 00 - 00 00 00 00 00 ef 4a 06 ..J...........J.
0018eed8 04 ef 18 00 4a 91 67 00 - 00 00 00 00 d0 98 5b 00 ....J.g.......[.
0018eee8 01 00 00 00 77 72 65 00 - 10 ef 18 00 0c 89 40 00 ....wre.......@.
0018eef8 04 ef 18 00 f0 11 4b 06 - 00 ef 4a 06 64 ef 18 00 ......K...J.d...
0018ef08 be 70 65 00 f8 5e 5b 01 - 1c ef 18 00 64 89 40 00 .pe..^[.....d.@.
0018ef18 64 ef 18 00 74 ef 18 00 - 0c 89 40 00 64 ef 18 00 [email protected]...
0018ef28 00 00 00 00 d0 98 5b 00 - f0 11 4b 06 00 00 00 00 ......[...K.....
0018ef38 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ef48 00 00 00 00 f0 11 4b 06 - 01 00 00 00 00 00 00 00 ......K.........
0018ef58 00 00 00 00 00 ef 4a 06 - 40 86 6d 0a 90 ef 18 00 [email protected].....
0018ef68 e2 98 5b 00 98 ef 18 00 - c8 97 5b 00 3c f0 18 00 ..[.......[.<...
0018ef78 dc 86 40 00 90 ef 18 00 - 00 00 00 00 fd 0c 7c 02 ..@...........|.
disassembling:
[...]
015b5ecf 884 mov eax, [ebp-8]
015b5ed2 mov eax, [eax+$250]
015b5ed8 mov edx, [eax]
015b5eda call dword ptr [edx+$44]
015b5edd 885 mov eax, [ebp-8]
015b5ee0 mov eax, [eax+$250]
015b5ee6 mov edx, $15b60c0
015b5eeb mov ecx, [eax]
015b5eed call dword ptr [ecx+$38]
015b5ef0 886 mov eax, [ebp-8]
015b5ef3 > call -$f5ee44 ($6570b4) ; Data.DB.TDataSet.Open
015b5ef8 xor eax, eax
015b5efa pop edx
015b5efb pop ecx
015b5efc pop ecx
015b5efd mov fs:[eax], edx
015b5f00 jmp loc_15b608b
015b5f05 jmp -$11ad932 ($4085d8) ; System.@HandleAnyException
015b5f0a 890 mov eax, [$160cdb0]
015b5f0f mov eax, [eax]
015b5f11 mov eax, [eax+$60]
[...]
thread $fd0:
7771f8da +0e ntdll.dll NtWaitForSingleObject
768415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7657118f +3e kernel32.dll WaitForSingleObjectEx
76571143 +0d kernel32.dll WaitForSingleObject
76573368 +10 kernel32.dll BaseThreadInitThunk
thread $ec:
77720166 +0e ntdll.dll NtWaitForMultipleObjects
76573368 +10 kernel32.dll BaseThreadInitThunk
thread $1374:
77721f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76573368 +10 kernel32.dll BaseThreadInitThunk
modules:
001c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
002a0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002d0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02600000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
062b0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063d0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6faa0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71790000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71920000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71940000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71980000 webio.dll 6.1.7601.23375 C:\Windows\
system32
719d0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71a30000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72520000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72540000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72620000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
727d0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
727f0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72800000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73740000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73760000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73880000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73890000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
738b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
738c0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73d40000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73ed0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73ee0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73ef0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73f50000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
74050000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
74110000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74140000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74170000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
741b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
741d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
741e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
741f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74250000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
742c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74460000 version.dll 6.1.7600.16385 C:\Windows\
system32
74470000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74f90000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74fa0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75060000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75090000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
750a0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
752e0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
753e0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75510000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75570000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75580000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
755c0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75710000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75810000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76460000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76530000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76540000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76550000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76560000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76670000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
766f0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76830000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76880000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
769e0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
769f0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76a90000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76aa0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76ac0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76b10000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76ba0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76c50000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76c70000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c80000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c90000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76e30000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e40000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76ed0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76f70000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76fd0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
772b0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
772e0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
776d0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77700000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 wininit.exe 0 0 0
0260 csrss.exe 1 0 0
0298 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03e0 MsMpEng.exe 0 0 0
0148 RapportMgmtService.exe 0 0 0
0318 svchost.exe 0 0 0
03d4 svchost.exe 0 0 0
040c svchost.exe 0 0 0
0438 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0650 svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0768 fbguard.exe 0 0 0
0790 svchost.exe 0 0 0
07c0 NetExpressUpdater.exe 0 0 0
046c svchost.exe 0 0 0
0598 scpbradserv.exe 0 0 0
06e0 svchost.exe 0 0 0
0758 core.exe 0 0 0
093c RapportInjService_x64.exe 0 0 0
09f8 fbserver.exe 0 0 0
0aec WUDFHost.exe 0 0 0
05f4 NisSrv.exe 0 0 0
0d5c WmiPrvSE.exe 0 0 0
0d88 OSPPSVC.EXE 0 0 0
0eb0 taskhost.exe 1 26 23 normal
0ed0 core.exe 1 9 20 normal
0f7c sppsvc.exe 0 0 0
0ccc GoogleCrashHandler.exe 0 0 0
0cd4 GoogleCrashHandler64.exe 0 0 0
0db0 PresentationFontCache.exe 0 0 0
0d28 dwm.exe 1 16 4 high
09a8 RapportService.exe 1 14 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0c70 explorer.exe 1 453 260 normal
01a0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0174 igfxEM.exe 1 14 13 normal
077c igfxHK.exe 1 14 12 normal
0324 RapportInjService_x64.exe 1 4 3 normal
0cbc msseces.exe 1 143 60 normal
0600 PrnStatusMX.exe 1 23 20 normal
1004 svchost.exe 0 0 0
106c SearchIndexer.exe 0 0 0
12e0 wuauclt.exe 1 12 6 normal
0508 audiodg.exe 0 0 0
125c chrome.exe 1 22 48 normal
05d8 chrome.exe 1 9 4 normal
0310 chrome.exe 1 7 5 above normal
0b40 chrome.exe 1 4 1 normal
0ea0 chrome.exe 1 4 1 idle
10cc chrome.exe 1 4 1 idle
111c chrome.exe 1 4 3 normal
0728 Store.exe 1 103 85 normal C:\Program Files (x86)\Store
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0448b140
ebx = 00002c0d
ecx = 00000000
edx = 00302ac8
esi = 00000000
edi = 00000000
eip = 0066e902
esp = 0018f020
ebp = 0018f0fc
stack dump:
0018f020 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018f030 34 f0 18 00 02 e9 66 00 - 40 b1 48 04 0d 2c 00 00 [email protected]..,..
0018f040 00 00 00 00 00 00 00 00 - fc f0 18 00 50 f0 18 00 ............P...
0018f050 00 00 00 00 0e e9 66 00 - 9f 44 67 00 68 f0 18 00 ......f..Dg.h...
0018f060 eb 8a 40 00 fc f0 18 00 - 74 f0 18 00 0c 89 40 00 [email protected].....@.
0018f070 fc f0 18 00 80 f0 18 00 - 0c 89 40 00 fc f0 18 00 ..........@.....
0018f080 14 f1 18 00 0c 89 40 00 - fc f0 18 00 00 00 00 00 ......@.........
0018f090 70 77 43 04 01 fa 51 06 - 00 00 00 00 00 00 00 00 pwC...Q.........
0018f0a0 00 00 00 00 00 00 00 00 - 00 00 00 00 e4 45 4d 06 .............EM.
0018f0b0 9c 22 45 00 00 04 00 00 - 01 00 00 00 34 ce 48 04 ."E.........4.H.
0018f0c0 08 00 00 00 e4 45 4d 06 - 08 00 00 00 30 2e 41 04 .....EM.....0.A.
0018f0d0 00 00 00 00 01 00 00 00 - 70 77 43 04 85 fc 66 00 ........pwC...f.
0018f0e0 e4 45 4d 06 01 00 00 00 - 00 00 00 00 00 00 00 07 .EM.............
0018f0f0 70 77 43 04 00 00 00 00 - 00 00 00 00 44 f1 18 00 pwC.........D...
0018f100 a4 54 64 00 b0 fa 51 06 - e4 45 4d 06 5f 54 64 00 .Td...Q..EM._Td.
0018f110 db 1c 67 00 20 f1 18 00 - eb 8a 40 00 44 f1 18 00 ..g. [email protected]...
0018f120 b0 f1 18 00 0c 89 40 00 - 44 f1 18 00 00 00 00 00 [email protected].......
0018f130 40 0a 45 04 40 0a 45 04 - 00 00 00 00 70 77 43 04 @[email protected].
0018f140 30 2e 41 04 c4 f1 18 00 - c1 92 67 00 00 c9 66 00 0.A.......g...f.
0018f150 c2 93 67 00 01 c9 66 00 - c4 f1 18 00 00 00 00 00 ..g...f.........
disassembling:
[...]
009d5b25 push $9d6414
009d5b2a lea eax, [ebp-$2c]
009d5b2d mov edx, 5
009d5b32 call -$5cb387 ($40a7b0) ; System.@UStrCatN
009d5b37 mov edx, [ebp-$2c]
009d5b3a mov eax, [ebp-$18]
009d5b3d mov eax, [eax+$250]
009d5b43 mov ecx, [eax]
009d5b45 call dword ptr [ecx+$38]
009d5b48 639 mov eax, [ebp-$18]
009d5b4b > call -$37ea9c ($6570b4) ; Data.DB.TDataSet.Open
009d5b50 641 mov eax, [$160cdb0]
009d5b55 mov eax, [eax]
009d5b57 mov eax, [eax+$e60]
009d5b5d cmp byte ptr [eax+$a8], 0
009d5b64 jz loc_9d5b80
009d5b66 mov eax, [$160cdb0]
009d5b6b mov eax, [eax]
009d5b6d mov eax, [eax+$e60]
009d5b73 cmp byte ptr [eax+$a9], 0
009d5b7a jnz loc_9d60e8
[...]
thread $fd0:
7771f8da +0e ntdll.dll NtWaitForSingleObject
768415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7657118f +3e kernel32.dll WaitForSingleObjectEx
76571143 +0d kernel32.dll WaitForSingleObject
76573368 +10 kernel32.dll BaseThreadInitThunk
thread $ec:
77720166 +0e ntdll.dll NtWaitForMultipleObjects
76573368 +10 kernel32.dll BaseThreadInitThunk
thread $1374:
77721f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76573368 +10 kernel32.dll BaseThreadInitThunk
thread $458:
7771f8da +0e ntdll.dll NtWaitForSingleObject
768415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7657118f +3e kernel32.dll WaitForSingleObjectEx
76571143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
76573368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($10dc) at:
74064c95 +00 winspool.drv
thread $1118:
77721f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76573368 +10 kernel32.dll BaseThreadInitThunk
thread $122c:
77721f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76573368 +10 kernel32.dll BaseThreadInitThunk
modules:
001c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
002a0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002d0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02600000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
05410000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
062b0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063d0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6faa0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
713c0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71650000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71790000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71920000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71940000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71980000 webio.dll 6.1.7601.23375 C:\Windows\
system32
719d0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71a30000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72520000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72540000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72620000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
727d0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
727f0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72800000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73710000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73740000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73760000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73880000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73890000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
738b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
738c0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73d10000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73d40000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73ed0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73ee0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73ef0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73f50000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
74050000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
740c0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74110000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74140000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74170000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
741b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
741d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
741e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
741f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74250000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
742c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74460000 version.dll 6.1.7600.16385 C:\Windows\
system32
74470000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74f90000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74fa0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75060000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75090000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
750a0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
752e0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
753e0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75510000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75570000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75580000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
755c0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75710000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75810000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76460000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76530000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76540000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76550000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76560000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76670000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
766f0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76830000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76880000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
769e0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
769f0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76a90000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76aa0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76ac0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76b10000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76ba0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76c50000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76c70000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c80000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c90000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76e30000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e40000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76ed0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76f70000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76fd0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
772b0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
772e0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
776d0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77700000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 wininit.exe 0 0 0
0260 csrss.exe 1 0 0
0298 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03e0 MsMpEng.exe 0 0 0
0148 RapportMgmtService.exe 0 0 0
0318 svchost.exe 0 0 0
03d4 svchost.exe 0 0 0
040c svchost.exe 0 0 0
0438 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0650 svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0768 fbguard.exe 0 0 0
0790 svchost.exe 0 0 0
07c0 NetExpressUpdater.exe 0 0 0
046c svchost.exe 0 0 0
0598 scpbradserv.exe 0 0 0
06e0 svchost.exe 0 0 0
0758 core.exe 0 0 0
093c RapportInjService_x64.exe 0 0 0
09f8 fbserver.exe 0 0 0
0aec WUDFHost.exe 0 0 0
05f4 NisSrv.exe 0 0 0
0d5c WmiPrvSE.exe 0 0 0
0d88 OSPPSVC.EXE 0 0 0
0eb0 taskhost.exe 1 26 21 normal
0ed0 core.exe 1 9 20 normal
0f7c sppsvc.exe 0 0 0
0ccc GoogleCrashHandler.exe 0 0 0
0cd4 GoogleCrashHandler64.exe 0 0 0
0db0 PresentationFontCache.exe 0 0 0
0d28 dwm.exe 1 16 4 high
09a8 RapportService.exe 1 14 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0c70 explorer.exe 1 483 267 normal
01a0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0174 igfxEM.exe 1 14 13 normal
077c igfxHK.exe 1 14 12 normal
0324 RapportInjService_x64.exe 1 4 3 normal
0cbc msseces.exe 1 143 60 normal
0600 PrnStatusMX.exe 1 23 20 normal
1004 svchost.exe 0 0 0
106c SearchIndexer.exe 0 0 0
12e0 wuauclt.exe 1 12 5 normal
125c chrome.exe 1 22 50 normal
05d8 chrome.exe 1 9 4 normal
0310 chrome.exe 1 7 5 above normal
0b40 chrome.exe 1 4 1 normal
0ea0 chrome.exe 1 4 1 idle
10cc chrome.exe 1 4 1 idle
111c chrome.exe 1 4 3 normal
0728 Store.exe 1 211 220 normal C:\Program Files (x86)\Store
116c splwow64.exe 1 9 3 normal
1104 chrome.exe 1 4 1 normal
1360 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 05ef8f78
ebx = 00003303
ecx = 00000000
edx = 00302ac8
esi = 0018e028
edi = 0066c9e4
eip = 0066e902
esp = 0018dfec
ebp = 0018e054
stack dump:
0018dfec 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018dffc 00 e0 18 00 02 e9 66 00 - 78 8f ef 05 03 33 00 00 ......f.x....3..
0018e00c 28 e0 18 00 e4 c9 66 00 - 54 e0 18 00 1c e0 18 00 (.....f.T.......
0018e01c 60 99 44 04 0e e9 66 00 - 34 e8 67 00 00 00 00 00 `.D...f.4.g.....
0018e02c 60 99 44 04 00 00 00 00 - 2f e7 67 00 60 e0 18 00 `.D...../.g.`...
0018e03c 0c 89 40 00 54 e0 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018e04c 69 e8 67 01 60 99 44 04 - 7c e0 18 00 87 e7 67 00 i.g.`.D.|.....g.
0018e05c a6 4b 67 00 94 e0 18 00 - 0c 89 40 00 7c e0 18 00 .Kg.......@.|...
0018e06c 60 99 44 04 00 00 00 00 - 00 00 00 00 60 99 44 04 `.D.........`.D.
0018e07c a8 e0 18 00 4a 91 67 00 - 68 e3 18 00 e0 26 ec 05 ....J.g.h....&..
0018e08c 01 00 00 00 77 72 65 00 - b4 e0 18 00 0c 89 40 00 ....wre.......@.
0018e09c a8 e0 18 00 e0 26 ec 05 - 60 99 44 04 2c e1 18 00 .....&..`.D.,...
0018e0ac be 70 65 00 83 59 20 01 - 34 e1 18 00 0c 89 40 00 .pe..Y .4.....@.
0018e0bc 2c e1 18 00 68 e3 18 00 - e0 26 ec 05 e0 26 ec 05 ,...h....&...&..
0018e0cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0dc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0ec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0fc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e10c 00 00 00 00 00 00 00 00 - 00 00 00 00 60 99 44 04 ............`.D.
0018e11c 00 00 00 00 10 1d 39 04 - 00 00 00 00 00 00 00 00 ......9.........
disassembling:
[...]
01205958 push $1205c6c
0120595d lea eax, [ebp-$30]
01205960 mov edx, 3
01205965 call -$dfb1ba ($40a7b0) ; System.@UStrCatN
0120596a mov edx, [ebp-$30]
0120596d mov eax, [ebp-$14]
01205970 mov eax, [eax+$250]
01205976 mov ecx, [eax]
01205978 call dword ptr [ecx+$38]
0120597b 56 mov eax, [ebp-$14]
0120597e > call -$bae8cf ($6570b4) ; Data.DB.TDataSet.Open
01205983 58 mov ecx, [ebp-$c]
01205986 mov dl, 1
01205988 mov eax, [$542b34]
0120598d call -$cb5c3a ($54fd58) ; Vcl.StdCtrls.TCustomMemo.Create
01205992 mov [ebp-$10], eax
01205995 59 mov edx, [ebp-$c]
01205998 mov eax, [ebp-$10]
0120599b mov ecx, [eax]
0120599d call dword ptr [ecx+$84]
012059a3 60 mov eax, [ebp-$10]
[...]
thread $fd0:
7771f8da +0e ntdll.dll NtWaitForSingleObject
768415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7657118f +3e kernel32.dll WaitForSingleObjectEx
76571143 +0d kernel32.dll WaitForSingleObject
76573368 +10 kernel32.dll BaseThreadInitThunk
thread $ec:
77720166 +0e ntdll.dll NtWaitForMultipleObjects
76573368 +10 kernel32.dll BaseThreadInitThunk
thread $458:
7771f8da +0e ntdll.dll NtWaitForSingleObject
768415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7657118f +3e kernel32.dll WaitForSingleObjectEx
76571143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
76573368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($10dc) at:
74064c95 +00 winspool.drv
thread $122c:
77721f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76573368 +10 kernel32.dll BaseThreadInitThunk
modules:
001c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
002a0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002d0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02600000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
05410000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
062b0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063d0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6faa0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
713c0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71650000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71790000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71920000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71940000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71980000 webio.dll 6.1.7601.23375 C:\Windows\
system32
719d0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71a30000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72520000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72540000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72620000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
727d0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
727f0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72800000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73710000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73740000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73760000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73880000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73890000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
738b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
738c0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73d10000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73d40000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73ed0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73ee0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73ef0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73f50000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
74050000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
740c0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74110000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74140000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74170000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
741b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
741d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
741e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
741f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74250000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
742c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74460000 version.dll 6.1.7600.16385 C:\Windows\
system32
74470000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74f90000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74fa0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75060000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75090000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
750a0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
752e0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
753e0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75510000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75570000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75580000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
755c0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75710000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75810000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76460000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76530000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76540000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76550000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76560000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76670000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
766f0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76830000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76880000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
769e0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
769f0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76a90000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76aa0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76ac0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76b10000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76ba0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76c50000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76c70000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c80000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c90000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76e30000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e40000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76ed0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76f70000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76fd0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
772b0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
772e0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
776d0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77700000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 wininit.exe 0 0 0
0260 csrss.exe 1 0 0
0298 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03e0 MsMpEng.exe 0 0 0
0148 RapportMgmtService.exe 0 0 0
0318 svchost.exe 0 0 0
03d4 svchost.exe 0 0 0
040c svchost.exe 0 0 0
0438 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0650 svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0768 fbguard.exe 0 0 0
0790 svchost.exe 0 0 0
07c0 NetExpressUpdater.exe 0 0 0
046c svchost.exe 0 0 0
0598 scpbradserv.exe 0 0 0
06e0 svchost.exe 0 0 0
0758 core.exe 0 0 0
093c RapportInjService_x64.exe 0 0 0
09f8 fbserver.exe 0 0 0
0aec WUDFHost.exe 0 0 0
05f4 NisSrv.exe 0 0 0
0d5c WmiPrvSE.exe 0 0 0
0d88 OSPPSVC.EXE 0 0 0
0eb0 taskhost.exe 1 26 21 normal
0ed0 core.exe 1 9 20 normal
0f7c sppsvc.exe 0 0 0
0ccc GoogleCrashHandler.exe 0 0 0
0cd4 GoogleCrashHandler64.exe 0 0 0
0db0 PresentationFontCache.exe 0 0 0
0d28 dwm.exe 1 16 4 high
09a8 RapportService.exe 1 14 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0c70 explorer.exe 1 485 266 normal
01a0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0174 igfxEM.exe 1 14 13 normal
077c igfxHK.exe 1 14 12 normal
0324 RapportInjService_x64.exe 1 4 3 normal
0cbc msseces.exe 1 143 60 normal
0600 PrnStatusMX.exe 1 23 20 normal
1004 svchost.exe 0 0 0
106c SearchIndexer.exe 0 0 0
12e0 wuauclt.exe 1 12 5 normal
125c chrome.exe 1 22 47 normal
05d8 chrome.exe 1 9 4 normal
0310 chrome.exe 1 7 5 above normal
0b40 chrome.exe 1 4 1 normal
0ea0 chrome.exe 1 4 1 idle
10cc chrome.exe 1 4 1 idle
111c chrome.exe 1 4 3 normal
0728 Store.exe 1 223 199 normal C:\Program Files (x86)\Store
116c splwow64.exe 1 9 2 normal
0b7c chrome.exe 1 4 1 normal
09ac audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 05efa9b8
ebx = 00003303
ecx = 00000000
edx = 00302ac8
esi = 0018ee84
edi = 0066c9e4
eip = 0066e902
esp = 0018ee48
ebp = 0018eeb0
stack dump:
0018ee48 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018ee58 5c ee 18 00 02 e9 66 00 - b8 a9 ef 05 03 33 00 00 \.....f......3..
0018ee68 84 ee 18 00 e4 c9 66 00 - b0 ee 18 00 78 ee 18 00 ......f.....x...
0018ee78 30 6d 49 06 0e e9 66 00 - 34 e8 67 00 00 00 00 00 0mI...f.4.g.....
0018ee88 30 6d 49 06 00 00 00 00 - 2f e7 67 00 bc ee 18 00 0mI...../.g.....
0018ee98 0c 89 40 00 b0 ee 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018eea8 69 e8 67 01 30 6d 49 06 - d8 ee 18 00 87 e7 67 00 i.g.0mI.......g.
0018eeb8 a6 4b 67 00 f0 ee 18 00 - 0c 89 40 00 d8 ee 18 00 .Kg.......@.....
0018eec8 30 6d 49 06 00 00 00 00 - 00 00 00 00 30 6d 49 06 0mI.........0mI.
0018eed8 04 ef 18 00 4a 91 67 00 - 00 00 00 00 d0 98 5b 00 ....J.g.......[.
0018eee8 01 00 00 00 77 72 65 00 - 10 ef 18 00 0c 89 40 00 ....wre.......@.
0018eef8 04 ef 18 00 50 06 2d 05 - 30 6d 49 06 64 ef 18 00 ....P.-.0mI.d...
0018ef08 be 70 65 00 f8 5e 5b 01 - 1c ef 18 00 64 89 40 00 .pe..^[.....d.@.
0018ef18 64 ef 18 00 74 ef 18 00 - 0c 89 40 00 64 ef 18 00 [email protected]...
0018ef28 00 00 00 00 d0 98 5b 00 - 50 06 2d 05 00 00 00 00 ......[.P.-.....
0018ef38 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ef48 00 00 00 00 50 06 2d 05 - 01 00 00 00 00 00 00 00 ....P.-.........
0018ef58 00 00 00 00 30 6d 49 06 - 60 5b 2b 05 90 ef 18 00 ....0mI.`[+.....
0018ef68 e2 98 5b 00 98 ef 18 00 - c8 97 5b 00 3c f0 18 00 ..[.......[.<...
0018ef78 dc 86 40 00 90 ef 18 00 - 00 00 00 00 fd 0c 14 04 ..@.............
disassembling:
[...]
015b5ecf 884 mov eax, [ebp-8]
015b5ed2 mov eax, [eax+$250]
015b5ed8 mov edx, [eax]
015b5eda call dword ptr [edx+$44]
015b5edd 885 mov eax, [ebp-8]
015b5ee0 mov eax, [eax+$250]
015b5ee6 mov edx, $15b60c0
015b5eeb mov ecx, [eax]
015b5eed call dword ptr [ecx+$38]
015b5ef0 886 mov eax, [ebp-8]
015b5ef3 > call -$f5ee44 ($6570b4) ; Data.DB.TDataSet.Open
015b5ef8 xor eax, eax
015b5efa pop edx
015b5efb pop ecx
015b5efc pop ecx
015b5efd mov fs:[eax], edx
015b5f00 jmp loc_15b608b
015b5f05 jmp -$11ad932 ($4085d8) ; System.@HandleAnyException
015b5f0a 890 mov eax, [$160cdb0]
015b5f0f mov eax, [eax]
015b5f11 mov eax, [eax+$60]
[...]
thread $13a4:
7757f8da +0e ntdll.dll NtWaitForSingleObject
771215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7683118f +3e kernel32.dll WaitForSingleObjectEx
76831143 +0d kernel32.dll WaitForSingleObject
76833368 +10 kernel32.dll BaseThreadInitThunk
thread $b04:
77580166 +0e ntdll.dll NtWaitForMultipleObjects
76833368 +10 kernel32.dll BaseThreadInitThunk
thread $d14:
77581f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76833368 +10 kernel32.dll BaseThreadInitThunk
thread $978:
77581f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76833368 +10 kernel32.dll BaseThreadInitThunk
thread $1268:
77581f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76833368 +10 kernel32.dll BaseThreadInitThunk
thread $1018:
77581f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76833368 +10 kernel32.dll BaseThreadInitThunk
modules:
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02670000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
026a0000 BCLW32.dll C:\Program
Files (x86)\Store
062b0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06360000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71300000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71320000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71640000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
717e0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71830000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71890000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72370000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72390000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72420000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72460000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72610000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72b10000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73610000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73690000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
736a0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
736c0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
736d0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
737b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
737c0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
738c0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73920000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73aa0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73ae0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73af0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73ec0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73f10000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
73f30000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
73fa0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73fd0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74010000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74030000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74040000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74050000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
740b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74120000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
742c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
742d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74df0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74e00000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74e60000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75ab0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75cf0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d00000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75d50000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75e80000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76020000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
760f0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76150000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
761f0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
762e0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
762f0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76380000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
763b0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
763c0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
763e0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76420000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76440000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
764d0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76580000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76590000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
765a0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76700000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76800000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76810000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76820000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76930000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76950000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76960000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76c10000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76ca0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76d50000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76d60000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76de0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76f30000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77010000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
770b0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77110000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77530000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77560000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0338 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
00a0 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0348 svchost.exe 0 0 0
0210 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
055c svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0650 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
01e0 svchost.exe 0 0 0
0554 scpbradserv.exe 0 0 0
06ac svchost.exe 0 0 0
07f8 core.exe 0 0 0
0950 RapportInjService_x64.exe 0 0 0
09e4 fbserver.exe 0 0 0
0b5c WUDFHost.exe 0 0 0
05f0 NisSrv.exe 0 0 0
0dec WmiPrvSE.exe 0 0 0
0e38 OSPPSVC.EXE 0 0 0
0d30 taskhost.exe 1 26 21 normal
0d5c core.exe 1 9 23 normal
08d0 sppsvc.exe 0 0 0
076c GoogleCrashHandler.exe 0 0 0
0f90 GoogleCrashHandler64.exe 0 0 0
0308 PresentationFontCache.exe 0 0 0
0fd0 dwm.exe 1 17 4 high
0a00 explorer.exe 1 400 237 normal
0a5c RapportService.exe 1 14 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
09ec scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0ba4 igfxEM.exe 1 14 14 normal
0ff8 igfxHK.exe 1 14 12 normal
0c88 msseces.exe 1 143 59 normal
0c9c RapportInjService_x64.exe 1 4 3 normal
0ca4 PrnStatusMX.exe 1 23 20 normal
0f7c svchost.exe 0 0 0
105c SearchIndexer.exe 0 0 0
0dac chrome.exe 1 23 46 normal
10d0 chrome.exe 1 9 4 normal
125c chrome.exe 1 7 7 above normal
1244 chrome.exe 1 4 1 normal
114c chrome.exe 1 4 1 idle
00d8 chrome.exe 1 4 1 idle
0f80 chrome.exe 1 4 3 normal
020c wuauclt.exe 1 12 6 normal
1314 svchost.exe 0 0 0
0614 taskeng.exe 1 9 3 normal
0d04 Store.exe 1 93 69 normal C:\Program Files (x86)\Store
0534 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 06534420
ebx = 00002c0d
ecx = 00000000
edx = 00242ac8
esi = 00000000
edi = 00000000
eip = 0066e902
esp = 0018fccc
ebp = 0018fda8
stack dump:
0018fccc 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018fcdc e0 fc 18 00 02 e9 66 00 - 20 44 53 06 0d 2c 00 00 ......f. DS..,..
0018fcec 00 00 00 00 00 00 00 00 - a8 fd 18 00 fc fc 18 00 ................
0018fcfc 00 00 00 00 0e e9 66 00 - 9f 44 67 00 14 fd 18 00 ......f..Dg.....
0018fd0c eb 8a 40 00 a8 fd 18 00 - 20 fd 18 00 0c 89 40 00 ..@..... .....@.
0018fd1c a8 fd 18 00 2c fd 18 00 - 0c 89 40 00 a8 fd 18 00 ....,.....@.....
0018fd2c c0 fd 18 00 0c 89 40 00 - a8 fd 18 00 00 00 00 00 ......@.........
0018fd3c 70 77 58 04 01 ea 4e 04 - 00 00 00 00 00 00 00 00 pwX...N.........
0018fd4c 00 00 00 00 00 00 00 00 - 00 00 00 00 84 e0 5a 06 ..............Z.
0018fd5c 9c 22 45 00 00 04 00 00 - 01 00 00 00 34 ce 5d 04 ."E.........4.].
0018fd6c 08 00 00 00 84 e0 5a 06 - 08 00 00 00 30 2e 56 04 ......Z.....0.V.
0018fd7c 00 00 00 00 01 00 00 00 - 70 77 58 04 85 fc 66 00 ........pwX...f.
0018fd8c 84 e0 5a 06 01 00 00 00 - 00 00 00 00 00 00 00 07 ..Z.............
0018fd9c 70 77 58 04 00 00 00 00 - 00 00 00 00 f0 fd 18 00 pwX.............
0018fdac a4 54 64 00 50 ea 4e 04 - 84 e0 5a 06 5f 54 64 00 .Td.P.N...Z._Td.
0018fdbc db 1c 67 00 cc fd 18 00 - eb 8a 40 00 f0 fd 18 00 ..g.......@.....
0018fdcc 5c fe 18 00 0c 89 40 00 - f0 fd 18 00 00 00 00 00 \.....@.........
0018fddc 70 72 4f 06 70 72 4f 06 - 00 00 00 00 70 77 58 04 prO.prO.....pwX.
0018fdec 30 2e 56 04 70 fe 18 00 - c1 92 67 00 00 c9 66 00 0.V.p.....g...f.
0018fdfc c2 93 67 00 01 c9 66 00 - 70 fe 18 00 00 00 00 00 ..g...f.p.......
disassembling:
[...]
009c8d37 121 mov eax, [ebp-8]
009c8d3a mov eax, [eax+$250]
009c8d40 mov edx, [eax]
009c8d42 call dword ptr [edx+$44]
009c8d45 122 mov edx, $9ca754
009c8d4a mov eax, [ebp-8]
009c8d4d mov eax, [eax+$250]
009c8d53 mov ecx, [eax]
009c8d55 call dword ptr [ecx+$38]
009c8d58 123 mov eax, [ebp-8]
009c8d5b > call -$371cac ($6570b4) ; Data.DB.TDataSet.Open
009c8d60 125 mov edx, $9ca7b0
009c8d65 mov eax, [ebp-4]
009c8d68 mov eax, [eax+$394]
009c8d6e call -$37093f ($658434) ; Data.DB.TDataSet.FieldByName
009c8d73 lea edx, [ebp-$10]
009c8d76 mov ecx, [eax]
009c8d78 call dword ptr [ecx+$80]
009c8d7e mov eax, [ebp-$10]
009c8d81 mov edx, $9ca7d8
009c8d86 call -$5be4cb ($40a8c0) ; System.@UStrEqual
[...]
thread $e7c:
77d0f8da +0e ntdll.dll NtWaitForSingleObject
769b15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
768a118f +3e kernel32.dll WaitForSingleObjectEx
768a1143 +0d kernel32.dll WaitForSingleObject
768a3368 +10 kernel32.dll BaseThreadInitThunk
thread $c44:
77d10166 +0e ntdll.dll NtWaitForMultipleObjects
768a3368 +10 kernel32.dll BaseThreadInitThunk
thread $1364:
77d10166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
768a3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1344) at:
74452713 +24f netbios.dll Netbios
thread $a28:
77d0f8da +0e ntdll.dll NtWaitForSingleObject
769b15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
768a118f +3e kernel32.dll WaitForSingleObjectEx
768a1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
768a3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1344) at:
745e4c95 +00 winspool.drv
thread $c70:
77d11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
768a3368 +10 kernel32.dll BaseThreadInitThunk
thread $1084:
77d11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
768a3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
045b0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06360000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71430000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
71500000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
71510000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
71530000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
71550000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
71560000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
71570000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
715c0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
715d0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71910000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
719b0000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
71a00000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
71a10000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71a50000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71a90000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71ab0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71ac0000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71de0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71f70000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71fc0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72020000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72890000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
728b0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72940000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
72bd0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72c10000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72dc0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72de0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72df0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
739a0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73c70000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
742b0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74400000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
74410000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
74420000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74450000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
74460000 security.dll 6.1.7600.16385 C:\Windows\
system32
74470000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
744d0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
745d0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
74630000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
746a0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
746b0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74700000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74730000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74760000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
747a0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
747c0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
747d0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
747e0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
747f0000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
74840000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74880000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74890000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
748b0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74a50000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a60000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75580000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75590000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
755f0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75750000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75760000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
757f0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75950000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75970000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75a20000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75a30000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75ae0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75bb0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75df0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75e50000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75e90000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75ea0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75f30000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f40000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75f50000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75f60000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75f90000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75fa0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75fc0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
760b0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
760c0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76160000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76300000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76320000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
765d0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
765e0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76600000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76660000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
766f0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76740000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76890000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
769a0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
769f0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77640000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77740000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77870000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
77cc0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77cf0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
00a8 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0340 svchost.exe 0 0 0
021c svchost.exe 0 0 0
0424 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0504 igfxCUIService.exe 0 0 0
0550 svchost.exe 0 0 0
061c spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
072c svchost.exe 0 0 0
0750 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
0790 NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
04d4 scpbradserv.exe 0 0 0
069c core.exe 0 0 0
0910 RapportInjService_x64.exe 0 0 0
09f8 fbserver.exe 0 0 0
0b94 WUDFHost.exe 0 0 0
0960 NisSrv.exe 0 0 0
0fc0 WmiPrvSE.exe 0 0 0
0ff0 OSPPSVC.EXE 0 0 0
0ec0 svchost.exe 0 0 0
0c78 sppsvc.exe 0 0 0
0c68 GoogleCrashHandler.exe 0 0 0
0ca4 GoogleCrashHandler64.exe 0 0 0
0cfc SearchIndexer.exe 0 0 0
0e30 taskhost.exe 1 26 22 normal
041c core.exe 1 9 21 normal
0458 PresentationFontCache.exe 0 0 0
0410 dwm.exe 1 17 4 high
0dc4 explorer.exe 1 441 251 normal
01a0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e84 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f64 igfxEM.exe 1 14 13 normal
07e0 igfxHK.exe 1 14 12 normal
0520 RapportInjService_x64.exe 1 4 3 normal
02a0 msseces.exe 1 143 59 normal
098c PrnStatusMX.exe 1 23 20 normal
1274 wuauclt.exe 1 12 7 normal
1068 Store.exe 1 1263 385 normal C:\Program Files (x86)\Store
03b0 splwow64.exe 1 9 3 normal
112c svchost.exe 0 0 0
0f8c DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
13bc OIS.EXE 1 133 52 normal
0ef0 chrome.exe 1 26 46 normal
0f24 chrome.exe 1 9 4 normal
11a0 chrome.exe 1 7 7 above normal
13e0 chrome.exe 1 4 1 normal
1300 chrome.exe 1 4 1 normal
1124 chrome.exe 1 4 1 idle
0d20 chrome.exe 1 4 3 normal
0bf0 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0b59f918
ebx = 00003303
ecx = 00000000
edx = 026d2ac8
esi = 0018ebe4
edi = 0066c9e4
eip = 0066e902
esp = 0018eba8
ebp = 0018ec10
stack dump:
0018eba8 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018ebb8 bc eb 18 00 02 e9 66 00 - 18 f9 59 0b 03 33 00 00 ......f...Y..3..
0018ebc8 e4 eb 18 00 e4 c9 66 00 - 10 ec 18 00 d8 eb 18 00 ......f.........
0018ebd8 20 d2 4f 06 0e e9 66 00 - 34 e8 67 00 00 00 00 00 .O...f.4.g.....
0018ebe8 20 d2 4f 06 00 00 00 00 - 2f e7 67 00 1c ec 18 00 .O...../.g.....
0018ebf8 0c 89 40 00 10 ec 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018ec08 69 e8 67 01 20 d2 4f 06 - 38 ec 18 00 87 e7 67 00 i.g. .O.8.....g.
0018ec18 a6 4b 67 00 50 ec 18 00 - 0c 89 40 00 38 ec 18 00 [email protected]...
0018ec28 20 d2 4f 06 00 00 00 00 - 00 00 00 00 20 d2 4f 06 .O......... .O.
0018ec38 64 ec 18 00 4a 91 67 00 - 07 00 00 00 ac 3a 62 00 d...J.g......:b.
0018ec48 01 00 00 00 77 72 65 00 - 70 ec 18 00 0c 89 40 00 ....wre.p.....@.
0018ec58 64 ec 18 00 00 8d ed 0a - 20 d2 4f 06 34 ed 18 00 d....... .O.4...
0018ec68 be 70 65 00 88 ba 16 01 - 68 ef 18 00 0c 89 40 00 .pe.....h.....@.
0018ec78 34 ed 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 4...............
0018ec88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ec98 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eca8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ecb8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ecc8 00 00 00 00 00 00 00 00 - 40 7e e5 40 00 8d ed 0a ........@~.@....
0018ecd8 00 00 00 00 fa a4 4f fa - 7f 7f e5 40 00 00 00 00 ......O....@....
disassembling:
[...]
0116ba5f mov eax, [ebp-$18]
0116ba62 mov eax, [eax+$250]
0116ba68 mov ecx, [eax]
0116ba6a call dword ptr [ecx+$38]
0116ba6d 425 mov edx, $116cac0
0116ba72 mov eax, [ebp-$18]
0116ba75 mov eax, [eax+$250]
0116ba7b mov ecx, [eax]
0116ba7d call dword ptr [ecx+$38]
0116ba80 427 mov eax, [ebp-$18]
0116ba83 > call -$b149d4 ($6570b4) ; Data.DB.TDataSet.Open
0116ba88 428 mov eax, [ebp-$18]
0116ba8b call -$b12114 ($65997c) ; Data.DB.TDataSet.First
0116ba90 429 mov eax, [ebp-$18]
0116ba93 cmp byte ptr [eax+$a9], 0
0116ba9a jz loc_116baa8
0116ba9c mov eax, [ebp-$18]
0116ba9f cmp byte ptr [eax+$a8], 0
0116baa6 jnz loc_116bab7
0116baa8 431 mov eax, [ebp-4]
0116baab call +$32fe8 ($119ea98) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $1598:
77cb0166 +0e ntdll.dll NtWaitForMultipleObjects
756a3368 +10 kernel32.dll BaseThreadInitThunk
thread $158c:
77cb1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
756a3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00390000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
06280000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06320000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71480000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
714a0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
714b0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
714d0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
715d0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71890000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
718e0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71940000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71be0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71e70000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71eb0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71ed0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
721b0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
72200000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72260000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72ab0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72ad0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72b70000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72bb0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72d60000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72d80000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72d90000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72f60000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73090000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
733d0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73c70000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73cd0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
74250000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
745a0000 security.dll 6.1.7600.16385 C:\Windows\
system32
745b0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
745e0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74650000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
746a0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
746d0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74700000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74740000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74760000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74770000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74780000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
747e0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74850000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
749f0000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a00000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75520000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75590000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
755a0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
755b0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75670000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75690000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
757a0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
757b0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
757c0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
758b0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
758c0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75970000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75aa0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75b30000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76780000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76810000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
769b0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
769c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76a10000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76a70000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76cc0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76d90000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76e10000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76e40000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76ee0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77030000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77040000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77060000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
770b0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
770c0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
771b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77260000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77360000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77610000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77770000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77780000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
777c0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
77860000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
77880000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77c60000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77c90000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0338 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
009c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0348 svchost.exe 0 0 0
01fc svchost.exe 0 0 0
041c svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0500 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0650 svchost.exe 0 0 0
06d0 armsvc.exe 0 0 0
06e8 atkexComSvc.exe 0 0 0
0728 svchost.exe 0 0 0
074c fbguard.exe 0 0 0
0770 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07ec svchost.exe 0 0 0
04f4 scpbradserv.exe 0 0 0
0724 core.exe 0 0 0
0958 RapportInjService_x64.exe 0 0 0
098c fbserver.exe 0 0 0
0ad0 WUDFHost.exe 0 0 0
0bc0 NisSrv.exe 0 0 0
0cb4 WmiPrvSE.exe 0 0 0
0ce4 OSPPSVC.EXE 0 0 0
0ff4 svchost.exe 0 0 0
014c sppsvc.exe 0 0 0
0710 GoogleCrashHandler.exe 0 0 0
084c GoogleCrashHandler64.exe 0 0 0
097c SearchIndexer.exe 0 0 0
0c3c taskhost.exe 1 26 22 normal
0ea0 core.exe 1 9 22 normal
0e80 PresentationFontCache.exe 0 0 0
0fa0 dwm.exe 1 20 5 high
0cc4 explorer.exe 1 435 285 normal
0614 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0fb0 igfxEM.exe 1 14 13 normal
0e84 igfxHK.exe 1 14 12 normal
0e8c RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0c54 msseces.exe 1 143 59 normal
0c78 PrnStatusMX.exe 1 23 20 normal
1160 RapportInjService_x64.exe 1 4 3 normal
11d0 wuauclt.exe 1 12 7 normal
1244 chrome.exe 1 75 54 normal
0f74 chrome.exe 1 9 4 normal
1258 chrome.exe 1 7 7 above normal
12f4 chrome.exe 1 4 1 normal
13a8 chrome.exe 1 4 1 normal
05f8 chrome.exe 1 4 1 idle
1360 chrome.exe 1 4 3 normal
0d44 svchost.exe 0 0 0
1278 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
10cc audiodg.exe 0 0 0
0db4 Store.exe 1 203 199 normal C:\Program Files (x86)\Store
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 045f83c8
ebx = 00002e36
ecx = 00000000
edx = 026e2ac8
esi = 045a9d00
edi = 0066c9e4
eip = 0066e902
esp = 0018e334
ebp = 0018e394
stack dump:
0018e334 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018e344 48 e3 18 00 02 e9 66 00 - c8 83 5f 04 36 2e 00 00 H.....f..._.6...
0018e354 00 9d 5a 04 e4 c9 66 00 - 94 e3 18 00 64 e3 18 00 ..Z...f.....d...
0018e364 36 2e 00 00 2a 92 67 00 - 00 9d 5a 04 3c a2 41 0a 6...*.g...Z.<.A.
0018e374 39 ea 67 00 a4 e3 18 00 - eb 8a 40 00 94 e3 18 00 9.g.......@.....
0018e384 e4 c9 66 00 00 9d 5a 04 - 01 9d 5a 04 00 9d 5a 04 ..f...Z...Z...Z.
0018e394 c4 e3 18 00 0d e9 67 00 - 00 9d 5a 04 f6 e4 67 00 ......g...Z...g.
0018e3a4 cc e3 18 00 0c 89 40 00 - c4 e3 18 00 00 9d 5a 04 [email protected].
0018e3b4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e3c4 f4 e3 18 00 ed e6 67 00 - d8 e3 18 00 0c 89 40 00 ......g.......@.
0018e3d4 f4 e3 18 00 00 e4 18 00 - 0c 89 40 00 f4 e3 18 00 ..........@.....
0018e3e4 00 00 00 00 00 00 00 00 - 69 e8 67 01 00 9d 5a 04 ........i.g...Z.
0018e3f4 1c e4 18 00 87 e7 67 00 - a6 4b 67 00 34 e4 18 00 ......g..Kg.4...
0018e404 0c 89 40 00 1c e4 18 00 - 00 9d 5a 04 00 00 00 00 [email protected].....
0018e414 00 00 00 00 00 9d 5a 04 - 48 e4 18 00 4a 91 67 00 ......Z.H...J.g.
0018e424 00 00 00 00 cc 5b 53 00 - 01 00 00 00 77 72 65 00 .....[S.....wre.
0018e434 54 e4 18 00 0c 89 40 00 - 48 e4 18 00 40 d5 53 06 [email protected][email protected].
0018e444 00 9d 5a 04 88 e4 18 00 - be 70 65 00 70 cd 16 01 ..Z......pe.p...
0018e454 a0 e4 18 00 0c 89 40 00 - 88 e4 18 00 00 00 00 00 ......@.........
0018e464 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
0116cd45 push $116ced4
0116cd4a lea eax, [ebp-$20]
0116cd4d mov edx, 3
0116cd52 call -$d625a7 ($40a7b0) ; System.@UStrCatN
0116cd57 mov edx, [ebp-$20]
0116cd5a mov eax, [ebp-8]
0116cd5d mov eax, [eax+$250]
0116cd63 mov ecx, [eax]
0116cd65 call dword ptr [ecx+$38]
0116cd68 463 mov eax, [ebp-8]
0116cd6b > call -$b15cbc ($6570b4) ; Data.DB.TDataSet.Open
0116cd70 464 mov eax, [ebp-8]
0116cd73 cmp byte ptr [eax+$a8], 0
0116cd7a jz loc_116cd9d
0116cd7c mov eax, [ebp-8]
0116cd7f cmp byte ptr [eax+$a9], 0
0116cd86 jz loc_116cd9d
0116cd88 465 mov edx, $116cee8
0116cd8d mov eax, [ebp-4]
0116cd90 mov eax, [eax+$4f4]
0116cd96 call -$c3e843 ($52e558) ; Vcl.Controls.TControl.SetText
[...]
thread $1474:
77caf8da +0e ntdll.dll NtWaitForSingleObject
769d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
756a118f +3e kernel32.dll WaitForSingleObjectEx
756a1143 +0d kernel32.dll WaitForSingleObject
756a3368 +10 kernel32.dll BaseThreadInitThunk
thread $1598:
77cb0166 +0e ntdll.dll NtWaitForMultipleObjects
756a3368 +10 kernel32.dll BaseThreadInitThunk
thread $1368:
77caf8da +0e ntdll.dll NtWaitForSingleObject
769d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
756a118f +3e kernel32.dll WaitForSingleObjectEx
756a1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
756a3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1540) at:
73c84c95 +00 winspool.drv
thread $14e4:
77cb1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
756a3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00390000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
06280000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06320000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71480000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
714a0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
714b0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
714d0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
715d0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71890000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
718e0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71940000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71be0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71e70000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71eb0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71ed0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
721b0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
72200000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72260000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72ab0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72ad0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72b70000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72bb0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72d60000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72d80000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72d90000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72f60000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73090000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
733d0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73c70000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73cd0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
74250000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
745a0000 security.dll 6.1.7600.16385 C:\Windows\
system32
745b0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
745e0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74650000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
746a0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
746d0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74700000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74740000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74760000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74770000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74780000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
747e0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74850000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
749f0000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a00000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75520000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75590000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
755a0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
755b0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75670000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75690000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
757a0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
757b0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
757c0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
758b0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
758c0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75970000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75aa0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75b30000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76780000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76810000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
769b0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
769c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76a10000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76a70000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76cb0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76cc0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76d90000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76e10000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76e40000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76ee0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77030000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77040000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77060000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
770b0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
770c0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
771b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77260000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77360000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77610000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77770000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77780000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
777c0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
77860000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
77880000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77c60000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77c90000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0338 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
009c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0348 svchost.exe 0 0 0
01fc svchost.exe 0 0 0
041c svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0500 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0650 svchost.exe 0 0 0
06d0 armsvc.exe 0 0 0
06e8 atkexComSvc.exe 0 0 0
0728 svchost.exe 0 0 0
074c fbguard.exe 0 0 0
0770 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07ec svchost.exe 0 0 0
04f4 scpbradserv.exe 0 0 0
0724 core.exe 0 0 0
0958 RapportInjService_x64.exe 0 0 0
098c fbserver.exe 0 0 0
0ad0 WUDFHost.exe 0 0 0
0bc0 NisSrv.exe 0 0 0
0cb4 WmiPrvSE.exe 0 0 0
0ce4 OSPPSVC.EXE 0 0 0
0ff4 svchost.exe 0 0 0
014c sppsvc.exe 0 0 0
0710 GoogleCrashHandler.exe 0 0 0
084c GoogleCrashHandler64.exe 0 0 0
097c SearchIndexer.exe 0 0 0
0c3c taskhost.exe 1 26 23 normal
0ea0 core.exe 1 9 22 normal
0e80 PresentationFontCache.exe 0 0 0
0fa0 dwm.exe 1 20 5 high
0cc4 explorer.exe 1 478 322 normal
0614 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0fb0 igfxEM.exe 1 14 13 normal
0e84 igfxHK.exe 1 14 12 normal
0e8c RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0c54 msseces.exe 1 143 59 normal
0c78 PrnStatusMX.exe 1 23 20 normal
1160 RapportInjService_x64.exe 1 4 3 normal
11d0 wuauclt.exe 1 12 7 normal
1244 chrome.exe 1 75 53 normal
0f74 chrome.exe 1 9 4 normal
1258 chrome.exe 1 7 7 above normal
12f4 chrome.exe 1 4 1 normal
13a8 chrome.exe 1 4 1 normal
05f8 chrome.exe 1 4 1 idle
1360 chrome.exe 1 4 3 normal
0d44 svchost.exe 0 0 0
1278 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0db4 Store.exe 1 1724 485 normal C:\Program Files (x86)\Store
1624 splwow64.exe 1 9 3 normal
1798 OIS.EXE 1 119 71 normal
15b4 audiodg.exe 0 0 0
14b8 Store.exe 1 310 172 normal C:\Program Files (x86)\Store
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 064a3830
ebx = 00003303
ecx = 00000000
edx = 026e2ac8
esi = 0018dae8
edi = 0066c9e4
eip = 0066e902
esp = 0018daac
ebp = 0018db14
stack dump:
0018daac 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018dabc c0 da 18 00 02 e9 66 00 - 30 38 4a 06 03 33 00 00 ......f.08J..3..
0018dacc e8 da 18 00 e4 c9 66 00 - 14 db 18 00 dc da 18 00 ......f.........
0018dadc 00 b0 4a 06 0e e9 66 00 - 34 e8 67 00 00 00 00 00 ..J...f.4.g.....
0018daec 00 b0 4a 06 00 00 00 00 - 2f e7 67 00 20 db 18 00 ..J...../.g. ...
0018dafc 0c 89 40 00 14 db 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018db0c 69 e8 67 01 00 b0 4a 06 - 3c db 18 00 87 e7 67 00 i.g...J.<.....g.
0018db1c a6 4b 67 00 54 db 18 00 - 0c 89 40 00 3c db 18 00 .Kg.T.....@.<...
0018db2c 00 b0 4a 06 00 00 00 00 - 00 00 00 00 00 b0 4a 06 ..J...........J.
0018db3c 68 db 18 00 4a 91 67 00 - 00 00 00 00 cc 5b 53 00 h...J.g......[S.
0018db4c 01 00 00 00 77 72 65 00 - 74 db 18 00 0c 89 40 00 ....wre.t.....@.
0018db5c 68 db 18 00 80 b1 3f 0a - 00 b0 4a 06 d8 e0 18 00 h.....?...J.....
0018db6c be 70 65 00 f2 ff f0 00 - e0 e0 18 00 0c 89 40 00 .pe...........@.
0018db7c d8 e0 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dbac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dbbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dbcc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dbdc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00f0ffc1 push $f1121c
00f0ffc6 lea eax, [ebp-$4bc]
00f0ffcc mov edx, 3
00f0ffd1 call -$b05826 ($40a7b0) ; System.@UStrCatN
00f0ffd6 mov edx, [ebp-$4bc]
00f0ffdc mov eax, [ebp-$34]
00f0ffdf mov eax, [eax+$250]
00f0ffe5 mov ecx, [eax]
00f0ffe7 call dword ptr [ecx+$38]
00f0ffea 4108 mov eax, [ebp-$34]
00f0ffed > call -$8b8f3e ($6570b4) ; Data.DB.TDataSet.Open
00f0fff2 4110 mov eax, [$160cdb0]
00f0fff7 mov eax, [eax]
00f0fff9 mov eax, [eax+$1710]
00f0ffff cmp byte ptr [eax+$a9], 0
00f10006 jz loc_f105c2
00f1000c mov eax, [$160cdb0]
00f10011 mov eax, [eax]
00f10013 mov eax, [eax+$1710]
00f10019 cmp byte ptr [eax+$a8], 0
00f10020 jz loc_f105c2
[...]
thread $1474:
77caf8da +0e ntdll.dll NtWaitForSingleObject
769d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
756a118f +3e kernel32.dll WaitForSingleObjectEx
756a1143 +0d kernel32.dll WaitForSingleObject
756a3368 +10 kernel32.dll BaseThreadInitThunk
thread $1598:
77cb0166 +0e ntdll.dll NtWaitForMultipleObjects
756a3368 +10 kernel32.dll BaseThreadInitThunk
thread $1368:
77caf8da +0e ntdll.dll NtWaitForSingleObject
769d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
756a118f +3e kernel32.dll WaitForSingleObjectEx
756a1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
756a3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1540) at:
73c84c95 +00 winspool.drv
thread $14e4:
77cb1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
756a3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00390000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
06280000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06320000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71480000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
714a0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
714b0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
714d0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
715d0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71890000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
718e0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71940000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71be0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71e70000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71eb0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71ed0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
721b0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
72200000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72260000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72ab0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72ad0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72b70000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72bb0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72d60000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72d80000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72d90000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72f60000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73090000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
733d0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73c70000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73cd0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
74250000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
745a0000 security.dll 6.1.7600.16385 C:\Windows\
system32
745b0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
745e0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74650000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
746a0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
746d0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74700000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74740000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74760000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74770000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74780000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
747e0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74850000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
749f0000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a00000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75520000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75590000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
755a0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
755b0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75670000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75690000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
757a0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
757b0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
757c0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
758b0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
758c0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75970000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75aa0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75b30000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76780000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76810000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
769b0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
769c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76a10000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76a70000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76cb0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76cc0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76d90000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76e10000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76e40000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76ee0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77030000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77040000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77060000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
770b0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
770c0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
771b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77260000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77360000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77610000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77770000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77780000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
777c0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
77860000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
77880000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77c60000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77c90000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0338 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
009c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0348 svchost.exe 0 0 0
01fc svchost.exe 0 0 0
041c svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0500 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0650 svchost.exe 0 0 0
06d0 armsvc.exe 0 0 0
06e8 atkexComSvc.exe 0 0 0
0728 svchost.exe 0 0 0
074c fbguard.exe 0 0 0
0770 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07ec svchost.exe 0 0 0
04f4 scpbradserv.exe 0 0 0
0724 core.exe 0 0 0
0958 RapportInjService_x64.exe 0 0 0
098c fbserver.exe 0 0 0
0ad0 WUDFHost.exe 0 0 0
0bc0 NisSrv.exe 0 0 0
0cb4 WmiPrvSE.exe 0 0 0
0ce4 OSPPSVC.EXE 0 0 0
0ff4 svchost.exe 0 0 0
014c sppsvc.exe 0 0 0
0710 GoogleCrashHandler.exe 0 0 0
084c GoogleCrashHandler64.exe 0 0 0
097c SearchIndexer.exe 0 0 0
0c3c taskhost.exe 1 26 23 normal
0ea0 core.exe 1 9 22 normal
0e80 PresentationFontCache.exe 0 0 0
0fa0 dwm.exe 1 20 5 high
0cc4 explorer.exe 1 478 324 normal
0614 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0fb0 igfxEM.exe 1 14 13 normal
0e84 igfxHK.exe 1 14 12 normal
0e8c RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0c54 msseces.exe 1 143 59 normal
0c78 PrnStatusMX.exe 1 23 20 normal
1160 RapportInjService_x64.exe 1 4 3 normal
11d0 wuauclt.exe 1 12 7 normal
1244 chrome.exe 1 75 52 normal
0f74 chrome.exe 1 9 4 normal
1258 chrome.exe 1 7 7 above normal
12f4 chrome.exe 1 4 1 normal
13a8 chrome.exe 1 4 1 normal
05f8 chrome.exe 1 4 1 idle
1360 chrome.exe 1 4 3 normal
0d44 svchost.exe 0 0 0
1278 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0db4 Store.exe 1 1723 486 normal C:\Program Files (x86)\Store
1624 splwow64.exe 1 9 3 normal
1798 OIS.EXE 1 119 71 normal
15b4 audiodg.exe 0 0 0
14b8 Store.exe 1 310 172 normal C:\Program Files (x86)\Store
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 064a3830
ebx = 00003303
ecx = 00000000
edx = 026e2ac8
esi = 0018dec8
edi = 0066c9e4
eip = 0066e902
esp = 0018de8c
ebp = 0018def4
stack dump:
0018de8c 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018de9c a0 de 18 00 02 e9 66 00 - 30 38 4a 06 03 33 00 00 ......f.08J..3..
0018deac c8 de 18 00 e4 c9 66 00 - f4 de 18 00 bc de 18 00 ......f.........
0018debc 00 b0 4a 06 0e e9 66 00 - 34 e8 67 00 00 00 00 00 ..J...f.4.g.....
0018decc 00 b0 4a 06 00 00 00 00 - 2f e7 67 00 00 df 18 00 ..J...../.g.....
0018dedc 0c 89 40 00 f4 de 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018deec 69 e8 67 01 00 b0 4a 06 - 1c df 18 00 87 e7 67 00 i.g...J.......g.
0018defc a6 4b 67 00 34 df 18 00 - 0c 89 40 00 1c df 18 00 .Kg.4.....@.....
0018df0c 00 b0 4a 06 00 00 00 00 - 00 00 00 00 00 b0 4a 06 ..J...........J.
0018df1c 48 df 18 00 4a 91 67 00 - 00 00 00 00 cc 5b 53 00 H...J.g......[S.
0018df2c 01 00 00 00 77 72 65 00 - 54 df 18 00 0c 89 40 00 ....wre.T.....@.
0018df3c 48 df 18 00 80 b1 3f 0a - 00 b0 4a 06 b8 e4 18 00 H.....?...J.....
0018df4c be 70 65 00 f2 ff f0 00 - c0 e4 18 00 0c 89 40 00 .pe...........@.
0018df5c b8 e4 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018df6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018df7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018df8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018df9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dfac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dfbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00f0ffc1 push $f1121c
00f0ffc6 lea eax, [ebp-$4bc]
00f0ffcc mov edx, 3
00f0ffd1 call -$b05826 ($40a7b0) ; System.@UStrCatN
00f0ffd6 mov edx, [ebp-$4bc]
00f0ffdc mov eax, [ebp-$34]
00f0ffdf mov eax, [eax+$250]
00f0ffe5 mov ecx, [eax]
00f0ffe7 call dword ptr [ecx+$38]
00f0ffea 4108 mov eax, [ebp-$34]
00f0ffed > call -$8b8f3e ($6570b4) ; Data.DB.TDataSet.Open
00f0fff2 4110 mov eax, [$160cdb0]
00f0fff7 mov eax, [eax]
00f0fff9 mov eax, [eax+$1710]
00f0ffff cmp byte ptr [eax+$a9], 0
00f10006 jz loc_f105c2
00f1000c mov eax, [$160cdb0]
00f10011 mov eax, [eax]
00f10013 mov eax, [eax+$1710]
00f10019 cmp byte ptr [eax+$a8], 0
00f10020 jz loc_f105c2
[...]
thread $fb4:
77c2f8da +0e ntdll.dll NtWaitForSingleObject
775715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
759c118f +3e kernel32.dll WaitForSingleObjectEx
759c1143 +0d kernel32.dll WaitForSingleObject
759c3368 +10 kernel32.dll BaseThreadInitThunk
thread $fd8:
77c30166 +0e ntdll.dll NtWaitForMultipleObjects
759c3368 +10 kernel32.dll BaseThreadInitThunk
thread $148c:
77c2f8da +0e ntdll.dll NtWaitForSingleObject
775715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
759c118f +3e kernel32.dll WaitForSingleObjectEx
759c1143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
759c3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1474) at:
73754c95 +00 winspool.drv
thread $17a0:
77c31f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
759c3368 +10 kernel32.dll BaseThreadInitThunk
thread $fe0:
77c31f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
759c3368 +10 kernel32.dll BaseThreadInitThunk
thread $14ac:
77c31f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
759c3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002e0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
047c0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06310000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71080000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
710f0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71450000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
718c0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71910000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
719b0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
719d0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71d00000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71e90000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71ee0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71f40000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72a30000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72a50000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72af0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72b30000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72ce0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72d00000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72d10000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73110000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73210000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
733f0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
736e0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73740000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73bf0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73ca0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73dc0000 security.dll 6.1.7600.16385 C:\Windows\
system32
74190000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
741b0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
741c0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
741e0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
741f0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
745d0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74620000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74650000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74680000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
746c0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
746e0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
746f0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74700000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74760000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
747d0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74970000 version.dll 6.1.7600.16385 C:\Windows\
system32
74980000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
754a0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
754b0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75510000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75550000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75560000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75570000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75590000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
755c0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75670000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75680000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75930000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75950000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
759b0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75ac0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75b60000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75c90000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75d80000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75f20000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75fc0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76200000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76210000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76280000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
762a0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76400000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76460000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
770e0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
771b0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
771c0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
771d0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77200000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77210000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
772a0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
772c0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
772d0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77380000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77560000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
775b0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77640000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
776c0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
777c0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77be0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77c10000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
00a4 RapportMgmtService.exe 0 0 0
02b0 svchost.exe 0 0 0
036c svchost.exe 0 0 0
0408 svchost.exe 0 0 0
042c svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0514 igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0650 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0790 NetExpressUpdater.exe 0 0 0
0434 svchost.exe 0 0 0
057c scpbradserv.exe 0 0 0
0700 svchost.exe 0 0 0
0814 core.exe 0 0 0
0948 RapportInjService_x64.exe 0 0 0
09f4 fbserver.exe 0 0 0
0b60 WUDFHost.exe 0 0 0
05e4 WmiPrvSE.exe 0 0 0
0964 OSPPSVC.EXE 0 0 0
0ba8 taskhost.exe 1 26 24 normal
0c2c core.exe 1 9 21 normal
0c50 NisSrv.exe 0 0 0
0ccc sppsvc.exe 0 0 0
0e14 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0200 RapportInjService_x64.exe 1 4 3 normal
0fec GoogleCrashHandler.exe 0 0 0
0bf4 GoogleCrashHandler64.exe 0 0 0
0dc8 svchost.exe 0 0 0
0ee0 PresentationFontCache.exe 0 0 0
0db4 dwm.exe 1 17 4 high
00d8 explorer.exe 1 482 259 normal
1024 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
10a8 igfxEM.exe 1 14 14 normal
10b8 igfxHK.exe 1 14 12 normal
113c msseces.exe 1 143 60 normal
114c PrnStatusMX.exe 1 23 20 normal
13c4 SearchIndexer.exe 0 0 0
0394 wuauclt.exe 1 12 6 normal
0ec0 chrome.exe 1 152 79 normal
130c chrome.exe 1 9 4 normal
1364 chrome.exe 1 11 7 above normal
11d0 chrome.exe 1 4 1 normal
0c90 chrome.exe 1 4 1 idle
1318 chrome.exe 1 4 3 normal
15dc chrome.exe 1 4 1 idle
1744 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
12ac Store.exe 1 2343 559 normal C:\Program Files (x86)\Store
0fa8 splwow64.exe 1 9 5 normal
05c4 OIS.EXE 1 142 112 normal
0460 EXCEL.EXE 1 321 99 normal
0160 audiodg.exe 0 0 0
0660 rundll32.exe 1 116 53 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 0a1af000
ecx = 04533190
edx = 0452e670
esi = 00593a80
edi = 0018de5c
eip = 006ff5b1
esp = 0018dce0
ebp = 0018dcec
stack dump:
0018dce0 00 f0 1a 0a 00 f0 1a 0a - 90 36 50 06 50 de 18 00 .........6P.P...
0018dcf0 81 03 53 00 00 f0 1a 0a - 85 3a 59 00 2a 08 53 00 ..S......:Y.*.S.
0018dd00 10 00 07 00 10 00 00 00 - 07 00 00 00 00 00 00 00 ................
0018dd10 00 00 00 00 21 00 00 00 - 16 00 00 00 10 00 07 00 ....!...........
0018dd20 00 f0 1a 0a 5c de 18 00 - 28 fe 52 00 10 00 07 00 ....\...(.R.....
0018dd30 58 df 18 00 00 f0 1a 0a - 00 f0 1a 0a c9 01 00 00 X...............
0018dd40 07 00 00 00 00 00 00 00 - c4 dd 18 00 1f b0 a5 72 ...............r
0018dd50 50 7f 9d 0a 64 06 10 00 - 02 02 00 00 0f 00 00 00 P...d...........
0018dd60 c9 01 07 00 00 00 00 00 - bb 80 a5 72 8e 81 a5 72 ...........r...r
0018dd70 10 2a 53 04 c9 01 07 00 - 64 06 10 00 00 00 00 00 .*S.....d.......
0018dd80 10 2a 53 04 58 47 83 04 - 07 00 00 00 1c 00 00 00 .*S.XG..........
0018dd90 50 e0 5c 04 94 de 18 00 - 00 00 00 00 00 00 00 00 P.\.............
0018dda0 bb 80 a5 72 01 00 00 00 - 40 de 18 00 00 00 00 00 ...r....@.......
0018ddb0 00 00 00 00 c4 dd 18 00 - 07 00 00 00 00 00 00 00 ................
0018ddc0 fc c7 b7 a0 f0 dd 18 00 - fa 62 6d 77 64 06 10 00 .........bmwd...
0018ddd0 02 02 00 00 00 00 00 00 - c9 01 07 00 bb 80 a5 72 ...............r
0018dde0 cd ab ba dc 00 00 00 00 - 00 00 00 00 08 de 18 00 ................
0018ddf0 63 fa 52 00 00 f0 1a 0a - 0a b0 00 00 00 00 00 00 c.R.............
0018de00 10 00 07 00 01 00 00 00 - 3c de 18 00 d5 3e 53 00 ........<....>S.
0018de10 10 00 07 00 10 2a 53 04 - 00 00 00 00 00 00 00 00 .....*S.........
disassembling:
[...]
006ff58a test al, al
006ff58c jnz loc_6ff59e
006ff58e 402 mov eax, [ebp-4]
006ff591 mov eax, [eax+$460]
006ff597 call +$eb20 ($70e0bc) ; QRPrntr.TQRPrinter.Print
006ff59c jmp loc_6ff5d3
006ff59e 405 mov eax, [$16148d8]
006ff5a3 call -$84ac ($6f70fc) ; QuickRpt.TCustomQuickRep.Print
006ff5a8 407 mov eax, [ebp-4]
006ff5ab mov eax, [eax+$3cc]
006ff5b1 > cmp dword ptr [eax+$2b8], 0
006ff5b8 jnz loc_6ff5d3
006ff5ba 409 mov eax, [$16148d8]
006ff5bf mov edx, [eax+$36c]
006ff5c5 mov eax, [ebp-4]
006ff5c8 mov eax, [eax+$3cc]
006ff5ce call +$a6f5 ($709cc8) ; QRPrntr.TQRPreview.SetQRPrinter
006ff5d3 412 pop ebx
006ff5d4 pop ecx
006ff5d5 pop ecx
006ff5d6 pop ebp
[...]
thread $1050:
779cf8da +0e ntdll.dll NtWaitForSingleObject
771d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76a0118f +3e kernel32.dll WaitForSingleObjectEx
76a01143 +0d kernel32.dll WaitForSingleObject
76a03368 +10 kernel32.dll BaseThreadInitThunk
thread $1054:
779d0166 +0e ntdll.dll NtWaitForMultipleObjects
76a03368 +10 kernel32.dll BaseThreadInitThunk
thread $1038:
779d0166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
76a03368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1044) at:
73c42713 +24f netbios.dll Netbios
thread $1090:
779cf8da +0e ntdll.dll NtWaitForSingleObject
771d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76a0118f +3e kernel32.dll WaitForSingleObjectEx
76a01143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
76a03368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1044) at:
73534c95 +00 winspool.drv
thread $11fc:
779d1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76a03368 +10 kernel32.dll BaseThreadInitThunk
thread $878:
779d1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76a03368 +10 kernel32.dll BaseThreadInitThunk
thread $14e4:
779d1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76a03368 +10 kernel32.dll BaseThreadInitThunk
modules:
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02670000 WINPPLA.DLL C:\Program
Files (x86)\Store
026b0000 BCLW32.dll C:\Program
Files (x86)\Store
06290000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063a0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
09720000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
712e0000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
71350000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
71450000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71490000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
714f0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71700000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71aa0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71c30000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c80000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71ce0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
727d0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
727f0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72890000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
728d0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72a80000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72aa0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72ab0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72ed0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
72f00000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73090000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73390000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
733c0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73420000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73520000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73a70000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73ae0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73af0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73c40000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73c50000 security.dll 6.1.7600.16385 C:\Windows\
system32
73c60000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73c70000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73c80000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73ca0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73cb0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
74370000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
743c0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
743f0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74420000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74460000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74480000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74490000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
744a0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74500000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74570000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74710000 version.dll 6.1.7600.16385 C:\Windows\
system32
74720000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75240000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75250000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
752b0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
752d0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75330000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75380000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75390000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75450000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
760a0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
760b0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
760c0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
761f0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76210000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76280000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76300000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
763d0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
763f0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76490000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
765f0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76600000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76610000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76850000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76940000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
769f0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76b00000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76c00000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76c10000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76cc0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76cd0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76ce0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76d70000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76e00000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76e10000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76e70000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76f10000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
771c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77210000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77360000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77370000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
77410000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77980000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
779b0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0344 svchost.exe 0 0 0
01a0 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0578 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0674 svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0764 fbguard.exe 0 0 0
0784 svchost.exe 0 0 0
079c NetExpressUpdater.exe 0 0 0
046c svchost.exe 0 0 0
05c0 scpbradserv.exe 0 0 0
06b4 svchost.exe 0 0 0
0808 core.exe 0 0 0
0950 RapportInjService_x64.exe 0 0 0
0a10 fbserver.exe 0 0 0
0ad8 taskhost.exe 1 26 23 normal
0af8 core.exe 1 9 21 normal
0af0 sppsvc.exe 0 0 0
0cac WUDFHost.exe 0 0 0
0dfc RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0ef4 NisSrv.exe 0 0 0
0f90 PresentationFontCache.exe 0 0 0
0f98 dwm.exe 1 17 4 high
0fa8 explorer.exe 1 683 456 normal
0d78 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0e78 igfxEM.exe 1 14 14 normal
0e8c igfxHK.exe 1 14 13 normal
0f64 msseces.exe 1 143 59 normal
0d7c RapportInjService_x64.exe 1 4 3 normal
0d30 PrnStatusMX.exe 1 23 20 normal
101c GoogleCrashHandler.exe 0 0 0
1030 GoogleCrashHandler64.exe 0 0 0
1108 SearchIndexer.exe 0 0 0
127c svchost.exe 0 0 0
1040 Store.exe 1 3810 683 normal C:\Program Files (x86)\Store
0d24 WmiPrvSE.exe 0 0 0
1360 OSPPSVC.EXE 0 0 0
0fb8 wuauclt.exe 1 12 5 normal
0660 splwow64.exe 1 9 4 normal
0b60 chrome.exe 1 76 53 normal
0af4 chrome.exe 1 9 4 normal
0684 chrome.exe 1 12 7 above normal
0c34 chrome.exe 1 4 1 normal
0fec slui.exe 1 43 31 normal
03e0 chrome.exe 1 4 1 normal
1114 chrome.exe 1 4 3 normal
12ac DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1444 OIS.EXE 1 106 47 normal
174c OIS.EXE 1 102 44 normal
10d0 chrome.exe 1 4 1 idle
16fc chrome.exe 1 4 1 idle
16a0 chrome.exe 1 4 1 idle
1338 chrome.exe 1 4 1 idle
16a8 chrome.exe 1 4 1 idle
0824 chrome.exe 1 4 1 idle
1588 chrome.exe 1 4 1 idle
1320 chrome.exe 1 4 1 idle
13c0 EXCEL.EXE 1 414 116 normal
121c audiodg.exe 0 0 0
01e0 rundll32.exe 1 116 53 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 0a317800
ecx = 04430290
edx = 0442e470
esi = 00593a80
edi = 0018de5c
eip = 006ff5b1
esp = 0018dce0
ebp = 0018dcec
stack dump:
0018dce0 00 78 31 0a 00 78 31 0a - 30 fe 82 06 50 de 18 00 .x1..x1.0...P...
0018dcf0 81 03 53 00 00 78 31 0a - 85 3a 59 00 2a 08 53 00 ..S..x1..:Y.*.S.
0018dd00 14 00 08 00 14 00 00 00 - 08 00 00 00 00 00 00 00 ................
0018dd10 00 00 00 00 21 00 00 00 - 16 00 00 00 14 00 08 00 ....!...........
0018dd20 00 78 31 0a 5c de 18 00 - 28 fe 52 00 14 00 08 00 .x1.\...(.R.....
0018dd30 58 df 18 00 00 78 31 0a - 00 78 31 0a cd 01 00 00 X....x1..x1.....
0018dd40 08 00 00 00 00 00 00 00 - c4 dd 18 00 1f b0 7f 72 ...............r
0018dd50 28 db 35 00 5e 07 0a 00 - 02 02 00 00 0f 00 00 00 (.5.^...........
0018dd60 cd 01 08 00 00 00 00 00 - bb 80 7f 72 8e 81 7f 72 ...........r...r
0018dd70 00 00 00 00 cd 01 08 00 - 5e 07 0a 00 00 00 00 00 ........^.......
0018dd80 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd90 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dda0 bb 80 7f 72 01 00 00 00 - 40 de 18 00 00 00 00 00 ...r....@.......
0018ddb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ddc0 74 b0 3c fc f0 dd 18 00 - fa 62 b1 76 5e 07 0a 00 t.<......b.v^...
0018ddd0 02 02 00 00 00 00 00 00 - cd 01 08 00 bb 80 7f 72 ...............r
0018dde0 cd ab ba dc 00 00 00 00 - 00 00 00 00 08 de 18 00 ................
0018ddf0 63 fa 52 00 00 78 31 0a - 0a b0 00 00 00 00 00 00 c.R..x1.........
0018de00 14 00 08 00 01 00 00 00 - 3c de 18 00 d5 3e 53 00 ........<....>S.
0018de10 14 00 08 00 90 2f 43 04 - 00 00 00 00 00 00 00 00 ...../C.........
disassembling:
[...]
006ff58a test al, al
006ff58c jnz loc_6ff59e
006ff58e 402 mov eax, [ebp-4]
006ff591 mov eax, [eax+$460]
006ff597 call +$eb20 ($70e0bc) ; QRPrntr.TQRPrinter.Print
006ff59c jmp loc_6ff5d3
006ff59e 405 mov eax, [$16148d8]
006ff5a3 call -$84ac ($6f70fc) ; QuickRpt.TCustomQuickRep.Print
006ff5a8 407 mov eax, [ebp-4]
006ff5ab mov eax, [eax+$3cc]
006ff5b1 > cmp dword ptr [eax+$2b8], 0
006ff5b8 jnz loc_6ff5d3
006ff5ba 409 mov eax, [$16148d8]
006ff5bf mov edx, [eax+$36c]
006ff5c5 mov eax, [ebp-4]
006ff5c8 mov eax, [eax+$3cc]
006ff5ce call +$a6f5 ($709cc8) ; QRPrntr.TQRPreview.SetQRPrinter
006ff5d3 412 pop ebx
006ff5d4 pop ecx
006ff5d5 pop ecx
006ff5d6 pop ebp
[...]
thread $1050:
779cf8da +0e ntdll.dll NtWaitForSingleObject
771d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76a0118f +3e kernel32.dll WaitForSingleObjectEx
76a01143 +0d kernel32.dll WaitForSingleObject
76a03368 +10 kernel32.dll BaseThreadInitThunk
thread $1054:
779d0166 +0e ntdll.dll NtWaitForMultipleObjects
76a03368 +10 kernel32.dll BaseThreadInitThunk
thread $1038:
779d0166 +00e ntdll.dll NtWaitForMultipleObjects
004d787d +00d Store.exe madExcept CallThreadProcSafe
004d78e7 +037 Store.exe madExcept ThreadExceptFrame
76a03368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1044) at:
73c42713 +24f netbios.dll Netbios
thread $1090:
779cf8da +0e ntdll.dll NtWaitForSingleObject
771d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76a0118f +3e kernel32.dll WaitForSingleObjectEx
76a01143 +0d kernel32.dll WaitForSingleObject
004d787d +0d Store.exe madExcept CallThreadProcSafe
004d78e7 +37 Store.exe madExcept ThreadExceptFrame
76a03368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1044) at:
73534c95 +00 winspool.drv
thread $14e4:
779d1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76a03368 +10 kernel32.dll BaseThreadInitThunk
modules:
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02670000 WINPPLA.DLL C:\Program
Files (x86)\Store
026b0000 BCLW32.dll C:\Program
Files (x86)\Store
06290000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063a0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
09720000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
712e0000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
71350000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
71450000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71490000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
714f0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71700000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71aa0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71c30000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c80000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71ce0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
727d0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
727f0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72890000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
728d0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72a80000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72aa0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72ab0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72ed0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
72f00000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73090000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73390000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
733c0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73420000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73520000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73a70000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73ae0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73af0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73c40000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73c50000 security.dll 6.1.7600.16385 C:\Windows\
system32
73c60000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73c70000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73c80000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73ca0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73cb0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
74370000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
743c0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
743f0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74420000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74460000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74480000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74490000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
744a0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74500000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74570000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74710000 version.dll 6.1.7600.16385 C:\Windows\
system32
74720000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75240000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75250000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
752b0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
752d0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75330000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75380000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75390000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75450000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
760a0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
760b0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
760c0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
761f0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76210000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76280000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76300000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
763d0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
763f0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76480000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76490000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
765f0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76600000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76610000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76850000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76940000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
769f0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76b00000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76c00000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76c10000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76cc0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76cd0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76ce0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76d70000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76e00000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76e10000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76e70000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76f10000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
771c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77210000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77360000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77370000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
77410000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77980000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
779b0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0344 svchost.exe 0 0 0
01a0 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0578 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0674 svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0764 fbguard.exe 0 0 0
0784 svchost.exe 0 0 0
079c NetExpressUpdater.exe 0 0 0
046c svchost.exe 0 0 0
05c0 scpbradserv.exe 0 0 0
06b4 svchost.exe 0 0 0
0808 core.exe 0 0 0
0950 RapportInjService_x64.exe 0 0 0
0a10 fbserver.exe 0 0 0
0ad8 taskhost.exe 1 26 23 normal
0af8 core.exe 1 9 21 normal
0af0 sppsvc.exe 0 0 0
0cac WUDFHost.exe 0 0 0
0dfc RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0ef4 NisSrv.exe 0 0 0
0f90 PresentationFontCache.exe 0 0 0
0f98 dwm.exe 1 17 4 high
0fa8 explorer.exe 1 659 451 normal
0d78 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0e78 igfxEM.exe 1 14 14 normal
0e8c igfxHK.exe 1 14 13 normal
0f64 msseces.exe 1 143 59 normal
0d7c RapportInjService_x64.exe 1 4 3 normal
0d30 PrnStatusMX.exe 1 23 20 normal
101c GoogleCrashHandler.exe 0 0 0
1030 GoogleCrashHandler64.exe 0 0 0
1108 SearchIndexer.exe 0 0 0
127c svchost.exe 0 0 0
1040 Store.exe 1 3882 836 normal C:\Program Files (x86)\Store
0d24 WmiPrvSE.exe 0 0 0
1360 OSPPSVC.EXE 0 0 0
0fb8 wuauclt.exe 1 12 5 normal
0660 splwow64.exe 1 9 3 normal
0b60 chrome.exe 1 76 55 normal
0af4 chrome.exe 1 9 4 normal
0684 chrome.exe 1 12 7 above normal
0c34 chrome.exe 1 4 1 normal
0fec slui.exe 1 43 31 normal
03e0 chrome.exe 1 4 1 normal
1114 chrome.exe 1 4 3 normal
12ac DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1444 OIS.EXE 1 106 47 normal
174c OIS.EXE 1 102 44 normal
10d0 chrome.exe 1 4 1 idle
16fc chrome.exe 1 4 1 idle
16a0 chrome.exe 1 4 1 idle
1338 chrome.exe 1 4 1 idle
16a8 chrome.exe 1 4 1 idle
0824 chrome.exe 1 4 1 idle
1588 chrome.exe 1 4 1 idle
1320 chrome.exe 1 4 1 idle
13c0 EXCEL.EXE 1 414 116 normal
121c audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0af784c0
ebx = 00003303
ecx = 00000000
edx = 00262ac8
esi = 0018d170
edi = 0066c9e4
eip = 0066e902
esp = 0018d134
ebp = 0018d19c
stack dump:
0018d134 02 e9 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018d144 48 d1 18 00 02 e9 66 00 - c0 84 f7 0a 03 33 00 00 H.....f......3..
0018d154 70 d1 18 00 e4 c9 66 00 - 9c d1 18 00 64 d1 18 00 p.....f.....d...
0018d164 20 d2 48 06 0e e9 66 00 - 34 e8 67 00 00 00 00 00 .H...f.4.g.....
0018d174 20 d2 48 06 00 00 00 00 - 2f e7 67 00 a8 d1 18 00 .H...../.g.....
0018d184 0c 89 40 00 9c d1 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018d194 69 e8 67 01 20 d2 48 06 - c4 d1 18 00 87 e7 67 00 i.g. .H.......g.
0018d1a4 a6 4b 67 00 dc d1 18 00 - 0c 89 40 00 c4 d1 18 00 .Kg.......@.....
0018d1b4 20 d2 48 06 00 00 00 00 - 00 00 00 00 20 d2 48 06 .H......... .H.
0018d1c4 f0 d1 18 00 4a 91 67 00 - b4 d7 18 00 f0 12 3a 0a ....J.g.......:.
0018d1d4 01 00 00 00 77 72 65 00 - fc d1 18 00 0c 89 40 00 ....wre.......@.
0018d1e4 f0 d1 18 00 f0 12 3a 0a - 20 d2 48 06 c0 d2 18 00 ......:. .H.....
0018d1f4 be 70 65 00 88 ba 16 01 - c8 d2 18 00 0c 89 40 00 .pe...........@.
0018d204 c0 d2 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d214 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d224 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d234 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d244 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d254 00 00 00 00 00 00 00 00 - 00 80 e5 40 a0 b9 41 06 [email protected].
0018d264 00 00 00 00 fa a4 4f fa - 1f 80 e5 40 00 00 00 00 ......O....@....
disassembling:
[...]
0116ba5f mov eax, [ebp-$18]
0116ba62 mov eax, [eax+$250]
0116ba68 mov ecx, [eax]
0116ba6a call dword ptr [ecx+$38]
0116ba6d 425 mov edx, $116cac0
0116ba72 mov eax, [ebp-$18]
0116ba75 mov eax, [eax+$250]
0116ba7b mov ecx, [eax]
0116ba7d call dword ptr [ecx+$38]
0116ba80 427 mov eax, [ebp-$18]
0116ba83 > call -$b149d4 ($6570b4) ; Data.DB.TDataSet.Open
0116ba88 428 mov eax, [ebp-$18]
0116ba8b call -$b12114 ($65997c) ; Data.DB.TDataSet.First
0116ba90 429 mov eax, [ebp-$18]
0116ba93 cmp byte ptr [eax+$a9], 0
0116ba9a jz loc_116baa8
0116ba9c mov eax, [ebp-$18]
0116ba9f cmp byte ptr [eax+$a8], 0
0116baa6 jnz loc_116bab7
0116baa8 431 mov eax, [ebp-4]
0116baab call +$32fe8 ($119ea98) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $a50:
7740f8da +0e ntdll.dll NtWaitForSingleObject
74dd15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76ef118f +3e kernel32.dll WaitForSingleObjectEx
76ef1143 +0d kernel32.dll WaitForSingleObject
76ef3368 +10 kernel32.dll BaseThreadInitThunk
thread $53c:
77410166 +0e ntdll.dll NtWaitForMultipleObjects
76ef3368 +10 kernel32.dll BaseThreadInitThunk
thread $57c:
77410166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
76ef3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d64) at:
72e82713 +24f netbios.dll Netbios
thread $10c4:
7740f8da +0e ntdll.dll NtWaitForSingleObject
74dd15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76ef118f +3e kernel32.dll WaitForSingleObjectEx
76ef1143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
76ef3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d64) at:
73004c95 +00 winspool.drv
thread $1574:
77411f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76ef3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003a0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
06290000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063a0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70ab0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
70b30000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
70ba0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
70cf0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70d00000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70d20000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70fb0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70fd0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71040000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
710a0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
712f0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71390000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
714b0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
714c0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71910000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71960000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
719c0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72210000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72230000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
722d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72310000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
724c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
724e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
724f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72700000 slc.dll 6.1.7600.16385 C:\Windows\
system32
72e50000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72e80000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
72e90000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
72ef0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72ff0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73140000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73670000 security.dll 6.1.7600.16385 C:\Windows\
system32
73690000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73890000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
738b0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73db0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73e00000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73e30000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73e60000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73ea0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73ec0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73ed0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73ee0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73f40000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73fb0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74150000 version.dll 6.1.7600.16385 C:\Windows\
system32
74160000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74c80000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74c90000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74cf0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
74dc0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74e10000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75a60000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75b50000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75c50000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75c60000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75f10000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75f20000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75f50000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75f70000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f80000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76030000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
760c0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
760d0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76140000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76210000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76220000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76460000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76480000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
765e0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76640000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76710000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76720000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76750000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
767b0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
767c0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76910000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
769a0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76ad0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76ae0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76c80000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76d30000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76dd0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76de0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76e00000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e10000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76e90000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76ee0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
773c0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
773f0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
00a0 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
036c svchost.exe 0 0 0
040c svchost.exe 0 0 0
0438 svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0514 igfxCUIService.exe 0 0 0
055c svchost.exe 0 0 0
0618 spoolsv.exe 0 0 0
0624 taskeng.exe 0 0 0
0648 svchost.exe 0 0 0
06cc armsvc.exe 0 0 0
06e4 atkexComSvc.exe 0 0 0
0728 svchost.exe 0 0 0
074c fbguard.exe 0 0 0
0770 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f0 svchost.exe 0 0 0
0500 scpbradserv.exe 0 0 0
06a8 svchost.exe 0 0 0
07d8 core.exe 0 0 0
096c RapportInjService_x64.exe 0 0 0
09e8 fbserver.exe 0 0 0
0b48 WUDFHost.exe 0 0 0
097c NisSrv.exe 0 0 0
0e74 WmiPrvSE.exe 0 0 0
0ea0 OSPPSVC.EXE 0 0 0
0e44 taskhost.exe 1 26 23 normal
0e6c core.exe 1 9 20 normal
0f5c GoogleCrashHandler.exe 0 0 0
0fb4 GoogleCrashHandler64.exe 0 0 0
0fc0 sppsvc.exe 0 0 0
0c70 svchost.exe 0 0 0
0c58 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
02f8 RapportInjService_x64.exe 1 4 3 normal
09d0 dwm.exe 1 17 4 high
0e34 PresentationFontCache.exe 0 0 0
020c explorer.exe 1 409 241 normal
0fc8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0830 igfxEM.exe 1 14 14 normal
067c igfxHK.exe 1 14 12 normal
0bb0 msseces.exe 1 143 59 normal
0e64 PrnStatusMX.exe 1 23 20 normal
11c8 SearchIndexer.exe 0 0 0
1308 wuauclt.exe 1 12 7 normal
11ac chrome.exe 1 73 49 normal
0e20 chrome.exe 1 9 4 normal
12a0 chrome.exe 1 8 6 above normal
13d8 chrome.exe 1 4 1 normal
0204 chrome.exe 1 4 1 normal
0344 chrome.exe 1 4 1 idle
1100 chrome.exe 1 4 3 normal
11b0 Store.exe 1 437 245 normal C:\Program Files (x86)\Store
139c slui.exe 1 43 31 normal
1168 splwow64.exe 1 9 3 normal
14ac RdrCEF.exe 1 9 20 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
1234 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
0654 audiodg.exe 0 0 0
1638 SearchProtocolHost.exe 0 0 0
1470 SearchFilterHost.exe 0 0 0 idle
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0ace19d8
ebx = 00003303
ecx = 00000000
edx = 026f2ac8
esi = 0018ea1c
edi = 0066c7e4
eip = 0066e702
esp = 0018e9e0
ebp = 0018ea48
stack dump:
0018e9e0 02 e7 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018e9f0 f4 e9 18 00 02 e7 66 00 - d8 19 ce 0a 03 33 00 00 ......f......3..
0018ea00 1c ea 18 00 e4 c7 66 00 - 48 ea 18 00 10 ea 18 00 ......f.H.......
0018ea10 50 50 51 06 0e e7 66 00 - 34 e6 67 00 00 00 00 00 PPQ...f.4.g.....
0018ea20 50 50 51 06 00 00 00 00 - 2f e5 67 00 54 ea 18 00 PPQ...../.g.T...
0018ea30 0c 89 40 00 48 ea 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018ea40 69 e6 67 01 50 50 51 06 - 70 ea 18 00 87 e5 67 00 i.g.PPQ.p.....g.
0018ea50 a6 49 67 00 88 ea 18 00 - 0c 89 40 00 70 ea 18 00 [email protected]...
0018ea60 50 50 51 06 00 00 00 00 - 00 00 00 00 50 50 51 06 PPQ.........PPQ.
0018ea70 9c ea 18 00 4a 8f 67 00 - e0 b7 50 04 00 00 00 00 ....J.g...P.....
0018ea80 01 00 00 00 77 70 65 00 - a8 ea 18 00 0c 89 40 00 ....wpe.......@.
0018ea90 9c ea 18 00 00 da 49 06 - 50 50 51 06 6c eb 18 00 ......I.PPQ.l...
0018eaa0 be 6e 65 00 1c 4c 16 01 - 74 eb 18 00 0c 89 40 00 .ne..L..t.....@.
0018eab0 6c eb 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 l...............
0018eac0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ead0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eae0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eaf0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eb00 00 00 00 00 00 00 00 00 - 80 6d e5 40 d0 2c 4a 06 .........m.@.,J.
0018eb10 00 00 00 00 fa a4 4f fa - 7f 80 e5 40 00 00 00 00 ......O....@....
disassembling:
[...]
01164bf3 mov eax, [ebp-$18]
01164bf6 mov eax, [eax+$250]
01164bfc mov ecx, [eax]
01164bfe call dword ptr [ecx+$38]
01164c01 425 mov edx, $1165c54
01164c06 mov eax, [ebp-$18]
01164c09 mov eax, [eax+$250]
01164c0f mov ecx, [eax]
01164c11 call dword ptr [ecx+$38]
01164c14 427 mov eax, [ebp-$18]
01164c17 > call -$b0dd68 ($656eb4) ; Data.DB.TDataSet.Open
01164c1c 428 mov eax, [ebp-$18]
01164c1f call -$b0b4a8 ($65977c) ; Data.DB.TDataSet.First
01164c24 429 mov eax, [ebp-$18]
01164c27 cmp byte ptr [eax+$a9], 0
01164c2e jz loc_1164c3c
01164c30 mov eax, [ebp-$18]
01164c33 cmp byte ptr [eax+$a8], 0
01164c3a jnz loc_1164c4b
01164c3c 431 mov eax, [ebp-4]
01164c3f call +$32fb4 ($1197bf8) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $a50:
7740f8da +0e ntdll.dll NtWaitForSingleObject
74dd15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76ef118f +3e kernel32.dll WaitForSingleObjectEx
76ef1143 +0d kernel32.dll WaitForSingleObject
76ef3368 +10 kernel32.dll BaseThreadInitThunk
thread $53c:
77410166 +0e ntdll.dll NtWaitForMultipleObjects
76ef3368 +10 kernel32.dll BaseThreadInitThunk
thread $57c:
77410166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
76ef3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d64) at:
72e82713 +24f netbios.dll Netbios
thread $10c4:
7740f8da +0e ntdll.dll NtWaitForSingleObject
74dd15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76ef118f +3e kernel32.dll WaitForSingleObjectEx
76ef1143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
76ef3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d64) at:
73004c95 +00 winspool.drv
thread $123c:
77411f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76ef3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003a0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
06290000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063a0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70ab0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
70b30000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
70ba0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
70cf0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70d00000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70d20000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70fb0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70fd0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71040000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
710a0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
712f0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71390000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
714b0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
714c0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71910000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71960000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
719c0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72210000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72230000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
722d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72310000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
724c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
724e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
724f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72700000 slc.dll 6.1.7600.16385 C:\Windows\
system32
72e50000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72e80000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
72e90000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
72ef0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72ff0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73140000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73670000 security.dll 6.1.7600.16385 C:\Windows\
system32
73690000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73890000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
738b0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73db0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73e00000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73e30000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73e60000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73ea0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73ec0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73ed0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73ee0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73f40000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73fb0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74150000 version.dll 6.1.7600.16385 C:\Windows\
system32
74160000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74c80000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74c90000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74cf0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
74dc0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74e10000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75a60000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75b50000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75c50000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75c60000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75f10000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75f20000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75f50000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75f70000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f80000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76030000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
760c0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
760d0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76140000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76210000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76220000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76460000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76480000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
765e0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76640000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76710000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76720000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76750000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
767b0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
767c0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76910000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
769a0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76ad0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76ae0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76c80000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76d30000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76dd0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76de0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76e00000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e10000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76e90000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76ee0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
773c0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
773f0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
00a0 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
036c svchost.exe 0 0 0
040c svchost.exe 0 0 0
0438 svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0514 igfxCUIService.exe 0 0 0
055c svchost.exe 0 0 0
0618 spoolsv.exe 0 0 0
0624 taskeng.exe 0 0 0
0648 svchost.exe 0 0 0
06cc armsvc.exe 0 0 0
06e4 atkexComSvc.exe 0 0 0
0728 svchost.exe 0 0 0
074c fbguard.exe 0 0 0
0770 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f0 svchost.exe 0 0 0
0500 scpbradserv.exe 0 0 0
06a8 svchost.exe 0 0 0
07d8 core.exe 0 0 0
096c RapportInjService_x64.exe 0 0 0
09e8 fbserver.exe 0 0 0
0b48 WUDFHost.exe 0 0 0
097c NisSrv.exe 0 0 0
0e74 WmiPrvSE.exe 0 0 0
0ea0 OSPPSVC.EXE 0 0 0
0e44 taskhost.exe 1 26 20 normal
0e6c core.exe 1 9 21 normal
0f5c GoogleCrashHandler.exe 0 0 0
0fb4 GoogleCrashHandler64.exe 0 0 0
0fc0 sppsvc.exe 0 0 0
0c70 svchost.exe 0 0 0
0c58 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
02f8 RapportInjService_x64.exe 1 4 3 normal
09d0 dwm.exe 1 17 4 high
0e34 PresentationFontCache.exe 0 0 0
020c explorer.exe 1 409 252 normal
0fc8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0830 igfxEM.exe 1 14 14 normal
067c igfxHK.exe 1 14 12 normal
0bb0 msseces.exe 1 143 59 normal
0e64 PrnStatusMX.exe 1 23 20 normal
11c8 SearchIndexer.exe 0 0 0
1308 wuauclt.exe 1 12 7 normal
11ac chrome.exe 1 74 50 normal
0e20 chrome.exe 1 9 4 normal
12a0 chrome.exe 1 8 6 above normal
13d8 chrome.exe 1 4 1 normal
0204 chrome.exe 1 4 1 normal
1100 chrome.exe 1 4 3 normal
11b0 Store.exe 1 1116 295 normal C:\Program Files (x86)\Store
1168 splwow64.exe 1 9 2 normal
14ac RdrCEF.exe 1 9 20 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
1234 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
11d4 chrome.exe 1 4 1 idle
1770 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a3ddd60
ebx = 05893d60
ecx = 00000000
edx = 026f2ac8
esi = 008c5804
edi = 058d6b60
eip = 00610a2e
esp = 0018dd08
ebp = 0018dd4c
stack dump:
0018dd08 2e 0a 61 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..a.............
0018dd18 1c dd 18 00 2e 0a 61 00 - 60 dd 3d 0a 60 3d 89 05 ......a.`.=.`=..
0018dd28 04 58 8c 00 60 6b 8d 05 - 4c dd 18 00 38 dd 18 00 .X..`k..L...8...
0018dd38 9c dd 18 00 0c 89 40 00 - 4c dd 18 00 00 00 00 00 [email protected].......
0018dd48 00 00 00 00 60 3d 89 05 - da e6 60 00 7c dd 18 00 ....`=....`.|...
0018dd58 00 00 00 00 04 58 8c 00 - 60 6b 8d 05 4b 74 53 00 .....X..`k..KtS.
0018dd68 00 f9 9a 05 68 e6 11 01 - 09 00 00 00 00 f9 9a 05 ....h...........
0018dd78 60 3d 89 05 90 dd 18 00 - 29 0c 6a 00 00 00 00 00 `=......).j.....
0018dd88 03 00 00 00 00 00 00 00 - bc dd 18 00 d9 34 6a 00 .............4j.
0018dd98 00 00 00 00 08 de 18 00 - 0c 89 40 00 bc dd 18 00 ..........@.....
0018dda8 00 f9 9a 05 00 00 00 00 - 03 00 00 00 09 00 00 00 ................
0018ddb8 00 f9 9a 05 d4 dd 18 00 - 4d 11 7c 00 00 00 00 00 ........M.|.....
0018ddc8 03 00 00 00 09 00 00 00 - 00 f9 9a 05 fc dd 18 00 ................
0018ddd8 6f 58 8c 00 00 00 00 00 - 09 00 00 00 03 00 00 00 oX..............
0018dde8 09 00 00 00 03 00 00 00 - 03 00 00 00 09 00 00 00 ................
0018ddf8 00 f9 9a 05 20 de 18 00 - 88 01 6a 00 00 00 00 00 .... .....j.....
0018de08 28 de 18 00 0c 89 40 00 - 20 de 18 00 60 ae 56 0a (.....@. ...`.V.
0018de18 60 e0 18 00 00 00 00 00 - 38 de 18 00 a5 ff 69 00 `.......8.....i.
0018de28 58 de 18 00 0c 89 40 00 - 38 de 18 00 00 f9 9a 05 [email protected].......
0018de38 4c de 18 00 d4 99 69 00 - 84 97 8c 00 60 e0 18 00 L.....i.....`...
disassembling:
0111e648 public UnitStatusProducao.TfrmStatusProducao.GridSetEditText: ;
function entry point
0111e648 853 push ebp
0111e649 mov ebp, esp
0111e64b add esp, -$c
0111e64e mov [ebp-$c], ecx
0111e651 mov [ebp-8], edx
0111e654 mov [ebp-4], eax
0111e657 854 mov eax, [ebp-4]
0111e65a mov eax, [eax+$3d0]
0111e660 mov edx, [eax]
0111e662 > call dword ptr [edx+$f4]
0111e668 856 mov esp, ebp
0111e66a pop ebp
0111e66b ret 8
thread $a50:
7740f8da +0e ntdll.dll NtWaitForSingleObject
74dd15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76ef118f +3e kernel32.dll WaitForSingleObjectEx
76ef1143 +0d kernel32.dll WaitForSingleObject
76ef3368 +10 kernel32.dll BaseThreadInitThunk
thread $53c:
77410166 +0e ntdll.dll NtWaitForMultipleObjects
76ef3368 +10 kernel32.dll BaseThreadInitThunk
thread $57c:
77410166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
76ef3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d64) at:
72e82713 +24f netbios.dll Netbios
thread $10c4:
7740f8da +0e ntdll.dll NtWaitForSingleObject
74dd15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76ef118f +3e kernel32.dll WaitForSingleObjectEx
76ef1143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
76ef3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d64) at:
73004c95 +00 winspool.drv
thread $1214:
77411f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76ef3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003a0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
06290000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063a0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70ab0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
70b30000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
70ba0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
70cf0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70d00000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70d20000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70fb0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70fd0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71040000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
710a0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
712f0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71390000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
714b0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
714c0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71910000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71960000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
719c0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72210000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72230000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
722d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72310000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
724c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
724e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
724f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72700000 slc.dll 6.1.7600.16385 C:\Windows\
system32
72e50000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72e80000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
72e90000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
72ef0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72ff0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73140000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73670000 security.dll 6.1.7600.16385 C:\Windows\
system32
73690000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73890000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
738b0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73db0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73e00000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73e30000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73e60000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73ea0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73ec0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73ed0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73ee0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73f40000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73fb0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74150000 version.dll 6.1.7600.16385 C:\Windows\
system32
74160000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74c80000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74c90000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74cf0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
74dc0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74e10000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75a60000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75b50000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75c50000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75c60000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75f10000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75f20000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75f50000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75f70000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f80000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76030000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
760c0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
760d0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76140000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76210000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76220000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76460000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76480000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
765e0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76640000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76710000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76720000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76750000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
767b0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
767c0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76910000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
769a0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76ad0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76ae0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76c80000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76d30000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76dd0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76de0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76e00000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e10000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76e90000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76ee0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
773c0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
773f0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
00a0 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
036c svchost.exe 0 0 0
040c svchost.exe 0 0 0
0438 svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0514 igfxCUIService.exe 0 0 0
055c svchost.exe 0 0 0
0618 spoolsv.exe 0 0 0
0624 taskeng.exe 0 0 0
0648 svchost.exe 0 0 0
06cc armsvc.exe 0 0 0
06e4 atkexComSvc.exe 0 0 0
0728 svchost.exe 0 0 0
074c fbguard.exe 0 0 0
0770 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f0 svchost.exe 0 0 0
0500 scpbradserv.exe 0 0 0
06a8 svchost.exe 0 0 0
07d8 core.exe 0 0 0
096c RapportInjService_x64.exe 0 0 0
09e8 fbserver.exe 0 0 0
0b48 WUDFHost.exe 0 0 0
097c NisSrv.exe 0 0 0
0e74 WmiPrvSE.exe 0 0 0
0ea0 OSPPSVC.EXE 0 0 0
0e44 taskhost.exe 1 26 24 normal
0e6c core.exe 1 9 21 normal
0f5c GoogleCrashHandler.exe 0 0 0
0fb4 GoogleCrashHandler64.exe 0 0 0
0fc0 sppsvc.exe 0 0 0
0c70 svchost.exe 0 0 0
0c58 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
02f8 RapportInjService_x64.exe 1 4 3 normal
09d0 dwm.exe 1 17 4 high
0e34 PresentationFontCache.exe 0 0 0
020c explorer.exe 1 534 364 normal
0fc8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0830 igfxEM.exe 1 14 14 normal
067c igfxHK.exe 1 14 12 normal
0bb0 msseces.exe 1 143 59 normal
0e64 PrnStatusMX.exe 1 23 20 normal
11c8 SearchIndexer.exe 0 0 0
1308 wuauclt.exe 1 12 7 normal
11ac chrome.exe 1 76 52 normal
0e20 chrome.exe 1 9 4 normal
12a0 chrome.exe 1 13 6 above normal
13d8 chrome.exe 1 4 1 normal
0204 chrome.exe 1 4 1 normal
1100 chrome.exe 1 4 3 normal
11b0 Store.exe 1 5249 959 normal C:\Program Files (x86)\Store
1168 splwow64.exe 1 9 2 normal
11d4 chrome.exe 1 4 1 idle
0494 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
16b4 OIS.EXE 1 131 51 normal
1578 OIS.EXE 1 114 50 normal
17dc OIS.EXE 1 115 50 normal
17d0 OIS.EXE 1 109 45 normal
12d4 OIS.EXE 1 105 43 normal
140c AcroRd32.exe 1 15 16 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader
1354 AcroRd32.exe 1 266 117 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader
15e0 RdrCEF.exe 1 9 23 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
0c14 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
175c RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
0e2c OIS.EXE 1 113 59 normal
1538 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0d4f05b0
ebx = 00003303
ecx = 00000000
edx = 026f2ac8
esi = 0018d174
edi = 0066c7e4
eip = 0066e702
esp = 0018d138
ebp = 0018d1a0
stack dump:
0018d138 02 e7 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018d148 4c d1 18 00 02 e7 66 00 - b0 05 4f 0d 03 33 00 00 L.....f...O..3..
0018d158 74 d1 18 00 e4 c7 66 00 - a0 d1 18 00 68 d1 18 00 t.....f.....h...
0018d168 50 50 51 06 0e e7 66 00 - 34 e6 67 00 00 00 00 00 PPQ...f.4.g.....
0018d178 50 50 51 06 00 00 00 00 - 2f e5 67 00 ac d1 18 00 PPQ...../.g.....
0018d188 0c 89 40 00 a0 d1 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018d198 69 e6 67 01 50 50 51 06 - c8 d1 18 00 87 e5 67 00 i.g.PPQ.......g.
0018d1a8 a6 49 67 00 e0 d1 18 00 - 0c 89 40 00 c8 d1 18 00 .Ig.......@.....
0018d1b8 50 50 51 06 00 00 00 00 - 00 00 00 00 50 50 51 06 PPQ.........PPQ.
0018d1c8 f4 d1 18 00 4a 8f 67 00 - b8 d7 18 00 10 3d 4f 0d ....J.g......=O.
0018d1d8 01 00 00 00 77 70 65 00 - 00 d2 18 00 0c 89 40 00 ....wpe.......@.
0018d1e8 f4 d1 18 00 10 3d 4f 0d - 50 50 51 06 c4 d2 18 00 .....=O.PPQ.....
0018d1f8 be 6e 65 00 1c 4c 16 01 - cc d2 18 00 0c 89 40 00 .ne..L........@.
0018d208 c4 d2 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d218 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d228 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d238 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d248 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d258 00 00 00 00 00 00 00 00 - 60 7d e5 40 d0 2c 4a 06 ........`}.@.,J.
0018d268 00 00 00 00 fa a4 4f fa - 7f 80 e5 40 00 00 00 00 ......O....@....
disassembling:
[...]
01164bf3 mov eax, [ebp-$18]
01164bf6 mov eax, [eax+$250]
01164bfc mov ecx, [eax]
01164bfe call dword ptr [ecx+$38]
01164c01 425 mov edx, $1165c54
01164c06 mov eax, [ebp-$18]
01164c09 mov eax, [eax+$250]
01164c0f mov ecx, [eax]
01164c11 call dword ptr [ecx+$38]
01164c14 427 mov eax, [ebp-$18]
01164c17 > call -$b0dd68 ($656eb4) ; Data.DB.TDataSet.Open
01164c1c 428 mov eax, [ebp-$18]
01164c1f call -$b0b4a8 ($65977c) ; Data.DB.TDataSet.First
01164c24 429 mov eax, [ebp-$18]
01164c27 cmp byte ptr [eax+$a9], 0
01164c2e jz loc_1164c3c
01164c30 mov eax, [ebp-$18]
01164c33 cmp byte ptr [eax+$a8], 0
01164c3a jnz loc_1164c4b
01164c3c 431 mov eax, [ebp-4]
01164c3f call +$32fb4 ($1197bf8) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $a68:
7796f8da +0e ntdll.dll NtWaitForSingleObject
755415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
756c118f +3e kernel32.dll WaitForSingleObjectEx
756c1143 +0d kernel32.dll WaitForSingleObject
756c3368 +10 kernel32.dll BaseThreadInitThunk
thread $3a4:
77970166 +0e ntdll.dll NtWaitForMultipleObjects
756c3368 +10 kernel32.dll BaseThreadInitThunk
thread $a60:
77970166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
756c3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($8e0) at:
738a2713 +24f netbios.dll Netbios
thread $10ac:
7796f8da +0e ntdll.dll NtWaitForSingleObject
755415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
756c118f +3e kernel32.dll WaitForSingleObjectEx
756c1143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
756c3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($8e0) at:
738c4c95 +00 winspool.drv
thread $1098:
77971f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
756c3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003a0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
062e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06340000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06ba0000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71190000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
71610000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
718b0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
718f0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71910000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71a40000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71bd0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c20000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71c80000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72770000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72790000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72830000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72870000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72a20000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72a40000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72a50000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
731e0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73230000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73260000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
732c0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73870000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
738a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
738b0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73910000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73aa0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73ac0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73db0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73dc0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73de0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73df0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73e10000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73e80000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74310000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74360000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74390000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743c0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74400000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74420000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74430000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74440000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
744a0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74510000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746b0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746c0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751e0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
751f0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75250000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
752b0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75400000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75440000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75460000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75470000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75480000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75520000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75530000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75580000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
756b0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
757c0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75890000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
758a0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75a00000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76650000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76660000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76760000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
767e0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76870000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
768d0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76960000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76a10000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76a40000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76a50000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76b50000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76b90000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ba0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76bc0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76d60000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77010000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
770b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77160000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77170000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77180000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
773c0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
773f0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
774e0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77500000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77920000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77950000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0378 svchost.exe 0 0 0
03cc MsMpEng.exe 0 0 0
00a8 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
030c svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0508 igfxCUIService.exe 0 0 0
054c svchost.exe 0 0 0
0614 spoolsv.exe 0 0 0
061c taskeng.exe 0 0 0
0644 svchost.exe 0 0 0
06cc armsvc.exe 0 0 0
06e4 atkexComSvc.exe 0 0 0
0724 svchost.exe 0 0 0
0750 fbguard.exe 0 0 0
0774 svchost.exe 0 0 0
0788 NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
052c scpbradserv.exe 0 0 0
0684 svchost.exe 0 0 0
06f8 core.exe 0 0 0
0920 RapportInjService_x64.exe 0 0 0
09e0 fbserver.exe 0 0 0
0b24 WUDFHost.exe 0 0 0
0870 WmiPrvSE.exe 0 0 0
05b4 OSPPSVC.EXE 0 0 0
0b84 taskhost.exe 1 26 24 normal
08bc core.exe 1 9 22 normal
0c3c sppsvc.exe 0 0 0
0de0 NisSrv.exe 0 0 0
0ff4 RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0f6c RapportInjService_x64.exe 1 4 3 normal
0160 GoogleCrashHandler.exe 0 0 0
0f14 GoogleCrashHandler64.exe 0 0 0
0740 svchost.exe 0 0 0
1124 PresentationFontCache.exe 0 0 0
113c dwm.exe 1 16 4 high
1148 explorer.exe 1 445 278 normal
11ac scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
1248 igfxEM.exe 1 14 13 normal
1250 igfxHK.exe 1 14 13 normal
12d8 msseces.exe 1 143 59 normal
12e0 PrnStatusMX.exe 1 23 20 normal
0e40 SearchIndexer.exe 0 0 0
0c8c Store.exe 1 1972 627 normal C:\Program Files (x86)\Store
1258 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0314 wuauclt.exe 1 12 7 normal
13a8 splwow64.exe 1 9 3 normal
13d8 chrome.exe 1 26 49 normal
0f28 chrome.exe 1 9 4 normal
0498 chrome.exe 1 12 6 above normal
103c chrome.exe 1 4 1 normal
1354 chrome.exe 1 4 1 normal
0a44 chrome.exe 1 4 3 normal
1330 OIS.EXE 1 132 52 normal
1294 RdrCEF.exe 1 9 19 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
07e0 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
08f4 audiodg.exe 0 0 0
0820 WMIC.exe 0 0 0
128c conhost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0b0e8b10
ebx = 00003303
ecx = 00000000
edx = 026f2ac8
esi = 0018e04c
edi = 0066c7e4
eip = 0066e702
esp = 0018e010
ebp = 0018e078
stack dump:
0018e010 02 e7 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018e020 24 e0 18 00 02 e7 66 00 - 10 8b 0e 0b 03 33 00 00 $.....f......3..
0018e030 4c e0 18 00 e4 c7 66 00 - 78 e0 18 00 40 e0 18 00 L.....f.x...@...
0018e040 f0 0b 4e 04 0e e7 66 00 - 34 e6 67 00 00 00 00 00 ..N...f.4.g.....
0018e050 f0 0b 4e 04 00 00 00 00 - 2f e5 67 00 84 e0 18 00 ..N...../.g.....
0018e060 0c 89 40 00 78 e0 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018e070 69 e6 67 01 f0 0b 4e 04 - a0 e0 18 00 87 e5 67 00 i.g...N.......g.
0018e080 a6 49 67 00 b8 e0 18 00 - 0c 89 40 00 a0 e0 18 00 .Ig.......@.....
0018e090 f0 0b 4e 04 00 00 00 00 - 00 00 00 00 f0 0b 4e 04 ..N...........N.
0018e0a0 cc e0 18 00 4a 8f 67 00 - b4 e3 18 00 20 50 7e 0a ....J.g..... P~.
0018e0b0 01 00 00 00 77 70 65 00 - d8 e0 18 00 0c 89 40 00 ....wpe.......@.
0018e0c0 cc e0 18 00 20 50 7e 0a - f0 0b 4e 04 54 e1 18 00 .... P~...N.T...
0018e0d0 be 6e 65 00 3d 61 ec 00 - 5c e1 18 00 0c 89 40 00 .ne.=a..\.....@.
0018e0e0 54 e1 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 T...............
0018e0f0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e100 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e110 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e120 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e130 70 ad 43 04 f0 0b 4e 04 - 90 0e 4e 04 30 11 4e 04 p.C...N...N.0.N.
0018e140 30 26 4e 04 50 f4 4d 04 - 90 f9 4d 04 f0 f6 4d 04 0&N.P.M...M...M.
disassembling:
[...]
00ec6112 push $ec62a4
00ec6117 lea eax, [ebp-$58]
00ec611a mov edx, 3
00ec611f call -$abb95c ($40a7c8) ; System.@UStrCatN
00ec6124 mov edx, [ebp-$58]
00ec6127 mov eax, [ebp-$20]
00ec612a mov eax, [eax+$250]
00ec6130 mov ecx, [eax]
00ec6132 call dword ptr [ecx+$38]
00ec6135 125 mov eax, [ebp-$20]
00ec6138 > call -$86f289 ($656eb4) ; Data.DB.TDataSet.Open
00ec613d 126 mov eax, [ebp-$20]
00ec6140 call -$86c9c9 ($65977c) ; Data.DB.TDataSet.First
00ec6145 128 lea edx, [ebp-$60]
00ec6148 mov eax, [$1605df0]
00ec614d mov eax, [eax]
00ec614f mov eax, [eax+$330]
00ec6155 mov ecx, [eax]
00ec6157 call dword ptr [ecx+$80]
00ec615d cmp dword ptr [ebp-$60], 0
00ec6161 jnz loc_ec616d
[...]
thread $394:
7796f8da +0e ntdll.dll NtWaitForSingleObject
755415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
756c118f +3e kernel32.dll WaitForSingleObjectEx
756c1143 +0d kernel32.dll WaitForSingleObject
756c3368 +10 kernel32.dll BaseThreadInitThunk
thread $44c:
77970166 +0e ntdll.dll NtWaitForMultipleObjects
756c3368 +10 kernel32.dll BaseThreadInitThunk
thread $a40:
7796f8da +0e ntdll.dll NtWaitForSingleObject
755415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
756c118f +3e kernel32.dll WaitForSingleObjectEx
756c1143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
756c3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($19e0) at:
73374c95 +00 winspool.drv
thread $1060:
77971f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
756c3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
06300000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06bb0000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71190000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
71610000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
718b0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
718f0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71910000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71a40000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71bd0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c20000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71c80000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72770000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72790000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72830000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72870000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72a20000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72a40000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72a50000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72e30000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
731e0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73230000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73260000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73360000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73870000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73910000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73aa0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73ac0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73db0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73dc0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73de0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73df0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73e10000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73e80000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74310000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74360000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74390000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743c0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74400000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74420000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74430000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74440000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
744a0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74510000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746b0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746c0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751e0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
751f0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75250000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
752b0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75400000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75440000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75460000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75470000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75480000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75520000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75530000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75580000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
756b0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
757c0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75890000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
758a0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75a00000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76650000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76660000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76760000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
767e0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76870000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
768d0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76960000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76a10000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76a40000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76a50000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76b50000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76b90000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ba0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76bc0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76d60000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77010000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
770b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77160000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77170000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77180000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
773c0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
773f0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
774e0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77500000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77920000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77950000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0378 svchost.exe 0 0 0
03cc MsMpEng.exe 0 0 0
00a8 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
030c svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0508 igfxCUIService.exe 0 0 0
054c svchost.exe 0 0 0
0614 spoolsv.exe 0 0 0
061c taskeng.exe 0 0 0
0644 svchost.exe 0 0 0
06cc armsvc.exe 0 0 0
06e4 atkexComSvc.exe 0 0 0
0724 svchost.exe 0 0 0
0750 fbguard.exe 0 0 0
0774 svchost.exe 0 0 0
0788 NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
052c scpbradserv.exe 0 0 0
0684 svchost.exe 0 0 0
06f8 core.exe 0 0 0
0920 RapportInjService_x64.exe 0 0 0
09e0 fbserver.exe 0 0 0
0b24 WUDFHost.exe 0 0 0
0870 WmiPrvSE.exe 0 0 0
05b4 OSPPSVC.EXE 0 0 0
0b84 taskhost.exe 1 26 22 normal
08bc core.exe 1 9 22 normal
0c3c sppsvc.exe 0 0 0
0de0 NisSrv.exe 0 0 0
0ff4 RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0f6c RapportInjService_x64.exe 1 4 3 normal
0160 GoogleCrashHandler.exe 0 0 0
0f14 GoogleCrashHandler64.exe 0 0 0
0740 svchost.exe 0 0 0
1124 PresentationFontCache.exe 0 0 0
113c dwm.exe 1 20 5 high
1148 explorer.exe 1 502 434 normal
11ac scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
1248 igfxEM.exe 1 14 13 normal
1250 igfxHK.exe 1 14 13 normal
12d8 msseces.exe 1 143 59 normal
12e0 PrnStatusMX.exe 1 23 20 normal
0e40 SearchIndexer.exe 0 0 0
1258 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0314 wuauclt.exe 1 12 6 normal
14c8 LogonUI.exe 1 0 0
173c chrome.exe 1 73 50 normal
1058 chrome.exe 1 9 4 normal
1778 chrome.exe 1 7 6 above normal
1b68 chrome.exe 1 4 1 normal
1854 chrome.exe 1 4 1 normal
1bd0 chrome.exe 1 4 1 idle
17dc chrome.exe 1 4 3 normal
0478 Store.exe 1 1620 494 normal C:\Program Files (x86)\Store
0cb4 splwow64.exe 1 9 4 normal
1a14 audiodg.exe 0 0 0
1614 rundll32.exe 1 116 51 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 045f3f00
ebx = 06529160
ecx = 00000000
edx = 006e9501
esi = 00593880
edi = 0018ea4c
eip = 004075f4
esp = 0018e8c0
ebp = 0018e8d0
stack dump:
0018e8c0 6a 2d 6f 00 00 3f 5f 04 - 00 00 00 00 d0 98 57 04 j-o..?_.......W.
0018e8d0 40 ea 18 00 68 a0 6f 00 - 80 38 59 00 e0 f1 2b 0a @...h.o..8Y...+.
0018e8e0 81 01 53 00 e0 f1 2b 0a - 85 38 59 00 2a 06 53 00 ..S...+..8Y.*.S.
0018e8f0 16 00 03 00 16 00 00 00 - 03 00 00 00 00 00 00 00 ................
0018e900 00 00 00 00 21 00 00 00 - 16 00 00 00 16 00 03 00 ....!...........
0018e910 e0 f1 2b 0a 4c ea 18 00 - 28 fc 52 00 16 00 03 00 ..+.L...(.R.....
0018e920 48 eb 18 00 e0 f1 2b 0a - e0 f1 2b 0a cf 01 00 00 H.....+...+.....
0018e930 03 00 00 00 00 00 00 00 - b4 e9 18 00 1f b0 79 72 ..............yr
0018e940 78 fe 43 0c 0a 05 1a 00 - 02 02 00 00 0f 00 00 00 x.C.............
0018e950 cf 01 03 00 00 00 00 00 - bb 80 79 72 8e 81 79 72 ..........yr..yr
0018e960 00 00 00 00 cf 01 03 00 - 0a 05 1a 00 00 00 00 00 ................
0018e970 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e980 00 00 00 00 00 00 00 01 - 00 00 00 00 00 00 00 00 ................
0018e990 bb 80 79 72 01 00 00 00 - 30 ea 18 00 00 00 00 00 ..yr....0.......
0018e9a0 00 00 01 00 00 00 00 01 - 07 00 00 00 00 00 00 00 ................
0018e9b0 96 d6 16 d6 e0 e9 18 00 - fa 62 a6 76 0a 05 1a 00 .........b.v....
0018e9c0 02 02 00 00 00 00 00 00 - cf 01 03 00 bb 80 79 72 ..............yr
0018e9d0 cd ab ba dc 00 00 00 00 - 00 00 00 00 f8 e9 18 00 ................
0018e9e0 63 f8 52 00 e0 f1 2b 0a - 0a b0 00 00 00 00 00 00 c.R...+.........
0018e9f0 16 00 03 00 01 00 00 00 - 2c ea 18 00 d5 3c 53 00 ........,....<S.
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $1614:
7796f8da +0e ntdll.dll NtWaitForSingleObject
755415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
756c118f +3e kernel32.dll WaitForSingleObjectEx
756c1143 +0d kernel32.dll WaitForSingleObject
756c3368 +10 kernel32.dll BaseThreadInitThunk
thread $84c:
77970166 +0e ntdll.dll NtWaitForMultipleObjects
756c3368 +10 kernel32.dll BaseThreadInitThunk
thread $1714:
7796f8da +0e ntdll.dll NtWaitForSingleObject
755415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
756c118f +3e kernel32.dll WaitForSingleObjectEx
756c1143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
756c3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($18e4) at:
73374c95 +00 winspool.drv
thread $169c:
77971f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
756c3368 +10 kernel32.dll BaseThreadInitThunk
thread $1900:
77971f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
756c3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003a0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
062d0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06c20000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71610000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
718b0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
718f0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71910000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71a40000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71bd0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c20000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71c80000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72770000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72790000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72830000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72870000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72a20000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72a40000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72a50000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72d30000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
72e30000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
731e0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73230000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73260000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73360000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73870000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73910000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73aa0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73ac0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73db0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73dc0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73de0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73df0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73e10000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73e80000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74310000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74360000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74390000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743c0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74400000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74420000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74430000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74440000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
744a0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74510000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746b0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746c0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751e0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
751f0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75250000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
752b0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75400000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75440000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75460000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75470000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75480000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75520000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75530000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75580000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
756b0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
757c0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75890000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
758a0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75a00000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76650000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76660000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76760000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
767e0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76870000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
768d0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76960000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76a10000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76a50000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76b50000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76b90000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ba0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76bc0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76d60000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77010000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
770b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77160000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77170000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77180000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
773c0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
773f0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
774e0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77500000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77920000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77950000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0378 svchost.exe 0 0 0
03cc MsMpEng.exe 0 0 0
00a8 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
030c svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0508 igfxCUIService.exe 0 0 0
054c svchost.exe 0 0 0
0614 spoolsv.exe 0 0 0
061c taskeng.exe 0 0 0
0644 svchost.exe 0 0 0
06cc armsvc.exe 0 0 0
06e4 atkexComSvc.exe 0 0 0
0724 svchost.exe 0 0 0
0750 fbguard.exe 0 0 0
0774 svchost.exe 0 0 0
0788 NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
052c scpbradserv.exe 0 0 0
0684 svchost.exe 0 0 0
06f8 core.exe 0 0 0
0920 RapportInjService_x64.exe 0 0 0
09e0 fbserver.exe 0 0 0
0b24 WUDFHost.exe 0 0 0
0870 WmiPrvSE.exe 0 0 0
05b4 OSPPSVC.EXE 0 0 0
0b84 taskhost.exe 1 26 23 normal
08bc core.exe 1 9 22 normal
0c3c sppsvc.exe 0 0 0
0de0 NisSrv.exe 0 0 0
0ff4 RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0f6c RapportInjService_x64.exe 1 4 3 normal
0160 GoogleCrashHandler.exe 0 0 0
0f14 GoogleCrashHandler64.exe 0 0 0
0740 svchost.exe 0 0 0
1124 PresentationFontCache.exe 0 0 0
113c dwm.exe 1 20 5 high
1148 explorer.exe 1 524 525 normal
11ac scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
1248 igfxEM.exe 1 14 13 normal
1250 igfxHK.exe 1 14 13 normal
12d8 msseces.exe 1 143 59 normal
12e0 PrnStatusMX.exe 1 23 20 normal
0e40 SearchIndexer.exe 0 0 0
1258 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0314 wuauclt.exe 1 12 6 normal
14c8 LogonUI.exe 1 0 0
17a4 chrome.exe 1 79 57 normal
1b50 chrome.exe 1 9 4 normal
1174 chrome.exe 1 12 7 above normal
17ec chrome.exe 1 4 1 normal
161c chrome.exe 1 4 1 normal
1940 chrome.exe 1 4 1 idle
1990 chrome.exe 1 4 3 normal
1240 Store.exe 1 1316 361 normal C:\Program Files (x86)\Store
13ec Store.exe 1 138 180 normal C:\Program Files (x86)\Store
0bbc chrome.exe 1 4 1 idle
1010 splwow64.exe 1 9 4 normal
1a24 OIS.EXE 1 132 69 normal
05b8 audiodg.exe 0 0 0
1988 rundll32.exe 1 116 53 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 06937390
ebx = 064e015c
ecx = 00000000
edx = 026f2ac8
esi = 0a3c29c8
edi = 004129f0
eip = 0055ec52
esp = 0018da58
ebp = 0018dab0
stack dump:
0018da58 52 ec 55 00 de fa ed 0e - 01 00 00 00 07 00 00 00 R.U.............
0018da68 6c da 18 00 52 ec 55 00 - 90 73 93 06 5c 01 4e 06 l...R.U..s..\.N.
0018da78 c8 29 3c 0a f0 29 41 00 - b0 da 18 00 88 da 18 00 .)<..)A.........
0018da88 01 1d 21 bb 0b f4 55 00 - d4 da 18 00 0c 89 40 00 ..!...U.......@.
0018da98 b0 da 18 00 b0 57 67 04 - c8 29 3c 0a c8 29 3c 0a .....Wg..)<..)<.
0018daa8 00 00 00 00 48 fa 36 0c - e8 da 18 00 bc f9 55 00 ....H.6.......U.
0018dab8 30 3c 68 04 16 5c 70 00 - 58 00 00 00 00 00 00 00 0<h..\p.X.......
0018dac8 30 63 60 04 30 3c 68 04 - bf 5d 70 00 80 dc 18 00 0c`.0<h..]p.....
0018dad8 0c 89 40 00 e8 da 18 00 - 30 63 60 04 00 00 00 00 [email protected]`.....
0018dae8 c4 dc 18 00 30 3d 6f 00 - 05 40 6e 00 55 55 55 55 [email protected]
0018daf8 c4 dc 18 00 6f dc 6e 00 - 00 00 00 00 00 00 00 c8 ....o.n.........
0018db08 05 40 00 00 c4 dc 18 00 - b0 57 67 04 5d 00 00 00 [email protected].]...
0018db18 30 63 60 04 2e 3b 6f 00 - c4 dc 18 00 d7 db 6e 00 0c`..;o.......n.
0018db28 00 00 00 00 00 00 00 c8 - 05 40 00 00 00 00 00 00 .........@......
0018db38 b0 57 67 04 5d 00 00 00 - 70 99 8c 06 e7 fb 6e 00 .Wg.]...p.....n.
0018db48 00 00 00 00 00 00 a0 b9 - 0a 40 6e 00 00 00 00 00 .........@n.....
0018db58 00 00 00 c8 05 40 8c 06 - 5d 00 00 00 70 99 8c 06 .....@..]...p...
0018db68 30 63 60 04 ff fe 6e 00 - 00 00 00 00 00 00 00 00 0c`...n.........
0018db78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00705bed call -$2f2e4a ($412da8) ; Winapi.Windows.StartPage
00705bf2 3730 mov eax, [ebx+4]
00705bf5 call -$1a6356 ($55f8a4) ; Vcl.Printers.TPrinter.GetCanvas
00705bfa mov [ebx+$28], eax
00705bfd 3731 mov eax, ebx
00705bff call -$140 ($705ac4) ; QRPrntr.TQRPrinter.GetCanvas
00705c04 mov edx, [eax]
00705c06 call dword ptr [edx+$80]
00705c0c 3733 push $58
00705c0e mov eax, [ebx+4]
00705c11 > call -$1a6266 ($55f9b0) ; Vcl.Printers.TPrinter.GetHandle
00705c16 push eax
00705c17 call -$2f3104 ($412b18) ; Winapi.Windows.GetDeviceCaps
00705c1c mov [esp], eax
00705c1f fild dword ptr [esp]
00705c22 fdiv dword ptr [$705c88]
00705c28 fstp tbyte ptr [ebx+$90]
00705c2e wait
00705c2f 3734 push $5a
00705c31 mov eax, [ebx+4]
00705c34 call -$1a6289 ($55f9b0) ; Vcl.Printers.TPrinter.GetHandle
[...]
thread $1614:
7796f8da +0e ntdll.dll NtWaitForSingleObject
755415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
756c118f +3e kernel32.dll WaitForSingleObjectEx
756c1143 +0d kernel32.dll WaitForSingleObject
756c3368 +10 kernel32.dll BaseThreadInitThunk
thread $84c:
77970166 +0e ntdll.dll NtWaitForMultipleObjects
756c3368 +10 kernel32.dll BaseThreadInitThunk
thread $1714:
7796f8da +0e ntdll.dll NtWaitForSingleObject
755415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
756c118f +3e kernel32.dll WaitForSingleObjectEx
756c1143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
756c3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($18e4) at:
73374c95 +00 winspool.drv
thread $169c:
77971f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
756c3368 +10 kernel32.dll BaseThreadInitThunk
thread $1900:
77971f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
756c3368 +10 kernel32.dll BaseThreadInitThunk
thread $10f0:
77971f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
756c3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003a0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
062d0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06c20000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71610000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
718b0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
718f0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71910000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71a40000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71bd0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c20000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71c80000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72770000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72790000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72830000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72870000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72a20000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72a40000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72a50000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72d30000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
72e30000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
731e0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73230000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73260000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73360000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73870000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73910000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73aa0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73ac0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73db0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73dc0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73de0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73df0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73e10000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73e80000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74310000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74360000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74390000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743c0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74400000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74420000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74430000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74440000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
744a0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74510000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746b0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746c0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751e0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
751f0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75250000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
752b0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75400000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75440000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75460000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75470000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75480000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75520000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75530000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75580000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
756b0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
757c0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75890000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
758a0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75a00000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76650000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76660000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76760000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
767e0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76870000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
768d0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76960000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76a10000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76a40000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76a50000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76b50000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76b90000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ba0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76bc0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76d60000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77010000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
770b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77160000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77170000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77180000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
773c0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
773f0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
774e0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77500000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77920000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77950000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0378 svchost.exe 0 0 0
03cc MsMpEng.exe 0 0 0
00a8 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
030c svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0508 igfxCUIService.exe 0 0 0
054c svchost.exe 0 0 0
0614 spoolsv.exe 0 0 0
061c taskeng.exe 0 0 0
0644 svchost.exe 0 0 0
06cc armsvc.exe 0 0 0
06e4 atkexComSvc.exe 0 0 0
0724 svchost.exe 0 0 0
0750 fbguard.exe 0 0 0
0774 svchost.exe 0 0 0
0788 NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
052c scpbradserv.exe 0 0 0
0684 svchost.exe 0 0 0
06f8 core.exe 0 0 0
0920 RapportInjService_x64.exe 0 0 0
09e0 fbserver.exe 0 0 0
0b24 WUDFHost.exe 0 0 0
0870 WmiPrvSE.exe 0 0 0
05b4 OSPPSVC.EXE 0 0 0
0b84 taskhost.exe 1 26 22 normal
08bc core.exe 1 9 22 normal
0c3c sppsvc.exe 0 0 0
0de0 NisSrv.exe 0 0 0
0ff4 RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0f6c RapportInjService_x64.exe 1 4 3 normal
0160 GoogleCrashHandler.exe 0 0 0
0f14 GoogleCrashHandler64.exe 0 0 0
0740 svchost.exe 0 0 0
1124 PresentationFontCache.exe 0 0 0
113c dwm.exe 1 20 5 high
1148 explorer.exe 1 524 522 normal
11ac scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
1248 igfxEM.exe 1 14 13 normal
1250 igfxHK.exe 1 14 13 normal
12d8 msseces.exe 1 143 59 normal
12e0 PrnStatusMX.exe 1 23 20 normal
0e40 SearchIndexer.exe 0 0 0
1258 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0314 wuauclt.exe 1 12 6 normal
14c8 LogonUI.exe 1 0 0
17a4 chrome.exe 1 79 57 normal
1b50 chrome.exe 1 9 4 normal
1174 chrome.exe 1 12 7 above normal
17ec chrome.exe 1 4 1 normal
161c chrome.exe 1 4 1 normal
1940 chrome.exe 1 4 1 idle
1990 chrome.exe 1 4 3 normal
1240 Store.exe 1 1316 361 normal C:\Program Files (x86)\Store
13ec Store.exe 1 138 180 normal C:\Program Files (x86)\Store
0bbc chrome.exe 1 4 1 idle
1010 splwow64.exe 1 9 4 normal
1a24 OIS.EXE 1 132 69 normal
05b8 audiodg.exe 0 0 0
1988 rundll32.exe 1 116 51 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 04683c30
ebx = 064b1630
ecx = 000204b0
edx = 006e9501
esi = 00593880
edi = 0018de60
eip = 00356d98
esp = 0018dcd0
ebp = 0018dce4
stack dump:
0018dcd0 f7 75 40 00 6a 2d 6f 00 - 30 3c 68 04 00 00 00 00 [email protected]<h.....
0018dce0 30 63 60 04 54 de 18 00 - 68 a0 6f 00 80 38 59 00 0c`.T...h.o..8Y.
0018dcf0 00 e1 44 0a 81 01 53 00 - 00 e1 44 0a 85 38 59 00 ..D...S...D..8Y.
0018dd00 2a 06 53 00 13 00 0c 00 - 13 00 00 00 0c 00 00 00 *.S.............
0018dd10 00 00 00 00 00 00 00 00 - 21 00 00 00 16 00 00 00 ........!.......
0018dd20 13 00 0c 00 00 e1 44 0a - 60 de 18 00 28 fc 52 00 ......D.`...(.R.
0018dd30 13 00 0c 00 5c df 18 00 - 00 e1 44 0a 00 e1 44 0a ....\.....D...D.
0018dd40 cc 01 00 00 0c 00 00 00 - 00 00 00 00 c8 dd 18 00 ................
0018dd50 1f b0 79 72 68 d2 79 02 - c2 08 21 00 02 02 00 00 ..yrh.y...!.....
0018dd60 0f 00 00 00 cc 01 0c 00 - 00 00 00 00 bb 80 79 72 ..............yr
0018dd70 8e 81 79 72 00 00 00 00 - cc 01 0c 00 c2 08 21 00 ..yr..........!.
0018dd80 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd90 00 00 00 00 00 00 00 00 - 00 00 00 01 00 00 00 00 ................
0018dda0 00 00 00 00 bb 80 79 72 - 01 00 00 00 44 de 18 00 ......yr....D...
0018ddb0 00 00 00 00 00 00 01 00 - 00 00 00 01 07 00 00 00 ................
0018ddc0 00 00 00 00 bb 96 22 42 - f4 dd 18 00 fa 62 a6 76 ......"B.....b.v
0018ddd0 c2 08 21 00 02 02 00 00 - 00 00 00 00 cc 01 0c 00 ..!.............
0018dde0 bb 80 79 72 cd ab ba dc - 00 00 00 00 00 00 00 00 ..yr............
0018ddf0 0c de 18 00 63 f8 52 00 - 00 e1 44 0a 0a b0 00 00 ....c.R...D.....
0018de00 00 00 00 00 13 00 0c 00 - 01 00 00 00 40 de 18 00 ............@...
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $fa0:
77a8f8da +0e ntdll.dll NtWaitForSingleObject
765915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7538118f +3e kernel32.dll WaitForSingleObjectEx
75381143 +0d kernel32.dll WaitForSingleObject
75383368 +10 kernel32.dll BaseThreadInitThunk
thread $17a8:
77a90166 +0e ntdll.dll NtWaitForMultipleObjects
75383368 +10 kernel32.dll BaseThreadInitThunk
thread $1530:
77a91f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75383368 +10 kernel32.dll BaseThreadInitThunk
thread $434:
77a8f8da +0e ntdll.dll NtWaitForSingleObject
765915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7538118f +3e kernel32.dll WaitForSingleObjectEx
75381143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75383368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($15b0) at:
73a04c95 +00 winspool.drv
thread $d04:
77a91f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75383368 +10 kernel32.dll BaseThreadInitThunk
thread $638:
77a91f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75383368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
003c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
062d0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70a60000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
71650000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
716c0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71880000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
718d0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71910000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71b30000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71b60000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71cf0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71d40000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71da0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72610000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72630000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72950000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72990000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72b40000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72b60000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72b70000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
731d0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
735c0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
736e0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
739c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
739e0000 security.dll 6.1.7600.16385 C:\Windows\
system32
739f0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73b30000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73b40000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73b60000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73b70000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73b90000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73f10000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73f30000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74480000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
744b0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
744e0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74520000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74540000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74550000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74560000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
745c0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74630000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
747d0000 version.dll 6.1.7600.16385 C:\Windows\
system32
747e0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75300000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75310000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75370000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75480000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75490000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75580000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75630000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
757d0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
757e0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75800000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75860000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75880000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
758c0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76510000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76560000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76580000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
765d0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
765e0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76740000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76840000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76860000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76930000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76a60000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76a70000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76a80000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76ab0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ac0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76d70000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76d80000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76e10000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76f10000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77000000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77010000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
770b0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
770c0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
77300000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
773b0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77500000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
77580000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
77610000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77a40000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77a70000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0338 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
00a0 RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02cc svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
04fc igfxCUIService.exe 0 0 0
0564 svchost.exe 0 0 0
060c spoolsv.exe 0 0 0
0614 taskeng.exe 0 0 0
0644 svchost.exe 0 0 0
06cc armsvc.exe 0 0 0
06e4 atkexComSvc.exe 0 0 0
0724 svchost.exe 0 0 0
074c fbguard.exe 0 0 0
0770 svchost.exe 0 0 0
0788 NetExpressUpdater.exe 0 0 0
07ec svchost.exe 0 0 0
04e0 scpbradserv.exe 0 0 0
0674 svchost.exe 0 0 0
0408 core.exe 0 0 0
0908 RapportInjService_x64.exe 0 0 0
09e4 fbserver.exe 0 0 0
0b58 WUDFHost.exe 0 0 0
05bc NisSrv.exe 0 0 0
0ed8 WmiPrvSE.exe 0 0 0
0f04 OSPPSVC.EXE 0 0 0
0d88 taskhost.exe 1 26 22 normal
0db4 core.exe 1 9 21 normal
0ea8 sppsvc.exe 0 0 0
0d28 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0a70 GoogleCrashHandler.exe 0 0 0
0534 GoogleCrashHandler64.exe 0 0 0
0c98 svchost.exe 0 0 0
0ff8 PresentationFontCache.exe 0 0 0
0fe4 dwm.exe 1 17 4 high
0c88 explorer.exe 1 431 261 normal
0da8 RapportInjService_x64.exe 1 4 3 normal
0e38 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0180 igfxEM.exe 1 14 13 normal
0dc0 igfxHK.exe 1 14 12 normal
050c msseces.exe 1 143 59 normal
0838 PrnStatusMX.exe 1 23 20 normal
11d8 SearchIndexer.exe 0 0 0
09ac wuauclt.exe 1 12 7 normal
124c chrome.exe 1 75 53 normal
1260 chrome.exe 1 9 4 normal
13b4 chrome.exe 1 12 6 above normal
13ac chrome.exe 1 4 1 normal
0e2c chrome.exe 1 4 1 idle
0f5c chrome.exe 1 4 1 idle
07c4 chrome.exe 1 4 3 normal
143c OIS.EXE 1 111 48 normal
1368 splwow64.exe 1 9 3 normal
1314 chrome.exe 1 4 1 idle
0658 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
1348 audiodg.exe 0 0 0
142c Store.exe 1 352 304 normal C:\Program Files (x86)\Store
1488 rundll32.exe 1 116 53 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 06488f70
ecx = 044a1ed0
edx = 0449e670
esi = 00593880
edi = 0018de60
eip = 006fa06e
esp = 0018dcec
ebp = 0018de54
stack dump:
0018dcec 80 38 59 00 c0 a8 31 0a - 81 01 53 00 c0 a8 31 0a .8Y...1...S...1.
0018dcfc 85 38 59 00 2a 06 53 00 - 10 00 09 00 10 00 00 00 .8Y.*.S.........
0018dd0c 09 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
0018dd1c 16 00 00 00 10 00 09 00 - c0 a8 31 0a 60 de 18 00 ..........1.`...
0018dd2c 28 fc 52 00 10 00 09 00 - 5c df 18 00 c0 a8 31 0a (.R.....\.....1.
0018dd3c c0 a8 31 0a c9 01 00 00 - 09 00 00 00 00 00 00 00 ..1.............
0018dd4c c8 dd 18 00 1f b0 63 72 - 18 3f 6c 0a aa 02 0a 00 ......cr.?l.....
0018dd5c 02 02 00 00 0f 00 00 00 - c9 01 09 00 00 00 00 00 ................
0018dd6c bb 80 63 72 8e 81 63 72 - 00 00 00 00 c9 01 09 00 ..cr..cr........
0018dd7c aa 02 0a 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd9c 00 00 00 00 00 00 00 00 - bb 80 63 72 01 00 00 00 ..........cr....
0018ddac 44 de 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 D...............
0018ddbc 00 00 00 00 00 00 00 00 - 41 21 7e fc f4 dd 18 00 ........A!~.....
0018ddcc fa 62 75 76 aa 02 0a 00 - 02 02 00 00 00 00 00 00 .buv............
0018dddc c9 01 09 00 bb 80 63 72 - cd ab ba dc 00 00 00 00 ......cr........
0018ddec 00 00 00 00 0c de 18 00 - 63 f8 52 00 c0 a8 31 0a ........c.R...1.
0018ddfc 0a b0 00 00 00 00 00 00 - 10 00 09 00 01 00 00 00 ................
0018de0c 40 de 18 00 d5 3c 53 00 - 10 00 09 00 90 22 4a 04 @....<S......"J.
0018de1c 00 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
disassembling:
[...]
006fa042 mov edx, [$6e95a4]
006fa048 call -$2f27a5 ($4078a8) ; System.@IsClass
006fa04d test al, al
006fa04f jnz loc_6fa05e
006fa051 402 mov eax, [ebx+$460]
006fa057 call +$cd78 ($706dd4) ; QRPrntr.TQRPrinter.Print
006fa05c jmp loc_6fa088
006fa05e 405 mov eax, [$160d8cc]
006fa063 call -$741c ($6f2c4c) ; QuickRpt.TCustomQuickRep.Print
006fa068 407 mov eax, [ebx+$3cc]
006fa06e > cmp dword ptr [eax+$2b8], 0
006fa075 jnz loc_6fa088
006fa077 409 mov edx, [$160d8cc]
006fa07d mov edx, [edx+$36c]
006fa083 call +$9920 ($7039a8) ; QRPrntr.TQRPreview.SetQRPrinter
006fa088 412 pop esi
006fa089 pop ebx
006fa08a ret
thread $bd0:
76faf8da +0e ntdll.dll NtWaitForSingleObject
765715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
753d118f +3e kernel32.dll WaitForSingleObjectEx
753d1143 +0d kernel32.dll WaitForSingleObject
753d3368 +10 kernel32.dll BaseThreadInitThunk
thread $1184:
76fb0166 +0e ntdll.dll NtWaitForMultipleObjects
753d3368 +10 kernel32.dll BaseThreadInitThunk
thread $11dc:
76fb0166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
753d3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($c6c) at:
733e2713 +24f netbios.dll Netbios
thread $b20:
76faf8da +0e ntdll.dll NtWaitForSingleObject
765715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
753d118f +3e kernel32.dll WaitForSingleObjectEx
753d1143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
753d3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($c6c) at:
734a4c95 +00 winspool.drv
thread $c20:
76fb1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
753d3368 +10 kernel32.dll BaseThreadInitThunk
modules:
001c0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00270000 BCLW32.dll C:\Program
Files (x86)\Store
003a0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02600000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
062b0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063b0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
709d0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70a70000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70c10000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
70c60000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70d30000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71080000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71210000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71260000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
712c0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71da0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71dc0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71e50000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71e90000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72040000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72770000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
72b50000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72b80000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73390000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
733a0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
733c0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
733e0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
733f0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73400000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73410000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73470000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73490000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73530000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73810000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73830000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
738b0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
738f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73940000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
73960000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
73980000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
739d0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73a00000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73a40000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73a60000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73a70000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73a80000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73ae0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73b50000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73cf0000 version.dll 6.1.7600.16385 C:\Windows\
system32
73d00000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74820000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74830000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74890000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
748a0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
74b50000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
74b80000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
74c10000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74db0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74dc0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
74e60000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
74e70000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74ec0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75010000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
750c0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75170000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75270000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75360000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
753c0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
754d0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75540000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75550000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75560000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
755e0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76230000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76240000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76260000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
764a0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76540000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76560000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
765b0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
765e0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
765f0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76750000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76760000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76830000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76890000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
768a0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
768c0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76950000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76ae0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76f60000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76f90000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0244 csrss.exe 1 0 0
024c wininit.exe 0 0 0
027c winlogon.exe 1 0 0
02a8 services.exe 0 0 0
02b8 lsass.exe 0 0 0
02c0 lsm.exe 0 0 0
0320 svchost.exe 0 0 0
036c svchost.exe 0 0 0
03bc MsMpEng.exe 0 0 0
009c RapportMgmtService.exe 0 0 0
0240 svchost.exe 0 0 0
0304 svchost.exe 0 0 0
0180 svchost.exe 0 0 0
0414 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0614 spoolsv.exe 0 0 0
061c taskeng.exe 0 0 0
0640 svchost.exe 0 0 0
06c8 armsvc.exe 0 0 0
06e0 atkexComSvc.exe 0 0 0
071c svchost.exe 0 0 0
0748 fbguard.exe 0 0 0
076c svchost.exe 0 0 0
0784 NetExpressUpdater.exe 0 0 0
03b8 svchost.exe 0 0 0
0540 scpbradserv.exe 0 0 0
06bc core.exe 0 0 0
0950 RapportInjService_x64.exe 0 0 0
0a0c fbserver.exe 0 0 0
0b80 WUDFHost.exe 0 0 0
08a8 NisSrv.exe 0 0 0
0d1c taskhost.exe 1 26 24 normal
0d34 core.exe 1 9 21 normal
0e50 sppsvc.exe 0 0 0
0d2c RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0f30 GoogleCrashHandler.exe 0 0 0
0f44 WmiPrvSE.exe 0 0 0
0f4c GoogleCrashHandler64.exe 0 0 0
0fb8 OSPPSVC.EXE 0 0 0
0fc0 svchost.exe 0 0 0
0cdc RapportInjService_x64.exe 1 4 3 normal
0ebc SearchIndexer.exe 0 0 0
0f58 PresentationFontCache.exe 0 0 0
0b24 dwm.exe 1 17 4 high
0f1c explorer.exe 1 520 315 normal
0d6c scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
09fc igfxEM.exe 1 14 13 normal
0b3c igfxHK.exe 1 14 12 normal
0b08 msseces.exe 1 143 60 normal
0898 PrnStatusMX.exe 1 23 20 normal
1250 wuauclt.exe 1 12 6 normal
0cb4 Store.exe 1 3058 987 normal C:\Program Files (x86)\Store
0f08 splwow64.exe 1 9 3 normal
124c EXCEL.EXE 1 317 99 normal
10d8 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
13e4 OIS.EXE 1 142 112 normal
0fa8 OIS.EXE 1 112 66 normal
0ad8 chrome.exe 1 26 53 normal
119c chrome.exe 1 9 4 normal
0794 chrome.exe 1 7 7 above normal
0750 chrome.exe 1 4 1 normal
0edc chrome.exe 1 4 1 normal
0bdc chrome.exe 1 4 1 idle
117c chrome.exe 1 4 3 normal
1078 OIS.EXE 1 109 45 normal
10c8 Store.exe 1 223 184 normal C:\Program Files (x86)\Store
0adc audiodg.exe 0 0 0
1388 VSSVC.exe 0 0 0
0514 svchost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 09a88ab8
ebx = 00003303
ecx = 00000000
edx = 002a2ac8
esi = 0018ebe8
edi = 0066c7e4
eip = 0066e702
esp = 0018ebac
ebp = 0018ec14
stack dump:
0018ebac 02 e7 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018ebbc c0 eb 18 00 02 e7 66 00 - b8 8a a8 09 03 33 00 00 ......f......3..
0018ebcc e8 eb 18 00 e4 c7 66 00 - 14 ec 18 00 dc eb 18 00 ......f.........
0018ebdc 50 50 54 06 0e e7 66 00 - 34 e6 67 00 00 00 00 00 PPT...f.4.g.....
0018ebec 50 50 54 06 00 00 00 00 - 2f e5 67 00 20 ec 18 00 PPT...../.g. ...
0018ebfc 0c 89 40 00 14 ec 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018ec0c 69 e6 67 01 50 50 54 06 - 3c ec 18 00 87 e5 67 00 i.g.PPT.<.....g.
0018ec1c a6 49 67 00 54 ec 18 00 - 0c 89 40 00 3c ec 18 00 .Ig.T.....@.<...
0018ec2c 50 50 54 06 00 00 00 00 - 00 00 00 00 50 50 54 06 PPT.........PPT.
0018ec3c 68 ec 18 00 4a 8f 67 00 - 11 00 00 00 ac 38 62 00 h...J.g......8b.
0018ec4c 01 00 00 00 77 70 65 00 - 74 ec 18 00 0c 89 40 00 ....wpe.t.....@.
0018ec5c 68 ec 18 00 d0 29 7f 05 - 50 50 54 06 38 ed 18 00 h....)..PPT.8...
0018ec6c be 6e 65 00 1c 4c 16 01 - 6c ef 18 00 0c 89 40 00 .ne..L..l.....@.
0018ec7c 38 ed 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 8...............
0018ec8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ec9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ecac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ecbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eccc 00 00 00 00 00 00 00 00 - e0 81 e5 40 d0 29 7f 05 ...........@.)..
0018ecdc 00 00 00 00 fa a4 4f fa - ff 81 e5 40 00 00 00 00 ......O....@....
disassembling:
[...]
01164bf3 mov eax, [ebp-$18]
01164bf6 mov eax, [eax+$250]
01164bfc mov ecx, [eax]
01164bfe call dword ptr [ecx+$38]
01164c01 425 mov edx, $1165c54
01164c06 mov eax, [ebp-$18]
01164c09 mov eax, [eax+$250]
01164c0f mov ecx, [eax]
01164c11 call dword ptr [ecx+$38]
01164c14 427 mov eax, [ebp-$18]
01164c17 > call -$b0dd68 ($656eb4) ; Data.DB.TDataSet.Open
01164c1c 428 mov eax, [ebp-$18]
01164c1f call -$b0b4a8 ($65977c) ; Data.DB.TDataSet.First
01164c24 429 mov eax, [ebp-$18]
01164c27 cmp byte ptr [eax+$a9], 0
01164c2e jz loc_1164c3c
01164c30 mov eax, [ebp-$18]
01164c33 cmp byte ptr [eax+$a8], 0
01164c3a jnz loc_1164c4b
01164c3c 431 mov eax, [ebp-4]
01164c3f call +$32fb4 ($1197bf8) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $d4c:
778af8da +0e ntdll.dll NtWaitForSingleObject
764415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7721118f +3e kernel32.dll WaitForSingleObjectEx
77211143 +0d kernel32.dll WaitForSingleObject
77213368 +10 kernel32.dll BaseThreadInitThunk
thread $2fc:
778b0166 +0e ntdll.dll NtWaitForMultipleObjects
77213368 +10 kernel32.dll BaseThreadInitThunk
thread $1278:
778b0166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
77213368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1250) at:
737f2713 +24f netbios.dll Netbios
thread $1348:
778af8da +0e ntdll.dll NtWaitForSingleObject
764415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7721118f +3e kernel32.dll WaitForSingleObjectEx
77211143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
77213368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1250) at:
733c4c95 +00 winspool.drv
thread $13a0:
778b1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
77213368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00390000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
04360000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06370000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06c40000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70ff0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
71070000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
710c0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
710d0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71180000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
711a0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
711c0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
711d0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
71550000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
718f0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71940000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71960000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71980000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71b10000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71b60000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71bc0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
726b0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
726d0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72770000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
727b0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72960000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72980000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72990000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73220000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73250000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
732b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
733b0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
734e0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
737f0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73ae0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73b00000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73dd0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74250000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
742a0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
742d0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74300000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74340000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74360000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74370000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74380000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
743e0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74450000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
745f0000 version.dll 6.1.7600.16385 C:\Windows\
system32
74600000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75120000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75130000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75190000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
751e0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
751f0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75e40000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75e70000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75e80000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76020000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76150000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
761e0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76330000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76340000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
763e0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
763f0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76430000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76480000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
764b0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
764c0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76620000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
766f0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76700000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
767a0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
767c0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
767d0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
767f0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76800000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76a40000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76ac0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76b20000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76bb0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76e60000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76f20000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76f30000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77010000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
77100000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77200000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
77310000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
773c0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
773d0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
77470000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77860000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77890000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
02b0 svchost.exe 0 0 0
0374 svchost.exe 0 0 0
01fc svchost.exe 0 0 0
0424 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0554 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0654 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
0218 svchost.exe 0 0 0
0534 scpbradserv.exe 0 0 0
0434 svchost.exe 0 0 0
07d8 core.exe 0 0 0
0960 RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b6c WUDFHost.exe 0 0 0
0be0 WmiPrvSE.exe 0 0 0
0838 OSPPSVC.EXE 0 0 0
097c NisSrv.exe 0 0 0
0d64 svchost.exe 0 0 0
0e4c sppsvc.exe 0 0 0
0e88 GoogleCrashHandler.exe 0 0 0
0ea4 GoogleCrashHandler64.exe 0 0 0
0390 SearchIndexer.exe 0 0 0
0f6c taskhost.exe 1 26 23 normal
0f78 core.exe 1 9 21 normal
0e34 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0b2c PresentationFontCache.exe 0 0 0
0a08 dwm.exe 1 20 5 high
03d8 explorer.exe 1 747 498 normal
016c scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0748 RapportInjService_x64.exe 1 4 3 normal
0d10 igfxEM.exe 1 14 14 normal
0fc0 igfxHK.exe 1 14 13 normal
0974 msseces.exe 1 143 59 normal
0764 PrnStatusMX.exe 1 23 20 normal
124c Store.exe 1 3976 892 normal C:\Program Files (x86)\Store
126c wuauclt.exe 1 12 6 normal
13b8 chrome.exe 1 28 58 normal
0ddc chrome.exe 1 9 4 normal
0db8 chrome.exe 1 8 6 above normal
0a5c chrome.exe 1 4 1 normal
0328 chrome.exe 1 4 1 normal
0c68 chrome.exe 1 4 1 idle
13f0 chrome.exe 1 4 3 normal
1228 splwow64.exe 1 9 4 normal
0db4 OIS.EXE 1 106 47 normal
0e04 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
16dc OIS.EXE 1 143 110 normal
1468 OIS.EXE 1 131 50 normal
15c8 chrome.exe 1 4 1 idle
1174 OIS.EXE 1 115 50 normal
1580 AcroRd32.exe 1 16 17 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader
0874 AcroRd32.exe 1 309 125 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader
1160 RdrCEF.exe 1 9 22 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
17d4 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
11b0 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
1560 audiodg.exe 0 0 0
1744 Store.exe 1 190 185 normal C:\Program Files (x86)\Store
14c8 WmiPrvSE.exe 0 0 0
1494 VSSVC.exe 0 0 0
14ac svchost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0c42c3a0
ebx = 00003303
ecx = 00000000
edx = 026e2ac8
esi = 0018ea0c
edi = 0066c7e4
eip = 0066e702
esp = 0018e9d0
ebp = 0018ea38
stack dump:
0018e9d0 02 e7 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018e9e0 e4 e9 18 00 02 e7 66 00 - a0 c3 42 0c 03 33 00 00 ......f...B..3..
0018e9f0 0c ea 18 00 e4 c7 66 00 - 38 ea 18 00 00 ea 18 00 ......f.8.......
0018ea00 50 50 56 06 0e e7 66 00 - 34 e6 67 00 00 00 00 00 PPV...f.4.g.....
0018ea10 50 50 56 06 00 00 00 00 - 2f e5 67 00 44 ea 18 00 PPV...../.g.D...
0018ea20 0c 89 40 00 38 ea 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018ea30 69 e6 67 01 50 50 56 06 - 60 ea 18 00 87 e5 67 00 i.g.PPV.`.....g.
0018ea40 a6 49 67 00 78 ea 18 00 - 0c 89 40 00 60 ea 18 00 .Ig.x.....@.`...
0018ea50 50 50 56 06 00 00 00 00 - 00 00 00 00 50 50 56 06 PPV.........PPV.
0018ea60 8c ea 18 00 4a 8f 67 00 - e0 44 0a 0c 00 00 00 00 ....J.g..D......
0018ea70 01 00 00 00 77 70 65 00 - 98 ea 18 00 0c 89 40 00 ....wpe.......@.
0018ea80 8c ea 18 00 80 cf 4e 06 - 50 50 56 06 5c eb 18 00 ......N.PPV.\...
0018ea90 be 6e 65 00 1c 4c 16 01 - 64 eb 18 00 0c 89 40 00 .ne..L..d.....@.
0018eaa0 5c eb 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 \...............
0018eab0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eac0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ead0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eae0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eaf0 00 00 00 00 00 00 00 00 - 20 7e e5 40 d0 2c 4f 06 ........ ~.@.,O.
0018eb00 00 00 00 00 fa a4 4f fa - 1f 82 e5 40 00 00 00 00 ......O....@....
disassembling:
[...]
01164bf3 mov eax, [ebp-$18]
01164bf6 mov eax, [eax+$250]
01164bfc mov ecx, [eax]
01164bfe call dword ptr [ecx+$38]
01164c01 425 mov edx, $1165c54
01164c06 mov eax, [ebp-$18]
01164c09 mov eax, [eax+$250]
01164c0f mov ecx, [eax]
01164c11 call dword ptr [ecx+$38]
01164c14 427 mov eax, [ebp-$18]
01164c17 > call -$b0dd68 ($656eb4) ; Data.DB.TDataSet.Open
01164c1c 428 mov eax, [ebp-$18]
01164c1f call -$b0b4a8 ($65977c) ; Data.DB.TDataSet.First
01164c24 429 mov eax, [ebp-$18]
01164c27 cmp byte ptr [eax+$a9], 0
01164c2e jz loc_1164c3c
01164c30 mov eax, [ebp-$18]
01164c33 cmp byte ptr [eax+$a8], 0
01164c3a jnz loc_1164c4b
01164c3c 431 mov eax, [ebp-4]
01164c3f call +$32fb4 ($1197bf8) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $d8:
77b4f8da +0e ntdll.dll NtWaitForSingleObject
76a915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76af118f +3e kernel32.dll WaitForSingleObjectEx
76af1143 +0d kernel32.dll WaitForSingleObject
76af3368 +10 kernel32.dll BaseThreadInitThunk
thread $1014:
77b50166 +0e ntdll.dll NtWaitForMultipleObjects
76af3368 +10 kernel32.dll BaseThreadInitThunk
thread $10dc:
77b50166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
76af3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($e00) at:
73d12713 +24f netbios.dll Netbios
thread $6e4:
77b4f8da +0e ntdll.dll NtWaitForSingleObject
76a915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76af118f +3e kernel32.dll WaitForSingleObjectEx
76af1143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
76af3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($e00) at:
73b74c95 +00 winspool.drv
thread $13a8:
77b51f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76af3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00350000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00380000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
06340000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06450000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71670000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
716c0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71750000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
718b0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
719e0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71c30000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c80000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71ce0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71d20000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
726d0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
726f0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a10000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a50000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c00000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c20000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c30000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
730e0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73630000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73680000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
736b0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73710000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73b50000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73b60000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73cb0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73cc0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73ce0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73cf0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73d10000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73d20000 security.dll 6.1.7600.16385 C:\Windows\
system32
73d30000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73d50000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73d70000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
744f0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74540000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74570000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
745a0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
745e0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74600000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74610000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74620000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74680000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
746f0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74890000 version.dll 6.1.7600.16385 C:\Windows\
system32
748a0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
753c0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75430000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75440000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75450000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75520000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
755b0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75640000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75650000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
756f0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75930000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75950000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75960000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75970000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
765c0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76670000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
766f0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76750000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76780000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
767c0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76920000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76970000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76980000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
769a0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
769b0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
769c0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76a70000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76a80000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76ad0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76ae0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76c20000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76ce0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76e80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e90000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76ef0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76ff0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77140000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
771e0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
772d0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77400000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
776b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77b00000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77b30000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02d0 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
0508 igfxCUIService.exe 0 0 0
0554 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
0410 svchost.exe 0 0 0
0570 scpbradserv.exe 0 0 0
06c0 svchost.exe 0 0 0
07e8 core.exe 0 0 0
08fc RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b88 WUDFHost.exe 0 0 0
0518 NisSrv.exe 0 0 0
0e84 taskhost.exe 1 26 23 normal
0e9c core.exe 1 9 22 normal
0f30 sppsvc.exe 0 0 0
0d34 GoogleCrashHandler.exe 0 0 0
0d40 GoogleCrashHandler64.exe 0 0 0
0d78 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0dc8 PresentationFontCache.exe 0 0 0
0dd0 dwm.exe 1 17 4 high
0de0 explorer.exe 1 410 240 normal
0e3c scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f18 RapportInjService_x64.exe 1 4 3 normal
0200 igfxEM.exe 1 14 13 normal
00a8 igfxHK.exe 1 14 12 normal
0c34 msseces.exe 1 143 59 normal
0dec PrnStatusMX.exe 1 23 20 normal
11bc svchost.exe 0 0 0
1294 SearchIndexer.exe 0 0 0
04f4 Store.exe 1 491 340 normal C:\Program Files (x86)\Store
0df4 WmiPrvSE.exe 0 0 0
10a8 OSPPSVC.EXE 0 0 0
08c8 wuauclt.exe 1 12 6 normal
1388 chrome.exe 1 74 50 normal
1024 chrome.exe 1 9 4 normal
03e0 chrome.exe 1 7 8 above normal
0acc chrome.exe 1 4 1 normal
0a10 chrome.exe 1 4 1 normal
114c chrome.exe 1 4 1 idle
0668 chrome.exe 1 4 3 normal
1284 audiodg.exe 0 0 0
109c splwow64.exe 1 9 2 normal
067c DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
12a0 SearchProtocolHost.exe 0 0 0
13f8 SearchFilterHost.exe 0 0 0 idle
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 05443258
ebx = 00003303
ecx = 00000000
edx = 029d2ac8
esi = 0018da4c
edi = 0066c7e4
eip = 0066e702
esp = 0018da10
ebp = 0018da78
stack dump:
0018da10 02 e7 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018da20 24 da 18 00 02 e7 66 00 - 58 32 44 05 03 33 00 00 $.....f.X2D..3..
0018da30 4c da 18 00 e4 c7 66 00 - 78 da 18 00 40 da 18 00 L.....f.x...@...
0018da40 30 2e 51 06 0e e7 66 00 - 34 e6 67 00 00 00 00 00 0.Q...f.4.g.....
0018da50 30 2e 51 06 00 00 00 00 - 2f e5 67 00 84 da 18 00 0.Q...../.g.....
0018da60 0c 89 40 00 78 da 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018da70 69 e6 67 01 30 2e 51 06 - a0 da 18 00 87 e5 67 00 i.g.0.Q.......g.
0018da80 a6 49 67 00 b8 da 18 00 - 0c 89 40 00 a0 da 18 00 .Ig.......@.....
0018da90 30 2e 51 06 00 00 00 00 - 00 00 00 00 30 2e 51 06 0.Q.........0.Q.
0018daa0 cc da 18 00 4a 8f 67 00 - 00 00 00 00 cc 59 53 00 ....J.g......YS.
0018dab0 01 00 00 00 77 70 65 00 - d8 da 18 00 0c 89 40 00 ....wpe.......@.
0018dac0 cc da 18 00 90 6e 4d 0a - 30 2e 51 06 3c e0 18 00 .....nM.0.Q.<...
0018dad0 be 6e 65 00 86 91 f0 00 - 44 e0 18 00 0c 89 40 00 .ne.....D.....@.
0018dae0 3c e0 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 <...............
0018daf0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db00 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db10 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db20 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db30 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db40 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00f09155 push $f0a3b0
00f0915a lea eax, [ebp-$4bc]
00f09160 mov edx, 3
00f09165 call -$afe9a2 ($40a7c8) ; System.@UStrCatN
00f0916a mov edx, [ebp-$4bc]
00f09170 mov eax, [ebp-$34]
00f09173 mov eax, [eax+$250]
00f09179 mov ecx, [eax]
00f0917b call dword ptr [ecx+$38]
00f0917e 4108 mov eax, [ebp-$34]
00f09181 > call -$8b22d2 ($656eb4) ; Data.DB.TDataSet.Open
00f09186 4110 mov eax, [$1605df0]
00f0918b mov eax, [eax]
00f0918d mov eax, [eax+$1710]
00f09193 cmp byte ptr [eax+$a9], 0
00f0919a jz loc_f09756
00f091a0 mov eax, [$1605df0]
00f091a5 mov eax, [eax]
00f091a7 mov eax, [eax+$1710]
00f091ad cmp byte ptr [eax+$a8], 0
00f091b4 jz loc_f09756
[...]
date/time : 2020-08-07, 08:50:40, 134ms
computer name : VIDRARIA-06
user name : Karina Kinaki <admin>
registered owner : Karina Kinaki
operating system : Windows 7 x64 Service Pack 1 build 7601
system language : Portuguese
system up time : 45 minutes 49 seconds
program up time : 44 minutes 45 seconds
processors : 4x Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
physical memory : 1906/3968 MB (free/total)
free disk space : (C:) 58,76 GB
display mode : 1600x900, 32 bit
process id : $4f4
allocated memory : 74,25 MB
largest free block : 956,91 MB
executable : Store.exe
exec. date/time : 2020-07-15 13:10
version : 1.0.0.0
bde version : 5.2.0.2
compiled with : Delphi XE2
madExcept version : 4.0.20
callstack crc : $60174286, $ad5d221a, $a31fd939
count : 2
exception number : 6
exception class : EDBEngineError
exception message : General SQL error. Error converting data type varchar to
numeric.
thread $d8:
77b4f8da +0e ntdll.dll NtWaitForSingleObject
76a915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76af118f +3e kernel32.dll WaitForSingleObjectEx
76af1143 +0d kernel32.dll WaitForSingleObject
76af3368 +10 kernel32.dll BaseThreadInitThunk
thread $1014:
77b50166 +0e ntdll.dll NtWaitForMultipleObjects
76af3368 +10 kernel32.dll BaseThreadInitThunk
thread $10dc:
77b50166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
76af3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($e00) at:
73d12713 +24f netbios.dll Netbios
thread $6e4:
77b4f8da +0e ntdll.dll NtWaitForSingleObject
76a915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76af118f +3e kernel32.dll WaitForSingleObjectEx
76af1143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
76af3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($e00) at:
73b74c95 +00 winspool.drv
thread $13a8:
77b51f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76af3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00350000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00380000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
06340000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06450000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71670000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
716c0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71750000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
718b0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
719e0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71c30000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c80000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71ce0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71d20000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
726d0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
726f0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a10000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a50000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c00000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c20000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c30000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
730e0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73630000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73680000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
736b0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73710000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73b50000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73b60000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73cb0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73cc0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73ce0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73cf0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73d10000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73d20000 security.dll 6.1.7600.16385 C:\Windows\
system32
73d30000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73d50000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73d70000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
744f0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74540000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74570000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
745a0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
745e0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74600000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74610000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74620000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74680000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
746f0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74890000 version.dll 6.1.7600.16385 C:\Windows\
system32
748a0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
753c0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75430000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75440000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75450000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75520000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
755b0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75640000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75650000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
756f0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75930000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75950000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75960000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75970000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
765c0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76670000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
766f0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76750000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76780000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
767c0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76920000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76970000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76980000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
769a0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
769b0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
769c0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76a70000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76a80000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76ad0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76ae0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76c20000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76ce0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76e80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e90000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76ef0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76ff0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77140000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
771e0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
772d0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77400000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
776b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77b00000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77b30000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02d0 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
0508 igfxCUIService.exe 0 0 0
0554 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
0410 svchost.exe 0 0 0
0570 scpbradserv.exe 0 0 0
06c0 svchost.exe 0 0 0
07e8 core.exe 0 0 0
08fc RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b88 WUDFHost.exe 0 0 0
0518 NisSrv.exe 0 0 0
0e84 taskhost.exe 1 26 24 normal
0e9c core.exe 1 9 22 normal
0f30 sppsvc.exe 0 0 0
0d34 GoogleCrashHandler.exe 0 0 0
0d40 GoogleCrashHandler64.exe 0 0 0
0d78 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0dc8 PresentationFontCache.exe 0 0 0
0dd0 dwm.exe 1 17 4 high
0de0 explorer.exe 1 410 240 normal
0e3c scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f18 RapportInjService_x64.exe 1 4 3 normal
0200 igfxEM.exe 1 14 13 normal
00a8 igfxHK.exe 1 14 12 normal
0c34 msseces.exe 1 143 59 normal
0dec PrnStatusMX.exe 1 23 20 normal
11bc svchost.exe 0 0 0
1294 SearchIndexer.exe 0 0 0
04f4 Store.exe 1 491 339 normal C:\Program Files (x86)\Store
0df4 WmiPrvSE.exe 0 0 0
10a8 OSPPSVC.EXE 0 0 0
08c8 wuauclt.exe 1 12 6 normal
1388 chrome.exe 1 74 50 normal
1024 chrome.exe 1 9 4 normal
03e0 chrome.exe 1 7 8 above normal
0acc chrome.exe 1 4 1 normal
0a10 chrome.exe 1 4 1 normal
114c chrome.exe 1 4 1 idle
0668 chrome.exe 1 4 3 normal
1284 audiodg.exe 0 0 0
109c splwow64.exe 1 9 2 normal
067c DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
12a0 SearchProtocolHost.exe 0 0 0
13f8 SearchFilterHost.exe 0 0 0 idle
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 054429e8
ebx = 00003303
ecx = 00000000
edx = 029d2ac8
esi = 0018decc
edi = 0066c7e4
eip = 0066e702
esp = 0018de90
ebp = 0018def8
stack dump:
0018de90 02 e7 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018dea0 a4 de 18 00 02 e7 66 00 - e8 29 44 05 03 33 00 00 ......f..)D..3..
0018deb0 cc de 18 00 e4 c7 66 00 - f8 de 18 00 c0 de 18 00 ......f.........
0018dec0 30 2e 51 06 0e e7 66 00 - 34 e6 67 00 00 00 00 00 0.Q...f.4.g.....
0018ded0 30 2e 51 06 00 00 00 00 - 2f e5 67 00 04 df 18 00 0.Q...../.g.....
0018dee0 0c 89 40 00 f8 de 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018def0 69 e6 67 01 30 2e 51 06 - 20 df 18 00 87 e5 67 00 i.g.0.Q. .....g.
0018df00 a6 49 67 00 38 df 18 00 - 0c 89 40 00 20 df 18 00 .Ig.8.....@. ...
0018df10 30 2e 51 06 00 00 00 00 - 00 00 00 00 30 2e 51 06 0.Q.........0.Q.
0018df20 4c df 18 00 4a 8f 67 00 - 00 00 00 00 cc 59 53 00 L...J.g......YS.
0018df30 01 00 00 00 77 70 65 00 - 58 df 18 00 0c 89 40 00 ....wpe.X.....@.
0018df40 4c df 18 00 90 6e 4d 0a - 30 2e 51 06 bc e4 18 00 L....nM.0.Q.....
0018df50 be 6e 65 00 86 91 f0 00 - c4 e4 18 00 0c 89 40 00 .ne...........@.
0018df60 bc e4 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018df70 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018df80 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018df90 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dfa0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dfb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dfc0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00f09155 push $f0a3b0
00f0915a lea eax, [ebp-$4bc]
00f09160 mov edx, 3
00f09165 call -$afe9a2 ($40a7c8) ; System.@UStrCatN
00f0916a mov edx, [ebp-$4bc]
00f09170 mov eax, [ebp-$34]
00f09173 mov eax, [eax+$250]
00f09179 mov ecx, [eax]
00f0917b call dword ptr [ecx+$38]
00f0917e 4108 mov eax, [ebp-$34]
00f09181 > call -$8b22d2 ($656eb4) ; Data.DB.TDataSet.Open
00f09186 4110 mov eax, [$1605df0]
00f0918b mov eax, [eax]
00f0918d mov eax, [eax+$1710]
00f09193 cmp byte ptr [eax+$a9], 0
00f0919a jz loc_f09756
00f091a0 mov eax, [$1605df0]
00f091a5 mov eax, [eax]
00f091a7 mov eax, [eax+$1710]
00f091ad cmp byte ptr [eax+$a8], 0
00f091b4 jz loc_f09756
[...]
thread $cc0:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $115c:
77980166 +0e ntdll.dll NtWaitForMultipleObjects
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $580:
77980166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75773368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
739f2713 +24f netbios.dll Netbios
thread $1224:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75773368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
73a44c95 +00 winspool.drv
thread $1724:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $1390:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $19b4:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $1568:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
044e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06380000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
711b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
71620000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
71670000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
71680000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
716c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71700000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71720000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71830000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71a50000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71be0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71c90000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72500000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72520000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725b0000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
72840000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72880000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72a30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72a50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72a60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72db0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72fa0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73020000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73600000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73760000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
73970000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
739d0000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
739f0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73a00000 security.dll 6.1.7600.16385 C:\Windows\
system32
73a10000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73a30000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73aa0000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
73ac0000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
73ae0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73af0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73b10000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73b20000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73b40000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73b60000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73c10000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
73c30000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73ec0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73f10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73f20000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74320000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74370000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
743a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74410000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74430000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74440000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74450000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74460000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
744b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
744f0000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74500000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
74520000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751f0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75200000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75260000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
752a0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75340000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75350000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75360000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75500000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75520000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75550000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
755b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75660000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75670000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75690000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75710000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75760000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75870000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75880000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
764d0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76710000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76720000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76730000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76750000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76a00000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76ab0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76b50000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76c20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d80000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76e10000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76e30000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76ed0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76f60000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77010000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77040000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77190000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
771a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77200000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
772f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
773f0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77520000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77930000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77960000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
01fc svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0554 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
04f4 scpbradserv.exe 0 0 0
0684 svchost.exe 0 0 0
07dc core.exe 0 0 0
0910 RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b8c WUDFHost.exe 0 0 0
09c8 NisSrv.exe 0 0 0
0ecc WmiPrvSE.exe 0 0 0
0ef8 OSPPSVC.EXE 0 0 0
0eb4 taskhost.exe 1 26 23 normal
0f18 core.exe 1 9 21 normal
0acc sppsvc.exe 0 0 0
08f8 svchost.exe 0 0 0
0b54 GoogleCrashHandler.exe 0 0 0
0a9c GoogleCrashHandler64.exe 0 0 0
0aec RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
03f4 dwm.exe 1 17 4 high
0d38 explorer.exe 1 872 670 normal
0d90 PresentationFontCache.exe 0 0 0
0d98 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c60 RapportInjService_x64.exe 1 4 3 normal
0e94 msseces.exe 1 143 59 normal
0ff0 igfxEM.exe 1 14 13 normal
0c6c PrnStatusMX.exe 1 23 19 normal
0560 igfxHK.exe 1 14 12 normal
0c24 SearchIndexer.exe 0 0 0
0f5c Store.exe 1 8818 2093 normal C:\Program Files (x86)\
Store
11d8 wuauclt.exe 1 12 6 normal
12f4 splwow64.exe 1 9 5 normal
1830 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1454 OIS.EXE 1 162 96 normal
0ab4 OIS.EXE 1 132 49 normal
16b0 OIS.EXE 1 103 44 normal
0e3c OIS.EXE 1 118 50 normal
16c8 OIS.EXE 1 103 44 normal
144c OIS.EXE 1 105 43 normal
0de4 DeviceDisplayObjectProvider.exe 1 9 5 normal
14c8 rundll32.exe 1 116 44 normal
08c4 audiodg.exe 0 0 0
1448 svchost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 0018de01
ecx = 0070002c
edx = 0018de01
esi = 00593880
edi = 045c40f0
eip = 0070588e
esp = 0018dc5c
ebp = 0018dc84
stack dump:
0018dc5c fb 54 70 00 00 de 18 00 - 80 38 59 00 b0 27 92 0b .Tp......8Y..'..
0018dc6c f7 75 40 00 3c 2d 6f 00 - 76 2d 6f 00 40 3c 5c 04 .u@.<-o.v-o.@<\.
0018dc7c 70 26 7b 10 d0 20 b7 11 - f4 dd 18 00 68 a0 6f 00 p&{.. ......h.o.
0018dc8c 80 38 59 00 30 03 5d 12 - 81 01 53 00 30 03 5d 12 .8Y.0.]...S.0.].
0018dc9c 85 38 59 00 2a 06 53 00 - 0c 00 06 00 0c 00 00 00 .8Y.*.S.........
0018dcac 06 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
0018dcbc 16 00 00 00 0c 00 06 00 - 30 03 5d 12 00 de 18 00 ........0.].....
0018dccc 28 fc 52 00 0c 00 06 00 - fc de 18 00 30 03 5d 12 (.R.........0.].
0018dcdc 30 03 5d 12 c5 01 00 00 - 06 00 00 00 00 00 00 00 0.].............
0018dcec 68 dd 18 00 1f b0 52 72 - 40 be a7 0f 3a 0e 15 00 h.....Rr@...:...
0018dcfc 02 02 00 00 0f 00 00 00 - c5 01 06 00 00 00 00 00 ................
0018dd0c bb 80 52 72 8e 81 52 72 - 00 00 00 00 c5 01 06 00 ..Rr..Rr........
0018dd1c 3a 0e 15 00 00 00 00 00 - 00 00 00 00 00 00 00 00 :...............
0018dd2c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd3c 00 00 00 00 00 00 00 00 - bb 80 52 72 01 00 00 00 ..........Rr....
0018dd4c e4 dd 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd5c 00 00 00 00 00 00 00 00 - 43 94 aa 6a 94 dd 18 00 ........C..j....
0018dd6c fa 62 30 77 3a 0e 15 00 - 02 02 00 00 00 00 00 00 .b0w:...........
0018dd7c c5 01 06 00 bb 80 52 72 - cd ab ba dc 00 00 00 00 ......Rr........
0018dd8c 00 00 00 00 ac dd 18 00 - 63 f8 52 00 30 03 5d 12 ........c.R.0.].
disassembling:
00705888 public QRPrntr.TQRPrinter.GetUseStandardPrinter: ; function entry
point
00705888 3462 mov eax, [eax+$b8]
0070588e > movzx eax, byte ptr [eax+$22]
00705892 3463 ret
thread $cc0:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $115c:
77980166 +0e ntdll.dll NtWaitForMultipleObjects
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $580:
77980166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75773368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
739f2713 +24f netbios.dll Netbios
thread $1224:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75773368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
73a44c95 +00 winspool.drv
thread $1724:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $1390:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $19b4:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $1568:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
044e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06380000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
711b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
71620000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
71670000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
71680000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
716c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71700000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71720000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71830000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71a50000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71be0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71c90000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72500000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72520000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725b0000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
72840000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72880000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72a30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72a50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72a60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72db0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72fa0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73020000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73600000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73760000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
73970000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
739d0000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
739f0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73a00000 security.dll 6.1.7600.16385 C:\Windows\
system32
73a10000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73a30000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73aa0000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
73ac0000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
73ae0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73af0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73b10000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73b20000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73b40000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73b60000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73c10000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
73c30000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73ec0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73f10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73f20000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74320000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74370000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
743a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74410000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74430000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74440000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74450000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74460000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
744b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
744f0000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74500000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
74520000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751f0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75200000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75260000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
752a0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75340000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75350000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75360000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75500000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75520000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75550000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
755b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75660000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75670000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75690000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75710000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75760000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75870000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75880000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
764d0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76710000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76720000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76730000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76750000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76a00000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76ab0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76b50000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76c20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d80000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76e10000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76e20000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e30000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76ed0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76f60000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77010000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77040000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77190000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
771a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77200000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
772f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
773f0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77520000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77930000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77960000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
01fc svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0554 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
04f4 scpbradserv.exe 0 0 0
0684 svchost.exe 0 0 0
07dc core.exe 0 0 0
0910 RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b8c WUDFHost.exe 0 0 0
09c8 NisSrv.exe 0 0 0
0ecc WmiPrvSE.exe 0 0 0
0ef8 OSPPSVC.EXE 0 0 0
0eb4 taskhost.exe 1 26 24 normal
0f18 core.exe 1 9 21 normal
0acc sppsvc.exe 0 0 0
08f8 svchost.exe 0 0 0
0b54 GoogleCrashHandler.exe 0 0 0
0a9c GoogleCrashHandler64.exe 0 0 0
0aec RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
03f4 dwm.exe 1 17 4 high
0d38 explorer.exe 1 872 666 normal
0d90 PresentationFontCache.exe 0 0 0
0d98 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c60 RapportInjService_x64.exe 1 4 3 normal
0e94 msseces.exe 1 143 59 normal
0ff0 igfxEM.exe 1 14 13 normal
0c6c PrnStatusMX.exe 1 23 19 normal
0560 igfxHK.exe 1 14 12 normal
0c24 SearchIndexer.exe 0 0 0
0f5c Store.exe 1 8820 2098 normal C:\Program Files (x86)\
Store
11d8 wuauclt.exe 1 12 6 normal
12f4 splwow64.exe 1 9 5 normal
1830 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1454 OIS.EXE 1 162 96 normal
0ab4 OIS.EXE 1 132 49 normal
16b0 OIS.EXE 1 103 44 normal
0e3c OIS.EXE 1 118 50 normal
16c8 OIS.EXE 1 103 44 normal
144c OIS.EXE 1 105 43 normal
0de4 DeviceDisplayObjectProvider.exe 1 9 5 normal
14c8 rundll32.exe 1 116 44 normal
08c4 audiodg.exe 0 0 0
1448 svchost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0047002e
ebx = 045c40f0
ecx = 006f2e80
edx = 045c40f0
esi = 11b720d0
edi = 00000000
eip = 006d007d
esp = 0018cc4c
ebp = 0018cc68
stack dump:
0018cc4c ab 60 70 00 f0 cd 18 00 - 0c 89 40 00 68 cc 18 00 .`[email protected]...
0018cc5c d0 20 b7 11 04 00 00 00 - f0 40 5c 04 9c cd 18 00 . .......@\.....
0018cc6c af 2e 6f 00 20 ce 18 00 - 28 fc 52 00 00 00 00 00 ..o. ...(.R.....
0018cc7c 01 01 ad 10 d0 20 b7 11 - d0 20 b7 11 38 ce 18 00 ..... ... ..8...
0018cc8c 28 fc 52 00 01 00 00 00 - 01 01 ad 10 d0 20 b7 11 (.R.......... ..
0018cc9c 58 cc 18 00 01 00 00 00 - d4 ce 18 00 b6 a6 36 77 X.............6w
0018ccac 1f 24 82 1d fe ff ff ff - 51 6d 30 77 3f 0d 31 77 .$......Qm0w?.1w
0018ccbc 00 00 00 00 30 2f 41 00 - 6a 0f 06 00 30 00 00 00 ....0/A.j...0...
0018cccc 66 34 0a 36 01 00 00 00 - 00 00 00 00 00 00 00 00 f4.6............
0018ccdc 30 00 00 00 d0 20 b7 11 - fc 95 6e 00 00 00 00 00 0.... ....n.....
0018ccec 0c cd 18 00 65 0d 31 77 - 30 2f 41 00 6a 0f 06 00 ....e.1w0/A.j...
0018ccfc 30 00 00 00 66 34 0a 36 - 01 00 00 00 00 00 00 00 0...f4.6........
0018cd0c 60 ce 18 00 85 46 53 00 - 30 2f 41 00 6a 0f 06 00 `....FS.0/A.j...
0018cd1c 30 00 00 00 66 34 0a 36 - 01 00 00 00 60 ce 18 00 0...f4.6....`...
0018cd2c d0 20 b7 11 d0 20 b7 11 - b8 ce 18 00 28 fc 52 00 . ... ......(.R.
0018cd3c d0 20 b7 11 d0 20 b7 11 - d0 20 b7 11 ef 47 99 77 . ... ... ...G.w
0018cd4c 01 00 00 00 00 00 40 00 - 00 00 00 00 00 00 00 00 ......@.........
0018cd5c 60 cd 18 00 23 84 aa 6a - 18 ce 18 00 44 aa 30 77 `...#..j....D.0w
0018cd6c 00 00 01 00 d0 cd 18 00 - 00 00 00 00 00 00 00 46 ...............F
0018cd7c 2f 01 00 00 b2 00 00 00 - 1a 03 00 00 63 04 00 00 /...........c...
disassembling:
[...]
006d0056 fnstsw ax
006d0058 sahf
006d0059 jz loc_6d0084
006d005b mov eax, [ebp-$4010]
006d0061 mov edx, [eax]
006d0063 call dword ptr [edx]
006d0065 mov [ebp-$4020], eax
006d006b mov [ebp-$401c], edx
006d0071 fild qword ptr [ebp-$4020]
006d0077 fdiv qword ptr [$160d830]
006d007d > fstp qword ptr [$160d830]
006d0083 wait
006d0084 396 xor eax, eax
006d0086 pop edx
006d0087 pop ecx
006d0088 pop ecx
006d0089 mov fs:[eax], edx
006d008c push $6d00af
006d0091 lea eax, [ebp-$4000]
006d0097 mov ecx, $1000
006d009c mov edx, [$44be10]
[...]
thread $cc0:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $115c:
77980166 +0e ntdll.dll NtWaitForMultipleObjects
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $580:
77980166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75773368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
739f2713 +24f netbios.dll Netbios
thread $1224:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75773368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
73a44c95 +00 winspool.drv
thread $1724:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $1390:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $19b4:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $1568:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
044e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06380000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
711b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
71620000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
71670000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
71680000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
716c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71700000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71720000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71830000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71a50000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71be0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71c90000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72500000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72520000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725b0000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
72840000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72880000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72a30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72a50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72a60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72db0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72fa0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73020000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73600000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73760000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
73970000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
739d0000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
739f0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73a00000 security.dll 6.1.7600.16385 C:\Windows\
system32
73a10000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73a30000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73aa0000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
73ac0000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
73ae0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73af0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73b10000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73b20000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73b40000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73b60000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73c10000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
73c30000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73ec0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73f10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73f20000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74320000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74370000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
743a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74410000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74430000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74440000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74450000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74460000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
744b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
744f0000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74500000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
74520000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751f0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75200000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75260000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
752a0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75340000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75350000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75360000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75500000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75520000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75550000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
755b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75660000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75670000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75690000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75710000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75760000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75870000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75880000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
764d0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76710000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76720000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76730000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76750000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76a00000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76ab0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76b50000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76c20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d80000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76e10000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76e20000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e30000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76ed0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76f60000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77010000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77040000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77190000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
771a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77200000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
772f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
773f0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77520000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77930000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77960000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
01fc svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0554 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
04f4 scpbradserv.exe 0 0 0
0684 svchost.exe 0 0 0
07dc core.exe 0 0 0
0910 RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b8c WUDFHost.exe 0 0 0
09c8 NisSrv.exe 0 0 0
0ecc WmiPrvSE.exe 0 0 0
0ef8 OSPPSVC.EXE 0 0 0
0eb4 taskhost.exe 1 26 24 normal
0f18 core.exe 1 9 21 normal
0acc sppsvc.exe 0 0 0
08f8 svchost.exe 0 0 0
0b54 GoogleCrashHandler.exe 0 0 0
0a9c GoogleCrashHandler64.exe 0 0 0
0aec RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
03f4 dwm.exe 1 17 4 high
0d38 explorer.exe 1 868 669 normal
0d90 PresentationFontCache.exe 0 0 0
0d98 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c60 RapportInjService_x64.exe 1 4 3 normal
0e94 msseces.exe 1 143 59 normal
0ff0 igfxEM.exe 1 14 13 normal
0c6c PrnStatusMX.exe 1 23 19 normal
0560 igfxHK.exe 1 14 12 normal
0c24 SearchIndexer.exe 0 0 0
0f5c Store.exe 1 8803 2091 normal C:\Program Files (x86)\
Store
11d8 wuauclt.exe 1 12 6 normal
12f4 splwow64.exe 1 9 5 normal
1830 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1454 OIS.EXE 1 162 96 normal
0ab4 OIS.EXE 1 132 49 normal
16b0 OIS.EXE 1 103 44 normal
0e3c OIS.EXE 1 118 50 normal
16c8 OIS.EXE 1 103 44 normal
144c OIS.EXE 1 105 43 normal
0de4 DeviceDisplayObjectProvider.exe 1 9 5 normal
14c8 rundll32.exe 1 116 44 normal
08c4 audiodg.exe 0 0 0
1448 svchost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 045c40f0
ebx = 77300100
ecx = 000204b0
edx = 0f0c6701
esi = 11b720d0
edi = 0018e3b4
eip = 00340034
esp = 0018e05c
ebp = 0018e0d0
stack dump:
0018e05c f7 75 40 00 89 1a 6f 00 - d0 20 b7 11 01 01 30 77 [email protected].. ....0w
0018e06c e7 51 6f 00 40 53 c0 0c - 40 53 c0 0c f7 75 40 00 .Qo.@[email protected]@.
0018e07c f3 c9 ec 00 d8 e0 18 00 - 0c 89 40 00 d0 e0 18 00 ..........@.....
0018e08c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e09c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0bc 00 00 00 00 00 00 00 00 - 00 00 00 00 80 16 93 11 ................
0018e0cc 30 2d b7 11 54 e1 18 00 - 75 61 ec 00 5c e1 18 00 0-..T...ua..\...
0018e0dc 0c 89 40 00 54 e1 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018e0ec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0fc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e10c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e11c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e12c 00 00 00 00 30 2d b7 11 - 20 7f 5f 04 c0 81 5f 04 ....0-.. ._..._.
0018e13c 60 84 5f 04 60 99 5f 04 - 80 67 5f 04 c0 6c 5f 04 `._.`._..g_..l_.
0018e14c 20 6a 5f 04 30 2d b7 11 - fc e1 18 00 bc de ee 00 j_.0-..........
0018e15c 64 e5 18 00 0c 89 40 00 - fc e1 18 00 00 00 00 00 d.....@.........
0018e16c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e17c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e18c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $cc0:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $115c:
77980166 +0e ntdll.dll NtWaitForMultipleObjects
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $580:
77980166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75773368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
739f2713 +24f netbios.dll Netbios
thread $1224:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75773368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
73a44c95 +00 winspool.drv
thread $1804:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $1b7c:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
044e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06380000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
711b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
71620000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
71670000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
71680000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
716c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71700000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71720000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71830000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71a50000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71be0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71c90000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72500000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72520000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725b0000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
72840000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72880000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72a30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72a50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72a60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72db0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72fa0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73020000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73600000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73760000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
73970000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
739d0000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
739f0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73a00000 security.dll 6.1.7600.16385 C:\Windows\
system32
73a10000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73a30000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73aa0000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
73ac0000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
73ae0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73af0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73b10000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73b20000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73b40000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73b60000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73c10000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
73c30000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73ec0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73f10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73f20000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74320000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74370000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
743a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74410000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74430000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74440000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74450000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74460000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
744b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
744f0000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74500000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
74520000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751f0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75200000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75260000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
752a0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75340000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75350000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75360000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75500000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75520000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75550000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
755b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75660000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75670000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75690000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75710000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75760000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75870000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75880000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
764d0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76710000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76720000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76730000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76750000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76a00000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76ab0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76b50000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76c20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d80000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76e10000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76e20000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e30000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76ed0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76f60000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77010000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77040000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77190000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
771a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77200000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
772f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
773f0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77520000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77930000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77960000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
01fc svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0554 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
04f4 scpbradserv.exe 0 0 0
0684 svchost.exe 0 0 0
07dc core.exe 0 0 0
0910 RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b8c WUDFHost.exe 0 0 0
09c8 NisSrv.exe 0 0 0
0ecc WmiPrvSE.exe 0 0 0
0ef8 OSPPSVC.EXE 0 0 0
0eb4 taskhost.exe 1 26 24 normal
0f18 core.exe 1 9 21 normal
0acc sppsvc.exe 0 0 0
08f8 svchost.exe 0 0 0
0b54 GoogleCrashHandler.exe 0 0 0
0a9c GoogleCrashHandler64.exe 0 0 0
0aec RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
03f4 dwm.exe 1 17 4 high
0d38 explorer.exe 1 875 662 normal
0d90 PresentationFontCache.exe 0 0 0
0d98 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c60 RapportInjService_x64.exe 1 4 3 normal
0e94 msseces.exe 1 143 59 normal
0ff0 igfxEM.exe 1 14 13 normal
0c6c PrnStatusMX.exe 1 23 19 normal
0560 igfxHK.exe 1 14 12 normal
0c24 SearchIndexer.exe 0 0 0
0f5c Store.exe 1 9642 2205 normal C:\Program Files (x86)\
Store
11d8 wuauclt.exe 1 12 6 normal
12f4 splwow64.exe 1 9 3 normal
1830 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1454 OIS.EXE 1 162 96 normal
0ab4 OIS.EXE 1 132 49 normal
16b0 OIS.EXE 1 103 44 normal
0e3c OIS.EXE 1 118 50 normal
16c8 OIS.EXE 1 103 44 normal
144c OIS.EXE 1 105 43 normal
0de4 DeviceDisplayObjectProvider.exe 1 9 5 normal
14c8 rundll32.exe 1 116 44 normal
08c4 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 045c3790
ebx = 121693e0
ecx = 00000000
edx = 0018da01
esi = 121693e0
edi = 00000000
eip = 004075f4
esp = 0018d8b8
ebp = 0018d9e8
stack dump:
0018d8b8 ba 2e 6f 00 6c da 18 00 - 28 fc 52 00 00 00 00 00 ..o.l...(.R.....
0018d8c8 8d 0a ad 10 e0 93 16 12 - e0 93 16 12 84 da 18 00 ................
0018d8d8 28 fc 52 00 01 00 00 00 - 8d 0a ad 10 e0 93 16 12 (.R.............
0018d8e8 a4 d8 18 00 01 00 00 00 - 20 db 18 00 b6 a6 36 77 ........ .....6w
0018d8f8 1f 24 82 1d fe ff ff ff - 51 6d 30 77 3f 0d 31 77 .$......Qm0w?.1w
0018d908 00 00 00 00 30 2f 41 00 - c8 0f 19 00 30 00 00 00 ....0/A.....0...
0018d918 66 34 0a 36 01 00 00 00 - 00 00 00 00 00 00 00 00 f4.6............
0018d928 30 00 00 00 e0 93 16 12 - fc 95 6e 00 00 00 00 00 0.........n.....
0018d938 58 d9 18 00 65 0d 31 77 - 30 2f 41 00 c8 0f 19 00 X...e.1w0/A.....
0018d948 30 00 00 00 66 34 0a 36 - 01 00 00 00 00 00 00 00 0...f4.6........
0018d958 ac da 18 00 85 46 53 00 - 30 2f 41 00 c8 0f 19 00 .....FS.0/A.....
0018d968 30 00 00 00 66 34 0a 36 - 01 00 00 00 ac da 18 00 0...f4.6........
0018d978 e0 93 16 12 e0 93 16 12 - 04 db 18 00 28 fc 52 00 ............(.R.
0018d988 e0 93 16 12 e0 93 16 12 - e0 93 16 12 ef 47 99 77 .............G.w
0018d998 01 00 00 00 00 00 40 00 - 00 00 00 00 00 00 00 00 ......@.........
0018d9a8 ac d9 18 00 f7 90 aa 6a - 64 da 18 00 44 aa 30 77 .......jd...D.0w
0018d9b8 00 00 01 00 1c da 18 00 - 00 00 00 00 00 00 00 46 ...............F
0018d9c8 2f 01 00 00 b2 00 00 00 - 1a 03 00 00 63 04 00 00 /...........c...
0018d9d8 92 0d 35 00 00 00 00 00 - 00 00 40 00 00 00 00 00 ..5.......@.....
0018d9e8 34 da 18 00 88 45 53 00 - 8d 0a ad 10 e0 93 16 12 4....ES.........
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $cc0:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $115c:
77980166 +0e ntdll.dll NtWaitForMultipleObjects
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $580:
77980166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75773368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
739f2713 +24f netbios.dll Netbios
thread $1224:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75773368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
73a44c95 +00 winspool.drv
thread $4d8:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $167c:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
044e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06380000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
711b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
71620000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
71670000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
71680000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
716c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71700000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71720000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71830000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71a50000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71be0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71c90000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72500000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72520000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725b0000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
72840000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72880000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72a30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72a50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72a60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72db0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72fa0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73020000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73600000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73760000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
73970000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
739d0000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
739f0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73a00000 security.dll 6.1.7600.16385 C:\Windows\
system32
73a10000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73a30000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73aa0000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
73ac0000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
73ae0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73af0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73b10000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73b20000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73b40000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73b60000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73c10000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
73c30000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73ec0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73f10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73f20000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74320000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74370000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
743a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74410000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74430000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74440000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74450000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74460000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
744b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
744f0000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74500000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
74520000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751f0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75200000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75260000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
752a0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75340000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75350000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75360000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75500000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75520000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75550000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
755b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75660000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75670000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75690000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75710000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75760000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75870000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75880000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
764d0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76710000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76720000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76730000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76750000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76a00000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76ab0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76b50000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76c20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d80000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76e10000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76e20000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e30000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76ed0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76f60000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77010000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77040000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77190000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
771a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77200000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
772f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
773f0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77520000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77930000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77960000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
01fc svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0554 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
04f4 scpbradserv.exe 0 0 0
0684 svchost.exe 0 0 0
07dc core.exe 0 0 0
0910 RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b8c WUDFHost.exe 0 0 0
09c8 NisSrv.exe 0 0 0
0ecc WmiPrvSE.exe 0 0 0
0ef8 OSPPSVC.EXE 0 0 0
0eb4 taskhost.exe 1 26 24 normal
0f18 core.exe 1 9 21 normal
0acc sppsvc.exe 0 0 0
08f8 svchost.exe 0 0 0
0b54 GoogleCrashHandler.exe 0 0 0
0a9c GoogleCrashHandler64.exe 0 0 0
0aec RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
03f4 dwm.exe 1 17 4 high
0d38 explorer.exe 1 864 665 normal
0d90 PresentationFontCache.exe 0 0 0
0d98 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c60 RapportInjService_x64.exe 1 4 3 normal
0e94 msseces.exe 1 143 59 normal
0ff0 igfxEM.exe 1 14 13 normal
0c6c PrnStatusMX.exe 1 23 19 normal
0560 igfxHK.exe 1 14 12 normal
0c24 SearchIndexer.exe 0 0 0
0f5c Store.exe 1 9995 2416 normal C:\Program Files (x86)\
Store
11d8 wuauclt.exe 1 12 6 normal
12f4 splwow64.exe 1 9 4 normal
1830 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1454 OIS.EXE 1 162 96 normal
0ab4 OIS.EXE 1 132 49 normal
16b0 OIS.EXE 1 103 44 normal
0e3c OIS.EXE 1 118 50 normal
16c8 OIS.EXE 1 103 44 normal
144c OIS.EXE 1 105 43 normal
0de4 DeviceDisplayObjectProvider.exe 1 9 5 normal
14c8 rundll32.exe 1 116 44 normal
08c4 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 11ec30b0
ebx = 00000000
ecx = 00473c34
edx = 0018cb14
esi = 00000000
edi = 00000000
eip = 00506880
esp = 0018cb44
ebp = 0018cb84
stack dump:
0018cb44 80 68 50 00 de fa ed 0e - 01 00 00 00 07 00 00 00 .hP.............
0018cb54 58 cb 18 00 80 68 50 00 - b0 30 ec 11 00 00 00 00 X....hP..0......
0018cb64 00 00 00 00 00 00 00 00 - 84 cb 18 00 74 cb 18 00 ............t...
0018cb74 8c cb 18 00 0c 89 40 00 - 84 cb 18 00 00 00 00 00 ......@.........
0018cb84 a0 cd 18 00 23 69 50 00 - 64 ce 18 00 0c 89 40 00 ....#iP.d.....@.
0018cb94 a0 cd 18 00 00 00 00 00 - 00 00 00 00 b5 1e 32 73 ..............2s
0018cba4 b0 cb 18 00 b0 cb 18 00 - cf 1f 32 73 01 00 00 00 ..........2s....
0018cbb4 01 00 00 00 c4 cb 18 00 - 00 00 00 00 00 00 00 00 ................
0018cbc4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018cbd4 00 00 00 00 00 08 00 00 - 00 02 00 00 00 02 00 00 ................
0018cbe4 10 cc 18 00 97 6c 74 75 - 00 00 00 00 00 00 00 00 .....ltu........
0018cbf4 b4 f0 d8 13 08 00 00 00 - a4 f0 d8 13 08 00 00 00 ................
0018cc04 00 00 00 00 00 00 00 00 - a4 f0 d8 13 48 cc 18 00 ............H...
0018cc14 9a ec 73 75 00 00 00 00 - 00 02 00 00 a4 f0 d8 13 ..su............
0018cc24 08 00 00 00 a4 f0 d8 13 - 08 00 00 00 4c 12 75 75 ............L.uu
0018cc34 00 00 00 00 00 00 00 00 - d0 cc 18 00 08 00 00 00 ................
0018cc44 35 38 38 39 35 cc 18 00 - 40 30 73 75 00 00 00 00 58895...@0su....
0018cc54 00 02 00 00 a4 f0 d8 13 - 08 00 00 00 a4 f0 d8 13 ................
0018cc64 08 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018cc74 98 cc 18 00 9e fc 30 77 - 00 04 00 00 00 02 00 00 ......0w........
disassembling:
[...]
01197eca mov eax, [eax+$464]
01197ed0 call -$ba5689 ($5f284c) ;
Vcl.ImgList.TCustomImageList.GetBitmap
01197ed5 3634 mov dl, 1
01197ed7 mov eax, [$50242c]
01197edc call -$c8c655 ($50b88c) ; Vcl.Graphics.TBitmap.Create
01197ee1 mov [ebp-$94], eax
01197ee7 3635 mov ecx, [ebp-$94]
01197eed mov edx, $10
01197ef2 mov eax, [ebp-4]
01197ef5 mov eax, [eax+$464]
01197efb > call -$ba56b4 ($5f284c) ;
Vcl.ImgList.TCustomImageList.GetBitmap
01197f00 3638 mov eax, [ebp-4]
01197f03 mov eax, [eax+$53c]
01197f09 mov [ebp-$98], eax
01197f0f 3640 mov eax, [ebp-$98]
01197f15 call -$b4105a ($656ec0) ; Data.DB.TDataSet.Close
01197f1a 3641 mov eax, [ebp-$98]
01197f20 mov eax, [eax+$250]
01197f26 mov edx, [eax]
01197f28 call dword ptr [edx+$44]
01197f2b 3642 mov eax, [ebp-$98]
[...]
thread $cc0:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $115c:
77980166 +0e ntdll.dll NtWaitForMultipleObjects
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $580:
77980166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75773368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
739f2713 +24f netbios.dll Netbios
thread $1224:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75773368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
73a44c95 +00 winspool.drv
thread $4d8:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $167c:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
044e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06380000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
711b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
71620000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
71670000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
71680000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
716c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71700000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71720000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71830000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71a50000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71be0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71c90000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72500000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72520000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725b0000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
72840000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72880000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72a30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72a50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72a60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72db0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72fa0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73020000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73600000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73760000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
73970000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
739d0000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
739f0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73a00000 security.dll 6.1.7600.16385 C:\Windows\
system32
73a10000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73a30000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73aa0000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
73ac0000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
73ae0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73af0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73b10000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73b20000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73b40000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73b60000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73c10000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
73c30000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73ec0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73f10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73f20000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74320000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74370000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
743a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74410000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74430000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74440000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74450000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74460000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
744b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
744f0000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74500000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
74520000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751f0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75200000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75260000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
752a0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75340000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75350000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75360000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75500000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75520000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75550000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
755b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75660000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75670000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75690000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75710000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75760000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75870000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75880000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
764d0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76710000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76720000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76730000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76750000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76a00000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76ab0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76b50000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76c20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d80000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76e10000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76e20000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e30000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76ed0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76f60000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77010000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77040000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77190000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
771a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77200000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
772f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
773f0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77520000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77930000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77960000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
01fc svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0554 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
04f4 scpbradserv.exe 0 0 0
0684 svchost.exe 0 0 0
07dc core.exe 0 0 0
0910 RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b8c WUDFHost.exe 0 0 0
09c8 NisSrv.exe 0 0 0
0ecc WmiPrvSE.exe 0 0 0
0ef8 OSPPSVC.EXE 0 0 0
0eb4 taskhost.exe 1 26 24 normal
0f18 core.exe 1 9 21 normal
0acc sppsvc.exe 0 0 0
08f8 svchost.exe 0 0 0
0b54 GoogleCrashHandler.exe 0 0 0
0a9c GoogleCrashHandler64.exe 0 0 0
0aec RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
03f4 dwm.exe 1 17 4 high
0d38 explorer.exe 1 864 665 normal
0d90 PresentationFontCache.exe 0 0 0
0d98 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c60 RapportInjService_x64.exe 1 4 3 normal
0e94 msseces.exe 1 143 59 normal
0ff0 igfxEM.exe 1 14 13 normal
0c6c PrnStatusMX.exe 1 23 19 normal
0560 igfxHK.exe 1 14 12 normal
0c24 SearchIndexer.exe 0 0 0
0f5c Store.exe 1 9985 2392 normal C:\Program Files (x86)\
Store
11d8 wuauclt.exe 1 12 6 normal
12f4 splwow64.exe 1 9 4 normal
1830 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1454 OIS.EXE 1 162 96 normal
0ab4 OIS.EXE 1 132 49 normal
16b0 OIS.EXE 1 103 44 normal
0e3c OIS.EXE 1 118 50 normal
16c8 OIS.EXE 1 103 44 normal
144c OIS.EXE 1 105 43 normal
0de4 DeviceDisplayObjectProvider.exe 1 9 5 normal
14c8 rundll32.exe 1 116 44 normal
08c4 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 11039d10
ebx = 00000057
ecx = 00473c34
edx = 0018d9c8
esi = 00000100
edi = 00000000
eip = 0050691c
esp = 0018d9f8
ebp = 0018dc3c
stack dump:
0018d9f8 1c 69 50 00 de fa ed 0e - 01 00 00 00 07 00 00 00 .iP.............
0018da08 0c da 18 00 1c 69 50 00 - 10 9d 03 11 57 00 00 00 .....iP.....W...
0018da18 00 01 00 00 00 00 00 00 - 3c dc 18 00 28 da 18 00 ........<...(...
0018da28 4c dc 18 00 0c 89 40 00 - 3c dc 18 00 00 00 00 00 L.....@.<.......
0018da38 00 00 00 00 50 00 61 00 - 72 00 e2 00 6d 00 65 00 ....P.a.r...m.e.
0018da48 74 00 72 00 6f 00 20 00 - 69 00 6e 00 63 00 6f 00 t.r.o. .i.n.c.o.
0018da58 72 00 72 00 65 00 74 00 - 6f 00 2e 00 0d 00 0a 00 r.r.e.t.o.......
0018da68 00 00 40 00 ce 3d 50 00 - b0 f4 63 04 b0 f4 63 04 ..@..=P...c...c.
0018da78 e0 85 5e 04 8e 40 50 01 - c0 76 5e 04 60 64 54 05 ..^[email protected]^.`dT.
0018da88 e0 85 5e 04 b8 da 18 00 - 4c 3e 50 00 b8 f4 63 04 ..^.....L>P...c.
0018da98 54 3e 50 00 10 4a 50 00 - bc 4f d0 11 dc da 18 00 T>P..JP..O......
0018daa8 b0 f4 63 04 b0 f4 63 04 - dc da 18 00 b0 f4 63 04 ..c...c.......c.
0018dab8 d4 da 18 00 c7 46 50 00 - 98 dc 18 00 dc 46 50 00 .....FP......FP.
0018dac8 e4 46 50 00 60 64 54 05 - 60 64 54 05 8c dc 18 00 .FP.`dT.`dT.....
0018dad8 62 4a 50 00 00 00 00 00 - f5 ff ff ff 00 00 00 00 bJP.............
0018dae8 00 00 00 06 54 61 68 6f - 6d 61 00 00 00 00 00 00 ....Tahoma......
0018daf8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db08 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db18 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db28 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00eede1e mov ecx, [eax]
00eede20 call dword ptr [ecx+$38]
00eede23 1231 mov eax, [ebp-$14]
00eede26 call -$896f77 ($656eb4) ; Data.DB.TDataSet.Open
00eede2b 1232 mov eax, [ebp-$14]
00eede2e call -$8946b7 ($65977c) ; Data.DB.TDataSet.First
00eede33 1234 mov ecx, [$1605230]
00eede39 mov eax, [$1605c10]
00eede3e mov eax, [eax]
00eede40 mov edx, [$ec5358]
00eede46 > call -$8d8913 ($615538) ; Vcl.Forms.TApplication.CreateForm
00eede4b 1235 lea edx, [ebp-$60]
00eede4e mov eax, [ebp-4]
00eede51 mov eax, [eax+$3f8]
00eede57 call -$85b2c0 ($692b9c) ; Vcl.Mask.TCustomMaskEdit.GetText
00eede5c mov edx, [ebp-$60]
00eede5f mov eax, [$1605230]
00eede64 mov eax, [eax]
00eede66 mov eax, [eax+$390]
00eede6c call -$9bfb19 ($52e358) ; Vcl.Controls.TControl.SetText
00eede71 1236 mov eax, [$1605df0]
[...]
thread $cc0:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $115c:
77980166 +0e ntdll.dll NtWaitForMultipleObjects
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $580:
77980166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75773368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
739f2713 +24f netbios.dll Netbios
thread $1224:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75773368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
73a44c95 +00 winspool.drv
thread $4d8:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $167c:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
044e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06380000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
711b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
71620000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
71670000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
71680000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
716c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71700000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71720000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71830000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71a50000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71be0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71c90000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72500000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72520000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725b0000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
72840000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72880000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72a30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72a50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72a60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72db0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72fa0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73020000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73600000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73760000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
73970000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
739d0000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
739f0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73a00000 security.dll 6.1.7600.16385 C:\Windows\
system32
73a10000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73a30000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73aa0000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
73ac0000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
73ae0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73af0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73b10000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73b20000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73b40000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73b60000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73c10000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
73c30000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73ec0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73f10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73f20000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74320000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74370000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
743a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74410000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74430000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74440000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74450000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74460000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
744b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
744f0000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74500000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
74520000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751f0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75200000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75260000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
752a0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75340000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75350000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75360000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75500000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75520000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75550000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
755b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75660000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75670000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75690000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75710000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75760000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75870000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75880000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
764d0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76710000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76720000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76730000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76750000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76a00000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76ab0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76b50000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76c20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d80000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76e10000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76e20000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e30000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76ed0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76f60000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77010000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77040000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77190000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
771a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77200000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
772f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
773f0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77520000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77930000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77960000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
01fc svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0554 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
04f4 scpbradserv.exe 0 0 0
0684 svchost.exe 0 0 0
07dc core.exe 0 0 0
0910 RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b8c WUDFHost.exe 0 0 0
09c8 NisSrv.exe 0 0 0
0ecc WmiPrvSE.exe 0 0 0
0ef8 OSPPSVC.EXE 0 0 0
0eb4 taskhost.exe 1 26 24 normal
0f18 core.exe 1 9 21 normal
0acc sppsvc.exe 0 0 0
08f8 svchost.exe 0 0 0
0b54 GoogleCrashHandler.exe 0 0 0
0a9c GoogleCrashHandler64.exe 0 0 0
0aec RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
03f4 dwm.exe 1 17 4 high
0d38 explorer.exe 1 864 661 normal
0d90 PresentationFontCache.exe 0 0 0
0d98 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c60 RapportInjService_x64.exe 1 4 3 normal
0e94 msseces.exe 1 143 59 normal
0ff0 igfxEM.exe 1 14 13 normal
0c6c PrnStatusMX.exe 1 23 19 normal
0560 igfxHK.exe 1 14 12 normal
0c24 SearchIndexer.exe 0 0 0
0f5c Store.exe 1 10000 2417 normal C:\Program Files (x86)\
Store
11d8 wuauclt.exe 1 12 6 normal
12f4 splwow64.exe 1 9 3 normal
1830 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1454 OIS.EXE 1 162 96 normal
0ab4 OIS.EXE 1 132 49 normal
16b0 OIS.EXE 1 103 44 normal
0e3c OIS.EXE 1 118 50 normal
16c8 OIS.EXE 1 103 44 normal
144c OIS.EXE 1 105 43 normal
0de4 DeviceDisplayObjectProvider.exe 1 9 5 normal
14c8 rundll32.exe 1 116 44 normal
08c4 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0e08ce20
ebx = 00000000
ecx = 00473c34
edx = 0018da88
esi = 13dc93e0
edi = b7083825
eip = 00506880
esp = 0018dab8
ebp = 0018daf8
stack dump:
0018dab8 80 68 50 00 de fa ed 0e - 01 00 00 00 07 00 00 00 .hP.............
0018dac8 cc da 18 00 80 68 50 00 - 20 ce 08 0e 00 00 00 00 .....hP. .......
0018dad8 e0 93 dc 13 25 38 08 b7 - f8 da 18 00 e8 da 18 00 ....%8..........
0018dae8 00 db 18 00 0c 89 40 00 - f8 da 18 00 00 00 00 00 ......@.........
0018daf8 14 dd 18 00 23 69 50 00 - 24 dd 18 00 0c 89 40 00 ....#iP.$.....@.
0018db08 14 dd 18 00 00 00 00 00 - 00 00 00 00 dc dc 18 00 ................
0018db18 d0 cc e0 13 dc dc 18 00 - 28 fc 52 00 dc dc 18 00 ........(.R.....
0018db28 9e 0b 36 04 d0 cc e0 13 - 70 dd 18 00 b6 a6 36 77 ..6.....p.....6w
0018db38 1f 24 82 1d fe ff ff ff - 51 6d 30 77 3f 0d 31 77 .$......Qm0w?.1w
0018db48 00 00 00 00 54 5f a0 77 - 24 10 0d 00 30 00 00 00 ....T_.w$...0...
0018db58 29 09 0a 07 01 00 00 00 - 00 00 00 00 00 00 00 00 )...............
0018db68 30 00 00 00 d0 cc e0 13 - 04 06 62 00 00 00 00 00 0.........b.....
0018db78 98 db 18 00 65 0d 31 77 - 54 5f a0 77 24 10 0d 00 ....e.1wT_.w$...
0018db88 30 00 00 00 29 09 0a 07 - 01 00 00 00 00 00 00 00 0...)...........
0018db98 ec dc 18 00 85 46 53 00 - 54 5f a0 77 24 10 0d 00 .....FS.T_.w$...
0018dba8 30 00 00 00 29 09 0a 07 - 01 00 00 00 ec dc 18 00 0...)...........
0018dbb8 04 dc 18 00 88 45 53 00 - 9e 0b 36 04 d0 cc e0 13 .....ES...6.....
0018dbc8 54 dd 18 00 00 00 04 00 - 00 b8 fd 7e f4 db 18 00 T..........~....
0018dbd8 dc 83 40 00 d0 9f 62 04 - c9 7f 40 00 01 00 04 00 [email protected]...@.....
0018dbe8 00 b8 fd 7e 89 7e 40 00 - 70 0d 63 04 73 81 40 00 [email protected].@.
disassembling:
[...]
00eedd87 mov eax, [eax+$3ac]
00eedd8d call -$9bfa3a ($52e358) ; Vcl.Controls.TControl.SetText
00eedd92 1219 mov edx, [$1605718]
00eedd98 mov edx, [edx]
00eedd9a mov eax, [$1605718]
00eedd9f mov eax, [eax]
00eedda1 call -$3024aa ($beb8fc) ;
UnitStatus.TfrmStatus.EditTransportadoraExit
00eedda6 1222 mov eax, [$1605718]
00eeddab mov eax, [eax]
00eeddad mov edx, [eax]
00eeddaf > call dword ptr [edx+$120]
00eeddb5 1223 mov eax, [$1605718]
00eeddba mov eax, [eax]
00eeddbc call -$ae67d5 ($4075ec) ; System.TObject.Free
00eeddc1 1226 mov eax, [$1605df0]
00eeddc6 mov eax, [eax]
00eeddc8 mov eax, [eax+$27c]
00eeddce mov [ebp-$14], eax
00eeddd1 1228 mov eax, [ebp-$14]
00eeddd4 call -$896f19 ($656ec0) ; Data.DB.TDataSet.Close
00eeddd9 1229 mov eax, [ebp-$14]
[...]
date/time : 2020-08-11, 20:19:16, 818ms
computer name : VIDRARIA-06
user name : Karina Kinaki <admin>
registered owner : Karina Kinaki
operating system : Windows 7 x64 Service Pack 1 build 7601
system language : Portuguese
system up time : 12 hours 52 minutes
program up time : 12 hours 49 minutes
processors : 4x Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
physical memory : 1993/3968 MB (free/total)
free disk space : (C:) 58,32 GB
display mode : 1600x900, 32 bit
process id : $f5c
allocated memory : 161,92 MB
largest free block : 895,25 MB
executable : Store.exe
exec. date/time : 2020-07-15 13:10
version : 1.0.0.0
bde version : 5.2.0.2
compiled with : Delphi XE2
madExcept version : 4.0.20
callstack crc : $c67320e6, $4d50aed1, $0bc41563
exception number : 11
exception class : EInvalidOperation
exception message : Canvas does not allow drawing.
thread $cc0:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $115c:
77980166 +0e ntdll.dll NtWaitForMultipleObjects
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $580:
77980166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75773368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
739f2713 +24f netbios.dll Netbios
thread $1224:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75773368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
73a44c95 +00 winspool.drv
thread $4d8:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $167c:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
044e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06380000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
711b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
71620000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
71670000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
71680000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
716c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71700000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71720000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71830000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71a50000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71be0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71c90000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72500000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72520000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725b0000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
72840000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72880000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72a30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72a50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72a60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72db0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72fa0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73020000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73600000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73760000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
73970000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
739d0000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
739f0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73a00000 security.dll 6.1.7600.16385 C:\Windows\
system32
73a10000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73a30000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73aa0000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
73ac0000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
73ae0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73af0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73b10000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73b20000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73b40000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73b60000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73c10000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
73c30000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73ec0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73f10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73f20000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74320000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74370000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
743a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74410000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74430000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74440000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74450000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74460000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
744b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
744f0000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74500000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
74520000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751f0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75200000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75260000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
752a0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75340000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75350000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75360000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75500000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75520000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75550000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
755b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75660000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75670000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75690000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75710000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75760000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75870000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75880000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
764d0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76710000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76720000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76730000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76750000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76a00000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76ab0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76b50000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76c20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d80000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76e10000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76e20000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e30000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76ed0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76f60000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77010000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77040000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77190000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
771a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77200000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
772f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
773f0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77520000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77930000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77960000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
01fc svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0554 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
04f4 scpbradserv.exe 0 0 0
0684 svchost.exe 0 0 0
07dc core.exe 0 0 0
0910 RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b8c WUDFHost.exe 0 0 0
09c8 NisSrv.exe 0 0 0
0ecc WmiPrvSE.exe 0 0 0
0ef8 OSPPSVC.EXE 0 0 0
0eb4 taskhost.exe 1 26 23 normal
0f18 core.exe 1 9 21 normal
0acc sppsvc.exe 0 0 0
08f8 svchost.exe 0 0 0
0b54 GoogleCrashHandler.exe 0 0 0
0a9c GoogleCrashHandler64.exe 0 0 0
0aec RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
03f4 dwm.exe 1 19 5 high
0d38 explorer.exe 1 896 667 normal
0d90 PresentationFontCache.exe 0 0 0
0d98 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c60 RapportInjService_x64.exe 1 4 3 normal
0e94 msseces.exe 1 143 59 normal
0ff0 igfxEM.exe 1 14 13 normal
0c6c PrnStatusMX.exe 1 23 19 normal
0560 igfxHK.exe 1 14 12 normal
0c24 SearchIndexer.exe 0 0 0
0f5c Store.exe 1 10000 2416 normal C:\Program Files (x86)\
Store
11d8 wuauclt.exe 1 12 6 normal
12f4 splwow64.exe 1 9 2 normal
1830 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1454 OIS.EXE 1 164 97 normal
0ab4 OIS.EXE 1 132 49 normal
16b0 OIS.EXE 1 103 44 normal
0e3c OIS.EXE 1 118 50 normal
16c8 OIS.EXE 1 103 44 normal
144c OIS.EXE 1 105 43 normal
0de4 DeviceDisplayObjectProvider.exe 1 9 5 normal
14c8 rundll32.exe 1 116 44 normal
08c4 audiodg.exe 0 0 0
1258 svchost.exe 0 0 0
15fc Store.exe 1 140 186 normal C:\Program Files (x86)\
Store
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0e08ce20
ebx = 00000000
ecx = 00473c34
edx = 0018da88
esi = 13dc93e0
edi = b7083825
eip = 00506880
esp = 0018dab8
ebp = 0018daf8
stack dump:
0018dab8 80 68 50 00 de fa ed 0e - 01 00 00 00 07 00 00 00 .hP.............
0018dac8 cc da 18 00 80 68 50 00 - 20 ce 08 0e 00 00 00 00 .....hP. .......
0018dad8 e0 93 dc 13 25 38 08 b7 - f8 da 18 00 e8 da 18 00 ....%8..........
0018dae8 00 db 18 00 0c 89 40 00 - f8 da 18 00 00 00 00 00 ......@.........
0018daf8 14 dd 18 00 23 69 50 00 - 24 dd 18 00 0c 89 40 00 ....#iP.$.....@.
0018db08 14 dd 18 00 00 00 00 00 - 00 00 00 00 dc dc 18 00 ................
0018db18 d0 cc e0 13 dc dc 18 00 - 28 fc 52 00 dc dc 18 00 ........(.R.....
0018db28 9e 0b 36 04 d0 cc e0 13 - 70 dd 18 00 b6 a6 36 77 ..6.....p.....6w
0018db38 1f 24 82 1d fe ff ff ff - 51 6d 30 77 3f 0d 31 77 .$......Qm0w?.1w
0018db48 00 00 00 00 54 5f a0 77 - 24 10 0d 00 30 00 00 00 ....T_.w$...0...
0018db58 29 09 0a 07 01 00 00 00 - 00 00 00 00 00 00 00 00 )...............
0018db68 30 00 00 00 d0 cc e0 13 - 04 06 62 00 00 00 00 00 0.........b.....
0018db78 98 db 18 00 65 0d 31 77 - 54 5f a0 77 24 10 0d 00 ....e.1wT_.w$...
0018db88 30 00 00 00 29 09 0a 07 - 01 00 00 00 00 00 00 00 0...)...........
0018db98 ec dc 18 00 85 46 53 00 - 54 5f a0 77 24 10 0d 00 .....FS.T_.w$...
0018dba8 30 00 00 00 29 09 0a 07 - 01 00 00 00 ec dc 18 00 0...)...........
0018dbb8 04 dc 18 00 88 45 53 00 - 9e 0b 36 04 d0 cc e0 13 .....ES...6.....
0018dbc8 54 dd 18 00 00 00 04 00 - 00 b8 fd 7e f4 db 18 00 T..........~....
0018dbd8 dc 83 40 00 d0 9f 62 04 - c9 7f 40 00 01 00 04 00 [email protected]...@.....
0018dbe8 00 b8 fd 7e 89 7e 40 00 - 70 0d 63 04 73 81 40 00 [email protected].@.
disassembling:
[...]
00eedd87 mov eax, [eax+$3ac]
00eedd8d call -$9bfa3a ($52e358) ; Vcl.Controls.TControl.SetText
00eedd92 1219 mov edx, [$1605718]
00eedd98 mov edx, [edx]
00eedd9a mov eax, [$1605718]
00eedd9f mov eax, [eax]
00eedda1 call -$3024aa ($beb8fc) ;
UnitStatus.TfrmStatus.EditTransportadoraExit
00eedda6 1222 mov eax, [$1605718]
00eeddab mov eax, [eax]
00eeddad mov edx, [eax]
00eeddaf > call dword ptr [edx+$120]
00eeddb5 1223 mov eax, [$1605718]
00eeddba mov eax, [eax]
00eeddbc call -$ae67d5 ($4075ec) ; System.TObject.Free
00eeddc1 1226 mov eax, [$1605df0]
00eeddc6 mov eax, [eax]
00eeddc8 mov eax, [eax+$27c]
00eeddce mov [ebp-$14], eax
00eeddd1 1228 mov eax, [ebp-$14]
00eeddd4 call -$896f19 ($656ec0) ; Data.DB.TDataSet.Close
00eeddd9 1229 mov eax, [ebp-$14]
[...]
thread $cc0:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $115c:
77980166 +0e ntdll.dll NtWaitForMultipleObjects
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $580:
77980166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75773368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
739f2713 +24f netbios.dll Netbios
thread $1224:
7797f8da +0e ntdll.dll NtWaitForSingleObject
757215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7577118f +3e kernel32.dll WaitForSingleObjectEx
75771143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75773368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1160) at:
73a44c95 +00 winspool.drv
thread $4d8:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
thread $167c:
77981f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75773368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
044e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06380000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
711b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
71620000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
71670000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
71680000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
716c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71700000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71720000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71830000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71a50000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71be0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71c90000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72500000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72520000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725b0000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
72840000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72880000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72a30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72a50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72a60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72db0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72fa0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73020000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73600000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73760000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
73970000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
739d0000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
739f0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73a00000 security.dll 6.1.7600.16385 C:\Windows\
system32
73a10000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73a30000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73aa0000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
73ac0000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
73ae0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73af0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73b10000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73b20000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73b40000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73b60000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73c10000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
73c30000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73ec0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73f10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73f20000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74320000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74370000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
743a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
743d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74410000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74430000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74440000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74450000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74460000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
744b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
744f0000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74500000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
74520000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
746c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
746d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
751f0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75200000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75260000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
752a0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75340000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75350000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75360000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75500000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75520000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75550000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
755b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75660000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75670000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75690000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75710000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75760000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75870000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75880000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
764d0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76710000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76720000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76730000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76750000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76a00000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76ab0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76b50000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76c20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d80000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76e10000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76e20000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e30000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76ed0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76f60000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77010000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77040000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77190000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
771a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77200000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
772f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
773f0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77520000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77930000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77960000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
01fc svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0554 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
04f4 scpbradserv.exe 0 0 0
0684 svchost.exe 0 0 0
07dc core.exe 0 0 0
0910 RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b8c WUDFHost.exe 0 0 0
09c8 NisSrv.exe 0 0 0
0ecc WmiPrvSE.exe 0 0 0
0ef8 OSPPSVC.EXE 0 0 0
0eb4 taskhost.exe 1 26 23 normal
0f18 core.exe 1 9 21 normal
0acc sppsvc.exe 0 0 0
08f8 svchost.exe 0 0 0
0b54 GoogleCrashHandler.exe 0 0 0
0a9c GoogleCrashHandler64.exe 0 0 0
0aec RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
03f4 dwm.exe 1 19 5 high
0d38 explorer.exe 1 896 667 normal
0d90 PresentationFontCache.exe 0 0 0
0d98 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c60 RapportInjService_x64.exe 1 4 3 normal
0e94 msseces.exe 1 143 59 normal
0ff0 igfxEM.exe 1 14 13 normal
0c6c PrnStatusMX.exe 1 23 19 normal
0560 igfxHK.exe 1 14 12 normal
0c24 SearchIndexer.exe 0 0 0
0f5c Store.exe 1 10000 2416 normal C:\Program Files (x86)\
Store
11d8 wuauclt.exe 1 12 6 normal
12f4 splwow64.exe 1 9 2 normal
1830 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1454 OIS.EXE 1 164 97 normal
0ab4 OIS.EXE 1 132 49 normal
16b0 OIS.EXE 1 103 44 normal
0e3c OIS.EXE 1 118 50 normal
16c8 OIS.EXE 1 103 44 normal
144c OIS.EXE 1 105 43 normal
0de4 DeviceDisplayObjectProvider.exe 1 9 5 normal
14c8 rundll32.exe 1 116 44 normal
08c4 audiodg.exe 0 0 0
1258 svchost.exe 0 0 0
15fc Store.exe 1 170 326 normal C:\Program Files (x86)\
Store
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0e08ce20
ebx = 00000000
ecx = 00473c34
edx = 0018da88
esi = 13dc93e0
edi = b7083825
eip = 00506880
esp = 0018dab8
ebp = 0018daf8
stack dump:
0018dab8 80 68 50 00 de fa ed 0e - 01 00 00 00 07 00 00 00 .hP.............
0018dac8 cc da 18 00 80 68 50 00 - 20 ce 08 0e 00 00 00 00 .....hP. .......
0018dad8 e0 93 dc 13 25 38 08 b7 - f8 da 18 00 e8 da 18 00 ....%8..........
0018dae8 00 db 18 00 0c 89 40 00 - f8 da 18 00 00 00 00 00 ......@.........
0018daf8 14 dd 18 00 23 69 50 00 - 24 dd 18 00 0c 89 40 00 ....#iP.$.....@.
0018db08 14 dd 18 00 00 00 00 00 - 00 00 00 00 dc dc 18 00 ................
0018db18 d0 cc e0 13 dc dc 18 00 - 28 fc 52 00 dc dc 18 00 ........(.R.....
0018db28 9e 0b 36 04 d0 cc e0 13 - 70 dd 18 00 b6 a6 36 77 ..6.....p.....6w
0018db38 1f 24 82 1d fe ff ff ff - 51 6d 30 77 3f 0d 31 77 .$......Qm0w?.1w
0018db48 00 00 00 00 54 5f a0 77 - 24 10 0d 00 30 00 00 00 ....T_.w$...0...
0018db58 29 09 0a 07 01 00 00 00 - 00 00 00 00 00 00 00 00 )...............
0018db68 30 00 00 00 d0 cc e0 13 - 04 06 62 00 00 00 00 00 0.........b.....
0018db78 98 db 18 00 65 0d 31 77 - 54 5f a0 77 24 10 0d 00 ....e.1wT_.w$...
0018db88 30 00 00 00 29 09 0a 07 - 01 00 00 00 00 00 00 00 0...)...........
0018db98 ec dc 18 00 85 46 53 00 - 54 5f a0 77 24 10 0d 00 .....FS.T_.w$...
0018dba8 30 00 00 00 29 09 0a 07 - 01 00 00 00 ec dc 18 00 0...)...........
0018dbb8 04 dc 18 00 88 45 53 00 - 9e 0b 36 04 d0 cc e0 13 .....ES...6.....
0018dbc8 54 dd 18 00 00 00 04 00 - 00 b8 fd 7e f4 db 18 00 T..........~....
0018dbd8 dc 83 40 00 d0 9f 62 04 - c9 7f 40 00 01 00 04 00 [email protected]...@.....
0018dbe8 00 b8 fd 7e 89 7e 40 00 - 70 0d 63 04 73 81 40 00 [email protected].@.
disassembling:
[...]
00eedd87 mov eax, [eax+$3ac]
00eedd8d call -$9bfa3a ($52e358) ; Vcl.Controls.TControl.SetText
00eedd92 1219 mov edx, [$1605718]
00eedd98 mov edx, [edx]
00eedd9a mov eax, [$1605718]
00eedd9f mov eax, [eax]
00eedda1 call -$3024aa ($beb8fc) ;
UnitStatus.TfrmStatus.EditTransportadoraExit
00eedda6 1222 mov eax, [$1605718]
00eeddab mov eax, [eax]
00eeddad mov edx, [eax]
00eeddaf > call dword ptr [edx+$120]
00eeddb5 1223 mov eax, [$1605718]
00eeddba mov eax, [eax]
00eeddbc call -$ae67d5 ($4075ec) ; System.TObject.Free
00eeddc1 1226 mov eax, [$1605df0]
00eeddc6 mov eax, [eax]
00eeddc8 mov eax, [eax+$27c]
00eeddce mov [ebp-$14], eax
00eeddd1 1228 mov eax, [ebp-$14]
00eeddd4 call -$896f19 ($656ec0) ; Data.DB.TDataSet.Close
00eeddd9 1229 mov eax, [ebp-$14]
[...]
thread $1328:
77caf8da +0e ntdll.dll NtWaitForSingleObject
76df15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7572118f +3e kernel32.dll WaitForSingleObjectEx
75721143 +0d kernel32.dll WaitForSingleObject
75723368 +10 kernel32.dll BaseThreadInitThunk
thread $12bc:
77cb0166 +0e ntdll.dll NtWaitForMultipleObjects
75723368 +10 kernel32.dll BaseThreadInitThunk
thread $1280:
77cb0166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75723368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($12dc) at:
73602713 +24f netbios.dll Netbios
thread $12c4:
77caf8da +0e ntdll.dll NtWaitForSingleObject
76df15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7572118f +3e kernel32.dll WaitForSingleObjectEx
75721143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75723368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($12dc) at:
737a4c95 +00 winspool.drv
thread $678:
77cb1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75723368 +10 kernel32.dll BaseThreadInitThunk
thread $d00:
77cb1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75723368 +10 kernel32.dll BaseThreadInitThunk
thread $ce4:
77cb1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75723368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
002f0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
04390000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063c0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71590000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
718c0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71b90000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71fb0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
72050000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
72070000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
72650000 webio.dll 6.1.7601.23375 C:\Windows\
system32
726b0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72710000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72ab0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72ad0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72b70000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72bb0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72d60000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72d80000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72d90000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72f30000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
735d0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73600000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73610000 security.dll 6.1.7600.16385 C:\Windows\
system32
73620000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73630000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73690000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73790000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73f90000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
741c0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74210000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74260000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74280000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
74290000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
742b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
742c0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
74590000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
746a0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
746d0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74700000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74740000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74760000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74770000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74780000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
747e0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74850000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
749f0000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a00000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75520000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75590000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
755e0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
756e0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75700000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75710000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75820000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75830000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75900000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75a50000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75a80000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75b10000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75d00000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75d20000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d30000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d40000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75d50000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75d60000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75e90000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75fa0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76bf0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76c90000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76d40000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76de0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76e40000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76e50000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76eb0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76f40000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76f70000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76f80000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
771c0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
771e0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77220000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77230000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
773d0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77430000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
776e0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77790000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
777a0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
77c60000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77c90000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f4 csrss.exe 0 0 0
0250 wininit.exe 0 0 0
0258 csrss.exe 1 0 0
0290 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
02ac svchost.exe 0 0 0
03cc svchost.exe 0 0 0
0408 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
0498 svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0570 svchost.exe 0 0 0
0630 spoolsv.exe 0 0 0
063c taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0724 svchost.exe 0 0 0
0748 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
0464 svchost.exe 0 0 0
053c scpbradserv.exe 0 0 0
0700 svchost.exe 0 0 0
07e4 core.exe 0 0 0
0984 fbserver.exe 0 0 0
0ad4 RapportInjService_x64.exe 0 0 0
0af4 WUDFHost.exe 0 0 0
0b5c taskhost.exe 1 26 23 normal
0ba0 core.exe 1 9 21 normal
05fc sppsvc.exe 0 0 0
0e54 NisSrv.exe 0 0 0
0f9c RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0c84 GoogleCrashHandler.exe 0 0 0
0c34 GoogleCrashHandler64.exe 0 0 0
0f3c RapportInjService_x64.exe 1 4 3 normal
0d84 PresentationFontCache.exe 0 0 0
0ea4 dwm.exe 1 18 4 high
08e0 explorer.exe 1 444 250 normal
0ef0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0cc4 igfxEM.exe 1 14 13 normal
0cb8 igfxHK.exe 1 14 12 normal
0c48 svchost.exe 0 0 0
10c8 msseces.exe 1 143 60 normal
10dc PrnStatusMX.exe 1 23 20 normal
1288 WmiPrvSE.exe 0 0 0
12c8 OSPPSVC.EXE 0 0 0
1354 SearchIndexer.exe 0 0 0
12e8 Store.exe 1 854 314 normal C:\Program Files (x86)\Store
1170 wuauclt.exe 1 12 6 normal
13b4 OIS.EXE 1 105 45 normal
1024 splwow64.exe 1 9 3 normal
13d0 chrome.exe 1 27 59 normal
11a8 chrome.exe 1 9 4 normal
0b94 chrome.exe 1 7 6 above normal
0670 chrome.exe 1 4 1 normal
10ec chrome.exe 1 4 1 normal
1208 chrome.exe 1 4 1 idle
09e4 chrome.exe 1 4 3 normal
09a0 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
0f70 audiodg.exe 0 0 0
0c9c OIS.EXE 1 117 71 normal
08c8 OIS.EXE 1 132 49 normal
0a30 svchost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 064d5170
ebx = 00003303
ecx = 00000000
edx = 02642ac8
esi = 0018df48
edi = 0066c7e4
eip = 0066e702
esp = 0018df0c
ebp = 0018df74
stack dump:
0018df0c 02 e7 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018df1c 20 df 18 00 02 e7 66 00 - 70 51 4d 06 03 33 00 00 .....f.pQM..3..
0018df2c 48 df 18 00 e4 c7 66 00 - 74 df 18 00 3c df 18 00 H.....f.t...<...
0018df3c 50 50 55 06 0e e7 66 00 - 34 e6 67 00 00 00 00 00 PPU...f.4.g.....
0018df4c 50 50 55 06 00 00 00 00 - 2f e5 67 00 80 df 18 00 PPU...../.g.....
0018df5c 0c 89 40 00 74 df 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018df6c 69 e6 67 01 50 50 55 06 - 9c df 18 00 87 e5 67 00 i.g.PPU.......g.
0018df7c a6 49 67 00 b4 df 18 00 - 0c 89 40 00 9c df 18 00 .Ig.......@.....
0018df8c 50 50 55 06 00 00 00 00 - 00 00 00 00 50 50 55 06 PPU.........PPU.
0018df9c c8 df 18 00 4a 8f 67 00 - 6c e3 18 00 40 32 3c 0b ....J.g.l...@2<.
0018dfac 01 00 00 00 77 70 65 00 - d4 df 18 00 0c 89 40 00 ....wpe.......@.
0018dfbc c8 df 18 00 40 32 3c 0b - 50 50 55 06 98 e0 18 00 ....@2<.PPU.....
0018dfcc be 6e 65 00 1c 4c 16 01 - a0 e0 18 00 0c 89 40 00 .ne..L........@.
0018dfdc 98 e0 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dfec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e00c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e01c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e02c 00 00 00 00 00 00 00 00 - 40 7b e5 40 d0 2c 4e 06 ........@{.@.,N.
0018e03c 00 00 00 00 fa a4 4f fa - ff 82 e5 40 00 00 00 00 ......O....@....
disassembling:
[...]
01164bf3 mov eax, [ebp-$18]
01164bf6 mov eax, [eax+$250]
01164bfc mov ecx, [eax]
01164bfe call dword ptr [ecx+$38]
01164c01 425 mov edx, $1165c54
01164c06 mov eax, [ebp-$18]
01164c09 mov eax, [eax+$250]
01164c0f mov ecx, [eax]
01164c11 call dword ptr [ecx+$38]
01164c14 427 mov eax, [ebp-$18]
01164c17 > call -$b0dd68 ($656eb4) ; Data.DB.TDataSet.Open
01164c1c 428 mov eax, [ebp-$18]
01164c1f call -$b0b4a8 ($65977c) ; Data.DB.TDataSet.First
01164c24 429 mov eax, [ebp-$18]
01164c27 cmp byte ptr [eax+$a9], 0
01164c2e jz loc_1164c3c
01164c30 mov eax, [ebp-$18]
01164c33 cmp byte ptr [eax+$a8], 0
01164c3a jnz loc_1164c4b
01164c3c 431 mov eax, [ebp-4]
01164c3f call +$32fb4 ($1197bf8) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $1328:
77caf8da +0e ntdll.dll NtWaitForSingleObject
76df15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7572118f +3e kernel32.dll WaitForSingleObjectEx
75721143 +0d kernel32.dll WaitForSingleObject
75723368 +10 kernel32.dll BaseThreadInitThunk
thread $12bc:
77cb0166 +0e ntdll.dll NtWaitForMultipleObjects
75723368 +10 kernel32.dll BaseThreadInitThunk
thread $1280:
77cb0166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75723368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($12dc) at:
73602713 +24f netbios.dll Netbios
thread $12c4:
77caf8da +0e ntdll.dll NtWaitForSingleObject
76df15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7572118f +3e kernel32.dll WaitForSingleObjectEx
75721143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75723368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($12dc) at:
737a4c95 +00 winspool.drv
thread $1380:
77cb1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75723368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
002f0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
04390000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063c0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71590000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
718c0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71b90000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71fb0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
72050000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
72070000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
72650000 webio.dll 6.1.7601.23375 C:\Windows\
system32
726b0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72710000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72ab0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72ad0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72b70000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72bb0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72d60000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72d80000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72d90000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72f30000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
735d0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73600000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73610000 security.dll 6.1.7600.16385 C:\Windows\
system32
73620000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73630000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73690000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73790000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73f90000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
741c0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74210000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74260000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74280000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
74290000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
742b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
742c0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
74590000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
746a0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
746d0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74700000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74740000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74760000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74770000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74780000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
747e0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74850000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
749f0000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a00000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75520000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75590000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
755e0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
756e0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75700000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75710000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75820000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75830000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75900000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75a50000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75a80000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75b10000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75d00000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75d20000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d30000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d40000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75d50000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75d60000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75e90000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75fa0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76bf0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76c90000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76d40000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76de0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76e30000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e40000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76e50000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76eb0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76f40000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76f70000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76f80000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
771c0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
771e0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77220000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77230000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
773d0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77430000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
776e0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77790000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
777a0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
77c60000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77c90000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f4 csrss.exe 0 0 0
0250 wininit.exe 0 0 0
0258 csrss.exe 1 0 0
0290 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
02ac svchost.exe 0 0 0
03cc svchost.exe 0 0 0
0408 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
0498 svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0570 svchost.exe 0 0 0
0630 spoolsv.exe 0 0 0
063c taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0724 svchost.exe 0 0 0
0748 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
0464 svchost.exe 0 0 0
053c scpbradserv.exe 0 0 0
0700 svchost.exe 0 0 0
07e4 core.exe 0 0 0
0984 fbserver.exe 0 0 0
0ad4 RapportInjService_x64.exe 0 0 0
0af4 WUDFHost.exe 0 0 0
0b5c taskhost.exe 1 26 23 normal
0ba0 core.exe 1 9 21 normal
05fc sppsvc.exe 0 0 0
0e54 NisSrv.exe 0 0 0
0f9c RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0c84 GoogleCrashHandler.exe 0 0 0
0c34 GoogleCrashHandler64.exe 0 0 0
0f3c RapportInjService_x64.exe 1 4 3 normal
0d84 PresentationFontCache.exe 0 0 0
0ea4 dwm.exe 1 18 4 high
08e0 explorer.exe 1 464 274 normal
0ef0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0cc4 igfxEM.exe 1 14 13 normal
0cb8 igfxHK.exe 1 14 12 normal
0c48 svchost.exe 0 0 0
10c8 msseces.exe 1 143 60 normal
10dc PrnStatusMX.exe 1 23 20 normal
1288 WmiPrvSE.exe 0 0 0
12c8 OSPPSVC.EXE 0 0 0
1354 SearchIndexer.exe 0 0 0
12e8 Store.exe 1 2013 508 normal C:\Program Files (x86)\Store
1170 wuauclt.exe 1 12 6 normal
13b4 OIS.EXE 1 105 45 normal
1024 splwow64.exe 1 9 4 normal
13d0 chrome.exe 1 28 52 normal
11a8 chrome.exe 1 9 4 normal
0b94 chrome.exe 1 7 7 above normal
0670 chrome.exe 1 4 1 normal
10ec chrome.exe 1 4 1 normal
09e4 chrome.exe 1 4 3 normal
09a0 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0c9c OIS.EXE 1 117 71 normal
08c8 OIS.EXE 1 132 49 normal
0478 OIS.EXE 1 112 49 normal
0680 audiodg.exe 0 0 0
084c chrome.exe 1 4 1 idle
09f0 rundll32.exe 1 116 52 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 045e3190
ebx = 0a3f70e0
ecx = 77caf8da
edx = 04653c40
esi = 005531a4
edi = 0018e334
eip = 0068710d
esp = 0018e18c
ebp = 0018e2cc
stack dump:
0018e18c 81 01 53 00 e0 70 3f 0a - c7 31 55 00 34 e3 18 00 ..S..p?..1U.4...
0018e19c f5 3c 55 00 e0 70 3f 0a - 28 fc 52 00 34 e3 18 00 .<U..p?.(.R.4...
0018e1ac 4c e5 18 00 e0 70 3f 0a - 3b 00 00 00 d4 e1 18 00 L....p?.;.......
0018e1bc 93 5d 63 75 20 00 00 00 - d0 e1 18 00 20 24 60 75 .]cu ....... $`u
0018e1cc 0a 80 00 00 70 e2 18 00 - ac 2f 62 75 0a 80 00 00 ....p..../bu....
0018e1dc 9e 03 64 00 fc ff ff ff - 00 00 00 00 00 00 00 00 ..d.............
0018e1ec f3 00 00 00 05 8b 61 75 - 3b 00 00 00 14 e2 18 00 ......au;.......
0018e1fc 93 5d 63 75 9e 03 64 00 - 01 00 00 00 75 09 10 1c .]cu..d.....u...
0018e20c b9 12 01 32 00 00 00 00 - b0 e2 18 00 00 00 00 00 ...2............
0018e21c 08 b5 47 0a 00 00 00 00 - 9e 03 64 00 00 00 00 00 ..G.......d.....
0018e22c f3 00 00 00 05 8b 61 75 - f3 00 00 00 05 8b 61 75 ......au......au
0018e23c 00 00 00 00 15 02 00 00 - 05 8b 61 75 75 09 10 1c ..........auu...
0018e24c b9 12 01 32 00 00 00 00 - d1 01 00 00 01 00 00 00 ...2............
0018e25c ea 28 60 75 00 00 00 00 - 00 00 00 00 01 00 00 00 .(`u............
0018e26c 00 00 00 00 00 00 00 00 - 00 00 00 00 9e 03 64 00 ..............d.
0018e27c 00 00 00 00 f3 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e28c 00 00 00 00 54 5f d3 77 - 00 00 00 00 c4 e2 18 00 ....T_.w........
0018e29c fa 62 5f 75 9e 03 64 00 - f3 00 00 00 00 00 00 00 .b_u..d.........
0018e2ac 00 00 00 00 54 5f d3 77 - cd ab ba dc 00 00 00 00 ....T_.w........
0018e2bc 00 00 00 00 00 00 00 00 - 00 00 00 00 7d fa ca 77 ............}..w
disassembling:
00687104 public QRPrgres.TQRProgressForm.CancelButtonClick: ; function entry
point
00687104 50 mov edx, [eax+$39c]
0068710a mov ecx, [edx+8]
0068710d > mov byte ptr [ecx+$3d0], 1
00687114 51 mov eax, edx
00687116 call +$7ecd1 ($705dec) ; QRPrntr.TQRPrinter.Cancel
0068711b 52 ret
thread $1328:
77caf8da +0e ntdll.dll NtWaitForSingleObject
76df15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7572118f +3e kernel32.dll WaitForSingleObjectEx
75721143 +0d kernel32.dll WaitForSingleObject
75723368 +10 kernel32.dll BaseThreadInitThunk
thread $12bc:
77cb0166 +0e ntdll.dll NtWaitForMultipleObjects
75723368 +10 kernel32.dll BaseThreadInitThunk
thread $1280:
77cb0166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75723368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($12dc) at:
73602713 +24f netbios.dll Netbios
thread $12c4:
77caf8da +0e ntdll.dll NtWaitForSingleObject
76df15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7572118f +3e kernel32.dll WaitForSingleObjectEx
75721143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75723368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($12dc) at:
737a4c95 +00 winspool.drv
thread $1380:
77cb1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75723368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
002f0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
04390000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063c0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71590000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
718c0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71b90000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71fb0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
72050000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
72070000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
72650000 webio.dll 6.1.7601.23375 C:\Windows\
system32
726b0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72710000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72ab0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72ad0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72b70000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72bb0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72d60000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72d80000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72d90000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72f30000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
735d0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73600000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73610000 security.dll 6.1.7600.16385 C:\Windows\
system32
73620000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73630000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73690000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73790000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73f90000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
741c0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74210000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74260000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74280000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
74290000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
742b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
742c0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
74590000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
746a0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
746d0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74700000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74740000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74760000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74770000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74780000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
747e0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74850000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
749f0000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a00000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75520000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75590000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
755e0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
756e0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75700000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75710000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75820000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75830000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75900000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75a50000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75a80000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75b10000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75d00000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75d20000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d30000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d40000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75d50000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75d60000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75e90000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75fa0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76bf0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76c90000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76d40000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76de0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76e30000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e40000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76e50000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76eb0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76f40000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76f70000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76f80000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
771c0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
771e0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77220000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77230000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
773d0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77430000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
776e0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77790000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
777a0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
77c60000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77c90000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f4 csrss.exe 0 0 0
0250 wininit.exe 0 0 0
0258 csrss.exe 1 0 0
0290 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
02ac svchost.exe 0 0 0
03cc svchost.exe 0 0 0
0408 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
0498 svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0570 svchost.exe 0 0 0
0630 spoolsv.exe 0 0 0
063c taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0724 svchost.exe 0 0 0
0748 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
0464 svchost.exe 0 0 0
053c scpbradserv.exe 0 0 0
0700 svchost.exe 0 0 0
07e4 core.exe 0 0 0
0984 fbserver.exe 0 0 0
0ad4 RapportInjService_x64.exe 0 0 0
0af4 WUDFHost.exe 0 0 0
0b5c taskhost.exe 1 26 23 normal
0ba0 core.exe 1 9 21 normal
05fc sppsvc.exe 0 0 0
0e54 NisSrv.exe 0 0 0
0f9c RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0c84 GoogleCrashHandler.exe 0 0 0
0c34 GoogleCrashHandler64.exe 0 0 0
0f3c RapportInjService_x64.exe 1 4 3 normal
0d84 PresentationFontCache.exe 0 0 0
0ea4 dwm.exe 1 18 4 high
08e0 explorer.exe 1 464 274 normal
0ef0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0cc4 igfxEM.exe 1 14 13 normal
0cb8 igfxHK.exe 1 14 12 normal
0c48 svchost.exe 0 0 0
10c8 msseces.exe 1 143 60 normal
10dc PrnStatusMX.exe 1 23 20 normal
1288 WmiPrvSE.exe 0 0 0
12c8 OSPPSVC.EXE 0 0 0
1354 SearchIndexer.exe 0 0 0
12e8 Store.exe 1 2015 513 normal C:\Program Files (x86)\Store
1170 wuauclt.exe 1 12 6 normal
13b4 OIS.EXE 1 105 45 normal
1024 splwow64.exe 1 9 4 normal
13d0 chrome.exe 1 28 52 normal
11a8 chrome.exe 1 9 4 normal
0b94 chrome.exe 1 7 7 above normal
0670 chrome.exe 1 4 1 normal
10ec chrome.exe 1 4 1 normal
09e4 chrome.exe 1 4 3 normal
09a0 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0c9c OIS.EXE 1 117 71 normal
08c8 OIS.EXE 1 132 49 normal
0478 OIS.EXE 1 112 49 normal
0680 audiodg.exe 0 0 0
084c chrome.exe 1 4 1 idle
09f0 rundll32.exe 1 116 51 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 04653c40
ebx = 045d8c70
ecx = 00000000
edx = 0018da01
esi = 045d8c70
edi = 00000000
eip = 004075f4
esp = 0018d8b8
ebp = 0018d9e8
stack dump:
0018d8b8 ba 2e 6f 00 6c da 18 00 - 28 fc 52 00 00 00 00 00 ..o.l...(.R.....
0018d8c8 a2 0c 32 06 70 8c 5d 04 - 70 8c 5d 04 84 da 18 00 ..2.p.].p.].....
0018d8d8 28 fc 52 00 01 00 00 00 - a2 0c 32 06 70 8c 5d 04 (.R.......2.p.].
0018d8e8 a4 d8 18 00 01 00 00 00 - 20 db 18 00 b6 a6 65 75 ........ .....eu
0018d8f8 69 25 64 19 fe ff ff ff - 51 6d 5f 75 3f 0d 60 75 i%d.....Qm_u?.`u
0018d908 00 00 00 00 30 2f 41 00 - cc 03 25 00 30 00 00 00 ....0/A...%.0...
0018d918 7b 14 0a 1a 01 00 00 00 - 00 00 00 00 00 00 00 00 {...............
0018d928 30 00 00 00 70 8c 5d 04 - fc 95 6e 00 00 00 00 00 0...p.]...n.....
0018d938 58 d9 18 00 65 0d 60 75 - 30 2f 41 00 cc 03 25 00 X...e.`u0/A...%.
0018d948 30 00 00 00 7b 14 0a 1a - 01 00 00 00 00 00 00 00 0...{...........
0018d958 ac da 18 00 85 46 53 00 - 30 2f 41 00 cc 03 25 00 .....FS.0/A...%.
0018d968 30 00 00 00 7b 14 0a 1a - 01 00 00 00 ac da 18 00 0...{...........
0018d978 70 8c 5d 04 70 8c 5d 04 - 04 db 18 00 28 fc 52 00 p.].p.].....(.R.
0018d988 70 8c 5d 04 70 8c 5d 04 - 70 8c 5d 04 ef 47 cc 77 p.].p.].p.]..G.w
0018d998 01 00 00 00 00 00 40 00 - 00 00 00 00 00 00 00 00 ......@.........
0018d9a8 ac d9 18 00 81 91 23 6c - 64 da 18 00 44 aa 5f 75 ......#ld...D._u
0018d9b8 00 00 01 00 1c da 18 00 - 00 00 00 00 00 00 00 46 ...............F
0018d9c8 2f 01 00 00 b2 00 00 00 - 1a 03 00 00 63 04 00 00 /...........c...
0018d9d8 12 03 2b 00 00 00 00 00 - 00 00 40 00 00 00 00 00 ..+.......@.....
0018d9e8 34 da 18 00 88 45 53 00 - a2 0c 32 06 70 8c 5d 04 4....ES...2.p.].
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $1328:
77caf8da +0e ntdll.dll NtWaitForSingleObject
76df15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7572118f +3e kernel32.dll WaitForSingleObjectEx
75721143 +0d kernel32.dll WaitForSingleObject
75723368 +10 kernel32.dll BaseThreadInitThunk
thread $12bc:
77cb0166 +0e ntdll.dll NtWaitForMultipleObjects
75723368 +10 kernel32.dll BaseThreadInitThunk
thread $1280:
77cb0166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75723368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($12dc) at:
73602713 +24f netbios.dll Netbios
thread $12c4:
77caf8da +0e ntdll.dll NtWaitForSingleObject
76df15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7572118f +3e kernel32.dll WaitForSingleObjectEx
75721143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75723368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($12dc) at:
737a4c95 +00 winspool.drv
thread $162c:
77cb1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75723368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
002f0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 BCLW32.dll C:\Program
Files (x86)\Store
04390000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063c0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70fe0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
71060000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
71590000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
718c0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71b90000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71fb0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
72050000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
72070000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
72650000 webio.dll 6.1.7601.23375 C:\Windows\
system32
726b0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72710000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72ab0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72ad0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72b70000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72bb0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72d60000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72d80000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72d90000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72f30000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
735d0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73600000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73610000 security.dll 6.1.7600.16385 C:\Windows\
system32
73620000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73630000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73690000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73790000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73f90000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
741c0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74210000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74260000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74280000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
74290000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
742b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
742c0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
742e0000 slc.dll 6.1.7600.16385 C:\Windows\
system32
74590000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
746a0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
746d0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74700000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74740000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74760000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74770000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74780000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
747e0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74850000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
749f0000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a00000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75520000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75590000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
755e0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
756e0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75700000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75710000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75820000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75830000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75900000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75a50000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75a80000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75b10000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75d00000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75d20000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d30000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d40000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75d50000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75d60000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75e90000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75fa0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76bf0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76c90000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76d40000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76de0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76e30000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e40000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76e50000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76eb0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76f40000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76f70000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76f80000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
771c0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
771e0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77220000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77230000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
773d0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77430000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
776e0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77790000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
777a0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
77c60000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77c90000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f4 csrss.exe 0 0 0
0250 wininit.exe 0 0 0
0258 csrss.exe 1 0 0
0290 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
02ac svchost.exe 0 0 0
03cc svchost.exe 0 0 0
0408 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
0498 svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0570 svchost.exe 0 0 0
0630 spoolsv.exe 0 0 0
063c taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0724 svchost.exe 0 0 0
0748 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
0464 svchost.exe 0 0 0
053c scpbradserv.exe 0 0 0
0700 svchost.exe 0 0 0
07e4 core.exe 0 0 0
0984 fbserver.exe 0 0 0
0ad4 RapportInjService_x64.exe 0 0 0
0af4 WUDFHost.exe 0 0 0
0b5c taskhost.exe 1 26 22 normal
0ba0 core.exe 1 9 22 normal
05fc sppsvc.exe 0 0 0
0e54 NisSrv.exe 0 0 0
0f9c RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0c84 GoogleCrashHandler.exe 0 0 0
0c34 GoogleCrashHandler64.exe 0 0 0
0f3c RapportInjService_x64.exe 1 4 3 normal
0d84 PresentationFontCache.exe 0 0 0
0ea4 dwm.exe 1 18 4 high
08e0 explorer.exe 1 569 402 normal
0ef0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0cc4 igfxEM.exe 1 14 13 normal
0cb8 igfxHK.exe 1 14 12 normal
0c48 svchost.exe 0 0 0
10c8 msseces.exe 1 143 60 normal
10dc PrnStatusMX.exe 1 23 20 normal
1288 WmiPrvSE.exe 0 0 0
12c8 OSPPSVC.EXE 0 0 0
1354 SearchIndexer.exe 0 0 0
12e8 Store.exe 1 6667 378 normal C:\Program Files (x86)\Store
1170 wuauclt.exe 1 12 5 normal
13b4 OIS.EXE 1 105 45 normal
1024 splwow64.exe 1 9 2 normal
13d0 chrome.exe 1 77 57 normal
11a8 chrome.exe 1 9 4 normal
0b94 chrome.exe 1 7 7 above normal
0670 chrome.exe 1 4 1 normal
10ec chrome.exe 1 4 1 normal
09e4 chrome.exe 1 4 3 normal
09a0 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
0c9c OIS.EXE 1 117 71 normal
08c8 OIS.EXE 1 132 49 normal
0478 OIS.EXE 1 113 49 normal
084c chrome.exe 1 4 1 idle
1310 OIS.EXE 1 109 44 normal
0cec OIS.EXE 1 143 111 normal
043c audiodg.exe 0 0 0
03d4 OIS.EXE 1 141 55 normal
0eec AcroRd32.exe 1 15 16 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader
076c AcroRd32.exe 1 273 121 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader
0d38 RdrCEF.exe 1 9 22 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
1648 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
17cc RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
143c OIS.EXE 1 132 50 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0018fe20
ebx = 004075b1
ecx = 00000007
edx = 00000000
esi = 004075b1
edi = 068cca90
eip = 76dec54f
esp = 0018fe20
ebp = 0018fe70
stack dump:
0018fe20 de fa ed 0e 01 00 00 00 - 00 00 00 00 4f c5 de 76 ............O..v
0018fe30 07 00 00 00 b1 75 40 00 - 58 80 6c 04 b1 75 40 00 [email protected]@.
0018fe40 b1 75 40 00 90 ca 8c 06 - bc fe 18 00 a4 fe 18 00 .u@.............
0018fe50 f3 5e 4d 00 90 ca 8c 06 - b1 75 40 00 bc fe 18 00 .^M......u@.....
0018fe60 74 fe 18 00 b1 75 40 00 - 44 fe 18 00 fc d8 44 00 [email protected].
0018fe70 bc fe 18 00 b1 75 40 00 - de fa ed 0e 01 00 00 00 .....u@.........
0018fe80 07 00 00 00 88 fe 18 00 - b1 75 40 00 58 80 6c 04 [email protected].
0018fe90 b1 75 40 00 b1 75 40 00 - 90 ca 8c 06 bc fe 18 00 [email protected]@.........
0018fea0 a4 fe 18 00 02 00 00 00 - f4 4c 40 00 70 8c 5d 04 [email protected].].
0018feb0 90 ca 8c 06 37 4d 40 00 - 90 ca 8c 02 e8 fe 18 00 ....7M@.........
0018fec0 b1 75 40 00 90 ca 8c 06 - 70 74 4d 00 00 40 47 00 [email protected]..@G.
0018fed0 73 65 48 00 70 8c 5d 04 - 70 8c 5d 04 00 40 47 00 seH.p.].p.]..@G.
0018fee0 24 ac 50 01 00 00 00 00 - 40 ff 18 00 f7 75 40 00 [email protected]@.
0018fef0 2d 1a 6f 00 70 8c 5d 04 - 01 40 47 00 e7 51 6f 00 -.o.p.][email protected].
0018ff00 10 f0 32 0a 02 00 00 00 - 3d 19 53 00 00 0f 4e 05 ..2.....=.S...N.
0018ff10 f8 a1 6b 04 10 f0 32 0a - 00 00 00 00 2c 9d 60 00 ..k...2.....,.`.
0018ff20 10 f0 32 0a 50 e0 67 04 - 06 af 60 00 78 ff 18 00 ..2.P.g...`.x...
0018ff30 0c 89 40 00 40 ff 18 00 - f8 a1 6b 01 10 f0 32 0a ..@[email protected].
0018ff40 88 ff 18 00 ae 01 49 00 - 54 70 60 01 18 9b 60 01 ......I.Tp`...`.
0018ff50 c8 8a 60 00 02 8b 60 00 - 2c 1c 45 00 04 1c 45 00 ..`...`.,.E...E.
disassembling:
004075a0 public System.TObject.FreeInstance: ; function entry point
004075a0 35 push ebx
004075a1 mov ebx, eax
004075a3 mov eax, ebx
004075a5 call +$a6 ($407650) ; System.TObject.CleanupInstance
004075aa mov eax, ebx
004075ac call -$29fd ($404bb4) ; System.@FreeMem
004075b1 > pop ebx
004075b2 ret
thread $144:
77b7f8da +0e ntdll.dll NtWaitForSingleObject
763915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7591118f +3e kernel32.dll WaitForSingleObjectEx
75911143 +0d kernel32.dll WaitForSingleObject
75913368 +10 kernel32.dll BaseThreadInitThunk
thread $378:
77b80166 +0e ntdll.dll NtWaitForMultipleObjects
75913368 +10 kernel32.dll BaseThreadInitThunk
thread $848:
77b80166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75913368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1248) at:
73b72713 +24f netbios.dll Netbios
thread $1034:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75913368 +10 kernel32.dll BaseThreadInitThunk
thread $9c0:
77b7f8da +0e ntdll.dll NtWaitForSingleObject
763915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7591118f +3e kernel32.dll WaitForSingleObjectEx
75911143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75913368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1248) at:
73884c95 +00 winspool.drv
thread $1628:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75913368 +10 kernel32.dll BaseThreadInitThunk
thread $15e8:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75913368 +10 kernel32.dll BaseThreadInitThunk
modules:
002d0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
062a0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063b0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71960000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
719b0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71c00000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71c20000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71c50000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71de0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71e30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71e90000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72700000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72720000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a40000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a80000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72fe0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
735b0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
735e0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73810000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73870000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73b70000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73b80000 security.dll 6.1.7600.16385 C:\Windows\
system32
73c90000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73ce0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73cf0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73d10000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73d20000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73d80000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73d90000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73e70000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
740c0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
740e0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74520000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74570000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
745a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
745d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74610000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74630000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74640000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74650000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
746b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74720000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
748c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
748d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
753f0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75400000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75460000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75470000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75480000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
754e0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75590000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
755a0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
755d0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75880000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75900000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75a10000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75a20000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75a30000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75ae0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b10000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75ba0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75de0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75f10000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75f20000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76010000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
760b0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
760c0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
761c0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76220000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76300000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76310000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76320000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76340000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76380000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
763d0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76530000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76600000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76680000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
772d0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77420000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
774b0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
774c0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77660000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
77680000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77690000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
77b30000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77b60000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02bc services.exe 0 0 0
02c4 lsass.exe 0 0 0
02cc lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02c8 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0410 svchost.exe 0 0 0
049c svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
061c spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
072c svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0774 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
0508 scpbradserv.exe 0 0 0
0678 svchost.exe 0 0 0
07d4 core.exe 0 0 0
090c RapportInjService_x64.exe 0 0 0
09f8 fbserver.exe 0 0 0
0bb4 WUDFHost.exe 0 0 0
05f0 NisSrv.exe 0 0 0
0ed8 taskhost.exe 1 26 24 normal
0eec core.exe 1 9 20 normal
0fa0 sppsvc.exe 0 0 0
0dc0 GoogleCrashHandler.exe 0 0 0
0dc8 GoogleCrashHandler64.exe 0 0 0
0e0c svchost.exe 0 0 0
0e30 RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e8c RapportInjService_x64.exe 1 4 3 normal
1068 WmiPrvSE.exe 0 0 0
1098 OSPPSVC.EXE 0 0 0
1278 TrustedInstaller.exe 0 0 0
1304 SearchIndexer.exe 0 0 0
114c PresentationFontCache.exe 0 0 0
1100 dwm.exe 1 16 4 high
1114 explorer.exe 1 384 226 normal
0cd8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
08e0 igfxEM.exe 1 14 14 normal
11e4 igfxHK.exe 1 14 13 normal
0a30 msseces.exe 1 143 59 normal
0a40 PrnStatusMX.exe 1 23 20 normal
1190 wuauclt.exe 1 12 7 normal
12d8 dllhost.exe 1 9 5 normal
1344 Store.exe 1 322 270 normal C:\Program Files (x86)\Store
1020 WmiPrvSE.exe 0 0 0
122c chrome.exe 1 22 49 normal
13a8 chrome.exe 1 9 4 normal
1354 chrome.exe 1 7 5 above normal
13a0 chrome.exe 1 4 1 normal
0aa0 chrome.exe 1 4 1 normal
13fc chrome.exe 1 4 1 idle
00a0 taskhost.exe 0 0 0
14c8 CompatTelRunner.exe 0 0 0
14b4 conhost.exe 0 0 0
14f0 CompatTelRunner.exe 0 0 0
03cc WmiPrvSE.exe 0 0 0
12a0 splwow64.exe 1 9 4 normal
1658 rundll32.exe 1 116 52 normal
15d4 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0047002e
ebx = 044135b0
ecx = 006f2e80
edx = 044135b0
esi = 04394230
edi = 00000000
eip = 006d007d
esp = 0018ccac
ebp = 0018ccc8
stack dump:
0018ccac ab 60 70 00 50 ce 18 00 - 0c 89 40 00 c8 cc 18 00 .`p.P.....@.....
0018ccbc 30 42 39 04 04 00 00 00 - b0 35 41 04 fc cd 18 00 0B9......5A.....
0018cccc af 2e 6f 00 80 ce 18 00 - 28 fc 52 00 00 00 00 00 ..o.....(.R.....
0018ccdc 99 0d 4e 04 30 42 39 04 - 30 42 39 04 98 ce 18 00 ..N.0B9.0B9.....
0018ccec 28 fc 52 00 01 00 00 00 - 99 0d 4e 04 30 42 39 04 (.R.......N.0B9.
0018ccfc b8 cc 18 00 01 00 00 00 - 34 cf 18 00 b6 a6 13 76 ........4......v
0018cd0c 1a 77 eb 60 fe ff ff ff - 51 6d 0d 76 3f 0d 0e 76 .w.`....Qm.v?..v
0018cd1c 00 00 00 00 30 2f 41 00 - 36 03 04 00 30 00 00 00 ....0/A.6...0...
0018cd2c 6a 08 0a b0 01 00 00 00 - 00 00 00 00 00 00 00 00 j...............
0018cd3c 30 00 00 00 30 42 39 04 - fc 95 6e 00 00 00 00 00 0...0B9...n.....
0018cd4c 6c cd 18 00 65 0d 0e 76 - 30 2f 41 00 36 03 04 00 l...e..v0/A.6...
0018cd5c 30 00 00 00 6a 08 0a b0 - 01 00 00 00 00 00 00 00 0...j...........
0018cd6c c0 ce 18 00 85 46 53 00 - 30 2f 41 00 36 03 04 00 .....FS.0/A.6...
0018cd7c 30 00 00 00 6a 08 0a b0 - 01 00 00 00 c0 ce 18 00 0...j...........
0018cd8c 30 42 39 04 30 42 39 04 - 18 cf 18 00 28 fc 52 00 0B9.0B9.....(.R.
0018cd9c 30 42 39 04 30 42 39 04 - 30 42 39 04 ef 47 b9 77 0B9.0B9.0B9..G.w
0018cdac 01 00 00 00 00 00 40 00 - 00 00 00 00 00 00 00 00 ......@.........
0018cdbc c0 cd 18 00 86 d7 fe 16 - 78 ce 18 00 44 aa 0d 76 ........x...D..v
0018cdcc 00 00 01 00 30 ce 18 00 - 00 00 00 00 00 00 00 46 ....0..........F
0018cddc 2f 01 00 00 b2 00 00 00 - 1a 03 00 00 63 04 00 00 /...........c...
disassembling:
[...]
006d0056 fnstsw ax
006d0058 sahf
006d0059 jz loc_6d0084
006d005b mov eax, [ebp-$4010]
006d0061 mov edx, [eax]
006d0063 call dword ptr [edx]
006d0065 mov [ebp-$4020], eax
006d006b mov [ebp-$401c], edx
006d0071 fild qword ptr [ebp-$4020]
006d0077 fdiv qword ptr [$160d830]
006d007d > fstp qword ptr [$160d830]
006d0083 wait
006d0084 396 xor eax, eax
006d0086 pop edx
006d0087 pop ecx
006d0088 pop ecx
006d0089 mov fs:[eax], edx
006d008c push $6d00af
006d0091 lea eax, [ebp-$4000]
006d0097 mov ecx, $1000
006d009c mov edx, [$44be10]
[...]
thread $144:
77b7f8da +0e ntdll.dll NtWaitForSingleObject
763915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7591118f +3e kernel32.dll WaitForSingleObjectEx
75911143 +0d kernel32.dll WaitForSingleObject
75913368 +10 kernel32.dll BaseThreadInitThunk
thread $378:
77b80166 +0e ntdll.dll NtWaitForMultipleObjects
75913368 +10 kernel32.dll BaseThreadInitThunk
thread $848:
77b80166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75913368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1248) at:
73b72713 +24f netbios.dll Netbios
thread $1034:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75913368 +10 kernel32.dll BaseThreadInitThunk
thread $9c0:
77b7f8da +0e ntdll.dll NtWaitForSingleObject
763915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7591118f +3e kernel32.dll WaitForSingleObjectEx
75911143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75913368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1248) at:
73884c95 +00 winspool.drv
thread $1628:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75913368 +10 kernel32.dll BaseThreadInitThunk
thread $15e8:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75913368 +10 kernel32.dll BaseThreadInitThunk
thread $a0c:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75913368 +10 kernel32.dll BaseThreadInitThunk
modules:
002d0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
062a0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063b0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71960000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
719b0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71c00000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71c20000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71c50000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71de0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71e30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71e90000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72700000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72720000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a40000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a80000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72fe0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
735b0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
735e0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73810000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73870000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73b70000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73b80000 security.dll 6.1.7600.16385 C:\Windows\
system32
73c90000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73ce0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73cf0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73d10000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73d20000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73d80000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73d90000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73e70000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
740c0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
740e0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74520000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74570000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
745a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
745d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74610000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74630000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74640000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74650000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
746b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74720000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
748c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
748d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
753f0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75400000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75460000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75470000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75480000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
754e0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75590000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
755a0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
755d0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75880000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75900000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75a10000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75a20000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75a30000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75ae0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b10000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75ba0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75de0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75f10000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75f20000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76010000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
760b0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
760c0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
761c0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76220000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76300000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76310000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76320000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76340000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76380000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
763d0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76530000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76600000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76680000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
772d0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77420000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
774b0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
774c0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77660000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
77680000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77690000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
77b30000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77b60000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02bc services.exe 0 0 0
02c4 lsass.exe 0 0 0
02cc lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02c8 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0410 svchost.exe 0 0 0
049c svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
061c spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
072c svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0774 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
0508 scpbradserv.exe 0 0 0
0678 svchost.exe 0 0 0
07d4 core.exe 0 0 0
090c RapportInjService_x64.exe 0 0 0
09f8 fbserver.exe 0 0 0
0bb4 WUDFHost.exe 0 0 0
05f0 NisSrv.exe 0 0 0
0ed8 taskhost.exe 1 26 24 normal
0eec core.exe 1 9 20 normal
0fa0 sppsvc.exe 0 0 0
0dc0 GoogleCrashHandler.exe 0 0 0
0dc8 GoogleCrashHandler64.exe 0 0 0
0e0c svchost.exe 0 0 0
0e30 RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e8c RapportInjService_x64.exe 1 4 3 normal
1068 WmiPrvSE.exe 0 0 0
1098 OSPPSVC.EXE 0 0 0
1278 TrustedInstaller.exe 0 0 0
1304 SearchIndexer.exe 0 0 0
114c PresentationFontCache.exe 0 0 0
1100 dwm.exe 1 16 4 high
1114 explorer.exe 1 384 224 normal
0cd8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
08e0 igfxEM.exe 1 14 14 normal
11e4 igfxHK.exe 1 14 13 normal
0a30 msseces.exe 1 143 59 normal
0a40 PrnStatusMX.exe 1 23 20 normal
1190 wuauclt.exe 1 12 7 normal
12d8 dllhost.exe 1 9 5 normal
1344 Store.exe 1 305 263 normal C:\Program Files (x86)\Store
1020 WmiPrvSE.exe 0 0 0
122c chrome.exe 1 22 49 normal
13a8 chrome.exe 1 9 4 normal
1354 chrome.exe 1 7 5 above normal
13a0 chrome.exe 1 4 1 normal
0aa0 chrome.exe 1 4 1 normal
13fc chrome.exe 1 4 1 idle
00a0 taskhost.exe 0 0 0
14c8 CompatTelRunner.exe 0 0 0
14b4 conhost.exe 0 0 0
14f0 CompatTelRunner.exe 0 0 0
03cc WmiPrvSE.exe 0 0 0
12a0 splwow64.exe 1 9 4 normal
1658 rundll32.exe 1 116 51 normal
15d4 audiodg.exe 0 0 0
13c8 GoogleUpdate.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 044135b0
ebx = 00180100
ecx = 000204b0
edx = 04404701
esi = 04394230
edi = 0018e36c
eip = 00340035
esp = 0018e0bb
ebp = 0018e130
stack dump:
0018e0bb 00 f7 75 40 00 89 1a 6f - 00 30 42 39 04 01 01 18 [email protected]....
0018e0cb 00 e7 51 6f 00 70 d5 79 - 0a 70 d5 79 0a f7 75 40 ..Qo.p.y.p.y..u@
0018e0db 00 f3 c9 ec 00 38 e1 18 - 00 0c 89 40 00 30 e1 18 [email protected]..
0018e0eb 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0fb 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e10b 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e11b 00 00 00 00 00 00 00 00 - 00 00 00 00 00 40 1b 7f .............@..
0018e12b 0a 50 04 39 04 b4 e1 18 - 00 75 61 ec 00 1c e5 18 .P.9.....ua.....
0018e13b 00 0c 89 40 00 b4 e1 18 - 00 00 00 00 00 00 00 00 ...@............
0018e14b 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e15b 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e16b 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e17b 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e18b 00 00 00 00 00 70 d5 79 - 0a 20 7f 44 04 c0 81 44 .....p.y. .D...D
0018e19b 04 60 84 44 04 60 99 44 - 04 80 67 44 04 c0 6c 44 .`.D.`.D..gD..lD
0018e1ab 04 20 6a 44 04 50 04 39 - 04 04 e3 18 00 81 01 53 . jD.P.9.......S
0018e1bb 00 70 d5 79 0a c7 31 55 - 00 6c e3 18 00 f6 40 62 .p.y..1U.l....@b
0018e1cb 00 4c 40 62 00 6c e3 18 - 00 f5 3c 55 00 70 d5 79 [email protected]....<U.p.y
0018e1db 0a 28 fc 52 00 6c e3 18 - 00 4c e5 18 00 70 d5 79 .(.R.l...L...p.y
0018e1eb 0a f3 00 00 00 05 8b 0f - 76 3b 00 00 00 14 e2 18 ........v;......
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $144:
77b7f8da +0e ntdll.dll NtWaitForSingleObject
763915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7591118f +3e kernel32.dll WaitForSingleObjectEx
75911143 +0d kernel32.dll WaitForSingleObject
75913368 +10 kernel32.dll BaseThreadInitThunk
thread $378:
77b80166 +0e ntdll.dll NtWaitForMultipleObjects
75913368 +10 kernel32.dll BaseThreadInitThunk
thread $848:
77b80166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75913368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1248) at:
73b72713 +24f netbios.dll Netbios
thread $9c0:
77b7f8da +0e ntdll.dll NtWaitForSingleObject
763915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7591118f +3e kernel32.dll WaitForSingleObjectEx
75911143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75913368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1248) at:
73884c95 +00 winspool.drv
thread $17b8:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75913368 +10 kernel32.dll BaseThreadInitThunk
thread $133c:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75913368 +10 kernel32.dll BaseThreadInitThunk
thread $163c:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75913368 +10 kernel32.dll BaseThreadInitThunk
modules:
002d0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
025c0000 BCLW32.dll C:\Program
Files (x86)\Store
062a0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063b0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70bd0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
70c50000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
71960000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
719b0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71c00000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71c20000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71c50000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71de0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71e30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71e90000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72700000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72720000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a40000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a80000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72fe0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
735b0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
735e0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73810000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73870000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73b70000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73b80000 security.dll 6.1.7600.16385 C:\Windows\
system32
73c90000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73ce0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73cf0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73d10000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73d20000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73d80000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73d90000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73e70000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
740c0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
740e0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74500000 slc.dll 6.1.7600.16385 C:\Windows\
system32
74520000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74570000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
745a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
745d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74610000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74630000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74640000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74650000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
746b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74720000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
748c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
748d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
753f0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75400000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75460000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75470000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75480000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
754e0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75590000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
755a0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
755d0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75880000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75900000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75a10000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75a20000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75a30000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75ae0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b10000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75ba0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75de0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75f10000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75f20000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76010000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
760b0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
760c0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
761c0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76220000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76300000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76310000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76320000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76340000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76380000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
763d0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76530000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76600000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76680000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
772d0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77420000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
774b0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
774c0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77660000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
77680000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77690000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
77b30000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77b60000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02bc services.exe 0 0 0
02c4 lsass.exe 0 0 0
02cc lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02c8 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0410 svchost.exe 0 0 0
049c svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
061c spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06ec atkexComSvc.exe 0 0 0
072c svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0774 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f8 svchost.exe 0 0 0
0508 scpbradserv.exe 0 0 0
0678 svchost.exe 0 0 0
07d4 core.exe 0 0 0
090c RapportInjService_x64.exe 0 0 0
09f8 fbserver.exe 0 0 0
0bb4 WUDFHost.exe 0 0 0
05f0 NisSrv.exe 0 0 0
0ed8 taskhost.exe 1 26 24 normal
0eec core.exe 1 9 21 normal
0fa0 sppsvc.exe 0 0 0
0dc0 GoogleCrashHandler.exe 0 0 0
0dc8 GoogleCrashHandler64.exe 0 0 0
0e0c svchost.exe 0 0 0
0e30 RapportService.exe 1 15 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e8c RapportInjService_x64.exe 1 4 3 normal
1068 WmiPrvSE.exe 0 0 0
1098 OSPPSVC.EXE 0 0 0
114c PresentationFontCache.exe 0 0 0
1100 dwm.exe 1 17 4 high
1114 explorer.exe 1 557 362 normal
0cd8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
08e0 igfxEM.exe 1 14 14 normal
11e4 igfxHK.exe 1 14 12 normal
0a30 msseces.exe 1 143 59 normal
0a40 PrnStatusMX.exe 1 23 20 normal
1190 wuauclt.exe 1 12 6 normal
1344 Store.exe 1 3816 659 normal C:\Program Files (x86)\Store
12a0 splwow64.exe 1 9 3 normal
1698 armsvc.exe 0 0 0
11cc SearchIndexer.exe 0 0 0
1748 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
11d4 OIS.EXE 1 133 50 normal
16bc OIS.EXE 1 125 111 normal
1618 chrome.exe 1 76 49 normal
1464 chrome.exe 1 9 4 normal
05c0 chrome.exe 1 16 7 above normal
0aec chrome.exe 1 4 1 normal
1330 chrome.exe 1 4 1 normal
107c chrome.exe 1 4 1 idle
0148 chrome.exe 1 4 3 normal
0318 OIS.EXE 1 113 50 normal
0478 OIS.EXE 1 132 49 normal
0430 OIS.EXE 1 132 49 normal
1164 audiodg.exe 0 0 0
0944 WmiPrvSE.exe 0 0 0
1354 VSSVC.exe 0 0 0
0e94 svchost.exe 0 0 0
04f0 rundll32.exe 1 116 51 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 002b0020
ebx = 06643cf0
ecx = 006f2e80
edx = 06643cf0
esi = 0439ca50
edi = 00000000
eip = 00660034
esp = 0018ccac
ebp = 0018ccc8
stack dump:
0018ccac ab 60 70 00 50 ce 18 00 - 0c 89 40 00 c8 cc 18 00 .`p.P.....@.....
0018ccbc 50 ca 39 04 04 00 00 00 - f0 3c 64 06 fc cd 18 00 P.9......<d.....
0018cccc af 2e 6f 00 80 ce 18 00 - 28 fc 52 00 00 00 00 00 ..o.....(.R.....
0018ccdc d8 06 9e 07 50 ca 39 04 - 50 ca 39 04 98 ce 18 00 ....P.9.P.9.....
0018ccec 28 fc 52 00 01 00 00 00 - d8 06 9e 07 50 ca 39 04 (.R.........P.9.
0018ccfc b8 cc 18 00 01 00 00 00 - 34 cf 18 00 b6 a6 13 76 ........4......v
0018cd0c 1a 77 eb 60 fe ff ff ff - 51 6d 0d 76 3f 0d 0e 76 .w.`....Qm.v?..v
0018cd1c 00 00 00 00 30 2f 41 00 - 90 05 2e 00 30 00 00 00 ....0/A.....0...
0018cd2c 6a 08 0a b0 01 00 00 00 - 00 00 00 00 00 00 00 00 j...............
0018cd3c 30 00 00 00 50 ca 39 04 - fc 95 6e 00 00 00 00 00 0...P.9...n.....
0018cd4c 6c cd 18 00 65 0d 0e 76 - 30 2f 41 00 90 05 2e 00 l...e..v0/A.....
0018cd5c 30 00 00 00 6a 08 0a b0 - 01 00 00 00 00 00 00 00 0...j...........
0018cd6c c0 ce 18 00 85 46 53 00 - 30 2f 41 00 90 05 2e 00 .....FS.0/A.....
0018cd7c 30 00 00 00 6a 08 0a b0 - 01 00 00 00 c0 ce 18 00 0...j...........
0018cd8c 50 ca 39 04 50 ca 39 04 - 18 cf 18 00 28 fc 52 00 P.9.P.9.....(.R.
0018cd9c 50 ca 39 04 50 ca 39 04 - 50 ca 39 04 ef 47 b9 77 P.9.P.9.P.9..G.w
0018cdac 01 00 00 00 00 00 40 00 - 00 00 00 00 00 00 00 00 ......@.........
0018cdbc c0 cd 18 00 86 d7 fe 16 - 78 ce 18 00 44 aa 0d 76 ........x...D..v
0018cdcc 00 00 01 00 30 ce 18 00 - 00 00 00 00 00 00 00 46 ....0..........F
0018cddc 2f 01 00 00 b2 00 00 00 - 1a 03 00 00 63 04 00 00 /...........c...
disassembling:
[...]
00706084 cmp byte ptr [eax+$8d], 1
0070608b jnz loc_706095
0070608d mov eax, [ebp-4]
00706090 call -$2a9 ($705dec) ; QRPrntr.TQRPrinter.Cancel
00706095 3858 mov eax, [ebp-4]
00706098 cmp word ptr [eax+$1a], 0
0070609d jz loc_7060ab
0070609f 3859 mov ebx, [ebp-4]
007060a2 mov edx, [ebp-4]
007060a5 mov eax, [ebx+$1c]
007060a8 > call dword ptr [ebx+$18]
007060ab xor eax, eax
007060ad pop edx
007060ae pop ecx
007060af pop ecx
007060b0 mov fs:[eax], edx
007060b3 push $7060da
007060b8 3861 mov eax, [ebp-4]
007060bb movzx edx, byte ptr [ebp-5]
007060bf mov [eax+$8c], dl
007060c5 ret
[...]
thread $1a0:
778df8da +0e ntdll.dll NtWaitForSingleObject
761d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75df118f +3e kernel32.dll WaitForSingleObjectEx
75df1143 +0d kernel32.dll WaitForSingleObject
75df3368 +10 kernel32.dll BaseThreadInitThunk
thread $418:
778e0166 +0e ntdll.dll NtWaitForMultipleObjects
75df3368 +10 kernel32.dll BaseThreadInitThunk
thread $1294:
778e0166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75df3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($684) at:
72c42713 +24f netbios.dll Netbios
thread $14f8:
778df8da +0e ntdll.dll NtWaitForSingleObject
761d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75df118f +3e kernel32.dll WaitForSingleObjectEx
75df1143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75df3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($684) at:
72d74c95 +00 winspool.drv
thread $10d0:
778e1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75df3368 +10 kernel32.dll BaseThreadInitThunk
thread $1720:
778e1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75df3368 +10 kernel32.dll BaseThreadInitThunk
thread $14bc:
778e1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75df3368 +10 kernel32.dll BaseThreadInitThunk
modules:
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02670000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
026a0000 BCLW32.dll C:\Program
Files (x86)\Store
062a0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063b0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
09fc0000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70c80000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
70d00000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
71490000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
714c0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
71570000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
715c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71860000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71880000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
719b0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71b40000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71b90000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71bf0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
726e0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72700000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
727a0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
727e0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72990000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
729b0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
729c0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72c40000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
72c50000 security.dll 6.1.7600.16385 C:\Windows\
system32
72c60000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72d60000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73370000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73470000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73a40000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73a50000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73a70000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73a80000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73aa0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73af0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73b40000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73b80000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73ba0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73bc0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74280000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
742d0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74300000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74330000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74370000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74390000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
743a0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
743b0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74410000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74480000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74620000 version.dll 6.1.7600.16385 C:\Windows\
system32
74630000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75150000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75160000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
751c0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
751d0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
751e0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75420000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
754d0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
754e0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75640000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75650000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75780000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75830000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75930000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
759d0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75a70000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75a80000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75d30000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75dc0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75de0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75ef0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75f80000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76120000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
761a0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
761c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76210000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76280000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
763d0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77020000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
77110000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77120000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77150000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77180000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77190000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
771d0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77230000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77240000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77250000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
77320000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77330000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77410000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77890000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
778c0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
009c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0304 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0528 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
03f0 svchost.exe 0 0 0
0574 scpbradserv.exe 0 0 0
0408 svchost.exe 0 0 0
0748 core.exe 0 0 0
0974 RapportInjService_x64.exe 0 0 0
09f8 fbserver.exe 0 0 0
0b54 WUDFHost.exe 0 0 0
05f0 WmiPrvSE.exe 0 0 0
0948 OSPPSVC.EXE 0 0 0
0600 NisSrv.exe 0 0 0
0ce4 taskhost.exe 1 26 22 normal
0d10 core.exe 1 9 21 normal
0e1c sppsvc.exe 0 0 0
0618 GoogleCrashHandler.exe 0 0 0
09d4 GoogleCrashHandler64.exe 0 0 0
06c0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0f68 PresentationFontCache.exe 0 0 0
0fa8 dwm.exe 1 20 5 high
0a3c explorer.exe 1 455 252 normal
0d20 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0750 RapportInjService_x64.exe 1 4 3 normal
0ddc igfxEM.exe 1 14 13 normal
0ff0 igfxHK.exe 1 14 13 normal
07dc msseces.exe 1 143 60 normal
0b04 PrnStatusMX.exe 1 23 20 normal
113c svchost.exe 0 0 0
0cf8 wuauclt.exe 1 12 7 normal
111c Store.exe 1 1000 304 normal C:\Program Files (x86)\Store
0d8c chrome.exe 1 73 49 normal
0f74 chrome.exe 1 9 4 normal
0934 chrome.exe 1 7 6 above normal
0eec chrome.exe 1 4 1 normal
0f30 chrome.exe 1 4 1 normal
1158 chrome.exe 1 4 3 normal
14d0 splwow64.exe 1 11 6 normal
1558 rundll32.exe 1 116 44 normal
1054 SearchIndexer.exe 0 0 0
1708 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a34baa0
ebx = 064d582c
ecx = 00000000
edx = 00242ac8
esi = 064e3198
edi = 004129f0
eip = 0055ec52
esp = 0018da58
ebp = 0018dab0
stack dump:
0018da58 52 ec 55 00 de fa ed 0e - 01 00 00 00 07 00 00 00 R.U.............
0018da68 6c da 18 00 52 ec 55 00 - a0 ba 34 0a 2c 58 4d 06 l...R.U...4.,XM.
0018da78 98 31 4e 06 f0 29 41 00 - b0 da 18 00 88 da 18 00 .1N..)A.........
0018da88 01 77 84 75 0b f4 55 00 - d4 da 18 00 0c 89 40 00 .w.u..U.......@.
0018da98 b0 da 18 00 b0 4f 4b 04 - 98 31 4e 06 98 31 4e 06 .....OK..1N..1N.
0018daa8 00 00 00 00 28 be 39 0a - e8 da 18 00 bc f9 55 00 ....(.9.......U.
0018dab8 20 3e 4c 04 16 5c 70 00 - 58 00 00 00 00 00 00 00 >L..\p.X.......
0018dac8 f0 5a 44 04 20 3e 4c 04 - bf 5d 70 00 80 dc 18 00 .ZD. >L..]p.....
0018dad8 0c 89 40 00 e8 da 18 00 - f0 5a 44 04 00 00 00 00 [email protected].....
0018dae8 c4 dc 18 00 30 3d 6f 00 - 05 40 6e 00 55 55 55 55 [email protected]
0018daf8 c4 dc 18 00 6f dc 6e 00 - 00 00 00 00 00 00 00 c8 ....o.n.........
0018db08 05 40 00 00 c4 dc 18 00 - b0 4f 4b 04 5d 00 00 00 [email protected].]...
0018db18 f0 5a 44 04 2e 3b 6f 00 - c4 dc 18 00 d7 db 6e 00 .ZD..;o.......n.
0018db28 00 00 00 00 00 00 00 c8 - 05 40 00 00 00 00 00 00 .........@......
0018db38 b0 4f 4b 04 5d 00 00 00 - 40 10 a6 0a e7 fb 6e 00 .OK.][email protected].
0018db48 00 00 00 00 00 00 a0 b9 - 0a 40 6e 00 00 00 00 00 .........@n.....
0018db58 00 00 00 c8 05 40 a6 0a - 5d 00 00 00 40 10 a6 0a .....@..]...@...
0018db68 f0 5a 44 04 ff fe 6e 00 - 00 00 00 00 00 00 00 00 .ZD...n.........
0018db78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00705bed call -$2f2e4a ($412da8) ; Winapi.Windows.StartPage
00705bf2 3730 mov eax, [ebx+4]
00705bf5 call -$1a6356 ($55f8a4) ; Vcl.Printers.TPrinter.GetCanvas
00705bfa mov [ebx+$28], eax
00705bfd 3731 mov eax, ebx
00705bff call -$140 ($705ac4) ; QRPrntr.TQRPrinter.GetCanvas
00705c04 mov edx, [eax]
00705c06 call dword ptr [edx+$80]
00705c0c 3733 push $58
00705c0e mov eax, [ebx+4]
00705c11 > call -$1a6266 ($55f9b0) ; Vcl.Printers.TPrinter.GetHandle
00705c16 push eax
00705c17 call -$2f3104 ($412b18) ; Winapi.Windows.GetDeviceCaps
00705c1c mov [esp], eax
00705c1f fild dword ptr [esp]
00705c22 fdiv dword ptr [$705c88]
00705c28 fstp tbyte ptr [ebx+$90]
00705c2e wait
00705c2f 3734 push $5a
00705c31 mov eax, [ebx+4]
00705c34 call -$1a6289 ($55f9b0) ; Vcl.Printers.TPrinter.GetHandle
[...]
thread $1a0:
778df8da +0e ntdll.dll NtWaitForSingleObject
761d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75df118f +3e kernel32.dll WaitForSingleObjectEx
75df1143 +0d kernel32.dll WaitForSingleObject
75df3368 +10 kernel32.dll BaseThreadInitThunk
thread $418:
778e0166 +0e ntdll.dll NtWaitForMultipleObjects
75df3368 +10 kernel32.dll BaseThreadInitThunk
thread $1294:
778e0166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
75df3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($684) at:
72c42713 +24f netbios.dll Netbios
thread $14f8:
778df8da +0e ntdll.dll NtWaitForSingleObject
761d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75df118f +3e kernel32.dll WaitForSingleObjectEx
75df1143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75df3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($684) at:
72d74c95 +00 winspool.drv
thread $14bc:
778e1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75df3368 +10 kernel32.dll BaseThreadInitThunk
modules:
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02670000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
026a0000 BCLW32.dll C:\Program
Files (x86)\Store
062a0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063b0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
09fc0000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70c80000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
70d00000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
71490000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
714c0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
71570000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
715c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71860000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71880000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
719b0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71b40000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71b90000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71bf0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
726e0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72700000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
727a0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
727e0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72990000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
729b0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
729c0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72c40000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
72c50000 security.dll 6.1.7600.16385 C:\Windows\
system32
72c60000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72d60000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73370000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73470000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73a40000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73a50000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73a70000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73a80000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73aa0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73af0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73b40000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73b80000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73ba0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73bc0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74280000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
742d0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74300000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74330000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74370000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74390000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
743a0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
743b0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74410000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74480000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74620000 version.dll 6.1.7600.16385 C:\Windows\
system32
74630000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75150000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75160000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
751c0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
751d0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
751e0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75420000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
754d0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
754e0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75640000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75650000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75780000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75830000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75930000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
759d0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75a70000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75a80000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75d30000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75dc0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75de0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75ef0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75f80000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76120000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
761a0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
761c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76210000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76270000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76280000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
763d0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77020000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
77110000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77120000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77150000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77180000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77190000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
771d0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77230000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77240000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77250000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
77320000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77330000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77410000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77890000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
778c0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
009c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0304 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0528 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
03f0 svchost.exe 0 0 0
0574 scpbradserv.exe 0 0 0
0408 svchost.exe 0 0 0
0748 core.exe 0 0 0
0974 RapportInjService_x64.exe 0 0 0
09f8 fbserver.exe 0 0 0
0b54 WUDFHost.exe 0 0 0
05f0 WmiPrvSE.exe 0 0 0
0948 OSPPSVC.EXE 0 0 0
0600 NisSrv.exe 0 0 0
0ce4 taskhost.exe 1 26 24 normal
0d10 core.exe 1 9 21 normal
0e1c sppsvc.exe 0 0 0
0618 GoogleCrashHandler.exe 0 0 0
09d4 GoogleCrashHandler64.exe 0 0 0
06c0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0f68 PresentationFontCache.exe 0 0 0
0fa8 dwm.exe 1 20 5 high
0a3c explorer.exe 1 443 249 normal
0d20 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0750 RapportInjService_x64.exe 1 4 3 normal
0ddc igfxEM.exe 1 14 13 normal
0ff0 igfxHK.exe 1 14 13 normal
07dc msseces.exe 1 143 60 normal
0b04 PrnStatusMX.exe 1 23 20 normal
113c svchost.exe 0 0 0
0cf8 wuauclt.exe 1 12 7 normal
111c Store.exe 1 998 305 normal C:\Program Files (x86)\Store
0d8c chrome.exe 1 74 54 normal
0f74 chrome.exe 1 9 4 normal
0934 chrome.exe 1 7 7 above normal
0eec chrome.exe 1 4 1 normal
0f30 chrome.exe 1 4 1 normal
1158 chrome.exe 1 4 3 normal
14d0 splwow64.exe 1 11 5 normal
1054 SearchIndexer.exe 0 0 0
1708 audiodg.exe 0 0 0
1324 chrome.exe 1 4 1 idle
0c84 taskhost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 044c3e20
ebx = 064b4560
ecx = 000204b0
edx = 006e9501
esi = 00593880
edi = 0018de60
eip = 00340036
esp = 0018dcd0
ebp = 0018dce4
stack dump:
0018dcd0 f7 75 40 00 6a 2d 6f 00 - 20 3e 4c 04 00 00 00 00 [email protected]. >L.....
0018dce0 f0 5a 44 04 54 de 18 00 - 68 a0 6f 00 80 38 59 00 .ZD.T...h.o..8Y.
0018dcf0 c0 8a 3a 0a 81 01 53 00 - c0 8a 3a 0a 85 38 59 00 ..:...S...:..8Y.
0018dd00 2a 06 53 00 19 00 09 00 - 19 00 00 00 09 00 00 00 *.S.............
0018dd10 00 00 00 00 00 00 00 00 - 21 00 00 00 16 00 00 00 ........!.......
0018dd20 19 00 09 00 c0 8a 3a 0a - 60 de 18 00 28 fc 52 00 ......:.`...(.R.
0018dd30 19 00 09 00 5c df 18 00 - c0 8a 3a 0a c0 8a 3a 0a ....\.....:...:.
0018dd40 d2 01 00 00 09 00 00 00 - 00 00 00 00 c8 dd 18 00 ................
0018dd50 1f b0 70 72 20 ab 08 0a - 94 04 16 00 02 02 00 00 ..pr ...........
0018dd60 0f 00 00 00 d2 01 09 00 - 00 00 00 00 bb 80 70 72 ..............pr
0018dd70 8e 81 70 72 00 00 00 00 - d2 01 09 00 94 04 16 00 ..pr............
0018dd80 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd90 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dda0 00 00 00 00 bb 80 70 72 - 01 00 00 00 44 de 18 00 ......pr....D...
0018ddb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ddc0 00 00 00 00 f2 1d 82 44 - f4 dd 18 00 fa 62 84 75 .......D.....b.u
0018ddd0 94 04 16 00 02 02 00 00 - 00 00 00 00 d2 01 09 00 ................
0018dde0 bb 80 70 72 cd ab ba dc - 00 00 00 00 00 00 00 00 ..pr............
0018ddf0 0c de 18 00 63 f8 52 00 - c0 8a 3a 0a 0a b0 00 00 ....c.R...:.....
0018de00 00 00 00 00 19 00 09 00 - 01 00 00 00 40 de 18 00 ............@...
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $16b0:
778df8da +0e ntdll.dll NtWaitForSingleObject
761d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75df118f +3e kernel32.dll WaitForSingleObjectEx
75df1143 +0d kernel32.dll WaitForSingleObject
75df3368 +10 kernel32.dll BaseThreadInitThunk
thread $b08:
778e0166 +0e ntdll.dll NtWaitForMultipleObjects
75df3368 +10 kernel32.dll BaseThreadInitThunk
thread $ec0:
778df8da +0e ntdll.dll NtWaitForSingleObject
761d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75df118f +3e kernel32.dll WaitForSingleObjectEx
75df1143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75df3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1760) at:
72d74c95 +00 winspool.drv
thread $e98:
778e1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75df3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063f0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71490000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
714c0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
71570000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
715c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71860000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71880000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
719b0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71b40000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71b90000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71bf0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
726e0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72700000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
727a0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
727e0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72990000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
729b0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
729c0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72c50000 security.dll 6.1.7600.16385 C:\Windows\
system32
72c60000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72d60000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73370000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73a40000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73a50000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73a70000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73a80000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73aa0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73af0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73b40000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73b80000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73ba0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73bc0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74280000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
742d0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74300000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74330000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74370000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74390000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
743a0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
743b0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74410000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74480000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74620000 version.dll 6.1.7600.16385 C:\Windows\
system32
74630000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75150000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75160000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
751c0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
751d0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
751e0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75420000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
754d0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
754e0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75640000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75650000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75780000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75830000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75930000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
759d0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75a70000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75a80000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75d30000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75dc0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75de0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75ef0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75f80000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76120000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
761a0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
761c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76210000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76270000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76280000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
763d0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77020000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
77110000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77120000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77150000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77180000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77190000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
771d0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77230000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77240000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77250000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
77320000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77330000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77410000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77890000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
778c0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
009c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0304 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0528 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
03f0 svchost.exe 0 0 0
0574 scpbradserv.exe 0 0 0
0408 svchost.exe 0 0 0
0748 core.exe 0 0 0
0974 RapportInjService_x64.exe 0 0 0
09f8 fbserver.exe 0 0 0
0b54 WUDFHost.exe 0 0 0
05f0 WmiPrvSE.exe 0 0 0
0948 OSPPSVC.EXE 0 0 0
0600 NisSrv.exe 0 0 0
0ce4 taskhost.exe 1 26 24 normal
0d10 core.exe 1 9 21 normal
0e1c sppsvc.exe 0 0 0
0618 GoogleCrashHandler.exe 0 0 0
09d4 GoogleCrashHandler64.exe 0 0 0
06c0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0f68 PresentationFontCache.exe 0 0 0
0fa8 dwm.exe 1 20 5 high
0a3c explorer.exe 1 525 304 normal
0d20 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0750 RapportInjService_x64.exe 1 4 3 normal
0ddc igfxEM.exe 1 14 13 normal
0ff0 igfxHK.exe 1 14 13 normal
07dc msseces.exe 1 143 60 normal
0b04 PrnStatusMX.exe 1 23 20 normal
113c svchost.exe 0 0 0
0cf8 wuauclt.exe 1 12 6 normal
111c Store.exe 1 973 288 normal C:\Program Files (x86)\Store
14d0 splwow64.exe 1 11 6 normal
1054 SearchIndexer.exe 0 0 0
1250 Store.exe 1 1433 550 normal C:\Program Files (x86)\Store
1720 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
1390 AcroRd32.exe 1 16 19 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader
0d70 AcroRd32.exe 1 237 122 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader
17d8 RdrCEF.exe 1 9 22 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
0f2c RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
1650 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
0cf4 OIS.EXE 1 132 49 normal
0904 OIS.EXE 1 135 51 normal
1418 audiodg.exe 0 0 0
1350 chrome.exe 1 25 51 normal
1578 chrome.exe 1 9 4 normal
1654 chrome.exe 1 7 7 above normal
17b0 chrome.exe 1 4 1 normal
1284 chrome.exe 1 4 1 idle
0e4c chrome.exe 1 4 1 normal
13b8 chrome.exe 1 4 3 normal
05c4 chrome.exe 1 4 1 idle
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 05c4c148
ebx = 00003303
ecx = 00000000
edx = 026b2ac8
esi = 0018d860
edi = 0066c7e4
eip = 0066e702
esp = 0018d824
ebp = 0018d88c
stack dump:
0018d824 02 e7 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018d834 38 d8 18 00 02 e7 66 00 - 48 c1 c4 05 03 33 00 00 8.....f.H....3..
0018d844 60 d8 18 00 e4 c7 66 00 - 8c d8 18 00 54 d8 18 00 `.....f.....T...
0018d854 20 7f 5a 04 0e e7 66 00 - 34 e6 67 00 00 00 00 00 .Z...f.4.g.....
0018d864 20 7f 5a 04 00 00 00 00 - 2f e5 67 00 98 d8 18 00 .Z...../.g.....
0018d874 0c 89 40 00 8c d8 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018d884 69 e6 67 01 20 7f 5a 04 - b4 d8 18 00 87 e5 67 00 i.g. .Z.......g.
0018d894 a6 49 67 00 cc d8 18 00 - 0c 89 40 00 b4 d8 18 00 .Ig.......@.....
0018d8a4 20 7f 5a 04 00 00 00 00 - 00 00 00 00 20 7f 5a 04 .Z......... .Z.
0018d8b4 e0 d8 18 00 4a 8f 67 00 - 00 00 00 00 cc 59 53 00 ....J.g......YS.
0018d8c4 01 00 00 00 77 70 65 00 - ec d8 18 00 0c 89 40 00 ....wpe.......@.
0018d8d4 e0 d8 18 00 10 d0 66 0b - 20 7f 5a 04 14 d9 18 00 ......f. .Z.....
0018d8e4 be 6e 65 00 97 b9 be 00 - 2c d9 18 00 0c 89 40 00 .ne.....,.....@.
0018d8f4 14 d9 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d904 00 00 00 00 10 d0 66 0b - 20 7f 5a 04 b0 52 4f 04 ......f. .Z..RO.
0018d914 58 d9 18 00 e7 59 53 00 - 08 db 18 00 9a 66 53 00 X....YS......fS.
0018d924 08 db 18 00 b3 f5 54 00 - 38 d9 18 00 eb 8a 40 00 ......T.8.....@.
0018d934 58 d9 18 00 d8 da 18 00 - 0c 89 40 00 58 d9 18 00 [email protected]...
0018d944 00 00 00 00 10 d0 66 0b - 08 db 18 00 00 00 00 00 ......f.........
0018d954 10 d0 66 0b 84 da 18 00 - 28 fc 52 00 00 00 00 00 ..f.....(.R.....
disassembling:
[...]
00beb96e mov ecx, [ebp-$18]
00beb971 lea eax, [ebp-$14]
00beb974 mov edx, $beba34
00beb979 call -$7e123e ($40a740) ; System.@UStrCat3
00beb97e mov edx, [ebp-$14]
00beb981 mov eax, [ebp-8]
00beb984 mov eax, [eax+$250]
00beb98a mov ecx, [eax]
00beb98c call dword ptr [ecx+$38]
00beb98f 474 mov eax, [ebp-8]
00beb992 > call -$594ae3 ($656eb4) ; Data.DB.TDataSet.Open
00beb997 475 mov eax, [ebp-8]
00beb99a cmp byte ptr [eax+$a8], 0
00beb9a1 jz loc_beb9c4
00beb9a3 mov eax, [ebp-8]
00beb9a6 cmp byte ptr [eax+$a9], 0
00beb9ad jz loc_beb9c4
00beb9af 476 mov edx, $bebaac
00beb9b4 mov eax, [ebp-4]
00beb9b7 mov eax, [eax+$3a8]
00beb9bd call -$6bd66a ($52e358) ; Vcl.Controls.TControl.SetText
[...]
thread $16b0:
778df8da +0e ntdll.dll NtWaitForSingleObject
761d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75df118f +3e kernel32.dll WaitForSingleObjectEx
75df1143 +0d kernel32.dll WaitForSingleObject
75df3368 +10 kernel32.dll BaseThreadInitThunk
thread $b08:
778e0166 +0e ntdll.dll NtWaitForMultipleObjects
75df3368 +10 kernel32.dll BaseThreadInitThunk
thread $ec0:
778df8da +0e ntdll.dll NtWaitForSingleObject
761d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75df118f +3e kernel32.dll WaitForSingleObjectEx
75df1143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
75df3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1760) at:
72d74c95 +00 winspool.drv
thread $e98:
778e1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75df3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063f0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71490000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
714c0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
71570000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
715c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71860000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71880000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
719b0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71b40000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71b90000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71bf0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
726e0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72700000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
727a0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
727e0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72990000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
729b0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
729c0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72c50000 security.dll 6.1.7600.16385 C:\Windows\
system32
72c60000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72d60000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73370000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73a40000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73a50000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73a70000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73a80000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73aa0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73af0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73b40000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73b80000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73ba0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73bc0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74280000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
742d0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74300000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74330000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74370000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74390000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
743a0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
743b0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74410000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74480000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74620000 version.dll 6.1.7600.16385 C:\Windows\
system32
74630000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75150000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75160000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
751c0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
751d0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
751e0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75420000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
754d0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
754e0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75640000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75650000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75780000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75830000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75930000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
759d0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75a70000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75a80000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75d30000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75dc0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75de0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75ef0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75f80000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76120000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
761a0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
761c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76210000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76270000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76280000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
763d0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77020000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
77110000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77120000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77150000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77180000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77190000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
771d0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77230000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77240000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77250000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
77320000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77330000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77410000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77890000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
778c0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
009c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0304 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0528 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
03f0 svchost.exe 0 0 0
0574 scpbradserv.exe 0 0 0
0408 svchost.exe 0 0 0
0748 core.exe 0 0 0
0974 RapportInjService_x64.exe 0 0 0
09f8 fbserver.exe 0 0 0
0b54 WUDFHost.exe 0 0 0
05f0 WmiPrvSE.exe 0 0 0
0948 OSPPSVC.EXE 0 0 0
0600 NisSrv.exe 0 0 0
0ce4 taskhost.exe 1 26 24 normal
0d10 core.exe 1 9 21 normal
0e1c sppsvc.exe 0 0 0
0618 GoogleCrashHandler.exe 0 0 0
09d4 GoogleCrashHandler64.exe 0 0 0
06c0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0f68 PresentationFontCache.exe 0 0 0
0fa8 dwm.exe 1 20 5 high
0a3c explorer.exe 1 535 307 normal
0d20 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0750 RapportInjService_x64.exe 1 4 3 normal
0ddc igfxEM.exe 1 14 13 normal
0ff0 igfxHK.exe 1 14 13 normal
07dc msseces.exe 1 143 60 normal
0b04 PrnStatusMX.exe 1 23 20 normal
113c svchost.exe 0 0 0
0cf8 wuauclt.exe 1 12 6 normal
111c Store.exe 1 973 288 normal C:\Program Files (x86)\Store
14d0 splwow64.exe 1 11 6 normal
1054 SearchIndexer.exe 0 0 0
1250 Store.exe 1 1464 535 normal C:\Program Files (x86)\Store
1720 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
1390 AcroRd32.exe 1 16 19 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader
0d70 AcroRd32.exe 1 237 122 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader
17d8 RdrCEF.exe 1 9 22 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
0f2c RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
1650 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
0cf4 OIS.EXE 1 132 49 normal
0904 OIS.EXE 1 135 51 normal
1418 audiodg.exe 0 0 0
1350 chrome.exe 1 25 50 normal
1578 chrome.exe 1 9 4 normal
1654 chrome.exe 1 7 7 above normal
17b0 chrome.exe 1 4 1 normal
1284 chrome.exe 1 4 1 idle
0e4c chrome.exe 1 4 1 normal
13b8 chrome.exe 1 4 3 normal
05c4 chrome.exe 1 4 1 idle
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a7c4e48
ebx = 00003303
ecx = 00000000
edx = 026b2ac8
esi = 0018e04c
edi = 0066c7e4
eip = 0066e702
esp = 0018e010
ebp = 0018e078
stack dump:
0018e010 02 e7 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018e020 24 e0 18 00 02 e7 66 00 - 48 4e 7c 0a 03 33 00 00 $.....f.HN|..3..
0018e030 4c e0 18 00 e4 c7 66 00 - 78 e0 18 00 40 e0 18 00 L.....f.x...@...
0018e040 20 7f 5a 04 0e e7 66 00 - 34 e6 67 00 00 00 00 00 .Z...f.4.g.....
0018e050 20 7f 5a 04 00 00 00 00 - 2f e5 67 00 84 e0 18 00 .Z...../.g.....
0018e060 0c 89 40 00 78 e0 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018e070 69 e6 67 01 20 7f 5a 04 - a0 e0 18 00 87 e5 67 00 i.g. .Z.......g.
0018e080 a6 49 67 00 b8 e0 18 00 - 0c 89 40 00 a0 e0 18 00 .Ig.......@.....
0018e090 20 7f 5a 04 00 00 00 00 - 00 00 00 00 20 7f 5a 04 .Z......... .Z.
0018e0a0 cc e0 18 00 4a 8f 67 00 - b4 e3 18 00 c0 c6 27 0a ....J.g.......'.
0018e0b0 01 00 00 00 77 70 65 00 - d8 e0 18 00 0c 89 40 00 ....wpe.......@.
0018e0c0 cc e0 18 00 c0 c6 27 0a - 20 7f 5a 04 54 e1 18 00 ......'. .Z.T...
0018e0d0 be 6e 65 00 3d 61 ec 00 - 5c e1 18 00 0c 89 40 00 .ne.=a..\.....@.
0018e0e0 54 e1 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 T...............
0018e0f0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e100 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e110 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e120 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e130 b0 52 4f 04 20 7f 5a 04 - c0 81 5a 04 60 84 5a 04 .RO. .Z...Z.`.Z.
0018e140 60 99 5a 04 80 67 5a 04 - c0 6c 5a 04 20 6a 5a 04 `.Z..gZ..lZ. jZ.
disassembling:
[...]
00ec6112 push $ec62a4
00ec6117 lea eax, [ebp-$58]
00ec611a mov edx, 3
00ec611f call -$abb95c ($40a7c8) ; System.@UStrCatN
00ec6124 mov edx, [ebp-$58]
00ec6127 mov eax, [ebp-$20]
00ec612a mov eax, [eax+$250]
00ec6130 mov ecx, [eax]
00ec6132 call dword ptr [ecx+$38]
00ec6135 125 mov eax, [ebp-$20]
00ec6138 > call -$86f289 ($656eb4) ; Data.DB.TDataSet.Open
00ec613d 126 mov eax, [ebp-$20]
00ec6140 call -$86c9c9 ($65977c) ; Data.DB.TDataSet.First
00ec6145 128 lea edx, [ebp-$60]
00ec6148 mov eax, [$1605df0]
00ec614d mov eax, [eax]
00ec614f mov eax, [eax+$330]
00ec6155 mov ecx, [eax]
00ec6157 call dword ptr [ecx+$80]
00ec615d cmp dword ptr [ebp-$60], 0
00ec6161 jnz loc_ec616d
[...]
thread $13bc:
77b80166 +0e ntdll.dll NtWaitForMultipleObjects
76e23368 +10 kernel32.dll BaseThreadInitThunk
thread $13c0:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e23368 +10 kernel32.dll BaseThreadInitThunk
thread $13d0:
77b80166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
76e23368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1134) at:
739c2713 +24f netbios.dll Netbios
thread $530:
77b7f8da +0e ntdll.dll NtWaitForSingleObject
761d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e2118f +3e kernel32.dll WaitForSingleObjectEx
76e21143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
76e23368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1134) at:
73a04c95 +00 winspool.drv
thread $504:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e23368 +10 kernel32.dll BaseThreadInitThunk
thread $b40:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e23368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00340000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
062d0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71810000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71bc0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71c00000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71c20000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71c50000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71de0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71e30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71e90000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72980000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
729a0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a40000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a80000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72ff0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73470000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
734c0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73630000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73640000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73660000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73670000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
736a0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
737d0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
739c0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
739d0000 security.dll 6.1.7600.16385 C:\Windows\
system32
739e0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
739f0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73ab0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73ad0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
740e0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74150000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74520000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74570000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
745a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
745d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74610000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74630000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74640000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74650000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
746b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74720000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
748c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
748d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
753f0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75400000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75460000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
760b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
760d0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
760e0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76170000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76180000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76190000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
761a0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
761b0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
761c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76210000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76260000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
763c0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
763e0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76480000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
766c0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
766e0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
766f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
768d0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76a70000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76af0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76bc0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76bd0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76be0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76c80000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ce0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76e10000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76f20000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76f30000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76f40000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
771f0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
772a0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
773f0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77430000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
774e0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77510000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
775a0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77600000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77700000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77b30000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77b60000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0338 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
0148 RapportMgmtService.exe 0 0 0
02e8 svchost.exe 0 0 0
0310 svchost.exe 0 0 0
03cc svchost.exe 0 0 0
041c svchost.exe 0 0 0
046c audiodg.exe 0 0 0
049c svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0550 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0654 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
0460 svchost.exe 0 0 0
0568 scpbradserv.exe 0 0 0
0704 svchost.exe 0 0 0
0810 core.exe 0 0 0
0930 RapportInjService_x64.exe 0 0 0
09ec fbserver.exe 0 0 0
0b38 WUDFHost.exe 0 0 0
05f8 taskhost.exe 1 26 24 normal
0be8 sppsvc.exe 0 0 0
0cf4 NisSrv.exe 0 0 0
0f08 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e28 PresentationFontCache.exe 0 0 0
0e6c dwm.exe 1 17 4 high
0174 explorer.exe 1 428 237 normal
0bec scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f8c RapportInjService_x64.exe 1 4 3 normal
0db4 igfxEM.exe 1 14 14 normal
0d4c igfxHK.exe 1 14 13 normal
0bf0 msseces.exe 1 143 59 normal
0ef8 PrnStatusMX.exe 1 23 20 normal
108c GoogleCrashHandler.exe 0 0 0
10ac GoogleCrashHandler64.exe 0 0 0
112c svchost.exe 0 0 0
11bc SearchIndexer.exe 0 0 0
1174 WmiPrvSE.exe 0 0 0
1274 OSPPSVC.EXE 0 0 0
124c core.exe 1 9 21 normal
0c2c Store.exe 1 373 269 normal C:\Program Files (x86)\
Store
10c8 slui.exe 1 43 31 normal
13a8 TrustedInstaller.exe 0 0 0
0abc wuauclt.exe 1 12 6 normal
0f30 chrome.exe 1 22 49 normal
0a30 chrome.exe 1 9 4 normal
11b0 chrome.exe 1 7 7 above normal
1314 chrome.exe 1 4 1 normal
11e8 chrome.exe 1 4 1 normal
0c54 chrome.exe 1 4 1 idle
1254 chrome.exe 1 4 3 normal
12ec WmiPrvSE.exe 0 0 0
1374 splwow64.exe 1 9 5 normal
1054 taskhost.exe 0 0 0
09cc CompatTelRunner.exe 0 0 0
05c0 conhost.exe 0 0 0
137c CompatTelRunner.exe 0 0 0
0970 DeviceDisplayObjectProvider.exe 0 0 0
13fc rundll32.exe 1 116 52 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0047002e
ebx = 044c3e00
ecx = 006f2e80
edx = 044c3e00
esi = 044439f0
edi = 00000000
eip = 006d007d
esp = 0018ccac
ebp = 0018ccc8
stack dump:
0018ccac ab 60 70 00 50 ce 18 00 - 0c 89 40 00 c8 cc 18 00 .`p.P.....@.....
0018ccbc f0 39 44 04 04 00 00 00 - 00 3e 4c 04 fc cd 18 00 .9D......>L.....
0018cccc af 2e 6f 00 80 ce 18 00 - 28 fc 52 00 00 00 00 00 ..o.....(.R.....
0018ccdc 35 0e 72 06 f0 39 44 04 - f0 39 44 04 98 ce 18 00 5.r..9D..9D.....
0018ccec 28 fc 52 00 01 00 00 00 - 35 0e 72 06 f0 39 44 04 (.R.....5.r..9D.
0018ccfc b8 cc 18 00 01 00 00 00 - 34 cf 18 00 b6 a6 67 77 ........4.....gw
0018cd0c 3b e9 95 32 fe ff ff ff - 51 6d 61 77 3f 0d 62 77 ;..2....Qmaw?.bw
0018cd1c 00 00 00 00 30 2f 41 00 - dc 03 04 00 30 00 00 00 ....0/A.....0...
0018cd2c 77 0b 0a 38 01 00 00 00 - 00 00 00 00 00 00 00 00 w..8............
0018cd3c 30 00 00 00 f0 39 44 04 - fc 95 6e 00 00 00 00 00 0....9D...n.....
0018cd4c 6c cd 18 00 65 0d 62 77 - 30 2f 41 00 dc 03 04 00 l...e.bw0/A.....
0018cd5c 30 00 00 00 77 0b 0a 38 - 01 00 00 00 00 00 00 00 0...w..8........
0018cd6c c0 ce 18 00 85 46 53 00 - 30 2f 41 00 dc 03 04 00 .....FS.0/A.....
0018cd7c 30 00 00 00 77 0b 0a 38 - 01 00 00 00 c0 ce 18 00 0...w..8........
0018cd8c f0 39 44 04 f0 39 44 04 - 18 cf 18 00 28 fc 52 00 .9D..9D.....(.R.
0018cd9c f0 39 44 04 f0 39 44 04 - f0 39 44 04 ef 47 b9 77 .9D..9D..9D..G.w
0018cdac 01 00 00 00 00 00 40 00 - 00 00 00 00 00 00 00 00 ......@.........
0018cdbc c0 cd 18 00 a7 49 ec 45 - 78 ce 18 00 44 aa 61 77 .....I.Ex...D.aw
0018cdcc 00 00 01 00 30 ce 18 00 - 00 00 00 00 00 00 00 46 ....0..........F
0018cddc 2f 01 00 00 b2 00 00 00 - 1a 03 00 00 63 04 00 00 /...........c...
disassembling:
[...]
006d0056 fnstsw ax
006d0058 sahf
006d0059 jz loc_6d0084
006d005b mov eax, [ebp-$4010]
006d0061 mov edx, [eax]
006d0063 call dword ptr [edx]
006d0065 mov [ebp-$4020], eax
006d006b mov [ebp-$401c], edx
006d0071 fild qword ptr [ebp-$4020]
006d0077 fdiv qword ptr [$160d830]
006d007d > fstp qword ptr [$160d830]
006d0083 wait
006d0084 396 xor eax, eax
006d0086 pop edx
006d0087 pop ecx
006d0088 pop ecx
006d0089 mov fs:[eax], edx
006d008c push $6d00af
006d0091 lea eax, [ebp-$4000]
006d0097 mov ecx, $1000
006d009c mov edx, [$44be10]
[...]
thread $13b8:
77b7f8da +0e ntdll.dll NtWaitForSingleObject
761d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e2118f +3e kernel32.dll WaitForSingleObjectEx
76e21143 +0d kernel32.dll WaitForSingleObject
76e23368 +10 kernel32.dll BaseThreadInitThunk
thread $13bc:
77b80166 +0e ntdll.dll NtWaitForMultipleObjects
76e23368 +10 kernel32.dll BaseThreadInitThunk
thread $13c0:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e23368 +10 kernel32.dll BaseThreadInitThunk
thread $13d0:
77b80166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
76e23368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1134) at:
739c2713 +24f netbios.dll Netbios
thread $530:
77b7f8da +0e ntdll.dll NtWaitForSingleObject
761d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e2118f +3e kernel32.dll WaitForSingleObjectEx
76e21143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
76e23368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1134) at:
73a04c95 +00 winspool.drv
thread $504:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e23368 +10 kernel32.dll BaseThreadInitThunk
thread $b40:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e23368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00340000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
062d0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71810000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71bc0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71c00000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71c20000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71c50000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71de0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71e30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71e90000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72980000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
729a0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a40000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a80000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72ff0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73470000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
734c0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73630000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73640000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73660000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73670000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
736a0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
737d0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
739c0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
739d0000 security.dll 6.1.7600.16385 C:\Windows\
system32
739e0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
739f0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73ab0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73ad0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
740e0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74150000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74520000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74570000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
745a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
745d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74610000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74630000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74640000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74650000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
746b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74720000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
748c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
748d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
753f0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75400000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75460000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
760b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
760d0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
760e0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76170000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76180000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76190000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
761a0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
761b0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
761c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76210000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76260000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
763c0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
763e0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76480000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
766c0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
766e0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
766f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
768d0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76a70000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76af0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76bc0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76bd0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76be0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76c80000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ce0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76e10000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76f20000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76f30000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76f40000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
771f0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
772a0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
773f0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77430000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
774e0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77510000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
775a0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77600000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77700000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77b30000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77b60000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0338 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
0148 RapportMgmtService.exe 0 0 0
02e8 svchost.exe 0 0 0
0310 svchost.exe 0 0 0
03cc svchost.exe 0 0 0
041c svchost.exe 0 0 0
046c audiodg.exe 0 0 0
049c svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0550 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0654 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
0460 svchost.exe 0 0 0
0568 scpbradserv.exe 0 0 0
0704 svchost.exe 0 0 0
0810 core.exe 0 0 0
0930 RapportInjService_x64.exe 0 0 0
09ec fbserver.exe 0 0 0
0b38 WUDFHost.exe 0 0 0
05f8 taskhost.exe 1 26 24 normal
0be8 sppsvc.exe 0 0 0
0cf4 NisSrv.exe 0 0 0
0f08 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e28 PresentationFontCache.exe 0 0 0
0e6c dwm.exe 1 17 4 high
0174 explorer.exe 1 428 241 normal
0bec scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f8c RapportInjService_x64.exe 1 4 3 normal
0db4 igfxEM.exe 1 14 14 normal
0d4c igfxHK.exe 1 14 13 normal
0bf0 msseces.exe 1 143 59 normal
0ef8 PrnStatusMX.exe 1 23 20 normal
108c GoogleCrashHandler.exe 0 0 0
10ac GoogleCrashHandler64.exe 0 0 0
112c svchost.exe 0 0 0
11bc SearchIndexer.exe 0 0 0
1174 WmiPrvSE.exe 0 0 0
1274 OSPPSVC.EXE 0 0 0
124c core.exe 1 9 21 normal
0c2c Store.exe 1 356 263 normal C:\Program Files (x86)\
Store
10c8 slui.exe 1 43 31 normal
13a8 TrustedInstaller.exe 0 0 0
0abc wuauclt.exe 1 12 6 normal
0f30 chrome.exe 1 22 49 normal
0a30 chrome.exe 1 9 4 normal
11b0 chrome.exe 1 7 7 above normal
1314 chrome.exe 1 4 1 normal
11e8 chrome.exe 1 4 1 normal
0c54 chrome.exe 1 4 1 idle
1254 chrome.exe 1 4 3 normal
12ec WmiPrvSE.exe 0 0 0
1374 splwow64.exe 1 9 5 normal
1054 taskhost.exe 0 0 0
09cc CompatTelRunner.exe 0 0 0
05c0 conhost.exe 0 0 0
137c CompatTelRunner.exe 0 0 0
0970 DeviceDisplayObjectProvider.exe 0 0 0
13fc rundll32.exe 1 116 52 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 044c3e00
ebx = 00180100
ecx = 000204b0
edx = 044b4501
esi = 044439f0
edi = 0018e36c
eip = 00340041
esp = 0018e0bc
ebp = 0018e130
stack dump:
0018e0bc f7 75 40 00 89 1a 6f 00 - f0 39 44 04 01 01 18 00 [email protected].....
0018e0cc e7 51 6f 00 70 83 b2 06 - 70 83 b2 06 f7 75 40 00 .Qo.p...p....u@.
0018e0dc f3 c9 ec 00 38 e1 18 00 - 0c 89 40 00 30 e1 18 00 [email protected]...
0018e0ec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0fc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e10c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e11c 00 00 00 00 00 00 00 00 - 00 00 00 00 40 7d b0 06 ............@}..
0018e12c 30 42 44 04 b4 e1 18 00 - 75 61 ec 00 1c e5 18 00 0BD.....ua......
0018e13c 0c 89 40 00 b4 e1 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e14c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e15c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e16c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e17c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e18c 00 00 00 00 70 83 b2 06 - c0 97 4e 04 60 9a 4e 04 ....p.....N.`.N.
0018e19c 00 9d 4e 04 00 b2 4e 04 - 20 80 4e 04 60 85 4e 04 ..N...N. .N.`.N.
0018e1ac c0 82 4e 04 30 42 44 04 - 04 e3 18 00 81 01 53 00 ..N.0BD.......S.
0018e1bc 70 83 b2 06 c7 31 55 00 - 6c e3 18 00 f6 40 62 00 p....1U.l....@b.
0018e1cc 4c 40 62 00 6c e3 18 00 - f5 3c 55 00 70 83 b2 06 [email protected]....<U.p...
0018e1dc 28 fc 52 00 6c e3 18 00 - 4c e5 18 00 70 83 b2 06 (.R.l...L...p...
0018e1ec f3 00 00 00 05 8b 63 77 - 68 74 61 77 d1 07 01 02 ......cwhtaw....
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $13b8:
77b7f8da +0e ntdll.dll NtWaitForSingleObject
761d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e2118f +3e kernel32.dll WaitForSingleObjectEx
76e21143 +0d kernel32.dll WaitForSingleObject
76e23368 +10 kernel32.dll BaseThreadInitThunk
thread $13bc:
77b80166 +0e ntdll.dll NtWaitForMultipleObjects
76e23368 +10 kernel32.dll BaseThreadInitThunk
thread $13c0:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e23368 +10 kernel32.dll BaseThreadInitThunk
thread $13d0:
77b80166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
76e23368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1134) at:
739c2713 +24f netbios.dll Netbios
thread $530:
77b7f8da +0e ntdll.dll NtWaitForSingleObject
761d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e2118f +3e kernel32.dll WaitForSingleObjectEx
76e21143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
76e23368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1134) at:
73a04c95 +00 winspool.drv
thread $504:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e23368 +10 kernel32.dll BaseThreadInitThunk
thread $b40:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e23368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00340000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
062d0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71810000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71bc0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71c00000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71c20000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71c50000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71de0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71e30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71e90000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72980000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
729a0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a40000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a80000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72ff0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73470000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
734c0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73630000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73640000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73660000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73670000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
736a0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
737d0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
739c0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
739d0000 security.dll 6.1.7600.16385 C:\Windows\
system32
739e0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
739f0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73ab0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73ad0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
740e0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74150000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74520000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74570000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
745a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
745d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74610000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74630000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74640000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74650000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
746b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74720000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
748c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
748d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
753f0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75400000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75460000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
760b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
760d0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
760e0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76170000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76180000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76190000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
761a0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
761b0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
761c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76210000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76260000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
763c0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
763e0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76480000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
766c0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
766e0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
766f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
768d0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76a70000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76af0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76bc0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76bd0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76be0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76c80000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ce0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76e10000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76f20000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76f30000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76f40000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
771f0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
772a0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
773f0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77430000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
774e0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77510000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
775a0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77600000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77700000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77b30000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77b60000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0338 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
0148 RapportMgmtService.exe 0 0 0
02e8 svchost.exe 0 0 0
0310 svchost.exe 0 0 0
03cc svchost.exe 0 0 0
041c svchost.exe 0 0 0
046c audiodg.exe 0 0 0
049c svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0550 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0654 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
0460 svchost.exe 0 0 0
0568 scpbradserv.exe 0 0 0
0704 svchost.exe 0 0 0
0810 core.exe 0 0 0
0930 RapportInjService_x64.exe 0 0 0
09ec fbserver.exe 0 0 0
0b38 WUDFHost.exe 0 0 0
05f8 taskhost.exe 1 26 23 normal
0be8 sppsvc.exe 0 0 0
0cf4 NisSrv.exe 0 0 0
0f08 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e28 PresentationFontCache.exe 0 0 0
0e6c dwm.exe 1 17 4 high
0174 explorer.exe 1 428 240 normal
0bec scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f8c RapportInjService_x64.exe 1 4 3 normal
0db4 igfxEM.exe 1 14 14 normal
0d4c igfxHK.exe 1 14 13 normal
0bf0 msseces.exe 1 143 59 normal
0ef8 PrnStatusMX.exe 1 23 20 normal
108c GoogleCrashHandler.exe 0 0 0
10ac GoogleCrashHandler64.exe 0 0 0
112c svchost.exe 0 0 0
11bc SearchIndexer.exe 0 0 0
1174 WmiPrvSE.exe 0 0 0
1274 OSPPSVC.EXE 0 0 0
124c core.exe 1 9 21 normal
0c2c Store.exe 1 356 261 normal C:\Program Files (x86)\
Store
10c8 slui.exe 1 43 31 normal
13a8 TrustedInstaller.exe 0 0 0
0abc wuauclt.exe 1 12 6 normal
0f30 chrome.exe 1 22 50 normal
0a30 chrome.exe 1 9 4 normal
11b0 chrome.exe 1 7 7 above normal
1314 chrome.exe 1 4 1 normal
11e8 chrome.exe 1 4 1 normal
0c54 chrome.exe 1 4 1 idle
1254 chrome.exe 1 4 3 normal
12ec WmiPrvSE.exe 0 0 0
1374 splwow64.exe 1 9 5 normal
1054 taskhost.exe 0 0 0
09cc CompatTelRunner.exe 0 0 0
05c0 conhost.exe 0 0 0
137c CompatTelRunner.exe 0 0 0
0970 DeviceDisplayObjectProvider.exe 0 0 0
13fc rundll32.exe 1 116 51 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 044c3e00
ebx = 00180100
ecx = 000204b0
edx = 044b4501
esi = 044439f0
edi = 0018e36c
eip = 00340041
esp = 0018e0bc
ebp = 0018e130
stack dump:
0018e0bc f7 75 40 00 89 1a 6f 00 - f0 39 44 04 01 01 18 00 [email protected].....
0018e0cc e7 51 6f 00 70 83 b2 06 - 70 83 b2 06 f7 75 40 00 .Qo.p...p....u@.
0018e0dc f3 c9 ec 00 38 e1 18 00 - 0c 89 40 00 30 e1 18 00 [email protected]...
0018e0ec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0fc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e10c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e11c 00 00 00 00 00 00 00 00 - 00 00 00 00 40 7d b0 06 ............@}..
0018e12c 30 42 44 04 b4 e1 18 00 - 75 61 ec 00 1c e5 18 00 0BD.....ua......
0018e13c 0c 89 40 00 b4 e1 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e14c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e15c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e16c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e17c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e18c 00 00 00 00 70 83 b2 06 - c0 97 4e 04 60 9a 4e 04 ....p.....N.`.N.
0018e19c 00 9d 4e 04 00 b2 4e 04 - 20 80 4e 04 60 85 4e 04 ..N...N. .N.`.N.
0018e1ac c0 82 4e 04 30 42 44 04 - 04 e3 18 00 81 01 53 00 ..N.0BD.......S.
0018e1bc 70 83 b2 06 c7 31 55 00 - 6c e3 18 00 f6 40 62 00 p....1U.l....@b.
0018e1cc 4c 40 62 00 6c e3 18 00 - f5 3c 55 00 70 83 b2 06 [email protected]....<U.p...
0018e1dc 28 fc 52 00 6c e3 18 00 - 4c e5 18 00 70 83 b2 06 (.R.l...L...p...
0018e1ec f3 00 00 00 05 8b 63 77 - 68 74 61 77 d1 07 01 02 ......cwhtaw....
disassembling:
[...]
006eb79e call -$2e41b7 ($4075ec) ; System.TObject.Free
006eb7a3 1375 mov eax, [esi+$5c]
006eb7a6 call -$2e41bf ($4075ec) ; System.TObject.Free
006eb7ab 1376 mov edx, ebx
006eb7ad and dl, -4
006eb7b0 mov eax, esi
006eb7b2 call -$25b8e3 ($48fed4) ; System.Classes.TComponent.Destroy
006eb7b7 1377 test bl, bl
006eb7b9 jle loc_6eb7c2
006eb7bb mov eax, esi
006eb7bd > call -$2e3b7a ($407c48) ; System.@ClassDestroy
006eb7c2 pop esi
006eb7c3 pop ebx
006eb7c4 ret
date/time : 2020-08-21, 08:23:27, 999ms
computer name : VIDRARIA-06
user name : Karina Kinaki <admin>
registered owner : Karina Kinaki
operating system : Windows 7 x64 Service Pack 1 build 7601
system language : Portuguese
system up time : 9 minutes 39 seconds
program up time : 8 minutes 17 seconds
processors : 4x Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
physical memory : 640/3968 MB (free/total)
free disk space : (C:) 58,80 GB
display mode : 1600x900, 32 bit
process id : $c2c
allocated memory : 73,89 MB
largest free block : 956,91 MB
executable : Store.exe
exec. date/time : 2020-07-15 13:10
version : 1.0.0.0
bde version : 5.2.0.2
compiled with : Delphi XE2
madExcept version : 4.0.20
callstack crc : $00000000, $240330f4, $7cd2e1a3
count : 4
exception number : 8
exception class : EAccessViolation
exception message : Access violation at address 00000000. Read of address
00000000.
thread $13b8:
77b7f8da +0e ntdll.dll NtWaitForSingleObject
761d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e2118f +3e kernel32.dll WaitForSingleObjectEx
76e21143 +0d kernel32.dll WaitForSingleObject
76e23368 +10 kernel32.dll BaseThreadInitThunk
thread $13bc:
77b80166 +0e ntdll.dll NtWaitForMultipleObjects
76e23368 +10 kernel32.dll BaseThreadInitThunk
thread $13c0:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e23368 +10 kernel32.dll BaseThreadInitThunk
thread $13d0:
77b80166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
76e23368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1134) at:
739c2713 +24f netbios.dll Netbios
thread $530:
77b7f8da +0e ntdll.dll NtWaitForSingleObject
761d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e2118f +3e kernel32.dll WaitForSingleObjectEx
76e21143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
76e23368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1134) at:
73a04c95 +00 winspool.drv
thread $504:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e23368 +10 kernel32.dll BaseThreadInitThunk
thread $b40:
77b81f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e23368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00340000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02590000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
062d0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71810000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71bc0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71c00000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71c20000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71c50000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71de0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71e30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71e90000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72980000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
729a0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a40000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a80000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72ff0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73470000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
734c0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73630000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73640000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73660000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73670000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
736a0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
737d0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
739c0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
739d0000 security.dll 6.1.7600.16385 C:\Windows\
system32
739e0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
739f0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73ab0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73ad0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
740e0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74150000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74520000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74570000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
745a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
745d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74610000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74630000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74640000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74650000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
746b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74720000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
748c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
748d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
753f0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75400000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75460000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
760b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
760d0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
760e0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76170000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76180000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76190000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
761a0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
761b0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
761c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76210000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76260000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
763c0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
763e0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76480000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
766c0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
766e0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
766f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
768d0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76a70000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76af0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76bc0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76bd0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76be0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76c80000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ce0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76e10000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76f20000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76f30000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76f40000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
771f0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
772a0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
773f0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77430000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
774e0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77510000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
775a0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77600000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77700000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77b30000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77b60000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0338 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
0148 RapportMgmtService.exe 0 0 0
02e8 svchost.exe 0 0 0
0310 svchost.exe 0 0 0
03cc svchost.exe 0 0 0
041c svchost.exe 0 0 0
046c audiodg.exe 0 0 0
049c svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0550 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0654 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
0460 svchost.exe 0 0 0
0568 scpbradserv.exe 0 0 0
0704 svchost.exe 0 0 0
0810 core.exe 0 0 0
0930 RapportInjService_x64.exe 0 0 0
09ec fbserver.exe 0 0 0
0b38 WUDFHost.exe 0 0 0
05f8 taskhost.exe 1 26 23 normal
0be8 sppsvc.exe 0 0 0
0cf4 NisSrv.exe 0 0 0
0f08 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e28 PresentationFontCache.exe 0 0 0
0e6c dwm.exe 1 17 4 high
0174 explorer.exe 1 428 235 normal
0bec scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f8c RapportInjService_x64.exe 1 4 3 normal
0db4 igfxEM.exe 1 14 14 normal
0d4c igfxHK.exe 1 14 13 normal
0bf0 msseces.exe 1 143 59 normal
0ef8 PrnStatusMX.exe 1 23 20 normal
108c GoogleCrashHandler.exe 0 0 0
10ac GoogleCrashHandler64.exe 0 0 0
112c svchost.exe 0 0 0
11bc SearchIndexer.exe 0 0 0
1174 WmiPrvSE.exe 0 0 0
1274 OSPPSVC.EXE 0 0 0
124c core.exe 1 9 22 normal
0c2c Store.exe 1 351 243 normal C:\Program Files (x86)\Store
10c8 slui.exe 1 43 31 normal
13a8 TrustedInstaller.exe 0 0 0
0abc wuauclt.exe 1 12 6 normal
0f30 chrome.exe 1 22 50 normal
0a30 chrome.exe 1 9 4 normal
11b0 chrome.exe 1 7 7 above normal
1314 chrome.exe 1 4 1 normal
11e8 chrome.exe 1 4 1 normal
0c54 chrome.exe 1 4 1 idle
1254 chrome.exe 1 4 3 normal
12ec WmiPrvSE.exe 0 0 0
1374 splwow64.exe 1 9 5 normal
1054 taskhost.exe 0 0 0
09cc CompatTelRunner.exe 0 0 0
05c0 conhost.exe 0 0 0
137c CompatTelRunner.exe 0 0 0
13fc rundll32.exe 1 116 51 normal
12e0 WmiPrvSE.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 044439f0
ebx = 000000a9
ecx = 00000000
edx = 05ccffc0
esi = 064e6510
edi = 05ccffc0
eip = 00000000
esp = 0018f41c
ebp = 006e959c
stack dump:
0018f41c b3 02 49 00 00 00 00 00 - e4 82 bf 00 c0 ff cc 05 ..I.............
0018f42c 10 65 4e 06 00 00 00 00 - 30 d5 52 00 10 65 4e 06 .eN.....0.R..eN.
0018f43c c0 ff cc 05 00 00 00 00 - 70 2e 53 00 10 65 4e 06 ........p.S..eN.
0018f44c c0 ff cc 05 00 00 00 00 - b0 b0 60 00 c0 ff cc 05 ..........`.....
0018f45c f0 f8 4d 04 0e 00 00 00 - b3 02 49 00 00 00 00 00 ..M.......I.....
0018f46c e0 f4 18 00 f0 f8 4d 04 - 54 57 60 00 54 57 60 00 ......M.TW`.TW`.
0018f47c 17 01 49 00 c0 ff cc 05 - f0 f8 4d 04 00 00 00 00 ..I.......M.....
0018f48c b4 fe 48 00 50 25 4d 04 - c0 ff cc 05 00 00 00 00 ..H.P%M.........
0018f49c 2f 11 49 00 c0 ff cc 05 - 00 00 00 00 63 3e 51 00 /.I.........c>Q.
0018f4ac c0 ff cc 05 01 5f b2 06 - ff 4b 56 00 e8 f4 18 00 ....._...KV.....
0018f4bc 64 89 40 00 e0 f4 18 00 - c0 ff cc 05 00 00 00 00 d.@.............
0018f4cc f0 f8 4d 04 78 63 61 00 - 50 25 4d 04 80 81 50 04 ..M.xca.P%M...P.
0018f4dc 2c ac 52 00 10 f5 18 00 - 3b 61 61 00 3c f5 18 00 ,.R.....;aa.<...
0018f4ec 0c 89 40 00 10 f5 18 00 - 50 25 4d 04 50 25 4d 04 [email protected]%M.P%M.
0018f4fc f0 f8 4d 04 00 00 00 00 - 00 00 00 00 50 25 4d 04 ..M.........P%M.
0018f50c f0 f8 4d 04 90 f5 18 00 - 38 54 61 00 7a 02 01 00 ..M.....8Ta.z...
0018f51c 02 02 00 00 00 00 00 00 - ca 01 1a 00 7c 16 03 00 ............|...
0018f52c ca 01 00 00 44 00 00 00 - 50 25 4d 04 4a 0c 61 00 ....D...P%M.J.a.
0018f53c 48 f5 18 00 0c 89 40 00 - 90 f5 18 00 54 f5 18 00 [email protected]...
0018f54c 0c 89 40 00 90 f5 18 00 - 60 f5 18 00 0c 89 40 00 ..@.....`.....@.
disassembling:
006f08b4 public QuickRpt.TQRCustomBand.Notification: ; function entry point
006f08b4 3371 push ebx
006f08b5 push esi
006f08b6 push edi
006f08b7 mov ebx, ecx
006f08b9 mov esi, edx
006f08bb mov edi, eax
006f08bd 3372 mov ecx, ebx
006f08bf mov edx, esi
006f08c1 mov eax, edi
006f08c3 > call -$1bda6c ($532e5c) ;
Vcl.Controls.TWinControl.Notification
006f08c8 3373 cmp bl, 1
006f08cb jnz loc_6f08dd
006f08cd cmp esi, [edi+$2fc]
006f08d3 jnz loc_6f08dd
006f08d5 3374 xor eax, eax
006f08d7 mov [edi+$2fc], eax
006f08dd 3375 pop edi
006f08de pop esi
006f08df pop ebx
006f08e0 ret
thread $1360:
77a5f8da +0e ntdll.dll NtWaitForSingleObject
754115c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76d2118f +3e kernel32.dll WaitForSingleObjectEx
76d21143 +0d kernel32.dll WaitForSingleObject
76d23368 +10 kernel32.dll BaseThreadInitThunk
thread $1364:
77a60166 +0e ntdll.dll NtWaitForMultipleObjects
76d23368 +10 kernel32.dll BaseThreadInitThunk
thread $1378:
77a60166 +00e ntdll.dll NtWaitForMultipleObjects
004d7691 +00d Store.exe madExcept CallThreadProcSafe
004d76fb +037 Store.exe madExcept ThreadExceptFrame
76d23368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1354) at:
73b42713 +24f netbios.dll Netbios
thread $47c:
77a5f8da +0e ntdll.dll NtWaitForSingleObject
754115c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76d2118f +3e kernel32.dll WaitForSingleObjectEx
76d21143 +0d kernel32.dll WaitForSingleObject
004d7691 +0d Store.exe madExcept CallThreadProcSafe
004d76fb +37 Store.exe madExcept ThreadExceptFrame
76d23368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1354) at:
73be4c95 +00 winspool.drv
thread $11bc:
77a61f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76d23368 +10 kernel32.dll BaseThreadInitThunk
thread $13c4:
77a61f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76d23368 +10 kernel32.dll BaseThreadInitThunk
thread $1068:
77a61f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76d23368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00350000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00380000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
04530000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06300000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71280000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
71950000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
719a0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
719e0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71b00000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71b30000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71cc0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71d10000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71d70000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72860000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72880000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72920000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72960000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72b10000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72b30000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72b40000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73870000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
738f0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73900000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73920000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73930000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
739a0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
739d0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73ad0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73b20000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73b40000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73b50000 security.dll 6.1.7600.16385 C:\Windows\
system32
73b60000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73b70000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73bd0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73d30000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73ff0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74400000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74450000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74480000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
744b0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
744f0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74510000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74520000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74530000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74590000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74600000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
747a0000 version.dll 6.1.7600.16385 C:\Windows\
system32
747b0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
752d0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
752e0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75340000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
753f0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75400000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75450000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
755f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75740000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75870000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
764c0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76550000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76590000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76680000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
766b0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
766c0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76750000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76760000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76770000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76780000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
767e0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
768b0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
768c0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
768e0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76940000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
769f0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76a30000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76a40000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76c80000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76d10000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76e20000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76e50000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76e60000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76e70000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76e90000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76fc0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
770c0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77370000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77420000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77580000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
77620000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77a10000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77a40000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
028c winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0304 svchost.exe 0 0 0
03f4 svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0564 svchost.exe 0 0 0
061c spoolsv.exe 0 0 0
0624 taskeng.exe 0 0 0
0654 svchost.exe 0 0 0
06cc armsvc.exe 0 0 0
06e4 atkexComSvc.exe 0 0 0
0724 svchost.exe 0 0 0
074c fbguard.exe 0 0 0
0770 svchost.exe 0 0 0
0788 NetExpressUpdater.exe 0 0 0
07f4 svchost.exe 0 0 0
04e0 scpbradserv.exe 0 0 0
067c svchost.exe 0 0 0
00bc core.exe 0 0 0
0948 RapportInjService_x64.exe 0 0 0
09f8 fbserver.exe 0 0 0
0bb4 WUDFHost.exe 0 0 0
0884 NisSrv.exe 0 0 0
0f50 WmiPrvSE.exe 0 0 0
0f8c OSPPSVC.EXE 0 0 0
0d44 taskhost.exe 1 26 24 normal
0d68 core.exe 1 9 20 normal
0e04 sppsvc.exe 0 0 0
06d8 RapportService.exe 1 14 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0a3c PresentationFontCache.exe 0 0 0
0af4 dwm.exe 1 17 4 high
0c3c explorer.exe 1 421 240 normal
0488 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
03f0 GoogleCrashHandler.exe 0 0 0
04fc GoogleCrashHandler64.exe 0 0 0
0cc0 RapportInjService_x64.exe 1 4 3 normal
0ec0 igfxEM.exe 1 14 13 normal
0e6c igfxHK.exe 1 14 13 normal
0200 msseces.exe 1 143 59 normal
0144 PrnStatusMX.exe 1 23 20 normal
1004 svchost.exe 0 0 0
10d0 SearchIndexer.exe 0 0 0
1350 Store.exe 1 1136 282 normal C:\Program Files (x86)\Store
0738 wuauclt.exe 1 12 6 normal
1258 splwow64.exe 1 9 4 normal
0ce8 chrome.exe 1 27 46 normal
1154 chrome.exe 1 9 4 normal
0a4c chrome.exe 1 7 6 above normal
13e4 chrome.exe 1 4 1 normal
1220 chrome.exe 1 4 1 normal
1024 chrome.exe 1 4 1 idle
0538 chrome.exe 1 4 3 normal
10f0 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
1250 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0bcb92b0
ebx = 00003303
ecx = 00000000
edx = 029b2ac8
esi = 0018e4b8
edi = 0066c7e4
eip = 0066e702
esp = 0018e47c
ebp = 0018e4e4
stack dump:
0018e47c 02 e7 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..f.............
0018e48c 90 e4 18 00 02 e7 66 00 - b0 92 cb 0b 03 33 00 00 ......f......3..
0018e49c b8 e4 18 00 e4 c7 66 00 - e4 e4 18 00 ac e4 18 00 ......f.........
0018e4ac 50 50 49 06 0e e7 66 00 - 34 e6 67 00 00 00 00 00 PPI...f.4.g.....
0018e4bc 50 50 49 06 00 00 00 00 - 2f e5 67 00 f0 e4 18 00 PPI...../.g.....
0018e4cc 0c 89 40 00 e4 e4 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e4dc 69 e6 67 01 50 50 49 06 - 0c e5 18 00 87 e5 67 00 i.g.PPI.......g.
0018e4ec a6 49 67 00 24 e5 18 00 - 0c 89 40 00 0c e5 18 00 .Ig.$.....@.....
0018e4fc 50 50 49 06 00 00 00 00 - 00 00 00 00 50 50 49 06 PPI.........PPI.
0018e50c 38 e5 18 00 4a 8f 67 00 - c0 e7 18 00 0c 01 53 00 8...J.g.......S.
0018e51c 01 00 00 00 77 70 65 00 - 44 e5 18 00 0c 89 40 00 ....wpe.D.....@.
0018e52c 38 e5 18 00 60 dc a3 0a - 50 50 49 06 08 e6 18 00 8...`...PPI.....
0018e53c be 6e 65 00 1c 4c 16 01 - 70 e9 18 00 0c 89 40 00 .ne..L..p.....@.
0018e54c 08 e6 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e55c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e56c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e57c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e58c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e59c 00 00 00 00 00 00 00 00 - e0 81 e5 40 60 dc a3 0a ...........@`...
0018e5ac 00 00 00 00 fa a4 4f fa - df 84 e5 40 00 00 00 00 ......O....@....
disassembling:
[...]
01164bf3 mov eax, [ebp-$18]
01164bf6 mov eax, [eax+$250]
01164bfc mov ecx, [eax]
01164bfe call dword ptr [ecx+$38]
01164c01 425 mov edx, $1165c54
01164c06 mov eax, [ebp-$18]
01164c09 mov eax, [eax+$250]
01164c0f mov ecx, [eax]
01164c11 call dword ptr [ecx+$38]
01164c14 427 mov eax, [ebp-$18]
01164c17 > call -$b0dd68 ($656eb4) ; Data.DB.TDataSet.Open
01164c1c 428 mov eax, [ebp-$18]
01164c1f call -$b0b4a8 ($65977c) ; Data.DB.TDataSet.First
01164c24 429 mov eax, [ebp-$18]
01164c27 cmp byte ptr [eax+$a9], 0
01164c2e jz loc_1164c3c
01164c30 mov eax, [ebp-$18]
01164c33 cmp byte ptr [eax+$a8], 0
01164c3a jnz loc_1164c4b
01164c3c 431 mov eax, [ebp-4]
01164c3f call +$32fb4 ($1197bf8) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $1214:
77a1f8da +0e ntdll.dll NtWaitForSingleObject
753915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7543118f +3e kernel32.dll WaitForSingleObjectEx
75431143 +0d kernel32.dll WaitForSingleObject
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $1230:
77a20166 +0e ntdll.dll NtWaitForMultipleObjects
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $344:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $1260:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $3bc:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $17cc:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
modules:
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02620000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02650000 BCLW32.dll C:\Program
Files (x86)\Store
062c0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063d0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71720000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71760000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
717a0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
717c0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71ae0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71c80000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71cd0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71d30000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
725a0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
725c0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
728e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72920000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72ad0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72af0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72b00000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72da0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
72ef0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
737c0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
738c0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73b00000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73b80000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73b90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73bb0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73bc0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73bf0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73c50000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73d00000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73d40000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73d60000 security.dll 6.1.7600.16385 C:\Windows\
system32
73f60000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73f80000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74410000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74440000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74470000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
744b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
744d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
744e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
744f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74550000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
745c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74760000 version.dll 6.1.7600.16385 C:\Windows\
system32
74770000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75290000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
752a0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75300000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75380000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75420000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75590000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
755c0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75800000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75950000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75960000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
759c0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75ac0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75ae0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75af0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b00000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b30000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75b50000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75b60000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75b70000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b80000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b90000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75bd0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75c70000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75d20000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75df0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75e90000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75ea0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76000000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76100000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76230000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76e80000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76f70000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77220000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
772d0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77470000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77490000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77520000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77570000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
779d0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77a00000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
032c svchost.exe 0 0 0
0378 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
00a8 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0308 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0564 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07fc svchost.exe 0 0 0
0550 scpbradserv.exe 0 0 0
042c svchost.exe 0 0 0
0764 core.exe 0 0 0
08fc RapportInjService_x64.exe 0 0 0
09f4 fbserver.exe 0 0 0
0b74 WUDFHost.exe 0 0 0
05e8 NisSrv.exe 0 0 0
0ee0 taskhost.exe 1 26 23 normal
0ef8 core.exe 1 9 21 normal
0fa4 sppsvc.exe 0 0 0
0d88 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0da4 GoogleCrashHandler.exe 0 0 0
0dbc GoogleCrashHandler64.exe 0 0 0
0e18 RapportInjService_x64.exe 1 4 3 normal
0c94 svchost.exe 0 0 0
0f1c WmiPrvSE.exe 0 0 0
0190 OSPPSVC.EXE 0 0 0
1050 PresentationFontCache.exe 0 0 0
1058 dwm.exe 1 18 4 high
1070 explorer.exe 1 657 418 normal
10c8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
114c igfxEM.exe 1 14 14 normal
1154 igfxHK.exe 1 14 13 normal
11c4 msseces.exe 1 143 60 normal
11dc PrnStatusMX.exe 1 23 20 normal
13d4 SearchIndexer.exe 0 0 0
166c wuauclt.exe 1 12 7 normal
05ec DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
16f8 OIS.EXE 1 102 44 normal
1534 chrome.exe 1 22 47 normal
140c chrome.exe 1 9 4 normal
1210 chrome.exe 1 7 6 above normal
162c chrome.exe 1 4 1 normal
0338 chrome.exe 1 4 1 idle
16a4 chrome.exe 1 4 1 idle
068c chrome.exe 1 4 3 normal
1430 Store.exe 1 180 217 normal C:\Program Files (x86)\Store
0cec WmiPrvSE.exe 0 0 0
0e4c VSSVC.exe 0 0 0
1590 svchost.exe 0 0 0
0c8c audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a226310
ebx = 00003303
ecx = 00000000
edx = 00242ac8
esi = 0018e134
edi = 0066cb50
eip = 0066ea6e
esp = 0018e0f8
ebp = 0018e160
stack dump:
0018e0f8 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e108 0c e1 18 00 6e ea 66 00 - 10 63 22 0a 03 33 00 00 ....n.f..c"..3..
0018e118 34 e1 18 00 50 cb 66 00 - 60 e1 18 00 28 e1 18 00 4...P.f.`...(...
0018e128 60 84 4a 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 `.J.z.f...g.....
0018e138 60 84 4a 04 00 00 00 00 - 9b e8 67 00 6c e1 18 00 `.J.......g.l...
0018e148 0c 89 40 00 60 e1 18 00 - 00 00 00 00 00 00 00 00 ..@.`...........
0018e158 d5 e9 67 01 60 84 4a 04 - 88 e1 18 00 f3 e8 67 00 ..g.`.J.......g.
0018e168 12 4d 67 00 a0 e1 18 00 - 0c 89 40 00 88 e1 18 00 .Mg.......@.....
0018e178 60 84 4a 04 00 00 00 00 - 00 00 00 00 60 84 4a 04 `.J.........`.J.
0018e188 b4 e1 18 00 b6 92 67 00 - 40 e4 18 00 74 e2 18 00 [email protected]...
0018e198 01 e1 18 00 e3 73 65 00 - c0 e1 18 00 0c 89 40 00 .....se.......@.
0018e1a8 b4 e1 18 00 50 46 23 0a - 60 84 4a 04 1c e2 18 00 ....PF#.`.J.....
0018e1b8 2a 72 65 00 c6 ea 16 01 - 48 e2 18 00 0c 89 40 00 *re.....H.....@.
0018e1c8 1c e2 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e1d8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e1e8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e1f8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e208 00 00 00 00 00 00 00 00 - 60 84 4a 04 00 00 00 00 ........`.J.....
0018e218 d0 14 3f 04 30 e2 18 00 - a4 f4 16 01 50 46 23 0a ..?.0.......PF#.
0018e228 74 e2 18 00 d0 14 3f 04 - 68 e2 18 00 b3 62 53 00 t.....?.h....bS.
disassembling:
[...]
0116ea9f call -$c4043c ($52e668) ; Vcl.Controls.TControl.GetText
0116eaa4 mov eax, [ebp-$2c]
0116eaa7 push eax
0116eaa8 mov eax, [ebp-$c]
0116eaab mov eax, [eax+$258]
0116eab1 xor edx, edx
0116eab3 call -$b1b440 ($653678) ; Data.DB.TParams.GetItem
0116eab8 pop edx
0116eab9 call -$b18c6e ($655e50) ; Data.DB.TParam.SetAsString
0116eabe 223 mov eax, [ebp-$c]
0116eac1 > call -$b178a6 ($657220) ; Data.DB.TDataSet.Open
0116eac6 226 mov eax, [ebp-4]
0116eac9 mov eax, [eax+$3b0]
0116eacf mov edx, [eax]
0116ead1 call dword ptr [edx+$f8]
0116ead7 cmp al, 1
0116ead9 jnz loc_116eb9b
0116eadf 228 mov eax, [$15bcdf0]
0116eae4 mov eax, [eax]
0116eae6 mov eax, [eax+$c0]
0116eaec mov [ebp-$10], eax
[...]
thread $1214:
77a1f8da +0e ntdll.dll NtWaitForSingleObject
753915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7543118f +3e kernel32.dll WaitForSingleObjectEx
75431143 +0d kernel32.dll WaitForSingleObject
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $1230:
77a20166 +0e ntdll.dll NtWaitForMultipleObjects
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $344:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
modules:
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02620000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02650000 BCLW32.dll C:\Program
Files (x86)\Store
062c0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063d0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71720000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71760000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
717a0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
717c0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71ae0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71c80000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71cd0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71d30000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
725a0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
725c0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
728e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72920000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72ad0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72af0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72b00000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72da0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
72ef0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
737c0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
738c0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73b00000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73b80000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73b90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73bb0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73bc0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73bf0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73c50000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73d00000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73d40000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73d60000 security.dll 6.1.7600.16385 C:\Windows\
system32
73f60000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73f80000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74410000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74440000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74470000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
744b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
744d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
744e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
744f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74550000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
745c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74760000 version.dll 6.1.7600.16385 C:\Windows\
system32
74770000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75290000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
752a0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75300000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75380000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75410000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75420000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75590000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
755c0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75800000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75950000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75960000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
759c0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75ac0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75ae0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75af0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b00000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b30000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75b50000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75b60000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75b70000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b80000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b90000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75bd0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75c70000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75d20000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75df0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75e90000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75ea0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76000000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76100000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76230000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76e80000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76f70000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77220000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
772d0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77470000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77490000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77520000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77570000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
779d0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77a00000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
032c svchost.exe 0 0 0
0378 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
00a8 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0308 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0564 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07fc svchost.exe 0 0 0
0550 scpbradserv.exe 0 0 0
042c svchost.exe 0 0 0
0764 core.exe 0 0 0
08fc RapportInjService_x64.exe 0 0 0
09f4 fbserver.exe 0 0 0
0b74 WUDFHost.exe 0 0 0
05e8 NisSrv.exe 0 0 0
0ee0 taskhost.exe 1 26 22 normal
0ef8 core.exe 1 9 21 normal
0fa4 sppsvc.exe 0 0 0
0d88 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0da4 GoogleCrashHandler.exe 0 0 0
0dbc GoogleCrashHandler64.exe 0 0 0
0e18 RapportInjService_x64.exe 1 4 3 normal
0c94 svchost.exe 0 0 0
0f1c WmiPrvSE.exe 0 0 0
0190 OSPPSVC.EXE 0 0 0
1050 PresentationFontCache.exe 0 0 0
1058 dwm.exe 1 18 4 high
1070 explorer.exe 1 659 418 normal
10c8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
114c igfxEM.exe 1 14 14 normal
1154 igfxHK.exe 1 14 13 normal
11c4 msseces.exe 1 143 60 normal
11dc PrnStatusMX.exe 1 23 20 normal
13d4 SearchIndexer.exe 0 0 0
166c wuauclt.exe 1 12 7 normal
05ec DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
16f8 OIS.EXE 1 102 44 normal
1534 chrome.exe 1 22 45 normal
140c chrome.exe 1 9 4 normal
1210 chrome.exe 1 7 6 above normal
162c chrome.exe 1 4 1 normal
0338 chrome.exe 1 4 1 idle
16a4 chrome.exe 1 4 1 idle
068c chrome.exe 1 4 3 normal
1430 Store.exe 1 201 339 normal C:\Program Files (x86)\Store
0e4c VSSVC.exe 0 0 0
1590 svchost.exe 0 0 0
0c8c audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 05fcd4e0
ebx = 00003303
ecx = 00000000
edx = 00242ac8
esi = 00000000
edi = 0018e3d4
eip = 0066ea6e
esp = 0018dd1c
ebp = 0018dd84
stack dump:
0018dd1c 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018dd2c 30 dd 18 00 6e ea 66 00 - e0 d4 fc 05 03 33 00 00 0...n.f......3..
0018dd3c 00 00 00 00 d4 e3 18 00 - 84 dd 18 00 4c dd 18 00 ............L...
0018dd4c 70 24 56 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 p$V.z.f...g.....
0018dd5c f0 f3 22 0a 50 cb 66 00 - 9b e8 67 00 8c dd 18 00 ..".P.f...g.....
0018dd6c 0c 89 40 00 84 dd 18 00 - 50 cb 66 00 00 00 00 00 [email protected].....
0018dd7c a8 dd 18 00 70 24 56 06 - a0 dd 18 00 31 e9 67 00 ....p$V.....1.g.
0018dd8c a8 dd 18 00 0c 89 40 00 - a0 dd 18 00 00 00 00 00 ......@.........
0018dd9c 70 24 56 06 dc dd 18 00 - 10 88 1c 01 f0 dd 18 00 p$V.............
0018ddac 0c 89 40 00 dc dd 18 00 - f0 f3 22 0a 00 00 00 00 ..@.......".....
0018ddbc 00 00 00 00 00 00 00 00 - 00 00 00 00 e0 84 e5 40 ...............@
0018ddcc 70 24 56 06 00 00 00 00 - 00 00 00 00 00 00 00 00 p$V.............
0018dddc 74 e1 18 00 e8 37 ec 00 - 00 00 00 00 00 00 00 00 t....7..........
0018ddec 00 00 00 00 7c e1 18 00 - 0c 89 40 00 74 e1 18 00 ....|[email protected]...
0018ddfc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018de0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018de1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018de2c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018de3c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018de4c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
011c87e6 call -$d6bcfb ($45caf0) ; System.SysUtils.StringReplace
011c87eb mov eax, [ebp-$1c]
011c87ee push eax
011c87ef mov edx, $11c8a34
011c87f4 mov eax, [ebp-$10]
011c87f7 mov eax, [eax+$258]
011c87fd call -$b74fe6 ($65381c) ; Data.DB.TParams.ParamByName
011c8802 pop edx
011c8803 call -$b72040 ($6567c8) ; Data.DB.TParam.SetAsMemo
011c8808 42 mov eax, [ebp-$10]
011c880b > call -$b49f1c ($67e8f4) ; Bde.DBTables.TQuery.ExecSQL
011c8810 43 mov eax, [ebp-$10]
011c8813 call -$b715ec ($65722c) ; Data.DB.TDataSet.Close
011c8818 45 xor eax, eax
011c881a pop edx
011c881b pop ecx
011c881c pop ecx
011c881d mov fs:[eax], edx
011c8820 push $11c8854
011c8825 lea eax, [ebp-$24]
011c8828 mov edx, 3
[...]
thread $f60:
77a1f8da +0e ntdll.dll NtWaitForSingleObject
753915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7543118f +3e kernel32.dll WaitForSingleObjectEx
75431143 +0d kernel32.dll WaitForSingleObject
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $1194:
77a20166 +0e ntdll.dll NtWaitForMultipleObjects
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $cc4:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $124c:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $149c:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $968:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00350000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00380000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
04840000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06350000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71720000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71760000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
717a0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
717c0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71ae0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71c80000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71cd0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71d30000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
725a0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
725c0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
728e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72920000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72ad0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72af0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72b00000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72da0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
72ef0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
737c0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
738c0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73b00000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73b80000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73b90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73bb0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73bc0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73bf0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73c50000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73d00000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73d40000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73d60000 security.dll 6.1.7600.16385 C:\Windows\
system32
73f60000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73f80000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74410000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74440000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74470000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
744b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
744d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
744e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
744f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74550000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
745c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74760000 version.dll 6.1.7600.16385 C:\Windows\
system32
74770000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75290000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
752a0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75300000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75380000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75410000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75420000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75590000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
755c0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75800000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75950000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75960000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
759c0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75ac0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75ae0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75af0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b00000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b30000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75b50000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75b60000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75b70000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b80000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b90000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75bd0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75c70000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75d20000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75df0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75e90000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75ea0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76000000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76100000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76230000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76e80000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76f70000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77220000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
772d0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77470000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77490000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77520000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77570000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
779d0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77a00000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
032c svchost.exe 0 0 0
0378 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
00a8 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0308 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0564 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07fc svchost.exe 0 0 0
0550 scpbradserv.exe 0 0 0
042c svchost.exe 0 0 0
0764 core.exe 0 0 0
08fc RapportInjService_x64.exe 0 0 0
09f4 fbserver.exe 0 0 0
0b74 WUDFHost.exe 0 0 0
05e8 NisSrv.exe 0 0 0
0ee0 taskhost.exe 1 26 23 normal
0ef8 core.exe 1 9 21 normal
0fa4 sppsvc.exe 0 0 0
0d88 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0da4 GoogleCrashHandler.exe 0 0 0
0dbc GoogleCrashHandler64.exe 0 0 0
0e18 RapportInjService_x64.exe 1 4 3 normal
0c94 svchost.exe 0 0 0
0f1c WmiPrvSE.exe 0 0 0
0190 OSPPSVC.EXE 0 0 0
1050 PresentationFontCache.exe 0 0 0
1058 dwm.exe 1 18 4 high
1070 explorer.exe 1 681 426 normal
10c8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
114c igfxEM.exe 1 14 14 normal
1154 igfxHK.exe 1 14 13 normal
11c4 msseces.exe 1 143 60 normal
11dc PrnStatusMX.exe 1 23 20 normal
13d4 SearchIndexer.exe 0 0 0
166c wuauclt.exe 1 12 7 normal
05ec DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
16f8 OIS.EXE 1 102 44 normal
1534 chrome.exe 1 22 46 normal
140c chrome.exe 1 9 4 normal
1210 chrome.exe 1 7 6 above normal
162c chrome.exe 1 4 1 normal
0338 chrome.exe 1 4 1 idle
16a4 chrome.exe 1 4 1 idle
068c chrome.exe 1 4 3 normal
1430 Store.exe 1 278 217 normal C:\Program Files (x86)\Store
1590 svchost.exe 0 0 0
0c8c audiodg.exe 0 0 0
16e4 splwow64.exe 1 9 3 normal
04dc Store.exe 1 165 218 normal C:\Program Files (x86)\Store
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a1ec700
ebx = 00003303
ecx = 00000000
edx = 02982ac8
esi = 0018de0c
edi = 0066cb50
eip = 0066ea6e
esp = 0018ddd0
ebp = 0018de38
stack dump:
0018ddd0 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018dde0 e4 dd 18 00 6e ea 66 00 - 00 c7 1e 0a 03 33 00 00 ....n.f......3..
0018ddf0 0c de 18 00 50 cb 66 00 - 38 de 18 00 00 de 18 00 ....P.f.8.......
0018de00 60 6f 61 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 `oa.z.f...g.....
0018de10 60 6f 61 04 00 00 00 00 - 9b e8 67 00 44 de 18 00 `oa.......g.D...
0018de20 0c 89 40 00 38 de 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018de30 d5 e9 67 01 60 6f 61 04 - 60 de 18 00 f3 e8 67 00 ..g.`oa.`.....g.
0018de40 12 4d 67 00 78 de 18 00 - 0c 89 40 00 60 de 18 00 .Mg.x.....@.`...
0018de50 60 6f 61 04 00 00 00 00 - 00 00 00 00 60 6f 61 04 `oa.........`oa.
0018de60 8c de 18 00 b6 92 67 00 - 04 00 00 00 2c df 18 00 ......g.....,...
0018de70 01 00 00 00 e3 73 65 00 - 98 de 18 00 0c 89 40 00 .....se.......@.
0018de80 8c de 18 00 30 c4 5b 04 - 60 6f 61 04 cc de 18 00 ....0.[.`oa.....
0018de90 2a 72 65 00 53 b8 75 00 - e4 de 18 00 0c 89 40 00 *re.S.u.......@.
0018dea0 cc de 18 00 30 c4 5b 04 - 00 00 00 00 00 00 00 00 ....0.[.........
0018deb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dec0 30 c4 5b 04 2c df 18 00 - b0 fa 56 06 48 df 18 00 0.[.,.....V.H...
0018ded0 8d 85 64 00 01 00 00 00 - 94 df 18 00 d0 37 4d 06 ..d..........7M.
0018dee0 ba 37 77 00 f0 de 18 00 - 0c 89 40 00 48 df 18 00 [email protected]...
0018def0 bc e0 18 00 0c 89 40 00 - 48 df 18 00 05 00 00 00 [email protected].......
0018df00 a0 e1 76 00 b0 e0 18 00 - 02 00 00 00 02 00 00 00 ..v.............
disassembling:
[...]
0075b82a mov edx, 3
0075b82f call -$35106c ($40a7c8) ; System.@UStrCatN
0075b834 mov edx, [ebp-$18]
0075b837 mov eax, [ebp-4]
0075b83a mov eax, [eax+$7c]
0075b83d mov eax, [eax+$250]
0075b843 mov ecx, [eax]
0075b845 call dword ptr [ecx+$38]
0075b848 2102 mov eax, [ebp-4]
0075b84b mov eax, [eax+$7c]
0075b84e > call -$104633 ($657220) ; Data.DB.TDataSet.Open
0075b853 2103 mov edx, $75b974
0075b858 mov eax, [ebp-4]
0075b85b mov eax, [eax+$7c]
0075b85e call -$1032c3 ($6585a0) ; Data.DB.TDataSet.FieldByName
0075b863 lea edx, [ebp-$20]
0075b866 mov ecx, [eax]
0075b868 call dword ptr [ecx+$80]
0075b86e mov edx, [ebp-$20]
0075b871 mov eax, [ebp-8]
0075b874 call -$352145 ($409734) ; System.@UStrAsg
[...]
thread $1314:
77a1f8da +0e ntdll.dll NtWaitForSingleObject
753915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7543118f +3e kernel32.dll WaitForSingleObjectEx
75431143 +0d kernel32.dll WaitForSingleObject
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $1138:
77a20166 +0e ntdll.dll NtWaitForMultipleObjects
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $1648:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $14d8:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $13ac:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $112c:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06290000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063a0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71720000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71760000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
717a0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
717c0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71ae0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71c80000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71cd0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71d30000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
725a0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
725c0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
728e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72920000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72ad0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72af0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72b00000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72da0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
72ef0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
737c0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
738c0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73b00000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73b80000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73b90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73bb0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73bc0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73bf0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73c50000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73d00000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73d40000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73d60000 security.dll 6.1.7600.16385 C:\Windows\
system32
73f60000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73f80000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74410000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74440000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74470000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
744b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
744d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
744e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
744f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74550000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
745c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74760000 version.dll 6.1.7600.16385 C:\Windows\
system32
74770000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75290000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
752a0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75300000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75380000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75420000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75590000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
755c0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75800000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75950000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75960000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
759c0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75ac0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75ae0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75af0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b00000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b30000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75b50000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75b60000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75b70000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b80000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b90000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75bd0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75c70000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75d20000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75df0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75e90000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75ea0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76000000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76100000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76230000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76e80000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76f70000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77220000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
772d0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77470000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77490000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77520000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77570000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
779d0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77a00000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
032c svchost.exe 0 0 0
0378 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
00a8 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0308 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0564 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07fc svchost.exe 0 0 0
0550 scpbradserv.exe 0 0 0
042c svchost.exe 0 0 0
0764 core.exe 0 0 0
08fc RapportInjService_x64.exe 0 0 0
09f4 fbserver.exe 0 0 0
0b74 WUDFHost.exe 0 0 0
05e8 NisSrv.exe 0 0 0
0ee0 taskhost.exe 1 26 23 normal
0ef8 core.exe 1 9 21 normal
0fa4 sppsvc.exe 0 0 0
0d88 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0da4 GoogleCrashHandler.exe 0 0 0
0dbc GoogleCrashHandler64.exe 0 0 0
0e18 RapportInjService_x64.exe 1 4 3 normal
0c94 svchost.exe 0 0 0
0f1c WmiPrvSE.exe 0 0 0
0190 OSPPSVC.EXE 0 0 0
1050 PresentationFontCache.exe 0 0 0
1058 dwm.exe 1 18 4 high
1070 explorer.exe 1 681 428 normal
10c8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
114c igfxEM.exe 1 14 14 normal
1154 igfxHK.exe 1 14 13 normal
11c4 msseces.exe 1 143 60 normal
11dc PrnStatusMX.exe 1 23 20 normal
13d4 SearchIndexer.exe 0 0 0
166c wuauclt.exe 1 12 7 normal
05ec DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
16f8 OIS.EXE 1 102 44 normal
1534 chrome.exe 1 22 44 normal
140c chrome.exe 1 9 4 normal
1210 chrome.exe 1 7 6 above normal
162c chrome.exe 1 4 1 normal
0338 chrome.exe 1 4 1 idle
16a4 chrome.exe 1 4 1 idle
068c chrome.exe 1 4 3 normal
1430 Store.exe 1 314 219 normal C:\Program Files (x86)\Store
0c8c audiodg.exe 0 0 0
16e4 splwow64.exe 1 9 2 normal
1730 svchost.exe 0 0 0
143c Store.exe 1 165 218 normal C:\Program Files (x86)\Store
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a294ec0
ebx = 00003303
ecx = 00000000
edx = 026f2ac8
esi = 0018e520
edi = 0066cb50
eip = 0066ea6e
esp = 0018e4e4
ebp = 0018e54c
stack dump:
0018e4e4 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e4f4 f8 e4 18 00 6e ea 66 00 - c0 4e 29 0a 03 33 00 00 ....n.f..N)..3..
0018e504 20 e5 18 00 50 cb 66 00 - 4c e5 18 00 14 e5 18 00 ...P.f.L.......
0018e514 60 84 53 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 `.S.z.f...g.....
0018e524 60 84 53 04 00 00 00 00 - 9b e8 67 00 58 e5 18 00 `.S.......g.X...
0018e534 0c 89 40 00 4c e5 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018e544 d5 e9 67 01 60 84 53 04 - 74 e5 18 00 f3 e8 67 00 ..g.`.S.t.....g.
0018e554 12 4d 67 00 8c e5 18 00 - 0c 89 40 00 74 e5 18 00 [email protected]...
0018e564 60 84 53 04 00 00 00 00 - 00 00 00 00 60 84 53 04 `.S.........`.S.
0018e574 a0 e5 18 00 b6 92 67 00 - c0 e7 18 00 f0 81 51 04 ......g.......Q.
0018e584 01 1c 54 00 e3 73 65 00 - ac e5 18 00 0c 89 40 00 ..T..se.......@.
0018e594 a0 e5 18 00 f0 81 51 04 - 60 84 53 04 e0 e5 18 00 ......Q.`.S.....
0018e5a4 2a 72 65 00 d0 fe 12 01 - e8 e5 18 00 0c 89 40 00 *re...........@.
0018e5b4 e0 e5 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e5c4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e5d4 d0 2c 3f 06 60 84 53 04 - d0 2c 3f 06 08 e6 18 00 .,?.`.S..,?.....
0018e5e4 86 fd 12 01 70 e9 18 00 - 0c 89 40 00 08 e6 18 00 ....p.....@.....
0018e5f4 00 00 00 00 00 00 00 00 - 00 00 00 00 f0 81 51 04 ..............Q.
0018e604 d0 2c 3f 06 58 e7 18 00 - ed 04 53 00 f0 81 51 04 .,?.X.....S...Q.
0018e614 33 35 55 00 c0 e7 18 00 - 62 44 62 00 b8 43 62 00 35U.....bDb..Cb.
disassembling:
[...]
0112fea5 push $1130034
0112feaa lea eax, [ebp-$20]
0112fead mov edx, 3
0112feb2 call -$d256ef ($40a7c8) ; System.@UStrCatN
0112feb7 mov edx, [ebp-$20]
0112feba mov eax, [ebp-8]
0112febd mov eax, [eax+$250]
0112fec3 mov ecx, [eax]
0112fec5 call dword ptr [ecx+$38]
0112fec8 463 mov eax, [ebp-8]
0112fecb > call -$ad8cb0 ($657220) ; Data.DB.TDataSet.Open
0112fed0 464 mov eax, [ebp-8]
0112fed3 cmp byte ptr [eax+$a8], 0
0112feda jz loc_112fefd
0112fedc mov eax, [ebp-8]
0112fedf cmp byte ptr [eax+$a9], 0
0112fee6 jz loc_112fefd
0112fee8 465 mov edx, $1130048
0112feed mov eax, [ebp-4]
0112fef0 mov eax, [eax+$4f4]
0112fef6 call -$c01837 ($52e6c4) ; Vcl.Controls.TControl.SetText
[...]
thread $1314:
77a1f8da +0e ntdll.dll NtWaitForSingleObject
753915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7543118f +3e kernel32.dll WaitForSingleObjectEx
75431143 +0d kernel32.dll WaitForSingleObject
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $1138:
77a20166 +0e ntdll.dll NtWaitForMultipleObjects
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $1648:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $14d8:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $13ac:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $112c:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06290000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063a0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71720000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71760000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
717a0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
717c0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71ae0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71c80000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71cd0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71d30000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
725a0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
725c0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
728e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72920000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72ad0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72af0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72b00000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72da0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
72ef0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
737c0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
738c0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73b00000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73b80000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73b90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73bb0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73bc0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73bf0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73c50000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73d00000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73d40000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73d60000 security.dll 6.1.7600.16385 C:\Windows\
system32
73f60000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73f80000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
74410000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74440000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74470000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
744b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
744d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
744e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
744f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74550000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
745c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74760000 version.dll 6.1.7600.16385 C:\Windows\
system32
74770000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75290000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
752a0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75300000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75380000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75410000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75420000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75590000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
755c0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75800000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75950000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75960000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
759c0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75ac0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75ae0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75af0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b00000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b30000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75b50000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75b60000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75b70000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b80000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b90000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75bd0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75c70000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75d20000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75df0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75e90000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75ea0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76000000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76100000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76230000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76e80000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76f70000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77220000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
772d0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77470000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77490000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77520000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77570000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
779d0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77a00000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
032c svchost.exe 0 0 0
0378 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
00a8 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0308 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0564 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07fc svchost.exe 0 0 0
0550 scpbradserv.exe 0 0 0
042c svchost.exe 0 0 0
0764 core.exe 0 0 0
08fc RapportInjService_x64.exe 0 0 0
09f4 fbserver.exe 0 0 0
0b74 WUDFHost.exe 0 0 0
05e8 NisSrv.exe 0 0 0
0ee0 taskhost.exe 1 26 20 normal
0ef8 core.exe 1 9 21 normal
0fa4 sppsvc.exe 0 0 0
0d88 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0da4 GoogleCrashHandler.exe 0 0 0
0dbc GoogleCrashHandler64.exe 0 0 0
0e18 RapportInjService_x64.exe 1 4 3 normal
0c94 svchost.exe 0 0 0
0f1c WmiPrvSE.exe 0 0 0
0190 OSPPSVC.EXE 0 0 0
1050 PresentationFontCache.exe 0 0 0
1058 dwm.exe 1 29 13 high
1070 explorer.exe 1 679 425 normal
10c8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
114c igfxEM.exe 1 14 14 normal
1154 igfxHK.exe 1 14 13 normal
11c4 msseces.exe 1 143 60 normal
11dc PrnStatusMX.exe 1 23 20 normal
13d4 SearchIndexer.exe 0 0 0
166c wuauclt.exe 1 12 7 normal
05ec DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
16f8 OIS.EXE 1 102 44 normal
1534 chrome.exe 1 22 43 normal
140c chrome.exe 1 9 4 normal
1210 chrome.exe 1 7 6 above normal
162c chrome.exe 1 4 1 normal
0338 chrome.exe 1 4 1 idle
16a4 chrome.exe 1 4 1 idle
068c chrome.exe 1 4 3 normal
1430 Store.exe 1 314 219 normal C:\Program Files (x86)\Store
0c8c audiodg.exe 0 0 0
16e4 splwow64.exe 1 9 2 normal
1730 svchost.exe 0 0 0
143c Store.exe 1 165 220 normal C:\Program Files (x86)\Store
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0457b168
ebx = 00003303
ecx = 00000000
edx = 026f2ac8
esi = 0018ec90
edi = 0066cb50
eip = 0066ea6e
esp = 0018ec54
ebp = 0018ecbc
stack dump:
0018ec54 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018ec64 68 ec 18 00 6e ea 66 00 - 68 b1 57 04 03 33 00 00 h...n.f.h.W..3..
0018ec74 90 ec 18 00 50 cb 66 00 - bc ec 18 00 84 ec 18 00 ....P.f.........
0018ec84 60 99 53 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 `.S.z.f...g.....
0018ec94 60 99 53 04 00 00 00 00 - 9b e8 67 00 c8 ec 18 00 `.S.......g.....
0018eca4 0c 89 40 00 bc ec 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018ecb4 d5 e9 67 01 60 99 53 04 - e4 ec 18 00 f3 e8 67 00 ..g.`.S.......g.
0018ecc4 12 4d 67 00 fc ec 18 00 - 0c 89 40 00 e4 ec 18 00 .Mg.......@.....
0018ecd4 60 99 53 04 00 00 00 00 - 00 00 00 00 60 99 53 04 `.S.........`.S.
0018ece4 10 ed 18 00 b6 92 67 00 - 08 00 00 00 18 3c 62 00 ......g......<b.
0018ecf4 01 00 00 00 e3 73 65 00 - 1c ed 18 00 0c 89 40 00 .....se.......@.
0018ed04 10 ed 18 00 10 de 25 0a - 60 99 53 04 38 ed 18 00 ......%.`.S.8...
0018ed14 2a 72 65 00 1b 8f 13 01 - 6c ef 18 00 0c 89 40 00 *re.....l.....@.
0018ed24 38 ed 18 00 00 00 00 00 - 10 de 25 0a 60 99 53 04 8.........%.`.S.
0018ed34 d0 2c 3f 06 5c ed 18 00 - ed 04 53 00 10 de 25 0a .,?.\.....S...%.
0018ed44 1d 3c 62 00 07 3c 62 00 - d8 ee 18 00 18 3b 62 00 .<b..<b......;b.
0018ed54 10 de 25 0a 01 00 00 00 - cc ee 18 00 25 09 53 00 ..%.........%.S.
0018ed64 08 00 00 00 16 00 00 00 - 00 00 00 00 d8 ee 18 00 ................
0018ed74 10 de 25 0a a1 09 53 00 - 16 00 08 00 d8 ee 18 00 ..%...S.........
0018ed84 4a 01 12 00 01 ee 18 00 - 2c e9 52 00 50 00 00 00 J.......,.R.P...
disassembling:
[...]
01138ef0 push $1139140
01138ef5 lea eax, [ebp-$10]
01138ef8 mov edx, 3
01138efd call -$d2e73a ($40a7c8) ; System.@UStrCatN
01138f02 mov edx, [ebp-$10]
01138f05 mov eax, [ebp-8]
01138f08 mov eax, [eax+$250]
01138f0e mov ecx, [eax]
01138f10 call dword ptr [ecx+$38]
01138f13 1150 mov eax, [ebp-8]
01138f16 > call -$ae1cfb ($657220) ; Data.DB.TDataSet.Open
01138f1b 1152 mov eax, [ebp-4]
01138f1e mov eax, [eax+$598]
01138f24 xor edx, edx
01138f26 mov [eax+$c], edx
01138f29 1153 mov ecx, [$15bc3ac]
01138f2f mov eax, [$15bcc10]
01138f34 mov eax, [eax]
01138f36 mov edx, [$eb7cf4]
01138f3c call -$b2369d ($6158a4) ; Vcl.Forms.TApplication.CreateForm
01138f41 1154 mov eax, [ebp-4]
[...]
thread $1314:
77a1f8da +0e ntdll.dll NtWaitForSingleObject
753915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7543118f +3e kernel32.dll WaitForSingleObjectEx
75431143 +0d kernel32.dll WaitForSingleObject
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $1138:
77a20166 +0e ntdll.dll NtWaitForMultipleObjects
75433368 +10 kernel32.dll BaseThreadInitThunk
thread $13ac:
77a21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75433368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06290000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063a0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71720000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71760000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
717a0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
717c0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71ae0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71c80000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71cd0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71d30000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
725a0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
725c0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
728e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72920000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72ad0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72af0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72b00000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72da0000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
72ef0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
737c0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
738c0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73b00000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73b80000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73b90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73bb0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73bc0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73bf0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73c50000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73d00000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73d40000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73d60000 security.dll 6.1.7600.16385 C:\Windows\
system32
73f60000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73f80000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
743c0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74410000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74440000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74470000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
744b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
744d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
744e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
744f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74550000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
745c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74760000 version.dll 6.1.7600.16385 C:\Windows\
system32
74770000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75290000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
752a0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75300000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75380000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75410000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75420000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75590000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
755c0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75800000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75950000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75960000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
759c0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75ac0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75ae0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75af0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b00000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75b30000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75b50000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75b60000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75b70000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b80000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b90000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75bd0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75c70000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75d20000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75df0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75e90000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75ea0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76000000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76100000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76230000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76e80000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76f70000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77220000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
772d0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77470000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77490000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77520000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77570000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
779d0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77a00000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 wininit.exe 0 0 0
025c csrss.exe 1 0 0
0294 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
032c svchost.exe 0 0 0
0378 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
00a8 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0308 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0564 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07fc svchost.exe 0 0 0
0550 scpbradserv.exe 0 0 0
042c svchost.exe 0 0 0
0764 core.exe 0 0 0
08fc RapportInjService_x64.exe 0 0 0
09f4 fbserver.exe 0 0 0
0b74 WUDFHost.exe 0 0 0
05e8 NisSrv.exe 0 0 0
0ee0 taskhost.exe 1 26 24 normal
0ef8 core.exe 1 9 21 normal
0fa4 sppsvc.exe 0 0 0
0d88 RapportService.exe 1 15 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0da4 GoogleCrashHandler.exe 0 0 0
0dbc GoogleCrashHandler64.exe 0 0 0
0e18 RapportInjService_x64.exe 1 4 3 normal
0c94 svchost.exe 0 0 0
0f1c WmiPrvSE.exe 0 0 0
0190 OSPPSVC.EXE 0 0 0
1050 PresentationFontCache.exe 0 0 0
1058 dwm.exe 1 17 4 high
1070 explorer.exe 1 657 423 normal
10c8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
114c igfxEM.exe 1 14 14 normal
1154 igfxHK.exe 1 14 13 normal
11c4 msseces.exe 1 143 60 normal
11dc PrnStatusMX.exe 1 23 20 normal
13d4 SearchIndexer.exe 0 0 0
166c wuauclt.exe 1 12 7 normal
05ec DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
16f8 OIS.EXE 1 102 44 normal
1534 chrome.exe 1 24 48 normal
140c chrome.exe 1 9 4 normal
1210 chrome.exe 1 7 6 above normal
162c chrome.exe 1 4 1 normal
0338 chrome.exe 1 4 1 normal
16a4 chrome.exe 1 4 1 idle
068c chrome.exe 1 4 3 normal
143c Store.exe 1 467 226 normal C:\Program Files (x86)\Store
12a8 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a60d310
ebx = 00003303
ecx = 00000000
edx = 026f2ac8
esi = 0018e500
edi = 0066cb50
eip = 0066ea6e
esp = 0018e4c4
ebp = 0018e52c
stack dump:
0018e4c4 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e4d4 d8 e4 18 00 6e ea 66 00 - 10 d3 60 0a 03 33 00 00 ....n.f...`..3..
0018e4e4 00 e5 18 00 50 cb 66 00 - 2c e5 18 00 f4 e4 18 00 ....P.f.,.......
0018e4f4 c0 ff 53 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 ..S.z.f...g.....
0018e504 c0 ff 53 04 00 00 00 00 - 9b e8 67 00 38 e5 18 00 ..S.......g.8...
0018e514 0c 89 40 00 2c e5 18 00 - 00 00 00 00 00 00 00 00 ..@.,...........
0018e524 d5 e9 67 01 c0 ff 53 04 - 54 e5 18 00 f3 e8 67 00 ..g...S.T.....g.
0018e534 12 4d 67 00 6c e5 18 00 - 0c 89 40 00 54 e5 18 00 [email protected]...
0018e544 c0 ff 53 04 00 00 00 00 - 00 00 00 00 c0 ff 53 04 ..S...........S.
0018e554 80 e5 18 00 b6 92 67 00 - 00 00 00 00 44 af 60 00 ......g.....D.`.
0018e564 01 00 00 00 e3 73 65 00 - 8c e5 18 00 0c 89 40 00 .....se.......@.
0018e574 80 e5 18 00 a0 6e 44 05 - c0 ff 53 04 b4 e5 18 00 .....nD...S.....
0018e584 2a 72 65 00 c2 1d 0e 01 - cc e5 18 00 0c 89 40 00 *re...........@.
0018e594 b4 e5 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e5a4 00 00 00 00 c0 ff 53 04 - 00 00 00 00 a0 6e 44 05 ......S......nD.
0018e5b4 c4 e5 18 00 14 ae 0e 01 - a0 6e 44 05 a0 6e 44 05 .........nD..nD.
0018e5c4 e8 e5 18 00 df b2 60 00 - fc e5 18 00 dc 86 40 00 ......`.......@.
0018e5d4 e8 e5 18 00 00 00 00 00 - 44 af 60 00 a0 6e 44 05 ........D.`..nD.
0018e5e4 a0 6e 44 05 18 e6 18 00 - 23 af 60 00 44 af 60 00 .nD.....#.`.D.`.
0018e5f4 00 00 00 00 70 7c 40 00 - 20 e6 18 00 7f 7c 40 00 ....p|@. ....|@.
disassembling:
[...]
010e1d99 088 mov eax, [ebp-$c]
010e1d9c mov eax, [eax+$250]
010e1da2 mov edx, [eax]
010e1da4 call dword ptr [edx+$44]
010e1da7 089 mov eax, [ebp-$c]
010e1daa mov eax, [eax+$250]
010e1db0 mov edx, $10e2900
010e1db5 mov ecx, [eax]
010e1db7 call dword ptr [ecx+$38]
010e1dba 090 mov eax, [ebp-$c]
010e1dbd > call -$a8aba2 ($657220) ; Data.DB.TDataSet.Open
010e1dc2 091 mov eax, [ebp-$c]
010e1dc5 call -$a882e2 ($659ae8) ; Data.DB.TDataSet.First
010e1dca 093 xor eax, eax
010e1dcc mov [ebp-8], eax
010e1dcf 094 mov eax, [ebp-4]
010e1dd2 mov eax, [eax+$3d4]
010e1dd8 call -$834db1 ($8ad02c) ;
AdvCGrid.TAdvColumnGrid.GetColumnCollection
010e1ddd mov edx, [ebp-8]
010e1de0 call -$835d81 ($8ac064) ;
AdvCGrid.TGridColumnCollection.GetItem
010e1de5 mov edx, $32
[...]
thread $103c:
7781f8da +0e ntdll.dll NtWaitForSingleObject
75f915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75c3118f +3e kernel32.dll WaitForSingleObjectEx
75c31143 +0d kernel32.dll WaitForSingleObject
75c33368 +10 kernel32.dll BaseThreadInitThunk
thread $1030:
77820166 +0e ntdll.dll NtWaitForMultipleObjects
75c33368 +10 kernel32.dll BaseThreadInitThunk
thread $131c:
77820166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
75c33368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1220) at:
73c12713 +24f netbios.dll Netbios
thread $13b8:
7781f8da +0e ntdll.dll NtWaitForSingleObject
75f915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75c3118f +3e kernel32.dll WaitForSingleObjectEx
75c31143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
75c33368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1220) at:
73db4c95 +00 winspool.drv
thread $163c:
77821f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75c33368 +10 kernel32.dll BaseThreadInitThunk
modules:
002d0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06240000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71190000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71400000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71460000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71730000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
719e0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71a20000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71a40000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71f70000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71fc0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72020000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72620000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72640000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
726e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72720000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
728d0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
728f0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72900000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73020000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73140000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
73180000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73410000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73900000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73980000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73990000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
739b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
739c0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
739f0000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73a30000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73b90000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73be0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73c10000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73c20000 security.dll 6.1.7600.16385 C:\Windows\
system32
73c30000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73c40000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73ca0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73da0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
741c0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74210000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74240000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74270000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
742b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
742d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
742e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
742f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74350000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
743c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74560000 version.dll 6.1.7600.16385 C:\Windows\
system32
74570000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75090000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
750a0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75100000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75130000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
751b0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
751c0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75220000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
752b0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75340000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75360000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75610000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75620000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75630000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
757d0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75830000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75990000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
759a0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
759f0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75a10000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75ab0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75af0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b00000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75b10000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75bb0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75c20000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75d30000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75f70000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f80000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75fd0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76c20000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76cf0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76de0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76df0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e00000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76eb0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76f60000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77090000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77150000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77250000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
773a0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
773c0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
777d0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77800000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0298 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
00a4 RapportMgmtService.exe 0 0 0
02b4 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
0408 svchost.exe 0 0 0
0434 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0508 igfxCUIService.exe 0 0 0
055c svchost.exe 0 0 0
061c spoolsv.exe 0 0 0
0624 taskeng.exe 0 0 0
064c svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06e8 atkexComSvc.exe 0 0 0
0728 svchost.exe 0 0 0
0750 fbguard.exe 0 0 0
0774 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f0 svchost.exe 0 0 0
04fc scpbradserv.exe 0 0 0
0698 svchost.exe 0 0 0
076c core.exe 0 0 0
09a0 RapportInjService_x64.exe 0 0 0
09d4 fbserver.exe 0 0 0
0b48 WUDFHost.exe 0 0 0
0bb0 taskhost.exe 1 26 23 normal
05c0 core.exe 1 9 21 normal
0db0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0cc4 dwm.exe 1 21 5 high
0170 PresentationFontCache.exe 0 0 0
0204 explorer.exe 1 586 332 normal
0f14 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f80 RapportInjService_x64.exe 1 4 3 normal
0d00 igfxEM.exe 1 14 13 normal
0178 igfxHK.exe 1 14 12 normal
0d5c msseces.exe 1 292 208 normal
09d0 PrnStatusMX.exe 1 23 20 normal
1080 WmiPrvSE.exe 0 0 0
1200 SearchIndexer.exe 0 0 0
13e0 GoogleCrashHandler.exe 0 0 0
13f8 svchost.exe 0 0 0
1008 GoogleCrashHandler64.exe 0 0 0
1218 Store.exe 1 2540 536 normal C:\Program Files (x86)\Store
04b8 wuauclt.exe 1 12 6 normal
09ec splwow64.exe 1 11 4 normal
11d8 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1564 Store.exe 1 91 69 normal C:\Program Files (x86)\Store
14d8 Store.exe 1 173 184 normal C:\Program Files (x86)\Store
0f00 OIS.EXE 1 117 55 normal
0850 OIS.EXE 1 114 46 normal
0ab8 OIS.EXE 1 109 45 normal
12d0 OIS.EXE 1 109 45 normal
15ec OIS.EXE 1 144 113 normal
0520 chrome.exe 1 74 47 normal
16f0 chrome.exe 1 9 4 normal
0678 chrome.exe 1 8 8 above normal
17cc chrome.exe 1 4 1 normal
0f0c chrome.exe 1 4 1 normal
17e4 chrome.exe 1 4 1 idle
177c chrome.exe 1 4 3 normal
13f0 svchost.exe 0 0 0
12b8 OSPPSVC.EXE 0 0 0
17bc sppsvc.exe 0 0 0
051c NisSrv.exe 0 0 0
0ce4 PrintIsolationHost.exe 0 0 0
0fe8 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0ac93788
ebx = 00003303
ecx = 00000000
edx = 025d2ac8
esi = 0018e0ac
edi = 0066cb50
eip = 0066ea6e
esp = 0018e070
ebp = 0018e0d8
stack dump:
0018e070 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e080 84 e0 18 00 6e ea 66 00 - 88 37 c9 0a 03 33 00 00 ....n.f..7...3..
0018e090 ac e0 18 00 50 cb 66 00 - d8 e0 18 00 a0 e0 18 00 ....P.f.........
0018e0a0 f0 0b 57 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 ..W.z.f...g.....
0018e0b0 f0 0b 57 04 00 00 00 00 - 9b e8 67 00 e4 e0 18 00 ..W.......g.....
0018e0c0 0c 89 40 00 d8 e0 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e0d0 d5 e9 67 01 f0 0b 57 04 - 00 e1 18 00 f3 e8 67 00 ..g...W.......g.
0018e0e0 12 4d 67 00 18 e1 18 00 - 0c 89 40 00 00 e1 18 00 .Mg.......@.....
0018e0f0 f0 0b 57 04 00 00 00 00 - 00 00 00 00 f0 0b 57 04 ..W...........W.
0018e100 2c e1 18 00 b6 92 67 00 - 6c e3 18 00 10 bf 74 0a ,.....g.l.....t.
0018e110 01 00 00 00 e3 73 65 00 - 38 e1 18 00 0c 89 40 00 .....se.8.....@.
0018e120 2c e1 18 00 10 bf 74 0a - f0 0b 57 04 b4 e1 18 00 ,.....t...W.....
0018e130 2a 72 65 00 d1 91 e9 00 - 1c e5 18 00 0c 89 40 00 *re...........@.
0018e140 b4 e1 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e150 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e160 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e170 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e180 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e190 10 bf 74 0a f0 0b 57 04 - 90 0e 57 04 30 11 57 04 ..t...W...W.0.W.
0018e1a0 30 26 57 04 50 f4 56 04 - 90 f9 56 04 f0 f6 56 04 0&W.P.V...V...V.
disassembling:
[...]
00e991a6 push $e99338
00e991ab lea eax, [ebp-$58]
00e991ae mov edx, 3
00e991b3 call -$a8e9f0 ($40a7c8) ; System.@UStrCatN
00e991b8 mov edx, [ebp-$58]
00e991bb mov eax, [ebp-$20]
00e991be mov eax, [eax+$250]
00e991c4 mov ecx, [eax]
00e991c6 call dword ptr [ecx+$38]
00e991c9 125 mov eax, [ebp-$20]
00e991cc > call -$841fb1 ($657220) ; Data.DB.TDataSet.Open
00e991d1 126 mov eax, [ebp-$20]
00e991d4 call -$83f6f1 ($659ae8) ; Data.DB.TDataSet.First
00e991d9 128 lea edx, [ebp-$60]
00e991dc mov eax, [$15bcdf0]
00e991e1 mov eax, [eax]
00e991e3 mov eax, [eax+$330]
00e991e9 mov ecx, [eax]
00e991eb call dword ptr [ecx+$80]
00e991f1 cmp dword ptr [ebp-$60], 0
00e991f5 jnz loc_e99201
[...]
thread $1718:
7781f8da +0e ntdll.dll NtWaitForSingleObject
75f915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75c3118f +3e kernel32.dll WaitForSingleObjectEx
75c31143 +0d kernel32.dll WaitForSingleObject
75c33368 +10 kernel32.dll BaseThreadInitThunk
thread $13d0:
77820166 +0e ntdll.dll NtWaitForMultipleObjects
75c33368 +10 kernel32.dll BaseThreadInitThunk
thread $15ac:
77821f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75c33368 +10 kernel32.dll BaseThreadInitThunk
modules:
001c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00290000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
025b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02690000 BCLW32.dll C:\Program
Files (x86)\Store
04350000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06330000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71190000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71400000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71460000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71730000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
719e0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71a20000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71a40000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71f70000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71fc0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72020000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72620000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72640000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
726e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72720000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
728d0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
728f0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72900000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73410000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73900000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73980000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73990000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
739b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
739c0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73a30000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73b90000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73be0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73c20000 security.dll 6.1.7600.16385 C:\Windows\
system32
73c30000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73c40000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73ca0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73da0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
74210000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74240000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74270000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
742b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
742d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
742e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
742f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74350000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
743c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74560000 version.dll 6.1.7600.16385 C:\Windows\
system32
74570000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75090000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
750a0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75100000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75130000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
751b0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
751c0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75220000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
752b0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75340000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75360000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75610000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75620000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75630000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
757d0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75830000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75990000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
759a0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
759f0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75a10000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75ab0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75af0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b00000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75b10000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75bb0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75c20000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75d30000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75f70000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f80000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75fd0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76c20000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76cf0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76de0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76df0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e00000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76eb0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76f60000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77090000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77150000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77250000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
773a0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
773c0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
777d0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77800000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0298 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
00a4 RapportMgmtService.exe 0 0 0
02b4 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
0408 svchost.exe 0 0 0
0434 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0508 igfxCUIService.exe 0 0 0
055c svchost.exe 0 0 0
061c spoolsv.exe 0 0 0
0624 taskeng.exe 0 0 0
064c svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06e8 atkexComSvc.exe 0 0 0
0728 svchost.exe 0 0 0
0750 fbguard.exe 0 0 0
0774 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f0 svchost.exe 0 0 0
04fc scpbradserv.exe 0 0 0
0698 svchost.exe 0 0 0
076c core.exe 0 0 0
09a0 RapportInjService_x64.exe 0 0 0
09d4 fbserver.exe 0 0 0
0b48 WUDFHost.exe 0 0 0
0bb0 taskhost.exe 1 26 23 normal
05c0 core.exe 1 9 21 normal
0db0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0cc4 dwm.exe 1 21 5 high
0170 PresentationFontCache.exe 0 0 0
0204 explorer.exe 1 584 336 normal
0f14 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f80 RapportInjService_x64.exe 1 4 3 normal
0d00 igfxEM.exe 1 14 13 normal
0178 igfxHK.exe 1 14 12 normal
0d5c msseces.exe 1 292 208 normal
09d0 PrnStatusMX.exe 1 23 20 normal
1080 WmiPrvSE.exe 0 0 0
1200 SearchIndexer.exe 0 0 0
13e0 GoogleCrashHandler.exe 0 0 0
13f8 svchost.exe 0 0 0
1008 GoogleCrashHandler64.exe 0 0 0
04b8 wuauclt.exe 1 12 6 normal
11d8 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1564 Store.exe 1 91 69 normal C:\Program Files (x86)\Store
14d8 Store.exe 1 173 184 normal C:\Program Files (x86)\Store
0f00 OIS.EXE 1 117 55 normal
0850 OIS.EXE 1 114 46 normal
0ab8 OIS.EXE 1 109 45 normal
12d0 OIS.EXE 1 109 45 normal
15ec OIS.EXE 1 144 113 normal
0520 chrome.exe 1 74 45 normal
16f0 chrome.exe 1 9 4 normal
0678 chrome.exe 1 8 8 above normal
17cc chrome.exe 1 4 1 normal
0f0c chrome.exe 1 4 1 idle
17e4 chrome.exe 1 4 1 idle
177c chrome.exe 1 4 3 normal
13f0 svchost.exe 0 0 0
12b8 OSPPSVC.EXE 0 0 0
17bc sppsvc.exe 0 0 0
051c NisSrv.exe 0 0 0
0fe8 audiodg.exe 0 0 0
14a4 Store.exe 1 91 69 normal C:\Program Files (x86)\Store
041c Store.exe 1 173 219 normal C:\Program Files (x86)\Store
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a18cb80
ebx = 00003303
ecx = 00000000
edx = 002e2ac8
esi = 0018e014
edi = 0066cb50
eip = 0066ea6e
esp = 0018dfd8
ebp = 0018e040
stack dump:
0018dfd8 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018dfe8 ec df 18 00 6e ea 66 00 - 80 cb 18 0a 03 33 00 00 ....n.f......3..
0018dff8 14 e0 18 00 50 cb 66 00 - 40 e0 18 00 08 e0 18 00 ....P.f.@.......
0018e008 f0 0b 56 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 ..V.z.f...g.....
0018e018 f0 0b 56 04 00 00 00 00 - 9b e8 67 00 4c e0 18 00 ..V.......g.L...
0018e028 0c 89 40 00 40 e0 18 00 - 00 00 00 00 00 00 00 00 ..@.@...........
0018e038 d5 e9 67 01 f0 0b 56 04 - 68 e0 18 00 f3 e8 67 00 ..g...V.h.....g.
0018e048 12 4d 67 00 80 e0 18 00 - 0c 89 40 00 68 e0 18 00 [email protected]...
0018e058 f0 0b 56 04 00 00 00 00 - 00 00 00 00 f0 0b 56 04 ..V...........V.
0018e068 94 e0 18 00 b6 92 67 00 - 6c e3 18 00 80 79 22 0a ......g.l....y".
0018e078 01 00 00 00 e3 73 65 00 - a0 e0 18 00 0c 89 40 00 .....se.......@.
0018e088 94 e0 18 00 80 79 22 0a - f0 0b 56 04 b4 e1 18 00 .....y"...V.....
0018e098 2a 72 65 00 07 a6 e9 00 - 1c e5 18 00 0c 89 40 00 *re...........@.
0018e0a8 b4 e1 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0b8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0c8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0d8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0e8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0f8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e108 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00e9a5dc push $e9b164
00e9a5e1 lea eax, [ebp-$70]
00e9a5e4 mov edx, 3
00e9a5e9 call -$a8fe26 ($40a7c8) ; System.@UStrCatN
00e9a5ee mov edx, [ebp-$70]
00e9a5f1 mov eax, [ebp-$24]
00e9a5f4 mov eax, [eax+$250]
00e9a5fa mov ecx, [eax]
00e9a5fc call dword ptr [ecx+$38]
00e9a5ff 317 mov eax, [ebp-$24]
00e9a602 > call -$8433e7 ($657220) ; Data.DB.TDataSet.Open
00e9a607 318 mov eax, [ebp-$24]
00e9a60a call -$840b27 ($659ae8) ; Data.DB.TDataSet.First
00e9a60f 321 mov eax, [$15bcdf0]
00e9a614 mov eax, [eax]
00e9a616 mov eax, [eax+$1b48]
00e9a61c mov [ebp-$28], eax
00e9a61f 323 mov eax, [ebp-$28]
00e9a622 call -$8433fb ($65722c) ; Data.DB.TDataSet.Close
00e9a627 324 mov eax, [ebp-$28]
00e9a62a mov eax, [eax+$250]
[...]
thread $1718:
7781f8da +0e ntdll.dll NtWaitForSingleObject
75f915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75c3118f +3e kernel32.dll WaitForSingleObjectEx
75c31143 +0d kernel32.dll WaitForSingleObject
75c33368 +10 kernel32.dll BaseThreadInitThunk
thread $13d0:
77820166 +0e ntdll.dll NtWaitForMultipleObjects
75c33368 +10 kernel32.dll BaseThreadInitThunk
thread $15ac:
77821f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75c33368 +10 kernel32.dll BaseThreadInitThunk
modules:
001c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00290000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
025b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02690000 BCLW32.dll C:\Program
Files (x86)\Store
04350000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06330000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71190000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71400000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71460000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71730000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
719e0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71a20000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71a40000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71f70000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71fc0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72020000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72620000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72640000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
726e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72720000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
728d0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
728f0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72900000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73410000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73900000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73980000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73990000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
739b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
739c0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73a30000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73b90000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73be0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73c20000 security.dll 6.1.7600.16385 C:\Windows\
system32
73c30000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73c40000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73ca0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73da0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
74210000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74240000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74270000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
742b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
742d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
742e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
742f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74350000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
743c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74560000 version.dll 6.1.7600.16385 C:\Windows\
system32
74570000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75090000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
750a0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75100000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75130000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
751b0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
751c0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75220000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
752b0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75340000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75360000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75610000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75620000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75630000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
757d0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75830000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75990000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
759a0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
759f0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75a10000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75ab0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75af0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b00000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75b10000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75bb0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75c20000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75d30000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75f70000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f80000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75fd0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76c20000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76cf0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76de0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76df0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e00000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76eb0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76f60000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77090000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77150000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77250000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
773a0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
773c0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
777d0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77800000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0298 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
00a4 RapportMgmtService.exe 0 0 0
02b4 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
0408 svchost.exe 0 0 0
0434 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0508 igfxCUIService.exe 0 0 0
055c svchost.exe 0 0 0
061c spoolsv.exe 0 0 0
0624 taskeng.exe 0 0 0
064c svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06e8 atkexComSvc.exe 0 0 0
0728 svchost.exe 0 0 0
0750 fbguard.exe 0 0 0
0774 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f0 svchost.exe 0 0 0
04fc scpbradserv.exe 0 0 0
0698 svchost.exe 0 0 0
076c core.exe 0 0 0
09a0 RapportInjService_x64.exe 0 0 0
09d4 fbserver.exe 0 0 0
0b48 WUDFHost.exe 0 0 0
0bb0 taskhost.exe 1 26 22 normal
05c0 core.exe 1 9 21 normal
0db0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0cc4 dwm.exe 1 21 5 high
0170 PresentationFontCache.exe 0 0 0
0204 explorer.exe 1 584 338 normal
0f14 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f80 RapportInjService_x64.exe 1 4 3 normal
0d00 igfxEM.exe 1 14 13 normal
0178 igfxHK.exe 1 14 12 normal
0d5c msseces.exe 1 292 208 normal
09d0 PrnStatusMX.exe 1 23 20 normal
1080 WmiPrvSE.exe 0 0 0
1200 SearchIndexer.exe 0 0 0
13e0 GoogleCrashHandler.exe 0 0 0
13f8 svchost.exe 0 0 0
1008 GoogleCrashHandler64.exe 0 0 0
04b8 wuauclt.exe 1 12 6 normal
11d8 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1564 Store.exe 1 91 69 normal C:\Program Files (x86)\Store
14d8 Store.exe 1 173 184 normal C:\Program Files (x86)\Store
0f00 OIS.EXE 1 117 55 normal
0850 OIS.EXE 1 114 46 normal
0ab8 OIS.EXE 1 109 45 normal
12d0 OIS.EXE 1 109 45 normal
15ec OIS.EXE 1 144 113 normal
0520 chrome.exe 1 74 45 normal
16f0 chrome.exe 1 9 4 normal
0678 chrome.exe 1 8 8 above normal
17cc chrome.exe 1 4 1 normal
0f0c chrome.exe 1 4 1 idle
17e4 chrome.exe 1 4 1 idle
177c chrome.exe 1 4 3 normal
13f0 svchost.exe 0 0 0
12b8 OSPPSVC.EXE 0 0 0
17bc sppsvc.exe 0 0 0
051c NisSrv.exe 0 0 0
0fe8 audiodg.exe 0 0 0
14a4 Store.exe 1 91 69 normal C:\Program Files (x86)\Store
041c Store.exe 1 173 219 normal C:\Program Files (x86)\Store
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a21e378
ebx = 00003303
ecx = 00000000
edx = 002e2ac8
esi = 0018e070
edi = 0066cb50
eip = 0066ea6e
esp = 0018e034
ebp = 0018e09c
stack dump:
0018e034 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e044 48 e0 18 00 6e ea 66 00 - 78 e3 21 0a 03 33 00 00 H...n.f.x.!..3..
0018e054 70 e0 18 00 50 cb 66 00 - 9c e0 18 00 64 e0 18 00 p...P.f.....d...
0018e064 f0 0b 56 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 ..V.z.f...g.....
0018e074 f0 0b 56 04 00 00 00 00 - 9b e8 67 00 a8 e0 18 00 ..V.......g.....
0018e084 0c 89 40 00 9c e0 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e094 d5 e9 67 01 f0 0b 56 04 - c4 e0 18 00 f3 e8 67 00 ..g...V.......g.
0018e0a4 12 4d 67 00 dc e0 18 00 - 0c 89 40 00 c4 e0 18 00 .Mg.......@.....
0018e0b4 f0 0b 56 04 00 00 00 00 - 00 00 00 00 f0 0b 56 04 ..V...........V.
0018e0c4 f0 e0 18 00 b6 92 67 00 - 6c e3 18 00 c0 7f 22 0a ......g.l.....".
0018e0d4 01 00 00 00 e3 73 65 00 - fc e0 18 00 0c 89 40 00 .....se.......@.
0018e0e4 f0 e0 18 00 c0 7f 22 0a - f0 0b 56 04 b4 e1 18 00 ......"...V.....
0018e0f4 2a 72 65 00 9a 0c ea 00 - 1c e5 18 00 0c 89 40 00 *re...........@.
0018e104 b4 e1 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e114 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e124 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e134 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e144 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e154 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e164 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00ea0c6f push $ea11b4
00ea0c74 lea eax, [ebp-$5c]
00ea0c77 mov edx, 3
00ea0c7c call -$a964b9 ($40a7c8) ; System.@UStrCatN
00ea0c81 mov edx, [ebp-$5c]
00ea0c84 mov eax, [ebp-$20]
00ea0c87 mov eax, [eax+$250]
00ea0c8d mov ecx, [eax]
00ea0c8f call dword ptr [ecx+$38]
00ea0c92 788 mov eax, [ebp-$20]
00ea0c95 > call -$849a7a ($657220) ; Data.DB.TDataSet.Open
00ea0c9a 789 mov eax, [ebp-$20]
00ea0c9d call -$8471ba ($659ae8) ; Data.DB.TDataSet.First
00ea0ca2 791 mov ecx, [$15bbb08]
00ea0ca8 mov eax, [$15bcc10]
00ea0cad mov eax, [eax]
00ea0caf mov edx, [$e93540]
00ea0cb5 call -$88b416 ($6158a4) ; Vcl.Forms.TApplication.CreateForm
00ea0cba 792 mov eax, [$15bbb08]
00ea0cbf mov eax, [eax]
00ea0cc1 mov eax, [eax+$5f4]
[...]
thread $1718:
7781f8da +0e ntdll.dll NtWaitForSingleObject
75f915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75c3118f +3e kernel32.dll WaitForSingleObjectEx
75c31143 +0d kernel32.dll WaitForSingleObject
75c33368 +10 kernel32.dll BaseThreadInitThunk
thread $13d0:
77820166 +0e ntdll.dll NtWaitForMultipleObjects
75c33368 +10 kernel32.dll BaseThreadInitThunk
thread $15ac:
77821f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75c33368 +10 kernel32.dll BaseThreadInitThunk
modules:
001c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00290000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
025b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02690000 BCLW32.dll C:\Program
Files (x86)\Store
04350000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06330000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
71190000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71400000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71460000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71730000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
719e0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71a20000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71a40000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71f70000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71fc0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72020000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72620000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72640000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
726e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72720000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
728d0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
728f0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72900000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73410000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73900000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73980000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73990000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
739b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
739c0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73a30000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73b90000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73be0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73c20000 security.dll 6.1.7600.16385 C:\Windows\
system32
73c30000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73c40000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73ca0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73da0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
74210000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74240000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74270000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
742b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
742d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
742e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
742f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74350000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
743c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74560000 version.dll 6.1.7600.16385 C:\Windows\
system32
74570000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75090000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
750a0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75100000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75130000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
751b0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
751c0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75220000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
752b0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75340000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75360000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75610000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75620000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75630000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
757d0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75830000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75990000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
759a0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
759f0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75a10000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75ab0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75af0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b00000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75b10000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75bb0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75c20000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75d30000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75f70000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f80000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75fd0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76c20000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76cf0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76de0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76df0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e00000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76eb0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76f60000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77090000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77150000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77250000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
773a0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
773c0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
777d0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77800000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0298 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
00a4 RapportMgmtService.exe 0 0 0
02b4 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
0408 svchost.exe 0 0 0
0434 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0508 igfxCUIService.exe 0 0 0
055c svchost.exe 0 0 0
061c spoolsv.exe 0 0 0
0624 taskeng.exe 0 0 0
064c svchost.exe 0 0 0
06d4 armsvc.exe 0 0 0
06e8 atkexComSvc.exe 0 0 0
0728 svchost.exe 0 0 0
0750 fbguard.exe 0 0 0
0774 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07f0 svchost.exe 0 0 0
04fc scpbradserv.exe 0 0 0
0698 svchost.exe 0 0 0
076c core.exe 0 0 0
09a0 RapportInjService_x64.exe 0 0 0
09d4 fbserver.exe 0 0 0
0b48 WUDFHost.exe 0 0 0
0bb0 taskhost.exe 1 26 23 normal
05c0 core.exe 1 9 21 normal
0db0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0cc4 dwm.exe 1 21 5 high
0170 PresentationFontCache.exe 0 0 0
0204 explorer.exe 1 584 337 normal
0f14 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f80 RapportInjService_x64.exe 1 4 3 normal
0d00 igfxEM.exe 1 14 13 normal
0178 igfxHK.exe 1 14 12 normal
0d5c msseces.exe 1 292 208 normal
09d0 PrnStatusMX.exe 1 23 20 normal
1080 WmiPrvSE.exe 0 0 0
1200 SearchIndexer.exe 0 0 0
13e0 GoogleCrashHandler.exe 0 0 0
13f8 svchost.exe 0 0 0
1008 GoogleCrashHandler64.exe 0 0 0
04b8 wuauclt.exe 1 12 6 normal
11d8 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1564 Store.exe 1 91 69 normal C:\Program Files (x86)\Store
14d8 Store.exe 1 173 184 normal C:\Program Files (x86)\Store
0f00 OIS.EXE 1 117 55 normal
0850 OIS.EXE 1 114 46 normal
0ab8 OIS.EXE 1 109 45 normal
12d0 OIS.EXE 1 109 45 normal
15ec OIS.EXE 1 144 113 normal
0520 chrome.exe 1 74 45 normal
16f0 chrome.exe 1 9 4 normal
0678 chrome.exe 1 8 8 above normal
17cc chrome.exe 1 4 1 normal
0f0c chrome.exe 1 4 1 idle
17e4 chrome.exe 1 4 1 idle
177c chrome.exe 1 4 3 normal
13f0 svchost.exe 0 0 0
12b8 OSPPSVC.EXE 0 0 0
17bc sppsvc.exe 0 0 0
051c NisSrv.exe 0 0 0
0fe8 audiodg.exe 0 0 0
14a4 Store.exe 1 91 69 normal C:\Program Files (x86)\Store
041c Store.exe 1 173 219 normal C:\Program Files (x86)\Store
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a18cfe0
ebx = 00003303
ecx = 00000000
edx = 002e2ac8
esi = 0018e090
edi = 0066cb50
eip = 0066ea6e
esp = 0018e054
ebp = 0018e0bc
stack dump:
0018e054 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e064 68 e0 18 00 6e ea 66 00 - e0 cf 18 0a 03 33 00 00 h...n.f......3..
0018e074 90 e0 18 00 50 cb 66 00 - bc e0 18 00 84 e0 18 00 ....P.f.........
0018e084 f0 0b 56 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 ..V.z.f...g.....
0018e094 f0 0b 56 04 00 00 00 00 - 9b e8 67 00 c8 e0 18 00 ..V.......g.....
0018e0a4 0c 89 40 00 bc e0 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e0b4 d5 e9 67 01 f0 0b 56 04 - e4 e0 18 00 f3 e8 67 00 ..g...V.......g.
0018e0c4 12 4d 67 00 fc e0 18 00 - 0c 89 40 00 e4 e0 18 00 .Mg.......@.....
0018e0d4 f0 0b 56 04 00 00 00 00 - 00 00 00 00 f0 0b 56 04 ..V...........V.
0018e0e4 10 e1 18 00 b6 92 67 00 - 6c e3 18 00 e0 82 22 0a ......g.l.....".
0018e0f4 01 00 00 00 e3 73 65 00 - 1c e1 18 00 0c 89 40 00 .....se.......@.
0018e104 10 e1 18 00 e0 82 22 0a - f0 0b 56 04 b4 e1 18 00 ......"...V.....
0018e114 2a 72 65 00 4e 2c ea 00 - 1c e5 18 00 0c 89 40 00 *re.N,........@.
0018e124 b4 e1 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e134 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e144 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e154 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e164 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e174 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e184 00 00 00 00 00 00 00 00 - 00 00 00 00 e0 82 22 0a ..............".
disassembling:
[...]
00ea2c23 push $ea2f2c
00ea2c28 lea eax, [ebp-$58]
00ea2c2b mov edx, 3
00ea2c30 call -$a9846d ($40a7c8) ; System.@UStrCatN
00ea2c35 mov edx, [ebp-$58]
00ea2c38 mov eax, [ebp-$20]
00ea2c3b mov eax, [eax+$250]
00ea2c41 mov ecx, [eax]
00ea2c43 call dword ptr [ecx+$38]
00ea2c46 0991 mov eax, [ebp-$20]
00ea2c49 > call -$84ba2e ($657220) ; Data.DB.TDataSet.Open
00ea2c4e 0992 mov eax, [ebp-$20]
00ea2c51 call -$84916e ($659ae8) ; Data.DB.TDataSet.First
00ea2c56 0994 mov ecx, [$15bb96c]
00ea2c5c mov eax, [$15bcc10]
00ea2c61 mov eax, [eax]
00ea2c63 mov edx, [$e95930]
00ea2c69 call -$88d3ca ($6158a4) ; Vcl.Forms.TApplication.CreateForm
00ea2c6e 0995 mov eax, [$15bd004]
00ea2c73 mov eax, [eax]
00ea2c75 mov edx, [eax+4]
[...]
thread $13e4:
7705f8da +0e ntdll.dll NtWaitForSingleObject
766b15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7640118f +3e kernel32.dll WaitForSingleObjectEx
76401143 +0d kernel32.dll WaitForSingleObject
76403368 +10 kernel32.dll BaseThreadInitThunk
thread $13e8:
77060166 +0e ntdll.dll NtWaitForMultipleObjects
76403368 +10 kernel32.dll BaseThreadInitThunk
thread $13f4:
77060166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76403368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13d8) at:
73142713 +24f netbios.dll Netbios
thread $114c:
7705f8da +0e ntdll.dll NtWaitForSingleObject
766b15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7640118f +3e kernel32.dll WaitForSingleObjectEx
76401143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76403368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13d8) at:
732e4c95 +00 winspool.drv
thread $1050:
77061f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76403368 +10 kernel32.dll BaseThreadInitThunk
thread $1068:
77061f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76403368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06250000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062c0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06b50000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6e800000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
700d0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70670000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70690000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
706a0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
706c0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
709e0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
709f0000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
70a00000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70a40000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
70a60000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
70a70000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70ad0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70b10000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
70d20000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
70ea0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70f30000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
70f40000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70f60000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
70f70000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71540000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71590000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
715f0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71e60000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71e80000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71f10000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
71f20000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71f60000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72110000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72130000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72140000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72f30000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73010000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73090000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
730a0000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
73100000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73110000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73140000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73150000 security.dll 6.1.7600.16385 C:\Windows\
system32
73160000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73170000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
731d0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
732d0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73440000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73640000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
736c0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73a00000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73a50000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73a80000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73ab0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73af0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73b10000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73b20000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73b30000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73b40000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
73b90000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73bd0000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
73be0000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
73c00000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73da0000 version.dll 6.1.7600.16385 C:\Windows\
system32
73db0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
748d0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
748e0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
749a0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
74af0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
74b80000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
74be0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
74e90000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
74f20000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
74f30000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74f90000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75090000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
750a0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75160000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75210000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75220000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75250000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75290000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75340000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75390000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
753a0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75470000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75490000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
755c0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75660000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75670000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75680000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75770000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75780000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75790000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
763e0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
763f0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76500000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
766a0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
766f0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76930000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76950000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76ab0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ac0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76b00000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76b20000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76ba0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
77010000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77040000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 wininit.exe 0 0 0
0260 csrss.exe 1 0 0
0298 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02d0 lsass.exe 0 0 0
02d8 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0344 svchost.exe 0 0 0
0200 svchost.exe 0 0 0
041c svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0630 spoolsv.exe 0 0 0
0638 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
07f0 OSPPSVC.EXE 0 0 0
05b4 svchost.exe 0 0 0
0698 scpbradserv.exe 0 0 0
0708 svchost.exe 0 0 0
0548 core.exe 0 0 0
097c RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b50 WUDFHost.exe 0 0 0
0948 NisSrv.exe 0 0 0
0ef8 WmiPrvSE.exe 0 0 0
0c64 svchost.exe 0 0 0
0914 GoogleCrashHandler.exe 0 0 0
0874 GoogleCrashHandler64.exe 0 0 0
0a48 SearchIndexer.exe 0 0 0
0fc4 taskhost.exe 1 26 24 normal
0c54 core.exe 1 9 21 normal
0540 PresentationFontCache.exe 0 0 0
0208 dwm.exe 1 17 4 high
08f8 explorer.exe 1 579 329 normal
0828 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
09cc igfxEM.exe 1 14 14 normal
0ee0 igfxHK.exe 1 14 13 normal
0ed0 msseces.exe 1 143 59 normal
0ed8 PrnStatusMX.exe 1 23 20 normal
10a8 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
1198 RapportInjService_x64.exe 1 4 3 normal
13d4 Store.exe 1 5668 868 normal C:\Program Files (x86)\Store
1208 wuauclt.exe 1 12 6 normal
1ba0 splwow64.exe 1 11 5 normal
0c74 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
143c OIS.EXE 1 88 38 normal
17fc OIS.EXE 1 131 115 normal
185c OIS.EXE 1 97 46 normal
17ac OIS.EXE 1 95 47 normal
1054 OIS.EXE 1 84 37 normal
12ec chrome.exe 1 74 57 normal
1b84 chrome.exe 1 9 4 normal
1834 chrome.exe 1 12 8 above normal
0fec chrome.exe 1 4 1 normal
0ba4 chrome.exe 1 4 1 normal
1384 chrome.exe 1 4 1 idle
0f30 chrome.exe 1 4 3 normal
16a0 Store.exe 1 313 185 normal C:\Program Files (x86)\Store
16d4 setup_wm.exe 1 36 38 normal C:\Program Files (x86)\
Windows Media Player
1368 OIS.EXE 1 120 50 normal
1914 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0cc69640
ebx = 00003303
ecx = 00000000
edx = 026b2ac8
esi = 0018ec84
edi = 0066cb50
eip = 0066ea6e
esp = 0018ec48
ebp = 0018ecb0
stack dump:
0018ec48 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018ec58 5c ec 18 00 6e ea 66 00 - 40 96 c6 0c 03 33 00 00 \[email protected]..
0018ec68 84 ec 18 00 50 cb 66 00 - b0 ec 18 00 78 ec 18 00 ....P.f.....x...
0018ec78 60 a4 60 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 `.`.z.f...g.....
0018ec88 60 a4 60 04 00 00 00 00 - 9b e8 67 00 bc ec 18 00 `.`.......g.....
0018ec98 0c 89 40 00 b0 ec 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018eca8 d5 e9 67 01 60 a4 60 04 - d8 ec 18 00 f3 e8 67 00 ..g.`.`.......g.
0018ecb8 12 4d 67 00 f0 ec 18 00 - 0c 89 40 00 d8 ec 18 00 .Mg.......@.....
0018ecc8 60 a4 60 04 00 00 00 00 - 00 00 00 00 60 a4 60 04 `.`.........`.`.
0018ecd8 04 ed 18 00 b6 92 67 00 - 04 00 00 00 18 3c 62 00 ......g......<b.
0018ece8 01 00 00 00 e3 73 65 00 - 10 ed 18 00 0c 89 40 00 .....se.......@.
0018ecf8 04 ed 18 00 10 7d 94 0c - 60 a4 60 04 38 ed 18 00 .....}..`.`.8...
0018ed08 2a 72 65 00 54 7a 13 01 - 6c ef 18 00 0c 89 40 00 *re.Tz..l.....@.
0018ed18 38 ed 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 8...............
0018ed28 00 00 00 00 10 7d 94 0c - 60 a4 60 04 00 c5 3e 06 .....}..`.`...>.
0018ed38 5c ed 18 00 ed 04 53 00 - 10 7d 94 0c 1d 3c 62 00 \.....S..}...<b.
0018ed48 07 3c 62 00 d8 ee 18 00 - 18 3b 62 00 10 7d 94 0c .<b......;b..}..
0018ed58 01 00 00 00 cc ee 18 00 - 25 09 53 00 04 00 00 00 ........%.S.....
0018ed68 11 00 00 00 00 00 00 00 - d8 ee 18 00 10 7d 94 0c .............}..
0018ed78 a1 09 53 00 11 00 04 00 - d8 ee 18 00 70 02 09 00 ..S.........p...
disassembling:
[...]
01137a29 push $1137bf0
01137a2e lea eax, [ebp-$10]
01137a31 mov edx, 3
01137a36 call -$d2d273 ($40a7c8) ; System.@UStrCatN
01137a3b mov edx, [ebp-$10]
01137a3e mov eax, [ebp-8]
01137a41 mov eax, [eax+$250]
01137a47 mov ecx, [eax]
01137a49 call dword ptr [ecx+$38]
01137a4c 1050 mov eax, [ebp-8]
01137a4f > call -$ae0834 ($657220) ; Data.DB.TDataSet.Open
01137a54 1052 mov eax, [$15bcdf0]
01137a59 mov eax, [eax]
01137a5b mov eax, [eax+$27c]
01137a61 mov edx, $1137c04
01137a66 call -$adf4cb ($6585a0) ; Data.DB.TDataSet.FieldByName
01137a6b lea edx, [ebp-$14]
01137a6e mov ecx, [eax]
01137a70 call dword ptr [ecx+$80]
01137a76 mov eax, [ebp-$14]
01137a79 mov edx, $1137c28
[...]
thread $1370:
77bff8da +0e ntdll.dll NtWaitForSingleObject
75df15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f3118f +3e kernel32.dll WaitForSingleObjectEx
76f31143 +0d kernel32.dll WaitForSingleObject
76f33368 +10 kernel32.dll BaseThreadInitThunk
thread $1374:
77c00166 +0e ntdll.dll NtWaitForMultipleObjects
76f33368 +10 kernel32.dll BaseThreadInitThunk
thread $1384:
77c00166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76f33368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1364) at:
741c2713 +24f netbios.dll Netbios
thread $ee8:
77c01f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f33368 +10 kernel32.dll BaseThreadInitThunk
thread $10e8:
77c01f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f33368 +10 kernel32.dll BaseThreadInitThunk
thread $114c:
77bffd9a +0e ntdll.dll NtDelayExecution
75df3d36 +5f KERNELBASE.dll SleepEx
75df4607 +0a KERNELBASE.dll Sleep
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76f33368 +10 kernel32.dll BaseThreadInitThunk
>> created by thread $e60 at:
771bd9be +00 ole32.dll
thread $bc0:
77c01e27 +0b ntdll.dll NtTraceControl
77c39fc9 +40 ntdll.dll EtwpNotificationThread
76f33368 +10 kernel32.dll BaseThreadInitThunk
thread $4bc:
77bff8da +0e ntdll.dll NtWaitForSingleObject
75df15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f3118f +3e kernel32.dll WaitForSingleObjectEx
76f31143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76f33368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1364) at:
74364c95 +00 winspool.drv
thread $ac8:
77c01f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f33368 +10 kernel32.dll BaseThreadInitThunk
thread $ad8:
77c01f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f33368 +10 kernel32.dll BaseThreadInitThunk
modules:
001c0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00270000 BCLW32.dll C:\Program
Files (x86)\Store
003a0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
025b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
06270000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06380000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f550000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70ee0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70f60000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
712e0000 dhcpcsvc.DLL 6.1.7600.16385 C:\Windows\
system32
715e0000 dhcpcsvc6.DLL 6.1.7601.17970 C:\Windows\
system32
715f0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71680000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
716c0000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
71710000 nlaapi.dll 6.1.7601.18685 C:\Windows\
System32
71920000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71aa0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71ae0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71b00000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71b10000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
720f0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
72140000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
721a0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72a00000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72a20000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72ab0000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
72ac0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72b00000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72cb0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72cd0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72ce0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73890000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73990000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73a70000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73d70000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73d80000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73da0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73db0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73df0000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
73e60000 slc.dll 6.1.7600.16385 C:\Windows\
system32
740b0000 npmproxy.dll 6.1.7600.16385 C:\Windows\
System32
740c0000 netprofm.dll 6.1.7600.16385 C:\Windows\
System32
74120000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
74130000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
74140000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74190000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
741c0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
741d0000 security.dll 6.1.7600.16385 C:\Windows\
system32
741e0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
741f0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
74250000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
74350000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
745a0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
745f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74620000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74650000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74690000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
746b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
746c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
746d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
746e0000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
74730000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74770000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74780000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
747a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74940000 version.dll 6.1.7600.16385 C:\Windows\
system32
74950000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75470000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75480000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
754e0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
755b0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
756c0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
756d0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75910000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75930000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75be0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75c80000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75cc0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75ce0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75cf0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75de0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75e30000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75e60000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76000000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76020000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76030000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
761c0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
761d0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76e20000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76eb0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ec0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76f20000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
77030000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77040000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
770e0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
77170000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77180000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77190000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
772f0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
77370000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
773a0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
774d0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
774f0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77540000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77690000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
776a0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77750000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77bb0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77be0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0340 svchost.exe 0 0 0
020c svchost.exe 0 0 0
0430 svchost.exe 0 0 0
0474 audiodg.exe 0 0 0
04a8 svchost.exe 0 0 0
0524 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06cc armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
0790 NetExpressUpdater.exe 0 0 0
07e0 OSPPSVC.EXE 0 0 0
0560 svchost.exe 0 0 0
0684 scpbradserv.exe 0 0 0
0698 svchost.exe 0 0 0
07d8 core.exe 0 0 0
0978 RapportInjService_x64.exe 0 0 0
09ec fbserver.exe 0 0 0
0b8c WUDFHost.exe 0 0 0
05c8 NisSrv.exe 0 0 0
0db8 WmiPrvSE.exe 0 0 0
0f44 taskhost.exe 1 26 23 normal
0f60 core.exe 1 9 20 normal
0fcc PresentationFontCache.exe 0 0 0
0fec dwm.exe 1 16 4 high
0c3c explorer.exe 1 379 227 normal
0b38 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0144 igfxEM.exe 1 14 13 normal
019c igfxHK.exe 1 14 12 normal
0ec4 RapportService.exe 1 14 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0664 msseces.exe 1 143 60 normal
0fdc PrnStatusMX.exe 1 23 19 normal
0b88 RapportInjService_x64.exe 1 4 3 normal
0170 WmiPrvSE.exe 0 0 0
1068 SearchIndexer.exe 0 0 0
10c0 svchost.exe 0 0 0
1110 sppsvc.exe 0 0 0
11c0 SearchProtocolHost.exe 0 0 0
11dc SearchFilterHost.exe 0 0 0 idle
1248 GoogleCrashHandler.exe 0 0 0
1250 GoogleCrashHandler64.exe 0 0 0
12a0 VSSVC.exe 0 0 0
12c0 svchost.exe 0 0 0
1360 Store.exe 1 270 264 normal C:\Program Files (x86)\Store
13f8 TrustedInstaller.exe 0 0 0
0bd8 wuauclt.exe 1 12 6 normal
0d94 taskhost.exe 0 0 0
06d4 CompatTelRunner.exe 0 0 0
1160 conhost.exe 0 0 0
0760 CompatTelRunner.exe 0 0 0
1378 splwow64.exe 1 11 4 normal
1078 PrintIsolationHost.exe 0 0 0
09d8 DeviceDisplayObjectProvider.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0ac79160
ebx = 064420ec
ecx = 00000000
edx = 002a2ac8
esi = 0052ee54
edi = 00000000
eip = 0055efbe
esp = 0018d86c
ebp = 0018d8b8
stack dump:
0018d86c be ef 55 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..U.............
0018d87c 80 d8 18 00 be ef 55 00 - 60 91 c7 0a ec 20 44 06 ......U.`.... D.
0018d88c 54 ee 52 00 00 00 00 00 - b8 d8 18 00 9c d8 18 00 T.R.............
0018d89c 90 d5 43 06 e3 f7 55 00 - d4 d8 18 00 0c 89 40 00 ..C...U.......@.
0018d8ac b8 d8 18 00 00 00 00 00 - 00 00 00 00 c8 d9 18 00 ................
0018d8bc 71 f5 55 00 90 d5 43 06 - e6 68 50 00 80 d9 18 00 q.U...C..hP.....
0018d8cc ab 68 6c 00 00 00 00 00 - 80 dc 18 00 0c 89 40 00 .hl...........@.
0018d8dc c8 d9 18 00 10 55 4a 04 - 90 d5 43 06 c0 ff dc 0a .....UJ...C.....
0018d8ec 98 bf 39 00 90 ec 38 00 - af 00 00 00 51 03 00 00 ..9...8.....Q...
0018d8fc 6a 01 00 00 9c 03 00 00 - 48 95 31 00 00 00 00 00 j.......H.1.....
0018d90c 00 00 c0 9e 05 40 18 00 - e3 93 0f 77 75 0a 21 18 [email protected].!.
0018d91c 00 17 87 00 00 00 00 00 - 00 00 00 00 80 01 14 77 ...............w
0018d92c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d93c 6c d9 18 00 d3 94 0f 77 - 00 00 00 00 01 00 00 00 l......w........
0018d94c 80 01 14 77 00 00 00 00 - 6c d9 18 00 e7 94 0f 77 ...w....l......w
0018d95c 00 00 00 00 c8 d9 18 00 - 00 00 00 00 00 00 00 00 ................
0018d96c 00 00 c0 e7 05 40 0f 77 - 75 0a 21 18 a4 6c 6c 00 [email protected].!..ll.
0018d97c 90 d5 43 06 c0 ff dc 0a - 00 00 00 00 00 00 00 00 ..C.............
0018d98c 00 00 28 dd 07 40 21 18 - a4 6c 6c 00 00 00 00 00 ..(..@!..ll.....
0018d99c 00 00 00 00 bc 00 00 00 - 46 00 00 00 11 11 11 11 ........F.......
disassembling:
[...]
006c6881 jz loc_6c688e
006c6883 1319 mov eax, [ebx]
006c6885 mov byte ptr [eax+$290], 0
006c688c jmp loc_6c6897
006c688e 1321 mov eax, [ebx]
006c6890 mov byte ptr [eax+$290], 1
006c6897 1322 push 0
006c6899 mov eax, [ebx]
006c689b mov eax, [eax+$294]
006c68a1 call +$3f58a ($705e30) ; QRPrntr.TQRPrinter.GetCanvas
006c68a6 > call -$1bffcf ($5068dc) ; Vcl.Graphics.TCanvas.GetHandle
006c68ab push eax
006c68ac call -$2b3be1 ($412cd0) ; Winapi.Windows.SelectClipRgn
006c68b1 1325 cmp byte ptr [ebp-$a9], 0
006c68b8 jz loc_6c68cc
006c68ba 1326 mov eax, [ebx]
006c68bc add eax, $2cc
006c68c1 mov edx, [ebp-$a4]
006c68c7 call -$2bd198 ($409734) ; System.@UStrAsg
006c68cc 1328 mov eax, [ebx]
006c68ce mov esi, [eax+$28c]
[...]
thread $f78:
77bff8da +0e ntdll.dll NtWaitForSingleObject
75df15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f3118f +3e kernel32.dll WaitForSingleObjectEx
76f31143 +0d kernel32.dll WaitForSingleObject
76f33368 +10 kernel32.dll BaseThreadInitThunk
thread $f70:
77c00166 +0e ntdll.dll NtWaitForMultipleObjects
76f33368 +10 kernel32.dll BaseThreadInitThunk
thread $72c:
77bff8da +0e ntdll.dll NtWaitForSingleObject
75df15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f3118f +3e kernel32.dll WaitForSingleObjectEx
76f31143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76f33368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($c60) at:
74364c95 +00 winspool.drv
thread $11e0:
77c01f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f33368 +10 kernel32.dll BaseThreadInitThunk
modules:
001c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00280000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
003c0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
025b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
06250000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06360000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f550000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70ee0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70f60000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
715f0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71680000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71920000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71aa0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71ae0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71b00000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
720f0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
72140000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
721a0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72a00000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72a20000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72ac0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72b00000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72cb0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72cd0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72ce0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73890000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73990000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73a70000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73d70000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73d80000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73da0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73db0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73df0000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
73e60000 slc.dll 6.1.7600.16385 C:\Windows\
system32
74140000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74190000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
741d0000 security.dll 6.1.7600.16385 C:\Windows\
system32
741e0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
741f0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
74250000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
74350000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
745a0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
745f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74620000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74650000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74690000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
746b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
746c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
746d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74730000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
747a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74940000 version.dll 6.1.7600.16385 C:\Windows\
system32
74950000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75470000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75480000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
754e0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
755b0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
756c0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
756d0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75910000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75920000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75930000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75be0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75c80000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75cc0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75ce0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75cf0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75de0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75e30000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75e60000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76000000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76020000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76030000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
761c0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
761d0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76e20000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76eb0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ec0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76f20000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
77030000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77040000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
770e0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
77170000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77180000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77190000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
772f0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
77370000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
773a0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
774d0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
774f0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77540000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77690000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
776a0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77750000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77bb0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77be0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0340 svchost.exe 0 0 0
020c svchost.exe 0 0 0
0430 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0524 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06cc armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
0790 NetExpressUpdater.exe 0 0 0
07e0 OSPPSVC.EXE 0 0 0
0560 svchost.exe 0 0 0
0684 scpbradserv.exe 0 0 0
0698 svchost.exe 0 0 0
07d8 core.exe 0 0 0
0978 RapportInjService_x64.exe 0 0 0
09ec fbserver.exe 0 0 0
0b8c WUDFHost.exe 0 0 0
05c8 NisSrv.exe 0 0 0
0db8 WmiPrvSE.exe 0 0 0
0f44 taskhost.exe 1 26 23 normal
0f60 core.exe 1 9 22 normal
0fcc PresentationFontCache.exe 0 0 0
0fec dwm.exe 1 17 4 high
0c3c explorer.exe 1 679 509 normal
0b38 scpbradguard.exe 1 31 11 normal C:\Program Files
(x86)\scpbrad
0144 igfxEM.exe 1 14 14 normal
019c igfxHK.exe 1 14 12 normal
0ec4 RapportService.exe 1 14 18 normal C:\Program Files
(x86)\Trusteer\Rapport\bin
0664 msseces.exe 1 143 59 normal
0fdc PrnStatusMX.exe 1 23 19 normal
0b88 RapportInjService_x64.exe 1 4 3 normal
1068 SearchIndexer.exe 0 0 0
10c0 svchost.exe 0 0 0
1248 GoogleCrashHandler.exe 0 0 0
1250 GoogleCrashHandler64.exe 0 0 0
1360 Store.exe 1 244 248 normal C:\Program Files
(x86)\Store
0bd8 wuauclt.exe 1 12 7 normal
1378 splwow64.exe 1 11 4 normal
1294 Store.exe 1 5408 1074 normal C:\Program Files
(x86)\Store
11d8 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
0dfc Store.exe 1 216 144 normal C:\Program Files
(x86)\Store
1600 OIS.EXE 1 131 110 normal
03c8 DeviceDisplayObjectProvider.exe 1 9 5 normal
0f90 setup_wm.exe 1 36 38 normal C:\Program Files
(x86)\Windows Media Player
15d8 audiodg.exe 0 0 0
12dc chrome.exe 1 22 50 normal
14f0 chrome.exe 1 9 4 normal
1054 chrome.exe 1 7 6 above normal
15f8 chrome.exe 1 4 1 normal
1390 chrome.exe 1 4 1 normal
1534 chrome.exe 1 4 1 idle
17e0 chrome.exe 1 4 3 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00610074
ebx = 0a785c40
ecx = 3de8c38b
edx = 00180101
esi = 0a785c40
edi = 0018e36c
eip = 004075f4
esp = 0018e09c
ebp = 0018e1b4
stack dump:
0018e09c 27 ab e9 00 1c e5 18 00 - 0c 89 40 00 b4 e1 18 00 '.........@.....
0018e0ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0dc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0ec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0fc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e10c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e11c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e12c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e13c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e14c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e15c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e16c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e17c 00 00 00 00 40 5c 78 0a - 00 00 00 00 70 b0 79 0a ....@\x.....p.y.
0018e18c a0 d6 4a 06 20 95 3c 04 - c0 97 3c 04 60 9a 3c 04 ..J. .<...<.`.<.
0018e19c 00 b2 3c 04 60 af 3c 04 - 80 7d 3c 04 c0 82 3c 04 ..<.`.<..}<...<.
0018e1ac 20 80 3c 04 10 e3 31 04 - 04 e3 18 00 ed 04 53 00 .<...1.......S.
0018e1bc 40 5c 78 0a 33 35 55 00 - 6c e3 18 00 62 44 62 00 @\x.35U.l...bDb.
0018e1cc b8 43 62 00 6c e3 18 00 - 61 40 55 00 40 5c 78 0a .Cb.l...a@U.@\x.
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $1160:
77b9f8da +0e ntdll.dll NtWaitForSingleObject
777415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7698118f +3e kernel32.dll WaitForSingleObjectEx
76981143 +0d kernel32.dll WaitForSingleObject
76983368 +10 kernel32.dll BaseThreadInitThunk
thread $a74:
77ba0166 +0e ntdll.dll NtWaitForMultipleObjects
76983368 +10 kernel32.dll BaseThreadInitThunk
thread $a88:
77ba0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76983368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1114) at:
73a72713 +24f netbios.dll Netbios
thread $15f0:
77b9f8da +0e ntdll.dll NtWaitForSingleObject
777415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7698118f +3e kernel32.dll WaitForSingleObjectEx
76981143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76983368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1114) at:
73ba4c95 +00 winspool.drv
thread $cc0:
77ba1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76983368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00350000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
062a0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06370000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6fa40000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
6fc10000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
71530000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
715a0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71870000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
718c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71900000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71920000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71a40000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71de0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71e30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71ea0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
729a0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
729c0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a60000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72aa0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c50000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c70000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c80000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73970000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
739a0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73a00000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73a10000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73a30000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73a40000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73a70000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73a80000 security.dll 6.1.7600.16385 C:\Windows\
system32
73a90000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73b90000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73bf0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73d40000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
73d80000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73f80000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
741a0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
74410000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
744e0000 slc.dll 6.1.7600.16385 C:\Windows\
system32
74540000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74590000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
745c0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
745f0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74630000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74650000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74660000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74670000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
746d0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74740000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
748e0000 version.dll 6.1.7600.16385 C:\Windows\
system32
748f0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75410000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75420000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75480000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75510000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75660000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
756c0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
756e0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
756f0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75700000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75710000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
759c0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75ab0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75b50000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75c00000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75c10000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75cb0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75d50000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75de0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75df0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75e00000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75f60000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75f70000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75fd0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76000000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76100000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76110000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76160000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
763a0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
764d0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76670000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76680000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76690000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76750000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76820000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76840000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
768f0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76970000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76a80000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76aa0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76ae0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77730000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77b50000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77b80000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
041c svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0514 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0668 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
07e8 OSPPSVC.EXE 0 0 0
0574 svchost.exe 0 0 0
048c scpbradserv.exe 0 0 0
0778 svchost.exe 0 0 0
0820 core.exe 0 0 0
0980 RapportInjService_x64.exe 0 0 0
0a2c fbserver.exe 0 0 0
0bec WUDFHost.exe 0 0 0
0b2c NisSrv.exe 0 0 0
0d94 taskhost.exe 1 26 22 normal
0da4 core.exe 1 9 22 normal
0e00 PresentationFontCache.exe 0 0 0
0e64 dwm.exe 1 17 4 high
0ea8 explorer.exe 1 425 266 normal
0950 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f68 msseces.exe 1 143 60 normal
0ed4 RapportService.exe 1 14 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0f64 PrnStatusMX.exe 1 23 20 normal
0c3c igfxEM.exe 1 14 13 normal
0ca0 igfxHK.exe 1 14 12 normal
113c RapportInjService_x64.exe 1 4 3 normal
11f8 SearchIndexer.exe 0 0 0
1310 svchost.exe 0 0 0
10dc GoogleCrashHandler.exe 0 0 0
10e4 GoogleCrashHandler64.exe 0 0 0
1384 WmiPrvSE.exe 0 0 0
13d4 wuauclt.exe 1 12 6 normal
04ec Store.exe 1 1429 423 normal C:\Program Files (x86)\Store
009c splwow64.exe 1 11 4 normal
155c DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
15fc OIS.EXE 1 120 50 normal
1090 chrome.exe 1 25 46 normal
17cc chrome.exe 1 9 4 normal
1294 chrome.exe 1 7 7 above normal
1704 chrome.exe 1 4 1 normal
1298 chrome.exe 1 4 1 normal
0848 chrome.exe 1 4 1 idle
1470 chrome.exe 1 4 3 normal
0b84 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 05aa69a0
ebx = 00003303
ecx = 00000000
edx = 02702ac8
esi = 0018e420
edi = 0066cb50
eip = 0066ea6e
esp = 0018e3e4
ebp = 0018e44c
stack dump:
0018e3e4 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e3f4 f8 e3 18 00 6e ea 66 00 - a0 69 aa 05 03 33 00 00 ....n.f..i...3..
0018e404 20 e4 18 00 50 cb 66 00 - 4c e4 18 00 14 e4 18 00 ...P.f.L.......
0018e414 d0 19 54 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 ..T.z.f...g.....
0018e424 d0 19 54 06 00 00 00 00 - 9b e8 67 00 58 e4 18 00 ..T.......g.X...
0018e434 0c 89 40 00 4c e4 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018e444 d5 e9 67 01 d0 19 54 06 - 74 e4 18 00 f3 e8 67 00 ..g...T.t.....g.
0018e454 12 4d 67 00 8c e4 18 00 - 0c 89 40 00 74 e4 18 00 [email protected]...
0018e464 d0 19 54 06 00 00 00 00 - 00 00 00 00 d0 19 54 06 ..T...........T.
0018e474 a0 e4 18 00 b6 92 67 00 - 04 e7 18 00 38 5d 53 00 ......g.....8]S.
0018e484 01 00 00 00 e3 73 65 00 - ac e4 18 00 0c 89 40 00 .....se.......@.
0018e494 a0 e4 18 00 20 1c 1f 0b - d0 19 54 06 dc e4 18 00 .... .....T.....
0018e4a4 2a 72 65 00 76 26 ed 00 - f4 e4 18 00 0c 89 40 00 *re.v&........@.
0018e4b4 dc e4 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e4c4 00 00 00 00 00 00 00 00 - 00 00 00 00 20 1c 1f 0b ............ ...
0018e4d4 d0 19 54 06 20 34 4b 06 - 14 e5 18 00 53 5d 53 00 ..T. 4K.....S]S.
0018e4e4 04 e7 18 00 06 6a 53 00 - 04 e7 18 00 4e 0e 55 00 .....jS.....N.U.
0018e4f4 a4 e6 18 00 0c 89 40 00 - 14 e5 18 00 04 e7 18 00 ......@.........
0018e504 20 1c 1f 0b 04 e7 18 00 - 00 00 00 00 20 1c 1f 0b ........... ...
0018e514 40 e6 18 00 94 ff 52 00 - 04 e7 18 00 20 1c 1f 0b @.....R..... ...
disassembling:
[...]
00ed264b push $ed2804
00ed2650 lea eax, [ebp-$10]
00ed2653 mov edx, 3
00ed2658 call -$ac7e95 ($40a7c8) ; System.@UStrCatN
00ed265d mov edx, [ebp-$10]
00ed2660 mov eax, [ebp-8]
00ed2663 mov eax, [eax+$250]
00ed2669 mov ecx, [eax]
00ed266b call dword ptr [ecx+$38]
00ed266e 2801 mov eax, [ebp-8]
00ed2671 > call -$87b456 ($657220) ; Data.DB.TDataSet.Open
00ed2676 2802 mov eax, [ebp-8]
00ed2679 call -$878b96 ($659ae8) ; Data.DB.TDataSet.First
00ed267e 2824 lea edx, [ebp-$18]
00ed2681 mov eax, [ebp-4]
00ed2684 mov eax, [eax+$48c]
00ed268a call -$9a4027 ($52e668) ; Vcl.Controls.TControl.GetText
00ed268f mov eax, [ebp-$18]
00ed2692 mov edx, $ed2814
00ed2697 call -$ac7dc4 ($40a8d8) ; System.@UStrEqual
00ed269c jnz loc_ed26c4
[...]
thread $1160:
77b9f8da +0e ntdll.dll NtWaitForSingleObject
777415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7698118f +3e kernel32.dll WaitForSingleObjectEx
76981143 +0d kernel32.dll WaitForSingleObject
76983368 +10 kernel32.dll BaseThreadInitThunk
thread $a74:
77ba0166 +0e ntdll.dll NtWaitForMultipleObjects
76983368 +10 kernel32.dll BaseThreadInitThunk
thread $a88:
77ba0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76983368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1114) at:
73a72713 +24f netbios.dll Netbios
thread $15f0:
77b9f8da +0e ntdll.dll NtWaitForSingleObject
777415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7698118f +3e kernel32.dll WaitForSingleObjectEx
76981143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76983368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1114) at:
73ba4c95 +00 winspool.drv
thread $e0c:
77ba1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76983368 +10 kernel32.dll BaseThreadInitThunk
thread $93c:
77ba1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76983368 +10 kernel32.dll BaseThreadInitThunk
thread $17b8:
77ba1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76983368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00350000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
062a0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06370000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6fa40000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
6fc10000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
71530000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
715a0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71870000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
718c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71900000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71920000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71a40000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71de0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71e30000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71ea0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
729a0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
729c0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72a60000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72aa0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72c50000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72c70000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72c80000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73970000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
739a0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73a00000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73a10000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73a30000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73a40000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73a70000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73a80000 security.dll 6.1.7600.16385 C:\Windows\
system32
73a90000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73b90000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73bf0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73d40000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
73d80000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73f80000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
741a0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
74410000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
744e0000 slc.dll 6.1.7600.16385 C:\Windows\
system32
74540000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74590000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
745c0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
745f0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74630000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74650000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74660000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74670000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
746d0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74740000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
748e0000 version.dll 6.1.7600.16385 C:\Windows\
system32
748f0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75410000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75420000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75480000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75510000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75660000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
756c0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
756e0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
756f0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75700000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75710000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
759c0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75ab0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75b50000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75c00000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75c10000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75cb0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75d50000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75de0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75df0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75e00000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75f60000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75f70000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75fd0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76000000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76100000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76110000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76160000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
763a0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
764d0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76670000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76680000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76690000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76750000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76820000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76840000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
768f0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76970000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76a80000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76aa0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76ae0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77730000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77b50000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77b80000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0370 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
041c svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0514 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0668 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
07e8 OSPPSVC.EXE 0 0 0
0574 svchost.exe 0 0 0
048c scpbradserv.exe 0 0 0
0778 svchost.exe 0 0 0
0820 core.exe 0 0 0
0980 RapportInjService_x64.exe 0 0 0
0a2c fbserver.exe 0 0 0
0bec WUDFHost.exe 0 0 0
0b2c NisSrv.exe 0 0 0
0d94 taskhost.exe 1 26 24 normal
0da4 core.exe 1 9 22 normal
0e00 PresentationFontCache.exe 0 0 0
0e64 dwm.exe 1 17 4 high
0ea8 explorer.exe 1 716 451 normal
0950 scpbradguard.exe 1 31 11 normal C:\Program Files
(x86)\scpbrad
0f68 msseces.exe 1 143 60 normal
0ed4 RapportService.exe 1 14 17 normal C:\Program Files
(x86)\Trusteer\Rapport\bin
0f64 PrnStatusMX.exe 1 23 20 normal
0c3c igfxEM.exe 1 14 13 normal
0ca0 igfxHK.exe 1 14 12 normal
113c RapportInjService_x64.exe 1 4 3 normal
11f8 SearchIndexer.exe 0 0 0
1310 svchost.exe 0 0 0
10dc GoogleCrashHandler.exe 0 0 0
10e4 GoogleCrashHandler64.exe 0 0 0
1384 WmiPrvSE.exe 0 0 0
13d4 wuauclt.exe 1 12 6 normal
04ec Store.exe 1 2435 537 normal C:\Program Files
(x86)\Store
009c splwow64.exe 1 11 4 normal
155c DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
15fc OIS.EXE 1 120 50 normal
1090 chrome.exe 1 27 54 normal
17cc chrome.exe 1 9 4 normal
1294 chrome.exe 1 7 7 above normal
1704 chrome.exe 1 4 1 normal
1298 chrome.exe 1 4 1 normal
1470 chrome.exe 1 4 3 normal
0a78 DeviceDisplayObjectProvider.exe 1 9 5 normal
06fc OIS.EXE 1 88 37 normal
0b04 OIS.EXE 1 88 38 normal
10ac OIS.EXE 1 93 46 normal
05d0 Store.exe 1 157 185 normal C:\Program Files
(x86)\Store
0f28 chrome.exe 1 4 1 idle
0ba4 chrome.exe 1 4 1 idle
0c84 chrome.exe 1 4 1 idle
1460 chrome.exe 1 4 1 idle
1004 chrome.exe 1 4 1 idle
020c chrome.exe 1 4 1 idle
165c chrome.exe 1 4 1 idle
0a18 chrome.exe 1 4 1 idle
043c chrome.exe 1 4 1 idle
16d4 chrome.exe 1 4 1 idle
1154 audiodg.exe 0 0 0
1450 PrintIsolationHost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0cc7ff88
ebx = 0000280f
ecx = 00000000
edx = 02702ac8
esi = 00000000
edi = 0018e338
eip = 0066ea6e
esp = 0018dcb8
ebp = 0018dd20
stack dump:
0018dcb8 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018dcc8 cc dc 18 00 6e ea 66 00 - 88 ff c7 0c 0f 28 00 00 ....n.f......(..
0018dcd8 00 00 00 00 38 e3 18 00 - 20 dd 18 00 e8 dc 18 00 ....8... .......
0018dce8 00 b2 46 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 ..F.z.f...g.....
0018dcf8 a0 0f 1f 0b 50 cb 66 00 - 9b e8 67 00 28 dd 18 00 ....P.f...g.(...
0018dd08 0c 89 40 00 20 dd 18 00 - 50 cb 66 00 00 00 00 00 ..@. ...P.f.....
0018dd18 44 dd 18 00 00 b2 46 04 - 3c dd 18 00 31 e9 67 00 D.....F.<...1.g.
0018dd28 44 dd 18 00 0c 89 40 00 - 3c dd 18 00 a0 0f 1f 0b D.....@.<.......
0018dd38 00 b2 46 04 c8 e0 18 00 - f0 37 ec 00 e0 e0 18 00 ..F......7......
0018dd48 0c 89 40 00 c8 e0 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018dd58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd98 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dda8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ddb8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ddc8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ddd8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dde8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00ec37c0 push eax
00ec37c1 lea edx, [ebp-$328]
00ec37c7 mov eax, [$15bc8d0]
00ec37cc mov eax, [eax]
00ec37ce call -$a7074b ($453088) ; System.SysUtils.IntToStr
00ec37d3 mov eax, [ebp-$328]
00ec37d9 mov ecx, $ec6c70
00ec37de mov edx, $ec6c9c
00ec37e3 call +$304e0c ($11c85f4) ; UnitMonitor.GravaMonitor
00ec37e8 1521 mov eax, [ebp-$20]
00ec37eb > call -$844efc ($67e8f4) ; Bde.DBTables.TQuery.ExecSQL
00ec37f0 1524 mov eax, [ebp-4]
00ec37f3 mov eax, [eax+$720]
00ec37f9 mov edx, $ec43ac
00ec37fe call -$ab8f2b ($40a8d8) ; System.@UStrEqual
00ec3803 jnz loc_ec3a6b
00ec3809 1526 mov eax, [$15bcdf0]
00ec380e mov eax, [eax]
00ec3810 mov eax, [eax+$27c]
00ec3816 mov [ebp-$24], eax
00ec3819 1528 mov eax, [ebp-$24]
[...]
thread $1534:
7762f8da +0e ntdll.dll NtWaitForSingleObject
769715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7511118f +3e kernel32.dll WaitForSingleObjectEx
75111143 +0d kernel32.dll WaitForSingleObject
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $d64:
77630166 +0e ntdll.dll NtWaitForMultipleObjects
75113368 +10 kernel32.dll BaseThreadInitThunk
thread $bbc:
77630166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
75113368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1508) at:
738b2713 +24f netbios.dll Netbios
thread $100c:
7762f8da +0e ntdll.dll NtWaitForSingleObject
769715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7511118f +3e kernel32.dll WaitForSingleObjectEx
75111143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
75113368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1508) at:
73d84c95 +00 winspool.drv
thread $878:
77631f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75113368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
06270000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06360000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
0ba90000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6eda0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70520000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
705b0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
705c0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
705e0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
705f0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
710a0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71350000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71390000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
713b0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
714d0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71880000 webio.dll 6.1.7601.23375 C:\Windows\
system32
718d0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71930000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72430000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72450000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
724f0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72530000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
726e0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72700000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72710000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73470000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
735a0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73770000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73830000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
738b0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
738c0000 security.dll 6.1.7600.16385 C:\Windows\
system32
738d0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73c00000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73c10000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73c70000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73d70000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73df0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73e20000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73f80000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73fd0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74020000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74050000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74080000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
740c0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
740e0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
740f0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74100000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74160000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
741d0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74370000 version.dll 6.1.7600.16385 C:\Windows\
system32
74380000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74ea0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74eb0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74f10000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
74fb0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74fc0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75060000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
750f0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75100000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75210000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75230000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75470000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
754e0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
754f0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75530000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76180000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
761a0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
761b0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
761f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76340000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76410000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76510000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76520000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76860000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76870000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76880000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76930000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76940000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76960000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
769b0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76a30000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76a80000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76b70000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76c20000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76dc0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76df0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76e20000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76e80000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76f10000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76f70000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
770a0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
770b0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
775e0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77610000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0290 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
0308 svchost.exe 0 0 0
01a4 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0660 svchost.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
07e8 OSPPSVC.EXE 0 0 0
056c svchost.exe 0 0 0
0674 scpbradserv.exe 0 0 0
0770 svchost.exe 0 0 0
0820 core.exe 0 0 0
0988 RapportInjService_x64.exe 0 0 0
0a0c fbserver.exe 0 0 0
0ad0 WUDFHost.exe 0 0 0
07e0 NisSrv.exe 0 0 0
0dec taskhost.exe 1 26 24 normal
0e0c core.exe 1 9 21 normal
0e6c PresentationFontCache.exe 0 0 0
0e90 dwm.exe 1 17 4 high
0eec explorer.exe 1 454 292 normal
0fac scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0cc8 igfxEM.exe 1 14 13 normal
0cd0 igfxHK.exe 1 14 12 normal
0d54 RapportService.exe 1 14 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0d6c msseces.exe 1 143 59 normal
0d94 PrnStatusMX.exe 1 23 20 normal
0ce4 RapportInjService_x64.exe 1 4 3 normal
0ce0 GoogleCrashHandler.exe 0 0 0
0cd8 GoogleCrashHandler64.exe 0 0 0
1084 svchost.exe 0 0 0
164c WmiPrvSE.exe 0 0 0
15ac wuauclt.exe 1 12 7 normal
150c Store.exe 1 2847 527 normal C:\Program Files (x86)\Store
05b0 splwow64.exe 1 11 4 normal
0458 armsvc.exe 0 0 0
1624 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0b1c SearchIndexer.exe 0 0 0
1700 Store.exe 1 416 209 normal C:\Program Files (x86)\Store
15bc EXCEL.EXE 1 305 92 normal
0b58 chrome.exe 1 26 49 normal
17e8 chrome.exe 1 9 4 normal
13f8 chrome.exe 1 7 7 above normal
0d70 chrome.exe 1 4 1 normal
0234 chrome.exe 1 4 1 normal
07d4 chrome.exe 1 4 1 idle
111c chrome.exe 1 4 3 normal
1174 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 05ef2010
ebx = 00003303
ecx = 00000000
edx = 02672ac8
esi = 0018e488
edi = 0066cb50
eip = 0066ea6e
esp = 0018e44c
ebp = 0018e4b4
stack dump:
0018e44c 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e45c 60 e4 18 00 6e ea 66 00 - 10 20 ef 05 03 33 00 00 `...n.f.. ...3..
0018e46c 88 e4 18 00 50 cb 66 00 - b4 e4 18 00 7c e4 18 00 ....P.f.....|...
0018e47c 60 84 55 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 `.U.z.f...g.....
0018e48c 60 84 55 04 00 00 00 00 - 9b e8 67 00 c0 e4 18 00 `.U.......g.....
0018e49c 0c 89 40 00 b4 e4 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e4ac d5 e9 67 01 60 84 55 04 - dc e4 18 00 f3 e8 67 00 ..g.`.U.......g.
0018e4bc 12 4d 67 00 f4 e4 18 00 - 0c 89 40 00 dc e4 18 00 .Mg.......@.....
0018e4cc 60 84 55 04 00 00 00 00 - 00 00 00 00 60 84 55 04 `.U.........`.U.
0018e4dc 08 e5 18 00 b6 92 67 00 - 00 00 00 00 38 5d 53 00 ......g.....8]S.
0018e4ec 01 00 00 00 e3 73 65 00 - 14 e5 18 00 0c 89 40 00 .....se.......@.
0018e4fc 08 e5 18 00 40 d5 57 06 - 60 84 55 04 48 e5 18 00 [email protected].`.U.H...
0018e50c 2a 72 65 00 d0 fe 12 01 - 60 e5 18 00 0c 89 40 00 *re.....`.....@.
0018e51c 48 e5 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 H...............
0018e52c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e53c 40 d5 57 06 60 84 55 04 - d0 2c 48 06 8c e5 18 00 @.W.`.U..,H.....
0018e54c 53 5d 53 00 3c e7 18 00 - 06 6a 53 00 3c e7 18 00 S]S.<....jS.<...
0018e55c 1f f9 54 00 6c e5 18 00 - eb 8a 40 00 8c e5 18 00 ..T.l.....@.....
0018e56c 0c e7 18 00 0c 89 40 00 - 8c e5 18 00 00 00 00 00 ......@.........
0018e57c 40 d5 57 06 3c e7 18 00 - 00 00 00 00 40 d5 57 06 @.W.<[email protected].
disassembling:
[...]
0112fea5 push $1130034
0112feaa lea eax, [ebp-$20]
0112fead mov edx, 3
0112feb2 call -$d256ef ($40a7c8) ; System.@UStrCatN
0112feb7 mov edx, [ebp-$20]
0112feba mov eax, [ebp-8]
0112febd mov eax, [eax+$250]
0112fec3 mov ecx, [eax]
0112fec5 call dword ptr [ecx+$38]
0112fec8 463 mov eax, [ebp-8]
0112fecb > call -$ad8cb0 ($657220) ; Data.DB.TDataSet.Open
0112fed0 464 mov eax, [ebp-8]
0112fed3 cmp byte ptr [eax+$a8], 0
0112feda jz loc_112fefd
0112fedc mov eax, [ebp-8]
0112fedf cmp byte ptr [eax+$a9], 0
0112fee6 jz loc_112fefd
0112fee8 465 mov edx, $1130048
0112feed mov eax, [ebp-4]
0112fef0 mov eax, [eax+$4f4]
0112fef6 call -$c01837 ($52e6c4) ; Vcl.Controls.TControl.SetText
[...]
thread $160:
7749f8da +0e ntdll.dll NtWaitForSingleObject
76f815c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e7118f +3e kernel32.dll WaitForSingleObjectEx
76e71143 +0d kernel32.dll WaitForSingleObject
76e73368 +10 kernel32.dll BaseThreadInitThunk
thread $d84:
774a0166 +0e ntdll.dll NtWaitForMultipleObjects
76e73368 +10 kernel32.dll BaseThreadInitThunk
thread $388:
774a0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76e73368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13b4) at:
72892713 +24f netbios.dll Netbios
thread $bbc:
7749f8da +0e ntdll.dll NtWaitForSingleObject
76f815c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e7118f +3e kernel32.dll WaitForSingleObjectEx
76e71143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76e73368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13b4) at:
72a34c95 +00 winspool.drv
thread $1710:
774a1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e73368 +10 kernel32.dll BaseThreadInitThunk
thread $c70:
774a1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e73368 +10 kernel32.dll BaseThreadInitThunk
thread $1534:
774a1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e73368 +10 kernel32.dll BaseThreadInitThunk
modules:
002d0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
04380000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
052d0000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
062c0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6dfa0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
6ec70000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
6fbe0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
70190000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70a80000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70a90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70ab0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70ac0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70b10000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70cf0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70d10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70f80000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
711c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71200000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71220000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71240000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
716f0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71740000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
717a0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
722a0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
722c0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72360000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
723a0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72550000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72570000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72580000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72860000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72890000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
728a0000 security.dll 6.1.7600.16385 C:\Windows\
system32
728b0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
728c0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
72920000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72a20000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73420000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
73490000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73e40000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73e90000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73ec0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73ef0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73f30000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73f50000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73f60000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73f70000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73fd0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74040000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
741e0000 version.dll 6.1.7600.16385 C:\Windows\
system32
741f0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74d10000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74d20000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74d80000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
74d90000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
74db0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
74ff0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75cd0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75d20000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75dd0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75e30000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75f90000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75fa0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
760a0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
760b0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76160000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
761f0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
764a0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76520000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76530000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76540000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76570000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76580000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
765e0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
766e0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
767b0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
767c0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76850000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
768f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76a40000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76b70000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76b80000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76b90000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76d40000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76d60000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76d70000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76e60000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76f70000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76fc0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77010000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77040000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77450000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77480000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0290 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0338 svchost.exe 0 0 0
038c svchost.exe 0 0 0
03e4 MsMpEng.exe 0 0 0
0180 RapportMgmtService.exe 0 0 0
02b4 svchost.exe 0 0 0
030c svchost.exe 0 0 0
0250 svchost.exe 0 0 0
041c svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0564 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
07ec OSPPSVC.EXE 0 0 0
057c svchost.exe 0 0 0
0498 scpbradserv.exe 0 0 0
0778 svchost.exe 0 0 0
0824 core.exe 0 0 0
0990 RapportInjService_x64.exe 0 0 0
0a30 fbserver.exe 0 0 0
0bc8 WUDFHost.exe 0 0 0
0a58 NisSrv.exe 0 0 0
0fb8 WmiPrvSE.exe 0 0 0
0ea8 svchost.exe 0 0 0
0fc0 GoogleCrashHandler.exe 0 0 0
0fc8 GoogleCrashHandler64.exe 0 0 0
087c SearchIndexer.exe 0 0 0
0904 taskhost.exe 1 26 23 normal
0cd0 core.exe 1 9 21 normal
0d50 PresentationFontCache.exe 0 0 0
0d94 dwm.exe 1 17 4 high
0db4 explorer.exe 1 462 300 normal
0548 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c84 igfxEM.exe 1 14 13 normal
0c78 igfxHK.exe 1 14 12 normal
0cc4 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0bd0 msseces.exe 1 143 60 normal
0888 PrnStatusMX.exe 1 23 20 normal
1120 RapportInjService_x64.exe 1 4 3 normal
0218 wuauclt.exe 1 12 6 normal
1128 Store.exe 1 2271 580 normal C:\Program Files (x86)\Store
1210 Store.exe 1 477 313 normal C:\Program Files (x86)\Store
1600 splwow64.exe 1 11 5 normal
16ec DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
05d4 OIS.EXE 1 93 45 normal
162c chrome.exe 1 26 47 normal
0490 chrome.exe 1 9 4 normal
0588 chrome.exe 1 7 8 above normal
0644 chrome.exe 1 4 1 normal
1398 chrome.exe 1 4 1 normal
1374 chrome.exe 1 4 1 idle
0a78 chrome.exe 1 4 3 normal
12d4 audiodg.exe 0 0 0
1494 PrintIsolationHost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0b6894a8
ebx = 00003303
ecx = 00000000
edx = 025d2ac8
esi = 0018e0ac
edi = 0066cb50
eip = 0066ea6e
esp = 0018e070
ebp = 0018e0d8
stack dump:
0018e070 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e080 84 e0 18 00 6e ea 66 00 - a8 94 68 0b 03 33 00 00 ....n.f...h..3..
0018e090 ac e0 18 00 50 cb 66 00 - d8 e0 18 00 a0 e0 18 00 ....P.f.........
0018e0a0 20 7f 4a 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 .J.z.f...g.....
0018e0b0 20 7f 4a 04 00 00 00 00 - 9b e8 67 00 e4 e0 18 00 .J.......g.....
0018e0c0 0c 89 40 00 d8 e0 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e0d0 d5 e9 67 01 20 7f 4a 04 - 00 e1 18 00 f3 e8 67 00 ..g. .J.......g.
0018e0e0 12 4d 67 00 18 e1 18 00 - 0c 89 40 00 00 e1 18 00 .Mg.......@.....
0018e0f0 20 7f 4a 04 00 00 00 00 - 00 00 00 00 20 7f 4a 04 .J......... .J.
0018e100 2c e1 18 00 b6 92 67 00 - 6c e3 18 00 a0 93 f8 05 ,.....g.l.......
0018e110 01 00 00 00 e3 73 65 00 - 38 e1 18 00 0c 89 40 00 .....se.8.....@.
0018e120 2c e1 18 00 a0 93 f8 05 - 20 7f 4a 04 b4 e1 18 00 ,....... .J.....
0018e130 2a 72 65 00 d1 91 e9 00 - 1c e5 18 00 0c 89 40 00 *re...........@.
0018e140 b4 e1 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e150 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e160 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e170 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e180 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e190 a0 93 f8 05 20 7f 4a 04 - c0 81 4a 04 60 84 4a 04 .... .J...J.`.J.
0018e1a0 60 99 4a 04 80 67 4a 04 - c0 6c 4a 04 20 6a 4a 04 `.J..gJ..lJ. jJ.
disassembling:
[...]
00e991a6 push $e99338
00e991ab lea eax, [ebp-$58]
00e991ae mov edx, 3
00e991b3 call -$a8e9f0 ($40a7c8) ; System.@UStrCatN
00e991b8 mov edx, [ebp-$58]
00e991bb mov eax, [ebp-$20]
00e991be mov eax, [eax+$250]
00e991c4 mov ecx, [eax]
00e991c6 call dword ptr [ecx+$38]
00e991c9 125 mov eax, [ebp-$20]
00e991cc > call -$841fb1 ($657220) ; Data.DB.TDataSet.Open
00e991d1 126 mov eax, [ebp-$20]
00e991d4 call -$83f6f1 ($659ae8) ; Data.DB.TDataSet.First
00e991d9 128 lea edx, [ebp-$60]
00e991dc mov eax, [$15bcdf0]
00e991e1 mov eax, [eax]
00e991e3 mov eax, [eax+$330]
00e991e9 mov ecx, [eax]
00e991eb call dword ptr [ecx+$80]
00e991f1 cmp dword ptr [ebp-$60], 0
00e991f5 jnz loc_e99201
[...]
thread $160:
7749f8da +0e ntdll.dll NtWaitForSingleObject
76f815c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e7118f +3e kernel32.dll WaitForSingleObjectEx
76e71143 +0d kernel32.dll WaitForSingleObject
76e73368 +10 kernel32.dll BaseThreadInitThunk
thread $d84:
774a0166 +0e ntdll.dll NtWaitForMultipleObjects
76e73368 +10 kernel32.dll BaseThreadInitThunk
thread $388:
774a0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76e73368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13b4) at:
72892713 +24f netbios.dll Netbios
thread $bbc:
7749f8da +0e ntdll.dll NtWaitForSingleObject
76f815c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e7118f +3e kernel32.dll WaitForSingleObjectEx
76e71143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76e73368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13b4) at:
72a34c95 +00 winspool.drv
thread $15ac:
774a1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e73368 +10 kernel32.dll BaseThreadInitThunk
modules:
002d0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
04380000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
052d0000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
062c0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6dfa0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
6ec70000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
6fbe0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
70190000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70a80000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70a90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70ab0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70ac0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70b10000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70cf0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70d10000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70f80000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
711c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71200000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71220000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71240000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
716f0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71740000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
717a0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
722a0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
722c0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72360000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
723a0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72550000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72570000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72580000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72860000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72890000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
728a0000 security.dll 6.1.7600.16385 C:\Windows\
system32
728b0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
728c0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
72920000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72a20000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73420000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
73490000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73e40000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73e90000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73ec0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73ef0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73f30000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73f50000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73f60000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73f70000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73fd0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74040000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
741e0000 version.dll 6.1.7600.16385 C:\Windows\
system32
741f0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74d10000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74d20000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74d80000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
74d90000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
74db0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
74ff0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75cd0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75d20000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75dd0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75e30000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75f90000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75fa0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
760a0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
760b0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76160000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
761f0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
764a0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76520000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76530000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76540000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76570000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76580000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
765e0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
766e0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
767b0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
767c0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76850000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
768f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76a40000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76b70000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76b80000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76b90000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76d30000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76d40000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76d60000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76d70000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76e60000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76f70000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76fc0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77010000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77040000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77450000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77480000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0290 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0338 svchost.exe 0 0 0
038c svchost.exe 0 0 0
03e4 MsMpEng.exe 0 0 0
0180 RapportMgmtService.exe 0 0 0
02b4 svchost.exe 0 0 0
030c svchost.exe 0 0 0
0250 svchost.exe 0 0 0
041c svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0564 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
07ec OSPPSVC.EXE 0 0 0
057c svchost.exe 0 0 0
0498 scpbradserv.exe 0 0 0
0778 svchost.exe 0 0 0
0824 core.exe 0 0 0
0990 RapportInjService_x64.exe 0 0 0
0a30 fbserver.exe 0 0 0
0bc8 WUDFHost.exe 0 0 0
0a58 NisSrv.exe 0 0 0
0fb8 WmiPrvSE.exe 0 0 0
0ea8 svchost.exe 0 0 0
0fc0 GoogleCrashHandler.exe 0 0 0
0fc8 GoogleCrashHandler64.exe 0 0 0
087c SearchIndexer.exe 0 0 0
0904 taskhost.exe 1 26 23 normal
0cd0 core.exe 1 9 21 normal
0d50 PresentationFontCache.exe 0 0 0
0d94 dwm.exe 1 17 4 high
0db4 explorer.exe 1 494 341 normal
0548 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c84 igfxEM.exe 1 14 13 normal
0c78 igfxHK.exe 1 14 12 normal
0cc4 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0bd0 msseces.exe 1 143 60 normal
0888 PrnStatusMX.exe 1 23 20 normal
1120 RapportInjService_x64.exe 1 4 3 normal
0218 wuauclt.exe 1 12 6 normal
1128 Store.exe 1 3759 960 normal C:\Program Files (x86)\Store
1210 Store.exe 1 484 286 normal C:\Program Files (x86)\Store
1600 splwow64.exe 1 11 4 normal
16ec DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
05d4 OIS.EXE 1 93 45 normal
162c chrome.exe 1 27 59 normal
0490 chrome.exe 1 9 4 normal
0588 chrome.exe 1 7 8 above normal
0644 chrome.exe 1 4 1 normal
1398 chrome.exe 1 4 1 normal
1374 chrome.exe 1 4 1 idle
0a78 chrome.exe 1 4 3 normal
17bc OIS.EXE 1 111 42 normal
1700 OIS.EXE 1 111 42 normal
10d8 audiodg.exe 0 0 0
047c chrome.exe 1 4 1 idle
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0c060d88
ebx = 00003303
ecx = 00000000
edx = 025d2ac8
esi = 0018da4c
edi = 0066cb50
eip = 0066ea6e
esp = 0018da10
ebp = 0018da78
stack dump:
0018da10 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018da20 24 da 18 00 6e ea 66 00 - 88 0d 06 0c 03 33 00 00 $...n.f......3..
0018da30 4c da 18 00 50 cb 66 00 - 78 da 18 00 40 da 18 00 L...P.f.x...@...
0018da40 30 34 45 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 04E.z.f...g.....
0018da50 30 34 45 06 00 00 00 00 - 9b e8 67 00 84 da 18 00 04E.......g.....
0018da60 0c 89 40 00 78 da 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018da70 d5 e9 67 01 30 34 45 06 - a0 da 18 00 f3 e8 67 00 ..g.04E.......g.
0018da80 12 4d 67 00 b8 da 18 00 - 0c 89 40 00 a0 da 18 00 .Mg.......@.....
0018da90 30 34 45 06 00 00 00 00 - 00 00 00 00 30 34 45 06 04E.........04E.
0018daa0 cc da 18 00 b6 92 67 00 - 00 00 00 00 38 5d 53 00 ......g.....8]S.
0018dab0 01 00 00 00 e3 73 65 00 - d8 da 18 00 0c 89 40 00 .....se.......@.
0018dac0 cc da 18 00 10 ce 16 0c - 30 34 45 06 3c e0 18 00 ........04E.<...
0018dad0 2a 72 65 00 ce c2 ed 00 - 44 e0 18 00 0c 89 40 00 *re.....D.....@.
0018dae0 3c e0 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 <...............
0018daf0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db00 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db10 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db20 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db30 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db40 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00edc29d push $edd4f8
00edc2a2 lea eax, [ebp-$4bc]
00edc2a8 mov edx, 3
00edc2ad call -$ad1aea ($40a7c8) ; System.@UStrCatN
00edc2b2 mov edx, [ebp-$4bc]
00edc2b8 mov eax, [ebp-$34]
00edc2bb mov eax, [eax+$250]
00edc2c1 mov ecx, [eax]
00edc2c3 call dword ptr [ecx+$38]
00edc2c6 4111 mov eax, [ebp-$34]
00edc2c9 > call -$8850ae ($657220) ; Data.DB.TDataSet.Open
00edc2ce 4113 mov eax, [$15bcdf0]
00edc2d3 mov eax, [eax]
00edc2d5 mov eax, [eax+$1710]
00edc2db cmp byte ptr [eax+$a9], 0
00edc2e2 jz loc_edc89e
00edc2e8 mov eax, [$15bcdf0]
00edc2ed mov eax, [eax]
00edc2ef mov eax, [eax+$1710]
00edc2f5 cmp byte ptr [eax+$a8], 0
00edc2fc jz loc_edc89e
[...]
thread $ccc:
772af8da +0e ntdll.dll NtWaitForSingleObject
76dd15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7601118f +3e kernel32.dll WaitForSingleObjectEx
76011143 +0d kernel32.dll WaitForSingleObject
76013368 +10 kernel32.dll BaseThreadInitThunk
thread $1304:
772b0166 +0e ntdll.dll NtWaitForMultipleObjects
76013368 +10 kernel32.dll BaseThreadInitThunk
thread $126c:
772b0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76013368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($c84) at:
737e2713 +24f netbios.dll Netbios
thread $5d4:
772af8da +0e ntdll.dll NtWaitForSingleObject
76dd15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7601118f +3e kernel32.dll WaitForSingleObjectEx
76011143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76013368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($c84) at:
734c4c95 +00 winspool.drv
thread $a4:
772b1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76013368 +10 kernel32.dll BaseThreadInitThunk
modules:
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02620000 WINPPLA.DLL C:\Program
Files (x86)\Store
02660000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02690000 BCLW32.dll C:\Program
Files (x86)\Store
06270000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06380000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06b50000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6ea30000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
701e0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70890000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70b10000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70b50000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70b70000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70b80000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70b90000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70bb0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
70e10000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71380000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71500000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71550000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
715b0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
720b0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
720d0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72170000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
721b0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72360000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72380000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72390000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73120000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
73160000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73220000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73320000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73350000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
733b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
734b0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
737e0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
737f0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73800000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73870000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73b90000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73c00000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73c50000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73ca0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73cd0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73d00000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73d40000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73d60000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73d70000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73d80000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73de0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73e50000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73ff0000 version.dll 6.1.7600.16385 C:\Windows\
system32
74000000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74b20000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74b30000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74bc0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75810000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75820000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75830000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75890000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75920000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75b60000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75b80000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75c70000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75c80000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75ca0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75cc0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75d00000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d10000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75db0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75e50000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75ea0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75f50000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75f60000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75ff0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76000000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76110000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76120000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
762b0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
762e0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76590000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76730000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76800000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76950000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
769b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76a60000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76a70000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76a80000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76b20000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76b30000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76b60000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76c60000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76dc0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76e10000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
77260000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77290000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02d0 lsass.exe 0 0 0
02d8 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02d4 svchost.exe 0 0 0
03f4 svchost.exe 0 0 0
0410 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
055c svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0668 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0784 svchost.exe 0 0 0
079c NetExpressUpdater.exe 0 0 0
07f8 OSPPSVC.EXE 0 0 0
0434 svchost.exe 0 0 0
047c scpbradserv.exe 0 0 0
07e8 svchost.exe 0 0 0
0824 core.exe 0 0 0
096c RapportInjService_x64.exe 0 0 0
0a30 fbserver.exe 0 0 0
0ba0 WUDFHost.exe 0 0 0
0b1c NisSrv.exe 0 0 0
0cb4 taskhost.exe 1 26 22 normal
0cc4 PresentationFontCache.exe 0 0 0
0cd8 dwm.exe 1 17 4 high
0d0c explorer.exe 1 405 223 normal
0e50 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0ff0 igfxEM.exe 1 14 13 normal
0c20 igfxHK.exe 1 14 12 normal
0c60 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e74 msseces.exe 1 143 59 normal
0f3c PrnStatusMX.exe 1 23 19 normal
0f64 RapportInjService_x64.exe 1 4 3 normal
1054 SearchIndexer.exe 0 0 0
12bc svchost.exe 0 0 0
12f8 WmiPrvSE.exe 0 0 0
1374 GoogleCrashHandler.exe 0 0 0
1388 GoogleCrashHandler64.exe 0 0 0
10e8 wuauclt.exe 1 12 7 normal
11f0 core.exe 1 9 21 normal
0234 Store.exe 1 583 200 normal C:\Program Files (x86)\Store
114c OIS.EXE 1 81 37 normal
124c splwow64.exe 1 11 3 normal
1330 chrome.exe 1 25 55 normal
05e0 chrome.exe 1 9 4 normal
1310 chrome.exe 1 7 7 above normal
0a9c chrome.exe 1 4 1 normal
0654 chrome.exe 1 4 1 normal
050c chrome.exe 1 4 1 idle
0a2c chrome.exe 1 4 3 normal
0f94 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0afcd190
ebx = 00003303
ecx = 00000000
edx = 00282ac8
esi = 0018e3cc
edi = 0066cb50
eip = 0066ea6e
esp = 0018e390
ebp = 0018e3f8
stack dump:
0018e390 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e3a0 a4 e3 18 00 6e ea 66 00 - 90 d1 fc 0a 03 33 00 00 ....n.f......3..
0018e3b0 cc e3 18 00 50 cb 66 00 - f8 e3 18 00 c0 e3 18 00 ....P.f.........
0018e3c0 00 9d 47 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 ..G.z.f...g.....
0018e3d0 00 9d 47 04 00 00 00 00 - 9b e8 67 00 04 e4 18 00 ..G.......g.....
0018e3e0 0c 89 40 00 f8 e3 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e3f0 d5 e9 67 01 00 9d 47 04 - 20 e4 18 00 f3 e8 67 00 ..g...G. .....g.
0018e400 12 4d 67 00 38 e4 18 00 - 0c 89 40 00 20 e4 18 00 .Mg.8.....@. ...
0018e410 00 9d 47 04 00 00 00 00 - 00 00 00 00 00 9d 47 04 ..G...........G.
0018e420 4c e4 18 00 b6 92 67 00 - 00 00 00 00 38 5d 53 00 L.....g.....8]S.
0018e430 01 00 00 00 e3 73 65 00 - 58 e4 18 00 0c 89 40 00 .....se.X.....@.
0018e440 4c e4 18 00 40 d5 4d 06 - 00 9d 47 04 8c e4 18 00 [email protected].....
0018e450 2a 72 65 00 d0 fe 12 01 - a4 e4 18 00 0c 89 40 00 *re...........@.
0018e460 8c e4 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e470 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e480 40 d5 4d 06 00 9d 47 04 - a0 b9 3d 06 d0 e4 18 00 @.M...G...=.....
0018e490 53 5d 53 00 80 e6 18 00 - 06 6a 53 00 80 e6 18 00 S]S......jS.....
0018e4a0 1f f9 54 00 b0 e4 18 00 - eb 8a 40 00 d0 e4 18 00 ..T.......@.....
0018e4b0 50 e6 18 00 0c 89 40 00 - d0 e4 18 00 00 00 00 00 P.....@.........
0018e4c0 40 d5 4d 06 80 e6 18 00 - 00 00 00 00 40 d5 4d 06 @[email protected].
disassembling:
[...]
0112fea5 push $1130034
0112feaa lea eax, [ebp-$20]
0112fead mov edx, 3
0112feb2 call -$d256ef ($40a7c8) ; System.@UStrCatN
0112feb7 mov edx, [ebp-$20]
0112feba mov eax, [ebp-8]
0112febd mov eax, [eax+$250]
0112fec3 mov ecx, [eax]
0112fec5 call dword ptr [ecx+$38]
0112fec8 463 mov eax, [ebp-8]
0112fecb > call -$ad8cb0 ($657220) ; Data.DB.TDataSet.Open
0112fed0 464 mov eax, [ebp-8]
0112fed3 cmp byte ptr [eax+$a8], 0
0112feda jz loc_112fefd
0112fedc mov eax, [ebp-8]
0112fedf cmp byte ptr [eax+$a9], 0
0112fee6 jz loc_112fefd
0112fee8 465 mov edx, $1130048
0112feed mov eax, [ebp-4]
0112fef0 mov eax, [eax+$4f4]
0112fef6 call -$c01837 ($52e6c4) ; Vcl.Controls.TControl.SetText
[...]
thread $954:
77510166 +0e ntdll.dll NtWaitForMultipleObjects
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $1194:
77510166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76e53368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d20) at:
737a2713 +24f netbios.dll Netbios
thread $994:
7750f8da +0e ntdll.dll NtWaitForSingleObject
770415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e5118f +3e kernel32.dll WaitForSingleObjectEx
76e51143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76e53368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d20) at:
735c4c95 +00 winspool.drv
thread $1750:
77511f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e53368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
04540000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06300000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
0a090000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f950000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71230000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71270000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71290000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
713c0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71760000 webio.dll 6.1.7601.23375 C:\Windows\
system32
717b0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71810000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72310000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72330000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
723d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72410000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
725c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
725e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
725f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
727f0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
72800000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
72820000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
72830000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
72bf0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
72d80000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73020000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
732d0000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
733d0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73420000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73450000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
734b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
735b0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
737a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
737b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
737c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73950000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73960000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73980000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
739f0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73eb0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73f00000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73f30000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73f60000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73fa0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73fc0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73fd0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73fe0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74040000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
740b0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74250000 version.dll 6.1.7600.16385 C:\Windows\
system32
74260000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74d80000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74d90000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74df0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
74ee0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
74ef0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
74f70000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75bc0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75d10000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75db0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75dc0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75dd0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75de0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76020000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76060000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76110000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76240000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
762c0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76460000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76470000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76500000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
767e0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76830000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76920000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76950000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
769e0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76ac0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76bc0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76bf0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76c10000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d80000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76d90000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76e30000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e40000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76f50000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76f70000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76f80000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77030000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77080000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
770e0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
774c0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
774f0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
030c svchost.exe 0 0 0
01a4 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
0570 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
066c svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f4 OSPPSVC.EXE 0 0 0
0650 svchost.exe 0 0 0
06a0 scpbradserv.exe 0 0 0
00bc svchost.exe 0 0 0
0814 core.exe 0 0 0
098c taskhost.exe 1 26 21 normal
09d0 core.exe 1 9 20 normal
0a34 dwm.exe 1 17 4 high
0a68 RapportInjService_x64.exe 0 0 0
0a88 explorer.exe 1 442 264 normal
05c4 PresentationFontCache.exe 0 0 0
0c50 msseces.exe 1 143 60 normal
0c90 PrnStatusMX.exe 1 23 20 normal
0cd0 fbserver.exe 0 0 0
0d10 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e28 igfxEM.exe 1 14 14 normal
0e4c igfxHK.exe 1 14 13 normal
0ee8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f50 WUDFHost.exe 0 0 0
016c NisSrv.exe 0 0 0
1034 SearchIndexer.exe 0 0 0
1154 RapportInjService_x64.exe 1 4 3 normal
1358 WmiPrvSE.exe 0 0 0
0ffc GoogleCrashHandler.exe 0 0 0
0ff0 GoogleCrashHandler64.exe 0 0 0
11d8 svchost.exe 0 0 0
0f10 Store.exe 1 1414 385 normal C:\Program Files (x86)\Store
0c8c chrome.exe 1 75 57 normal
1050 chrome.exe 1 9 4 normal
0ef4 chrome.exe 1 7 7 above normal
13b0 chrome.exe 1 4 1 normal
148c chrome.exe 1 4 1 normal
157c chrome.exe 1 4 1 idle
15f4 chrome.exe 1 4 3 normal
17fc wuauclt.exe 1 12 7 normal
0d50 splwow64.exe 1 11 3 normal
1584 OIS.EXE 1 113 42 normal
1794 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0b371c68
ebx = 00003303
ecx = 00000000
edx = 02672ac8
esi = 0018e85c
edi = 0066cb50
eip = 0066ea6e
esp = 0018e820
ebp = 0018e888
stack dump:
0018e820 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e830 34 e8 18 00 6e ea 66 00 - 68 1c 37 0b 03 33 00 00 4...n.f.h.7..3..
0018e840 5c e8 18 00 50 cb 66 00 - 88 e8 18 00 50 e8 18 00 \...P.f.....P...
0018e850 30 10 43 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 0.C.z.f...g.....
0018e860 30 10 43 04 00 00 00 00 - 9b e8 67 00 94 e8 18 00 0.C.......g.....
0018e870 0c 89 40 00 88 e8 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e880 d5 e9 67 01 30 10 43 04 - b0 e8 18 00 f3 e8 67 00 ..g.0.C.......g.
0018e890 12 4d 67 00 c8 e8 18 00 - 0c 89 40 00 b0 e8 18 00 .Mg.......@.....
0018e8a0 30 10 43 04 00 00 00 00 - 00 00 00 00 30 10 43 04 0.C.........0.C.
0018e8b0 dc e8 18 00 b6 92 67 00 - 00 00 00 00 38 5d 53 00 ......g.....8]S.
0018e8c0 01 00 00 00 e3 73 65 00 - e8 e8 18 00 0c 89 40 00 .....se.......@.
0018e8d0 dc e8 18 00 80 cf 5f 06 - 30 10 43 04 1c e9 18 00 ......_.0.C.....
0018e8e0 2a 72 65 00 d0 fe 12 01 - 34 e9 18 00 0c 89 40 00 *re.....4.....@.
0018e8f0 1c e9 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e900 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e910 80 cf 5f 06 30 10 43 04 - a0 b9 4f 06 60 e9 18 00 .._.0.C...O.`...
0018e920 53 5d 53 00 10 eb 18 00 - 06 6a 53 00 10 eb 18 00 S]S......jS.....
0018e930 1f f9 54 00 40 e9 18 00 - eb 8a 40 00 60 e9 18 00 ..T.@.....@.`...
0018e940 e0 ea 18 00 0c 89 40 00 - 60 e9 18 00 00 00 00 00 ......@.`.......
0018e950 80 cf 5f 06 10 eb 18 00 - 00 00 00 00 80 cf 5f 06 .._..........._.
disassembling:
[...]
0112fea5 push $1130034
0112feaa lea eax, [ebp-$20]
0112fead mov edx, 3
0112feb2 call -$d256ef ($40a7c8) ; System.@UStrCatN
0112feb7 mov edx, [ebp-$20]
0112feba mov eax, [ebp-8]
0112febd mov eax, [eax+$250]
0112fec3 mov ecx, [eax]
0112fec5 call dword ptr [ecx+$38]
0112fec8 463 mov eax, [ebp-8]
0112fecb > call -$ad8cb0 ($657220) ; Data.DB.TDataSet.Open
0112fed0 464 mov eax, [ebp-8]
0112fed3 cmp byte ptr [eax+$a8], 0
0112feda jz loc_112fefd
0112fedc mov eax, [ebp-8]
0112fedf cmp byte ptr [eax+$a9], 0
0112fee6 jz loc_112fefd
0112fee8 465 mov edx, $1130048
0112feed mov eax, [ebp-4]
0112fef0 mov eax, [eax+$4f4]
0112fef6 call -$c01837 ($52e6c4) ; Vcl.Controls.TControl.SetText
[...]
thread $960:
7750f8da +0e ntdll.dll NtWaitForSingleObject
770415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e5118f +3e kernel32.dll WaitForSingleObjectEx
76e51143 +0d kernel32.dll WaitForSingleObject
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $954:
77510166 +0e ntdll.dll NtWaitForMultipleObjects
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $1194:
77510166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76e53368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d20) at:
737a2713 +24f netbios.dll Netbios
thread $994:
7750f8da +0e ntdll.dll NtWaitForSingleObject
770415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e5118f +3e kernel32.dll WaitForSingleObjectEx
76e51143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76e53368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d20) at:
735c4c95 +00 winspool.drv
thread $1750:
77511f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e53368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
04540000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06300000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
0a090000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f950000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71230000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71270000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71290000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
713c0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71760000 webio.dll 6.1.7601.23375 C:\Windows\
system32
717b0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71810000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72310000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72330000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
723d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72410000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
725c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
725e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
725f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
727f0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
72800000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
72820000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
72830000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
72bf0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
72d80000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73020000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
732d0000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
733d0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73420000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73450000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
734b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
735b0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
737a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
737b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
737c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73950000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73960000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73980000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
739f0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73eb0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73f00000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73f30000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73f60000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73fa0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73fc0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73fd0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73fe0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74040000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
740b0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74250000 version.dll 6.1.7600.16385 C:\Windows\
system32
74260000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74d80000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74d90000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74df0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
74ee0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
74ef0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
74f70000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75bc0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75d10000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75db0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75dc0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75dd0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75de0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76020000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76060000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76110000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76240000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
762c0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76460000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76470000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76500000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
767e0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76830000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76920000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76950000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
769e0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76ab0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76ac0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76bc0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76bf0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76c10000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d80000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76d90000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76e30000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e40000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76f50000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76f70000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76f80000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77030000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77080000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
770e0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
774c0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
774f0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
030c svchost.exe 0 0 0
01a4 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
0570 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
066c svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f4 OSPPSVC.EXE 0 0 0
0650 svchost.exe 0 0 0
06a0 scpbradserv.exe 0 0 0
00bc svchost.exe 0 0 0
0814 core.exe 0 0 0
098c taskhost.exe 1 26 22 normal
09d0 core.exe 1 9 20 normal
0a34 dwm.exe 1 17 4 high
0a68 RapportInjService_x64.exe 0 0 0
0a88 explorer.exe 1 430 262 normal
05c4 PresentationFontCache.exe 0 0 0
0c50 msseces.exe 1 143 60 normal
0c90 PrnStatusMX.exe 1 23 20 normal
0cd0 fbserver.exe 0 0 0
0d10 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e28 igfxEM.exe 1 14 14 normal
0e4c igfxHK.exe 1 14 13 normal
0ee8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f50 WUDFHost.exe 0 0 0
016c NisSrv.exe 0 0 0
1034 SearchIndexer.exe 0 0 0
1154 RapportInjService_x64.exe 1 4 3 normal
1358 WmiPrvSE.exe 0 0 0
0ffc GoogleCrashHandler.exe 0 0 0
0ff0 GoogleCrashHandler64.exe 0 0 0
11d8 svchost.exe 0 0 0
0f10 Store.exe 1 1414 385 normal C:\Program Files (x86)\Store
0c8c chrome.exe 1 75 57 normal
1050 chrome.exe 1 9 4 normal
0ef4 chrome.exe 1 7 7 above normal
13b0 chrome.exe 1 4 1 normal
148c chrome.exe 1 4 1 normal
157c chrome.exe 1 4 1 idle
15f4 chrome.exe 1 4 3 normal
17fc wuauclt.exe 1 12 7 normal
0d50 splwow64.exe 1 11 3 normal
1584 OIS.EXE 1 113 42 normal
1794 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0b371c68
ebx = 00003303
ecx = 00000000
edx = 02672ac8
esi = 0018daf0
edi = 0066cb50
eip = 0066ea6e
esp = 0018dab4
ebp = 0018db1c
stack dump:
0018dab4 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018dac4 c8 da 18 00 6e ea 66 00 - 68 1c 37 0b 03 33 00 00 ....n.f.h.7..3..
0018dad4 f0 da 18 00 50 cb 66 00 - 1c db 18 00 e4 da 18 00 ....P.f.........
0018dae4 30 10 43 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 0.C.z.f...g.....
0018daf4 30 10 43 04 00 00 00 00 - 9b e8 67 00 28 db 18 00 0.C.......g.(...
0018db04 0c 89 40 00 1c db 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018db14 d5 e9 67 01 30 10 43 04 - 44 db 18 00 f3 e8 67 00 ..g.0.C.D.....g.
0018db24 12 4d 67 00 5c db 18 00 - 0c 89 40 00 44 db 18 00 .Mg.\[email protected]...
0018db34 30 10 43 04 00 00 00 00 - 00 00 00 00 30 10 43 04 0.C.........0.C.
0018db44 70 db 18 00 b6 92 67 00 - 00 00 00 00 38 5d 53 00 p.....g.....8]S.
0018db54 01 00 00 00 e3 73 65 00 - 7c db 18 00 0c 89 40 00 .....se.|.....@.
0018db64 70 db 18 00 80 cf 5f 06 - 30 10 43 04 b0 db 18 00 p....._.0.C.....
0018db74 2a 72 65 00 d0 fe 12 01 - c8 db 18 00 0c 89 40 00 *re...........@.
0018db84 b0 db 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db94 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dba4 80 cf 5f 06 30 10 43 04 - a0 b9 4f 06 f4 db 18 00 .._.0.C...O.....
0018dbb4 53 5d 53 00 a4 dd 18 00 - 06 6a 53 00 a4 dd 18 00 S]S......jS.....
0018dbc4 1f f9 54 00 d4 db 18 00 - eb 8a 40 00 f4 db 18 00 ..T.......@.....
0018dbd4 74 dd 18 00 0c 89 40 00 - f4 db 18 00 00 00 00 00 t.....@.........
0018dbe4 80 cf 5f 06 a4 dd 18 00 - 00 00 00 00 80 cf 5f 06 .._..........._.
disassembling:
[...]
0112fea5 push $1130034
0112feaa lea eax, [ebp-$20]
0112fead mov edx, 3
0112feb2 call -$d256ef ($40a7c8) ; System.@UStrCatN
0112feb7 mov edx, [ebp-$20]
0112feba mov eax, [ebp-8]
0112febd mov eax, [eax+$250]
0112fec3 mov ecx, [eax]
0112fec5 call dword ptr [ecx+$38]
0112fec8 463 mov eax, [ebp-8]
0112fecb > call -$ad8cb0 ($657220) ; Data.DB.TDataSet.Open
0112fed0 464 mov eax, [ebp-8]
0112fed3 cmp byte ptr [eax+$a8], 0
0112feda jz loc_112fefd
0112fedc mov eax, [ebp-8]
0112fedf cmp byte ptr [eax+$a9], 0
0112fee6 jz loc_112fefd
0112fee8 465 mov edx, $1130048
0112feed mov eax, [ebp-4]
0112fef0 mov eax, [eax+$4f4]
0112fef6 call -$c01837 ($52e6c4) ; Vcl.Controls.TControl.SetText
[...]
thread $960:
7750f8da +0e ntdll.dll NtWaitForSingleObject
770415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e5118f +3e kernel32.dll WaitForSingleObjectEx
76e51143 +0d kernel32.dll WaitForSingleObject
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $954:
77510166 +0e ntdll.dll NtWaitForMultipleObjects
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $1194:
77510166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76e53368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d20) at:
737a2713 +24f netbios.dll Netbios
thread $994:
7750f8da +0e ntdll.dll NtWaitForSingleObject
770415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e5118f +3e kernel32.dll WaitForSingleObjectEx
76e51143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76e53368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d20) at:
735c4c95 +00 winspool.drv
thread $10cc:
77511f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $f9c:
77511f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $560:
77511f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e53368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
04540000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06300000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
0a090000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f950000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71230000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71270000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71290000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
713c0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71760000 webio.dll 6.1.7601.23375 C:\Windows\
system32
717b0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71810000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72310000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72330000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
723d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72410000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
725c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
725e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
725f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
727f0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
72800000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
72820000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
72830000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
72bf0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
72d80000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73020000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
732d0000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
733d0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73420000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73450000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
734b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
735b0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
737a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
737b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
737c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73950000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73960000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73980000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
739f0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73eb0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73f00000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73f30000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73f60000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73fa0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73fc0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73fd0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73fe0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74040000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
740b0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74250000 version.dll 6.1.7600.16385 C:\Windows\
system32
74260000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74d80000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74d90000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74df0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
74ee0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
74ef0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
74f70000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75bc0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75d10000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75db0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75dc0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75dd0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75de0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76020000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76060000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76110000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76240000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
762c0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76460000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76470000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76500000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
767e0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76830000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76920000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76950000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
769e0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76ab0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76ac0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76bc0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76bf0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76c10000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d80000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76d90000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76e30000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e40000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76f50000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76f70000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76f80000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77030000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77080000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
770e0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
774c0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
774f0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
030c svchost.exe 0 0 0
01a4 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
0570 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
066c svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f4 OSPPSVC.EXE 0 0 0
0650 svchost.exe 0 0 0
06a0 scpbradserv.exe 0 0 0
00bc svchost.exe 0 0 0
0814 core.exe 0 0 0
098c taskhost.exe 1 26 23 normal
09d0 core.exe 1 9 20 normal
0a34 dwm.exe 1 17 4 high
0a68 RapportInjService_x64.exe 0 0 0
0a88 explorer.exe 1 452 286 normal
05c4 PresentationFontCache.exe 0 0 0
0c50 msseces.exe 1 143 60 normal
0c90 PrnStatusMX.exe 1 23 20 normal
0cd0 fbserver.exe 0 0 0
0d10 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e28 igfxEM.exe 1 14 14 normal
0e4c igfxHK.exe 1 14 13 normal
0ee8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f50 WUDFHost.exe 0 0 0
016c NisSrv.exe 0 0 0
1034 SearchIndexer.exe 0 0 0
1154 RapportInjService_x64.exe 1 4 3 normal
1358 WmiPrvSE.exe 0 0 0
0ffc GoogleCrashHandler.exe 0 0 0
0ff0 GoogleCrashHandler64.exe 0 0 0
11d8 svchost.exe 0 0 0
0f10 Store.exe 1 2069 480 normal C:\Program Files (x86)\Store
0c8c chrome.exe 1 76 57 normal
1050 chrome.exe 1 9 4 normal
0ef4 chrome.exe 1 7 7 above normal
13b0 chrome.exe 1 4 1 normal
148c chrome.exe 1 4 1 idle
157c chrome.exe 1 4 1 idle
15f4 chrome.exe 1 4 3 normal
17fc wuauclt.exe 1 12 7 normal
0d50 splwow64.exe 1 11 5 normal
1584 OIS.EXE 1 113 42 normal
12ec OIS.EXE 1 120 52 normal
1294 audiodg.exe 0 0 0
0950 PrintIsolationHost.exe 0 0 0
12f8 PrintIsolationHost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 04403960
ebx = 00000100
ecx = 00000000
edx = 043f4601
esi = 043898d0
edi = 0018e36c
eip = 004075f4
esp = 0018e0c0
ebp = 0018e130
stack dump:
0018e0c0 f5 1d 6f 00 d0 98 38 04 - 01 01 00 00 53 55 6f 00 ..o...8.....SUo.
0018e0d0 60 3d 05 0a 60 3d 05 0a - f7 75 40 00 87 fa e9 00 `=..`=...u@.....
0018e0e0 38 e1 18 00 0c 89 40 00 - 30 e1 18 00 00 00 00 00 [email protected].......
0018e0f0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e100 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e110 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e120 00 00 00 00 00 00 00 00 - 60 eb 07 0a 90 90 38 04 ........`.....8.
0018e130 b4 e1 18 00 09 92 e9 00 - 1c e5 18 00 0c 89 40 00 ..............@.
0018e140 b4 e1 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e150 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e160 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e170 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e180 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e190 60 3d 05 0a f0 0a 43 04 - 90 0d 43 04 30 10 43 04 `=....C...C.0.C.
0018e1a0 30 25 43 04 50 f3 42 04 - 90 f8 42 04 f0 f5 42 04 0%C.P.B...B...B.
0018e1b0 90 90 38 04 04 e3 18 00 - ed 04 53 00 60 3d 05 0a ..8.......S.`=..
0018e1c0 33 35 55 00 6c e3 18 00 - 62 44 62 00 b8 43 62 00 35U.l...bDb..Cb.
0018e1d0 6c e3 18 00 61 40 55 00 - 60 3d 05 0a 94 ff 52 00 l...a@U.`=....R.
0018e1e0 6c e3 18 00 4c e5 18 00 - 60 3d 05 0a f3 00 00 00 l...L...`=......
0018e1f0 05 8b af 76 3b 00 00 00 - 14 e2 18 00 93 5d b1 76 ...v;........].v
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $960:
7750f8da +0e ntdll.dll NtWaitForSingleObject
770415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e5118f +3e kernel32.dll WaitForSingleObjectEx
76e51143 +0d kernel32.dll WaitForSingleObject
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $954:
77510166 +0e ntdll.dll NtWaitForMultipleObjects
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $1194:
77510166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76e53368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d20) at:
737a2713 +24f netbios.dll Netbios
thread $994:
7750f8da +0e ntdll.dll NtWaitForSingleObject
770415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e5118f +3e kernel32.dll WaitForSingleObjectEx
76e51143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76e53368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d20) at:
735c4c95 +00 winspool.drv
thread $10cc:
77511f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $f9c:
77511f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $560:
77511f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e53368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
04540000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06300000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
0a090000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f950000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71230000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71270000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71290000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
713c0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71760000 webio.dll 6.1.7601.23375 C:\Windows\
system32
717b0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71810000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72310000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72330000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
723d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72410000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
725c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
725e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
725f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
727f0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
72800000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
72820000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
72830000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
72bf0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
72d80000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73020000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
732d0000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
733d0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73420000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73450000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
734b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
735b0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
737a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
737b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
737c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73950000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73960000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73980000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
739f0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73eb0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73f00000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73f30000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73f60000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73fa0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73fc0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73fd0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73fe0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74040000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
740b0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74250000 version.dll 6.1.7600.16385 C:\Windows\
system32
74260000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74d80000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74d90000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74df0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
74ee0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
74ef0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
74f70000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75bc0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75d10000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75db0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75dc0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75dd0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75de0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76020000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76060000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76110000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76240000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
762c0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76460000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76470000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76500000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
767e0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76830000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76920000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76950000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
769e0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76ab0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76ac0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76bc0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76bf0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76c10000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d80000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76d90000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76e30000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e40000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76f50000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76f70000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76f80000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77030000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77080000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
770e0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
774c0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
774f0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
030c svchost.exe 0 0 0
01a4 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
0570 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
066c svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f4 OSPPSVC.EXE 0 0 0
0650 svchost.exe 0 0 0
06a0 scpbradserv.exe 0 0 0
00bc svchost.exe 0 0 0
0814 core.exe 0 0 0
098c taskhost.exe 1 26 24 normal
09d0 core.exe 1 9 20 normal
0a34 dwm.exe 1 17 4 high
0a68 RapportInjService_x64.exe 0 0 0
0a88 explorer.exe 1 452 280 normal
05c4 PresentationFontCache.exe 0 0 0
0c50 msseces.exe 1 143 60 normal
0c90 PrnStatusMX.exe 1 23 20 normal
0cd0 fbserver.exe 0 0 0
0d10 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e28 igfxEM.exe 1 14 14 normal
0e4c igfxHK.exe 1 14 13 normal
0ee8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f50 WUDFHost.exe 0 0 0
016c NisSrv.exe 0 0 0
1034 SearchIndexer.exe 0 0 0
1154 RapportInjService_x64.exe 1 4 3 normal
1358 WmiPrvSE.exe 0 0 0
0ffc GoogleCrashHandler.exe 0 0 0
0ff0 GoogleCrashHandler64.exe 0 0 0
11d8 svchost.exe 0 0 0
0f10 Store.exe 1 2071 486 normal C:\Program Files (x86)\Store
0c8c chrome.exe 1 76 57 normal
1050 chrome.exe 1 9 4 normal
0ef4 chrome.exe 1 7 7 above normal
13b0 chrome.exe 1 4 1 normal
148c chrome.exe 1 4 1 idle
157c chrome.exe 1 4 1 idle
15f4 chrome.exe 1 4 3 normal
17fc wuauclt.exe 1 12 7 normal
0d50 splwow64.exe 1 11 5 normal
1584 OIS.EXE 1 113 42 normal
12ec OIS.EXE 1 120 52 normal
1294 audiodg.exe 0 0 0
0950 PrintIsolationHost.exe 0 0 0
12f8 PrintIsolationHost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 04403960
ebx = 043898d0
ecx = 00000000
edx = 0018da01
esi = 043898d0
edi = 00000000
eip = 004075f4
esp = 0018d8b8
ebp = 0018d9e8
stack dump:
0018d8b8 26 32 6f 00 6c da 18 00 - 94 ff 52 00 00 00 00 00 &2o.l.....R.....
0018d8c8 cd 00 3f 00 d0 98 38 04 - d0 98 38 04 84 da 18 00 ..?...8...8.....
0018d8d8 94 ff 52 00 01 00 00 00 - cd 00 3f 00 d0 98 38 04 ..R.......?...8.
0018d8e8 a4 d8 18 00 01 00 00 00 - 20 db 18 00 b6 a6 b3 76 ........ ......v
0018d8f8 c1 e8 2f 44 fe ff ff ff - 51 6d ad 76 3f 0d ae 76 ../D....Qm.v?..v
0018d908 00 00 00 00 30 2f 41 00 - 24 05 0f 00 30 00 00 00 ....0/A.$...0...
0018d918 de 13 0a 5a 01 00 00 00 - 00 00 00 00 00 00 00 00 ...Z............
0018d928 30 00 00 00 d0 98 38 04 - 68 99 6e 00 00 00 00 00 0.....8.h.n.....
0018d938 58 d9 18 00 65 0d ae 76 - 30 2f 41 00 24 05 0f 00 X...e..v0/A.$...
0018d948 30 00 00 00 de 13 0a 5a - 01 00 00 00 00 00 00 00 0......Z........
0018d958 ac da 18 00 f1 49 53 00 - 30 2f 41 00 24 05 0f 00 .....IS.0/A.$...
0018d968 30 00 00 00 de 13 0a 5a - 01 00 00 00 ac da 18 00 0......Z........
0018d978 d0 98 38 04 d0 98 38 04 - 04 db 18 00 94 ff 52 00 ..8...8.......R.
0018d988 d0 98 38 04 d0 98 38 04 - d0 98 38 04 ef 47 52 77 ..8...8...8..GRw
0018d998 01 00 00 00 00 00 40 00 - 00 00 00 00 00 00 00 00 ......@.........
0018d9a8 ac d9 18 00 29 5c 9a 32 - 64 da 18 00 44 aa ad 76 ....)\.2d...D..v
0018d9b8 00 00 01 00 1c da 18 00 - 00 00 00 00 00 00 00 46 ...............F
0018d9c8 2f 01 00 00 b2 00 00 00 - 1a 03 00 00 63 04 00 00 /...........c...
0018d9d8 4c 03 3b 00 00 00 00 00 - 00 00 40 00 00 00 00 00 L.;.......@.....
0018d9e8 34 da 18 00 f4 48 53 00 - cd 00 3f 00 d0 98 38 04 4....HS...?...8.
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $960:
7750f8da +0e ntdll.dll NtWaitForSingleObject
770415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e5118f +3e kernel32.dll WaitForSingleObjectEx
76e51143 +0d kernel32.dll WaitForSingleObject
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $954:
77510166 +0e ntdll.dll NtWaitForMultipleObjects
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $1194:
77510166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76e53368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d20) at:
737a2713 +24f netbios.dll Netbios
thread $994:
7750f8da +0e ntdll.dll NtWaitForSingleObject
770415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e5118f +3e kernel32.dll WaitForSingleObjectEx
76e51143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76e53368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d20) at:
735c4c95 +00 winspool.drv
thread $1474:
77511f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e53368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
002a0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
04540000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06300000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
0a090000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f950000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71230000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71270000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71290000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
713c0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71760000 webio.dll 6.1.7601.23375 C:\Windows\
system32
717b0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71810000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72310000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72330000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
723d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72410000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
725c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
725e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
725f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
727f0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
72800000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
72820000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
72830000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
72bf0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
72d80000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73020000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
732d0000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
733d0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73420000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73450000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
734b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
735b0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
737a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
737b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
737c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73950000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73960000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73980000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
739f0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73eb0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73f00000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73f30000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73f60000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73fa0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73fc0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73fd0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73fe0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74040000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
740b0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74250000 version.dll 6.1.7600.16385 C:\Windows\
system32
74260000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74d80000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74d90000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74df0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
74ee0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
74ef0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
74f70000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75bc0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75d10000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75db0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75dc0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75dd0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75de0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76020000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76060000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76110000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76240000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
762c0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76460000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76470000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76500000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
767e0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76830000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76920000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76950000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
769e0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76ab0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76ac0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76bc0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76bf0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76c10000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d80000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76d90000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76e30000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e40000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76f50000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76f70000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76f80000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77030000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77080000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
770e0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
774c0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
774f0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
030c svchost.exe 0 0 0
01a4 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
0570 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
066c svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f4 OSPPSVC.EXE 0 0 0
0650 svchost.exe 0 0 0
06a0 scpbradserv.exe 0 0 0
00bc svchost.exe 0 0 0
0814 core.exe 0 0 0
098c taskhost.exe 1 26 20 normal
09d0 core.exe 1 9 20 normal
0a34 dwm.exe 1 17 4 high
0a68 RapportInjService_x64.exe 0 0 0
0a88 explorer.exe 1 450 277 normal
05c4 PresentationFontCache.exe 0 0 0
0c50 msseces.exe 1 143 60 normal
0c90 PrnStatusMX.exe 1 23 20 normal
0cd0 fbserver.exe 0 0 0
0d10 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e28 igfxEM.exe 1 14 14 normal
0e4c igfxHK.exe 1 14 13 normal
0ee8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f50 WUDFHost.exe 0 0 0
016c NisSrv.exe 0 0 0
1034 SearchIndexer.exe 0 0 0
1154 RapportInjService_x64.exe 1 4 3 normal
1358 WmiPrvSE.exe 0 0 0
0ffc GoogleCrashHandler.exe 0 0 0
0ff0 GoogleCrashHandler64.exe 0 0 0
11d8 svchost.exe 0 0 0
0f10 Store.exe 1 2150 342 normal C:\Program Files (x86)\Store
0c8c chrome.exe 1 76 57 normal
1050 chrome.exe 1 9 4 normal
0ef4 chrome.exe 1 7 7 above normal
13b0 chrome.exe 1 4 1 normal
148c chrome.exe 1 4 1 idle
157c chrome.exe 1 4 1 idle
15f4 chrome.exe 1 4 3 normal
17fc wuauclt.exe 1 12 7 normal
0d50 splwow64.exe 1 11 3 normal
1584 OIS.EXE 1 113 42 normal
12ec OIS.EXE 1 120 54 normal
1204 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0018fe30
ebx = 004075b1
ecx = 00000007
edx = 00000000
esi = 004075b1
edi = 043898d0
eip = 7703c54f
esp = 0018fe30
ebp = 0018fe80
stack dump:
0018fe30 de fa ed 0e 01 00 00 00 - 00 00 00 00 4f c5 03 77 ............O..w
0018fe40 07 00 00 00 b1 75 40 00 - 58 80 47 04 b1 75 40 00 [email protected]@.
0018fe50 b1 75 40 00 d0 98 38 04 - cc fe 18 00 b4 fe 18 00 [email protected].........
0018fe60 df 61 4d 00 d0 98 38 04 - b1 75 40 00 cc fe 18 00 .aM...8..u@.....
0018fe70 84 fe 18 00 b1 75 40 00 - 54 fe 18 00 a4 db 44 00 [email protected].
0018fe80 cc fe 18 00 b1 75 40 00 - de fa ed 0e 01 00 00 00 .....u@.........
0018fe90 07 00 00 00 98 fe 18 00 - b1 75 40 00 58 80 47 04 [email protected].
0018fea0 b1 75 40 00 b1 75 40 00 - d0 98 38 04 cc fe 18 00 [email protected]@...8.....
0018feb0 b4 fe 18 00 02 00 00 00 - f4 4c 40 00 00 fa 9c 05 .........L@.....
0018fec0 00 fa 9c 05 37 4d 40 00 - 00 fa 9c 02 40 ff 18 00 ....7M@.....@...
0018fed0 b1 75 40 00 00 fa 9c 05 - 5c 77 4d 00 01 49 2d 0c .u@.....\wM..I-.
0018fee0 cc 3d 48 00 d0 98 38 04 - 00 43 47 00 f7 75 40 00 .=H...8..CG..u@.
0018fef0 99 1d 6f 00 d0 98 38 04 - 01 43 47 00 53 55 6f 00 ..o...8..CG.SUo.
0018ff00 00 54 17 0b 02 00 00 00 - a9 1c 53 00 00 87 15 05 .T........S.....
0018ff10 f8 a1 46 04 00 54 17 0b - 00 00 00 00 98 a0 60 00 ..F..T........`.
0018ff20 00 54 17 0b 20 6c 42 04 - 72 b2 60 00 78 ff 18 00 .T.. lB.r.`.x...
0018ff30 0c 89 40 00 40 ff 18 00 - f8 a1 46 01 00 54 17 0b ..@[email protected]..
0018ff40 88 ff 18 00 56 04 49 00 - 54 e0 5b 01 18 0b 5c 01 ....V.I.T.[...\.
0018ff50 34 8e 60 00 6e 8e 60 00 - d4 1e 45 00 ac 1e 45 00 4.`.n.`...E...E.
0018ff60 af 90 40 00 88 ff 18 00 - 00 00 00 00 00 00 00 00 ..@.............
disassembling:
004075a0 public System.TObject.FreeInstance: ; function entry point
004075a0 35 push ebx
004075a1 mov ebx, eax
004075a3 mov eax, ebx
004075a5 call +$a6 ($407650) ; System.TObject.CleanupInstance
004075aa mov eax, ebx
004075ac call -$29fd ($404bb4) ; System.@FreeMem
004075b1 > pop ebx
004075b2 ret
date/time : 2020-10-09, 14:35:51, 783ms
computer name : VIDRARIA-06
user name : Karina Kinaki <admin>
registered owner : Karina Kinaki
operating system : Windows 7 x64 Service Pack 1 build 7601
system language : Portuguese
system up time : 6 hours 23 minutes
program up time : 1 hour 15 minutes
processors : 4x Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
physical memory : 1656/3968 MB (free/total)
free disk space : (C:) 57,85 GB
display mode : 1600x900, 32 bit
process id : $1544
allocated memory : 72,12 MB
largest free block : 956,91 MB
executable : Store.exe
exec. date/time : 2020-08-27 16:36
version : 1.0.0.0
bde version : 5.2.0.2
compiled with : Delphi XE2
madExcept version : 4.0.21
callstack crc : $387b5854, $1969a168, $1969a168
count : 3
exception number : 1
exception class : EAccessViolation
exception message : Access violation at address 00705BFA in module 'Store.exe'.
Read of address 00000022.
thread $e18:
7750f8da +0e ntdll.dll NtWaitForSingleObject
770415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e5118f +3e kernel32.dll WaitForSingleObjectEx
76e51143 +0d kernel32.dll WaitForSingleObject
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $1058:
77510166 +0e ntdll.dll NtWaitForMultipleObjects
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $b60:
7750f8da +0e ntdll.dll NtWaitForSingleObject
770415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e5118f +3e kernel32.dll WaitForSingleObjectEx
76e51143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76e53368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1354) at:
73354c95 +00 winspool.drv
thread $123c:
77511f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e53368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00350000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06260000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063a0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
07910000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f950000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71230000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71270000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71290000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
713c0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71760000 webio.dll 6.1.7601.23375 C:\Windows\
system32
717b0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71810000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72310000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72330000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
723d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72410000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
725c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
725e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
725f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
727f0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
72800000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
72820000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
72830000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
72bf0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
72c80000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73030000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73240000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73340000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
733d0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
734e0000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
73520000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
737a0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
738b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
738c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73960000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73980000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
739f0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73eb0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73f00000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73f30000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73f60000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73fa0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73fc0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73fd0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73fe0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74040000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
740b0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74250000 version.dll 6.1.7600.16385 C:\Windows\
system32
74260000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74d80000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74d90000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74df0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
74ee0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
74ef0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
74f70000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75bc0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75d10000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75db0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75dc0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75dd0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75de0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76020000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76060000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76110000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76240000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
762c0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76460000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76470000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76500000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
767e0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76830000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76920000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76950000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
769e0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76ac0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76bc0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76bf0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76c10000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d80000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76d90000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76e30000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e40000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76f50000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76f70000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76f80000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77030000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77080000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
770e0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
774c0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
774f0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
030c svchost.exe 0 0 0
01a4 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
0570 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
066c svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f4 OSPPSVC.EXE 0 0 0
0650 svchost.exe 0 0 0
06a0 scpbradserv.exe 0 0 0
00bc svchost.exe 0 0 0
0814 core.exe 0 0 0
098c taskhost.exe 1 26 22 normal
09d0 core.exe 1 9 21 normal
0a34 dwm.exe 1 17 4 high
0a68 RapportInjService_x64.exe 0 0 0
0a88 explorer.exe 1 466 292 normal
05c4 PresentationFontCache.exe 0 0 0
0c50 msseces.exe 1 143 60 normal
0c90 PrnStatusMX.exe 1 23 20 normal
0cd0 fbserver.exe 0 0 0
0d10 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e28 igfxEM.exe 1 14 14 normal
0e4c igfxHK.exe 1 14 13 normal
0ee8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f50 WUDFHost.exe 0 0 0
016c NisSrv.exe 0 0 0
1034 SearchIndexer.exe 0 0 0
1154 RapportInjService_x64.exe 1 4 3 normal
1358 WmiPrvSE.exe 0 0 0
0ffc GoogleCrashHandler.exe 0 0 0
0ff0 GoogleCrashHandler64.exe 0 0 0
11d8 svchost.exe 0 0 0
0c8c chrome.exe 1 76 51 normal
1050 chrome.exe 1 9 4 normal
0ef4 chrome.exe 1 12 7 above normal
13b0 chrome.exe 1 4 1 normal
148c chrome.exe 1 4 1 idle
157c chrome.exe 1 4 1 idle
15f4 chrome.exe 1 4 3 normal
17fc wuauclt.exe 1 12 7 normal
1584 OIS.EXE 1 113 42 normal
1544 Store.exe 1 327 232 normal C:\Program Files (x86)\Store
0a78 splwow64.exe 1 11 6 normal
1140 Store.exe 1 364 152 normal C:\Program Files (x86)\Store
1450 audiodg.exe 0 0 0
0a94 PrintIsolationHost.exe 0 0 0
03f0 PrintIsolationHost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 0018df01
ecx = 00700398
edx = 0018df01
esi = 00593bec
edi = 04373780
eip = 00705bfa
esp = 0018dcbc
ebp = 0018dce4
stack dump:
0018dcbc 67 58 70 00 60 de 18 00 - ec 3b 59 00 90 3d 42 06 gXp.`....;Y..=B.
0018dccc f7 75 40 00 a8 30 6f 00 - e2 30 6f 00 a0 35 37 04 [email protected].
0018dcdc 10 29 30 04 90 4e 2f 04 - 54 de 18 00 d4 a3 6f 00 .)0..N/.T.....o.
0018dcec ec 3b 59 00 40 25 28 0a - ed 04 53 00 40 25 28 0a .;Y.@%(...S.@%(.
0018dcfc f1 3b 59 00 96 09 53 00 - 0a 00 02 00 0a 00 00 00 .;Y...S.........
0018dd0c 02 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
0018dd1c 16 00 00 00 0a 00 02 00 - 40 25 28 0a 60 de 18 00 ........@%(.`...
0018dd2c 94 ff 52 00 0a 00 02 00 - 5c df 18 00 40 25 28 0a ..R.....\...@%(.
0018dd3c 40 25 28 0a c3 01 00 00 - 02 00 00 00 00 00 00 00 @%(.............
0018dd4c c8 dd 18 00 1f b0 33 72 - 98 ee 01 0a 26 04 39 00 ......3r....&.9.
0018dd5c 02 02 00 00 0f 00 00 00 - c3 01 02 00 00 00 00 00 ................
0018dd6c bb 80 33 72 8e 81 33 72 - 00 00 00 00 c3 01 02 00 ..3r..3r........
0018dd7c 26 04 39 00 00 00 00 00 - 00 00 00 00 00 00 00 00 &.9.............
0018dd8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd9c 00 00 00 00 00 00 00 00 - bb 80 33 72 01 00 00 00 ..........3r....
0018ddac 44 de 18 00 00 00 00 00 - 00 00 01 00 00 00 00 01 D...............
0018ddbc 07 00 00 00 00 00 00 00 - 0f 74 30 98 f4 dd 18 00 .........t0.....
0018ddcc fa 62 ad 76 26 04 39 00 - 02 02 00 00 00 00 00 00 .b.v&.9.........
0018dddc c3 01 02 00 bb 80 33 72 - cd ab ba dc 00 00 00 00 ......3r........
0018ddec 00 00 00 00 0c de 18 00 - cf fb 52 00 40 25 28 0a ..........R.@%(.
disassembling:
00705bf4 public QRPrntr.TQRPrinter.GetUseStandardPrinter: ; function entry
point
00705bf4 3462 mov eax, [eax+$b8]
00705bfa > movzx eax, byte ptr [eax+$22]
00705bfe 3463 ret
thread $e18:
7750f8da +0e ntdll.dll NtWaitForSingleObject
770415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e5118f +3e kernel32.dll WaitForSingleObjectEx
76e51143 +0d kernel32.dll WaitForSingleObject
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $1058:
77510166 +0e ntdll.dll NtWaitForMultipleObjects
76e53368 +10 kernel32.dll BaseThreadInitThunk
thread $b60:
7750f8da +0e ntdll.dll NtWaitForSingleObject
770415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76e5118f +3e kernel32.dll WaitForSingleObjectEx
76e51143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76e53368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1354) at:
73354c95 +00 winspool.drv
thread $123c:
77511f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76e53368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00350000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06260000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063a0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
07910000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f950000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71230000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71270000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71290000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
713c0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71760000 webio.dll 6.1.7601.23375 C:\Windows\
system32
717b0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71810000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72310000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72330000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
723d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72410000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
725c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
725e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
725f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
727f0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
72800000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
72820000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
72830000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
72bf0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
72c80000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73030000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73240000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73340000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
733d0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
734e0000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
73520000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
737a0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
738b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
738c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73960000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73980000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
739f0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73eb0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73f00000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73f30000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73f60000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73fa0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73fc0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73fd0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73fe0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74040000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
740b0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74250000 version.dll 6.1.7600.16385 C:\Windows\
system32
74260000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74d80000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74d90000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74df0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
74ee0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
74ef0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
74f70000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75bc0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75d10000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75db0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75dc0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75dd0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75de0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76020000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76060000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76110000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76240000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
762c0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76460000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76470000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76500000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
767e0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76830000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76920000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76950000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
769e0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76ab0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76ac0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76bc0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76bf0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76c10000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d80000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76d90000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76e30000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76e40000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76f50000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76f70000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76f80000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77030000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77080000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
770e0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
774c0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
774f0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
030c svchost.exe 0 0 0
01a4 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
0570 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
066c svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f4 OSPPSVC.EXE 0 0 0
0650 svchost.exe 0 0 0
06a0 scpbradserv.exe 0 0 0
00bc svchost.exe 0 0 0
0814 core.exe 0 0 0
098c taskhost.exe 1 26 23 normal
09d0 core.exe 1 9 21 normal
0a34 dwm.exe 1 17 4 high
0a68 RapportInjService_x64.exe 0 0 0
0a88 explorer.exe 1 454 287 normal
05c4 PresentationFontCache.exe 0 0 0
0c50 msseces.exe 1 143 60 normal
0c90 PrnStatusMX.exe 1 23 20 normal
0cd0 fbserver.exe 0 0 0
0d10 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e28 igfxEM.exe 1 14 14 normal
0e4c igfxHK.exe 1 14 13 normal
0ee8 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f50 WUDFHost.exe 0 0 0
016c NisSrv.exe 0 0 0
1034 SearchIndexer.exe 0 0 0
1154 RapportInjService_x64.exe 1 4 3 normal
1358 WmiPrvSE.exe 0 0 0
0ffc GoogleCrashHandler.exe 0 0 0
0ff0 GoogleCrashHandler64.exe 0 0 0
11d8 svchost.exe 0 0 0
0c8c chrome.exe 1 76 51 normal
1050 chrome.exe 1 9 4 normal
0ef4 chrome.exe 1 12 7 above normal
13b0 chrome.exe 1 4 1 normal
148c chrome.exe 1 4 1 idle
157c chrome.exe 1 4 1 idle
15f4 chrome.exe 1 4 3 normal
17fc wuauclt.exe 1 12 7 normal
1584 OIS.EXE 1 113 42 normal
1544 Store.exe 1 329 239 normal C:\Program Files (x86)\Store
0a78 splwow64.exe 1 11 6 normal
1140 Store.exe 1 364 152 normal C:\Program Files (x86)\Store
1450 audiodg.exe 0 0 0
0a94 PrintIsolationHost.exe 0 0 0
03f0 PrintIsolationHost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3CE0ED (HP LaserJet P2055dn)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0047002e
ebx = 04373780
ecx = 8b000001
edx = 00000000
esi = 042f4e90
edi = 00000000
eip = 00487029
esp = 00188c4c
ebp = 00188c54
stack dump:
00188c4c 00 00 00 00 00 00 00 00 - ac cc 18 00 ca 00 6d 00 ..............m.
00188c5c 00 00 00 00 00 00 00 00 - b0 cc 18 00 0c 89 40 00 ..............@.
00188c6c ac cc 18 00 90 4e 2f 04 - 80 37 37 04 00 00 00 00 .....N/..77.....
00188c7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188c8c 00 00 00 00 00 00 00 00 - 80 37 37 04 00 00 00 00 .........77.....
00188c9c 2e 00 47 00 00 00 00 00 - 00 00 00 00 01 00 00 00 ..G.............
00188cac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188cbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188ccc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188cdc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188cec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188cfc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d2c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d3c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d4c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d5c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
006d00a3 push ebp
006d00a4 push $6d0414 ; System.@HandleFinally
006d00a9 push dword ptr fs:[eax]
006d00ac mov fs:[eax], esp
006d00af 339 call -$277ea8 ($45820c) ; System.SysUtils.Now
006d00b4 fstp qword ptr [$15c4828]
006d00ba wait
006d00bb 340 push 0
006d00bd push 0
006d00bf mov eax, [ebp-$4010]
006d00c5 > call -$2490ae ($48701c) ; System.Classes.TStream.SetPosition
006d00ca 341 xor eax, eax
006d00cc mov [ebp-$400c], eax
006d00d2 342 xor eax, eax
006d00d4 mov [ebp-$4014], eax
006d00da 343 push ebp
006d00db call -$21c ($6cfec4) ; LZW.InitTable
006d00e0 pop ecx
006d00e1 344 push ebp
006d00e2 call -$1bb ($6cff2c) ; LZW.ReadCode
006d00e7 pop ecx
[...]
thread $430:
76fbf8da +0e ntdll.dll NtWaitForSingleObject
749115c8 +92 KERNELBASE.dll WaitForSingleObjectEx
762e118f +3e kernel32.dll WaitForSingleObjectEx
762e1143 +0d kernel32.dll WaitForSingleObject
762e3368 +10 kernel32.dll BaseThreadInitThunk
thread $8a4:
76fc0166 +0e ntdll.dll NtWaitForMultipleObjects
762e3368 +10 kernel32.dll BaseThreadInitThunk
thread $13bc:
76fbf8da +0e ntdll.dll NtWaitForSingleObject
749115c8 +92 KERNELBASE.dll WaitForSingleObjectEx
762e118f +3e kernel32.dll WaitForSingleObjectEx
762e1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
762e3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($de4) at:
73684c95 +00 winspool.drv
thread $7f4:
76fc1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
762e3368 +10 kernel32.dll BaseThreadInitThunk
modules:
001c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00280000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
003c0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
025b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
06230000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06300000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6feb0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70300000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
709a0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
709e0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70b00000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70b40000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71090000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71210000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71260000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
712c0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71db0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71dd0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71e60000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71ea0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72050000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72470000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
72b00000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
72b10000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
72b30000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
72b40000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
72bb0000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
72cd0000 icm32.dll 6.1.7601.23677 C:\Windows\
system32
72d10000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
730c0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
733c0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73460000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73480000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
734e0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73530000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73550000 security.dll 6.1.7600.16385 C:\Windows\
system32
73560000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73570000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73670000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73900000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73950000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
73970000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
73980000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
739e0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73a10000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73a50000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73a70000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73a80000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73a90000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73af0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73b60000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73d00000 version.dll 6.1.7600.16385 C:\Windows\
system32
73d10000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74830000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74840000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74900000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74950000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
74a00000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
74cb0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
74cf0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
74d00000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
74dd0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74de0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74f80000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
74fa0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75020000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75070000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75cc0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75cd0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75ce0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75d70000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d80000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75de0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76020000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76030000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
760c0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
760e0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76230000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
762d0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
763f0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76490000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
764a0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76590000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76660000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
767c0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76870000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
768a0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
768d0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76a00000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76b00000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76b10000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76b20000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76b80000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76f70000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76fa0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0340 svchost.exe 0 0 0
038c svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
0314 svchost.exe 0 0 0
0350 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0488 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0564 svchost.exe 0 0 0
061c spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
064c svchost.exe 0 0 0
06cc armsvc.exe 0 0 0
06e4 atkexComSvc.exe 0 0 0
0724 svchost.exe 0 0 0
074c fbguard.exe 0 0 0
0770 svchost.exe 0 0 0
0788 NetExpressUpdater.exe 0 0 0
07e0 OSPPSVC.EXE 0 0 0
0544 svchost.exe 0 0 0
0680 scpbradserv.exe 0 0 0
06f4 svchost.exe 0 0 0
0740 core.exe 0 0 0
0940 RapportInjService_x64.exe 0 0 0
0a08 fbserver.exe 0 0 0
0bdc WUDFHost.exe 0 0 0
0b2c NisSrv.exe 0 0 0
0f0c WmiPrvSE.exe 0 0 0
0d24 taskhost.exe 1 26 23 normal
0d44 core.exe 1 9 21 normal
091c PresentationFontCache.exe 0 0 0
0d9c dwm.exe 1 17 4 high
0dc4 explorer.exe 1 649 395 normal
0e9c scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
02c4 RapportService.exe 1 14 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0c20 igfxEM.exe 1 14 13 normal
0498 igfxHK.exe 1 14 12 normal
04f0 msseces.exe 1 143 59 normal
032c PrnStatusMX.exe 1 23 20 normal
0c80 RapportInjService_x64.exe 1 4 3 normal
0e60 SearchIndexer.exe 0 0 0
0c60 svchost.exe 0 0 0
113c GoogleCrashHandler.exe 0 0 0
1150 GoogleCrashHandler64.exe 0 0 0
1114 wuauclt.exe 1 12 5 normal
0298 Store.exe 1 2738 629 normal C:\Program Files (x86)\Store
11f4 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0c94 splwow64.exe 1 11 4 normal
0f88 chrome.exe 1 27 53 normal
12fc chrome.exe 1 9 4 normal
0518 chrome.exe 1 7 7 above normal
0820 chrome.exe 1 4 1 normal
1204 chrome.exe 1 4 1 idle
1398 chrome.exe 1 4 1 idle
0a20 chrome.exe 1 4 3 normal
0230 Store.exe 1 750 788 normal C:\Program Files (x86)\Store
10a0 OIS.EXE 1 97 45 normal
139c OIS.EXE 1 93 46 normal
11c4 OIS.EXE 1 81 36 normal
1298 svchost.exe 0 0 0
0a9c audiodg.exe 0 0 0
130c chrome.exe 1 4 1 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 05b67220
ebx = 0000280f
ecx = 00000000
edx = 002c2ac8
esi = 00000000
edi = 05b8ba10
eip = 0066ea6e
esp = 0018c548
ebp = 0018c5b0
stack dump:
0018c548 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018c558 5c c5 18 00 6e ea 66 00 - 20 72 b6 05 0f 28 00 00 \...n.f. r...(..
0018c568 00 00 00 00 10 ba b8 05 - b0 c5 18 00 78 c5 18 00 ............x...
0018c578 30 26 42 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 0&B.z.f...g.....
0018c588 10 ba b8 05 50 cb 66 00 - 9b e8 67 00 b8 c5 18 00 ....P.f...g.....
0018c598 0c 89 40 00 b0 c5 18 00 - 50 cb 66 00 00 00 00 00 [email protected].....
0018c5a8 d4 c5 18 00 30 26 42 04 - cc c5 18 00 31 e9 67 00 ....0&B.....1.g.
0018c5b8 d4 c5 18 00 0c 89 40 00 - cc c5 18 00 10 ba b8 05 ......@.........
0018c5c8 30 26 42 04 5c c6 18 00 - 9c 1a bb 00 64 c6 18 00 0&B.\.......d...
0018c5d8 0c 89 40 00 5c c6 18 00 - 00 00 00 00 00 00 00 00 ..@.\...........
0018c5e8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018c5f8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018c608 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018c618 00 00 00 00 00 8b e5 40 - 00 00 00 00 00 00 00 00 .......@........
0018c628 00 00 00 00 69 e0 33 52 - 14 8b e5 40 00 00 00 00 ....i.3R...@....
0018c638 00 00 00 00 69 e0 33 52 - 14 8b e5 40 00 00 00 00 ....i.3R...@....
0018c648 00 00 00 00 30 26 42 04 - 10 4d 58 06 00 00 00 00 ....0&B..MX.....
0018c658 90 38 42 06 24 c9 18 00 - 6b 32 bb 00 e8 cf 18 00 .8B.$...k2......
0018c668 0c 89 40 00 24 c9 18 00 - 00 00 00 00 00 00 00 00 ..@.$...........
0018c678 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00bb1a72 push eax
00bb1a73 lea edx, [ebp-$74]
00bb1a76 mov eax, [$15bc8d0]
00bb1a7b mov eax, [eax]
00bb1a7d call -$75e9fa ($453088) ; System.SysUtils.IntToStr
00bb1a82 mov eax, [ebp-$74]
00bb1a85 mov ecx, $bb1ec4
00bb1a8a mov edx, $bb1ee0
00bb1a8f call +$616b60 ($11c85f4) ; UnitMonitor.GravaMonitor
00bb1a94 1289 mov eax, [ebp-$10]
00bb1a97 > call -$5331a8 ($67e8f4) ; Bde.DBTables.TQuery.ExecSQL
00bb1a9c 1291 mov eax, [ebp-$c]
00bb1a9f call -$7aa4b8 ($4075ec) ; System.TObject.Free
00bb1aa4 1294 mov eax, [$15bcdf0]
00bb1aa9 mov eax, [eax]
00bb1aab mov eax, [eax+$27c]
00bb1ab1 mov [ebp-$14], eax
00bb1ab4 1296 mov eax, [ebp-$14]
00bb1ab7 call -$55a890 ($65722c) ; Data.DB.TDataSet.Close
00bb1abc 1297 mov eax, [ebp-$14]
00bb1abf mov eax, [eax+$250]
[...]
thread $10bc:
7739f8da +0e ntdll.dll NtWaitForSingleObject
763115c8 +92 KERNELBASE.dll WaitForSingleObjectEx
752f118f +3e kernel32.dll WaitForSingleObjectEx
752f1143 +0d kernel32.dll WaitForSingleObject
752f3368 +10 kernel32.dll BaseThreadInitThunk
thread $10c0:
773a0166 +0e ntdll.dll NtWaitForMultipleObjects
752f3368 +10 kernel32.dll BaseThreadInitThunk
thread $cf8:
773a0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
752f3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($10b0) at:
730e2713 +24f netbios.dll Netbios
thread $4a0:
7739f8da +0e ntdll.dll NtWaitForSingleObject
763115c8 +92 KERNELBASE.dll WaitForSingleObjectEx
752f118f +3e kernel32.dll WaitForSingleObjectEx
752f1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
752f3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($10b0) at:
73284c95 +00 winspool.drv
thread $d40:
773a1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
752f3368 +10 kernel32.dll BaseThreadInitThunk
modules:
002d0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06260000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6eac0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
6f8d0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
70630000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70640000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70da0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70db0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70de0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
71060000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
710b0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71240000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71280000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
712a0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71890000 webio.dll 6.1.7601.23375 C:\Windows\
system32
718e0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71940000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
721a0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
721c0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72260000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
722a0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72450000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72470000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72480000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73060000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
730b0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
730e0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
730f0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73100000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73110000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73170000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73270000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73900000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73970000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73d30000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73d80000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73dc0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73df0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73e30000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73e50000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73e60000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73e70000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73ed0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73f40000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
740e0000 version.dll 6.1.7600.16385 C:\Windows\
system32
740f0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74c10000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74c20000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74c80000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74ce0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
74d60000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
74d80000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75030000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
750d0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750e0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750f0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75180000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75210000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
752e0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
753f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
754f0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76140000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76150000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76160000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
762d0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
762e0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
762f0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76300000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76350000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
763f0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76420000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76430000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76440000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76680000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
766b0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
767a0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
767c0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76910000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76ad0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76be0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76c40000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76c80000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76ca0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76ce0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d30000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ed0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77350000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77380000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0340 svchost.exe 0 0 0
038c svchost.exe 0 0 0
03e4 MsMpEng.exe 0 0 0
0164 RapportMgmtService.exe 0 0 0
02b4 svchost.exe 0 0 0
030c svchost.exe 0 0 0
0404 svchost.exe 0 0 0
042c svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f0 OSPPSVC.EXE 0 0 0
05c0 svchost.exe 0 0 0
0488 scpbradserv.exe 0 0 0
0410 svchost.exe 0 0 0
0830 core.exe 0 0 0
09a0 RapportInjService_x64.exe 0 0 0
0a48 fbserver.exe 0 0 0
0b90 taskhost.exe 1 26 22 normal
0ba8 core.exe 1 9 22 normal
08ec dwm.exe 1 29 13 high
08d0 explorer.exe 1 658 405 normal
0c78 PresentationFontCache.exe 0 0 0
0d20 scpbradguard.exe 1 31 11 normal C:\Program Files
(x86)\scpbrad
0d30 WUDFHost.exe 0 0 0
0e38 RapportService.exe 1 14 18 normal C:\Program Files
(x86)\Trusteer\Rapport\bin
0f60 NisSrv.exe 0 0 0
0fd8 igfxEM.exe 1 14 13 normal
0fe4 igfxHK.exe 1 14 12 normal
0d70 msseces.exe 1 143 60 normal
0e44 PrnStatusMX.exe 1 23 20 normal
1148 SearchIndexer.exe 0 0 0
1174 RapportInjService_x64.exe 1 4 3 normal
13d4 WmiPrvSE.exe 0 0 0
1308 svchost.exe 0 0 0
1348 GoogleCrashHandler.exe 0 0 0
1030 GoogleCrashHandler64.exe 0 0 0
10a8 Store.exe 1 2138 543 normal C:\Program Files
(x86)\Store
1678 wuauclt.exe 1 12 5 normal
1244 OIS.EXE 1 131 55 normal
0764 DeviceDisplayObjectProvider.exe 1 9 6 normal
0648 Store.exe 1 659 238 normal C:\Program Files
(x86)\Store
1664 splwow64.exe 1 9 3 normal
1450 chrome.exe 1 27 58 normal
0ae4 chrome.exe 1 9 4 normal
0cf0 chrome.exe 1 13 7 above normal
13c0 chrome.exe 1 4 1 normal
0eb0 chrome.exe 1 4 1 idle
0888 chrome.exe 1 4 1 idle
12b4 chrome.exe 1 4 3 normal
15bc OIS.EXE 1 88 38 normal
1628 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
0718 audiodg.exe 0 0 0
17e4 VSSVC.exe 0 0 0
0304 svchost.exe 0 0 0
11a8 svchost.exe 0 0 0
041c wermgr.exe 1 4 1 normal C:\Windows\SysWOW64
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0b10a498
ebx = 00003303
ecx = 00000000
edx = 025d2ac8
esi = 0018dde8
edi = 0066cb50
eip = 0066ea6e
esp = 0018ddac
ebp = 0018de14
stack dump:
0018ddac 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018ddbc c0 dd 18 00 6e ea 66 00 - 98 a4 10 0b 03 33 00 00 ....n.f......3..
0018ddcc e8 dd 18 00 50 cb 66 00 - 14 de 18 00 dc dd 18 00 ....P.f.........
0018dddc 00 f5 46 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 ..F.z.f...g.....
0018ddec 00 f5 46 06 00 00 00 00 - 9b e8 67 00 20 de 18 00 ..F.......g. ...
0018ddfc 0c 89 40 00 14 de 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018de0c d5 e9 67 01 00 f5 46 06 - 3c de 18 00 f3 e8 67 00 ..g...F.<.....g.
0018de1c 12 4d 67 00 54 de 18 00 - 0c 89 40 00 3c de 18 00 .Mg.T.....@.<...
0018de2c 00 f5 46 06 00 00 00 00 - 00 00 00 00 00 f5 46 06 ..F...........F.
0018de3c 68 de 18 00 b6 92 67 00 - 00 00 00 00 3c 9a 5b 00 h.....g.....<.[.
0018de4c 01 00 00 00 e3 73 65 00 - 74 de 18 00 0c 89 40 00 .....se.t.....@.
0018de5c 68 de 18 00 f0 17 47 06 - 00 f5 46 06 c8 de 18 00 h.....G...F.....
0018de6c 2a 72 65 00 78 5a 56 01 - 80 de 18 00 64 89 40 00 *re.xZV.....d.@.
0018de7c c8 de 18 00 d8 de 18 00 - 0c 89 40 00 c8 de 18 00 ..........@.....
0018de8c 00 00 00 00 3c 9a 5b 00 - f0 17 47 06 00 00 00 00 ....<.[...G.....
0018de9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018deac 00 00 00 00 f0 17 47 06 - 01 00 00 00 00 00 00 00 ......G.........
0018debc 00 00 00 00 00 f5 46 06 - 40 86 2e 0a f4 de 18 00 ......F.@.......
0018decc 4e 9a 5b 00 fc de 18 00 - 34 99 5b 00 a0 df 18 00 N.[.....4.[.....
0018dedc dc 86 40 00 f4 de 18 00 - 00 00 00 00 fd 0c 83 02 ..@.............
disassembling:
[...]
01565a4f 884 mov eax, [ebp-8]
01565a52 mov eax, [eax+$250]
01565a58 mov edx, [eax]
01565a5a call dword ptr [edx+$44]
01565a5d 885 mov eax, [ebp-8]
01565a60 mov eax, [eax+$250]
01565a66 mov edx, $1565c40
01565a6b mov ecx, [eax]
01565a6d call dword ptr [ecx+$38]
01565a70 886 mov eax, [ebp-8]
01565a73 > call -$f0e858 ($657220) ; Data.DB.TDataSet.Open
01565a78 xor eax, eax
01565a7a pop edx
01565a7b pop ecx
01565a7c pop ecx
01565a7d mov fs:[eax], edx
01565a80 jmp loc_1565c0b
01565a85 jmp -$115d4b2 ($4085d8) ; System.@HandleAnyException
01565a8a 890 mov eax, [$15bcdf0]
01565a8f mov eax, [eax]
01565a91 mov eax, [eax+$60]
[...]
thread $10bc:
7739f8da +0e ntdll.dll NtWaitForSingleObject
763115c8 +92 KERNELBASE.dll WaitForSingleObjectEx
752f118f +3e kernel32.dll WaitForSingleObjectEx
752f1143 +0d kernel32.dll WaitForSingleObject
752f3368 +10 kernel32.dll BaseThreadInitThunk
thread $10c0:
773a0166 +0e ntdll.dll NtWaitForMultipleObjects
752f3368 +10 kernel32.dll BaseThreadInitThunk
thread $cf8:
773a0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
752f3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($10b0) at:
730e2713 +24f netbios.dll Netbios
thread $4a0:
7739f8da +0e ntdll.dll NtWaitForSingleObject
763115c8 +92 KERNELBASE.dll WaitForSingleObjectEx
752f118f +3e kernel32.dll WaitForSingleObjectEx
752f1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
752f3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($10b0) at:
73284c95 +00 winspool.drv
thread $d40:
773a1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
752f3368 +10 kernel32.dll BaseThreadInitThunk
modules:
002d0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06260000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6eac0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
6f8d0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
70630000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70640000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70da0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70db0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70de0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
71060000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
710b0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71240000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71280000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
712a0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71890000 webio.dll 6.1.7601.23375 C:\Windows\
system32
718e0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71940000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
721a0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
721c0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72260000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
722a0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72450000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72470000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72480000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73060000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
730b0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
730e0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
730f0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73100000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73110000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73170000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73270000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73900000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73970000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73d30000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73d80000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73dc0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73df0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73e30000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73e50000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73e60000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73e70000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73ed0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73f40000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
740e0000 version.dll 6.1.7600.16385 C:\Windows\
system32
740f0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74c10000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74c20000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74c80000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74ce0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
74d60000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
74d80000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75030000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
750d0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750e0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750f0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75180000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75210000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
752e0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
753f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
754f0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76140000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76150000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76160000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
762c0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
762d0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
762e0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
762f0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76300000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76350000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
763f0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76420000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76430000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76440000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76680000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
766b0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
767a0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
767c0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76910000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76ad0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76be0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76c40000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76c80000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76ca0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76ce0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d30000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ed0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77350000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77380000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0340 svchost.exe 0 0 0
038c svchost.exe 0 0 0
03e4 MsMpEng.exe 0 0 0
0164 RapportMgmtService.exe 0 0 0
02b4 svchost.exe 0 0 0
030c svchost.exe 0 0 0
0404 svchost.exe 0 0 0
042c svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f0 OSPPSVC.EXE 0 0 0
05c0 svchost.exe 0 0 0
0488 scpbradserv.exe 0 0 0
0410 svchost.exe 0 0 0
0830 core.exe 0 0 0
09a0 RapportInjService_x64.exe 0 0 0
0a48 fbserver.exe 0 0 0
0b90 taskhost.exe 1 26 22 normal
0ba8 core.exe 1 9 22 normal
08ec dwm.exe 1 17 4 high
08d0 explorer.exe 1 640 398 normal
0c78 PresentationFontCache.exe 0 0 0
0d20 scpbradguard.exe 1 31 11 normal C:\Program Files
(x86)\scpbrad
0d30 WUDFHost.exe 0 0 0
0e38 RapportService.exe 1 14 18 normal C:\Program Files
(x86)\Trusteer\Rapport\bin
0f60 NisSrv.exe 0 0 0
0fd8 igfxEM.exe 1 14 13 normal
0fe4 igfxHK.exe 1 14 12 normal
0d70 msseces.exe 1 143 60 normal
0e44 PrnStatusMX.exe 1 23 20 normal
1148 SearchIndexer.exe 0 0 0
1174 RapportInjService_x64.exe 1 4 3 normal
13d4 WmiPrvSE.exe 0 0 0
1308 svchost.exe 0 0 0
1348 GoogleCrashHandler.exe 0 0 0
1030 GoogleCrashHandler64.exe 0 0 0
10a8 Store.exe 1 2135 545 normal C:\Program Files
(x86)\Store
1678 wuauclt.exe 1 12 5 normal
1244 OIS.EXE 1 131 55 normal
0764 DeviceDisplayObjectProvider.exe 1 9 6 normal
0648 Store.exe 1 667 240 normal C:\Program Files
(x86)\Store
1664 splwow64.exe 1 9 3 normal
1450 chrome.exe 1 27 59 normal
0ae4 chrome.exe 1 9 4 normal
0cf0 chrome.exe 1 13 7 above normal
13c0 chrome.exe 1 4 1 normal
0eb0 chrome.exe 1 4 1 normal
0888 chrome.exe 1 4 1 idle
12b4 chrome.exe 1 4 3 normal
15bc OIS.EXE 1 88 38 normal
1628 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
0718 audiodg.exe 0 0 0
17a4 svchost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0b10a498
ebx = 00003303
ecx = 00000000
edx = 025d2ac8
esi = 0018dde8
edi = 0066cb50
eip = 0066ea6e
esp = 0018ddac
ebp = 0018de14
stack dump:
0018ddac 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018ddbc c0 dd 18 00 6e ea 66 00 - 98 a4 10 0b 03 33 00 00 ....n.f......3..
0018ddcc e8 dd 18 00 50 cb 66 00 - 14 de 18 00 dc dd 18 00 ....P.f.........
0018dddc 00 f5 46 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 ..F.z.f...g.....
0018ddec 00 f5 46 06 00 00 00 00 - 9b e8 67 00 20 de 18 00 ..F.......g. ...
0018ddfc 0c 89 40 00 14 de 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018de0c d5 e9 67 01 00 f5 46 06 - 3c de 18 00 f3 e8 67 00 ..g...F.<.....g.
0018de1c 12 4d 67 00 54 de 18 00 - 0c 89 40 00 3c de 18 00 .Mg.T.....@.<...
0018de2c 00 f5 46 06 00 00 00 00 - 00 00 00 00 00 f5 46 06 ..F...........F.
0018de3c 68 de 18 00 b6 92 67 00 - 00 00 00 00 3c 9a 5b 00 h.....g.....<.[.
0018de4c 01 00 00 00 e3 73 65 00 - 74 de 18 00 0c 89 40 00 .....se.t.....@.
0018de5c 68 de 18 00 f0 17 47 06 - 00 f5 46 06 c8 de 18 00 h.....G...F.....
0018de6c 2a 72 65 00 78 5a 56 01 - 80 de 18 00 64 89 40 00 *re.xZV.....d.@.
0018de7c c8 de 18 00 d8 de 18 00 - 0c 89 40 00 c8 de 18 00 ..........@.....
0018de8c 00 00 00 00 3c 9a 5b 00 - f0 17 47 06 00 00 00 00 ....<.[...G.....
0018de9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018deac 00 00 00 00 f0 17 47 06 - 01 00 00 00 00 00 00 00 ......G.........
0018debc 00 00 00 00 00 f5 46 06 - 40 86 2e 0a f4 de 18 00 ......F.@.......
0018decc 4e 9a 5b 00 fc de 18 00 - 34 99 5b 00 a0 df 18 00 N.[.....4.[.....
0018dedc dc 86 40 00 f4 de 18 00 - 00 00 00 00 fd 0c 83 02 ..@.............
disassembling:
[...]
01565a4f 884 mov eax, [ebp-8]
01565a52 mov eax, [eax+$250]
01565a58 mov edx, [eax]
01565a5a call dword ptr [edx+$44]
01565a5d 885 mov eax, [ebp-8]
01565a60 mov eax, [eax+$250]
01565a66 mov edx, $1565c40
01565a6b mov ecx, [eax]
01565a6d call dword ptr [ecx+$38]
01565a70 886 mov eax, [ebp-8]
01565a73 > call -$f0e858 ($657220) ; Data.DB.TDataSet.Open
01565a78 xor eax, eax
01565a7a pop edx
01565a7b pop ecx
01565a7c pop ecx
01565a7d mov fs:[eax], edx
01565a80 jmp loc_1565c0b
01565a85 jmp -$115d4b2 ($4085d8) ; System.@HandleAnyException
01565a8a 890 mov eax, [$15bcdf0]
01565a8f mov eax, [eax]
01565a91 mov eax, [eax+$60]
[...]
thread $10bc:
7739f8da +0e ntdll.dll NtWaitForSingleObject
763115c8 +92 KERNELBASE.dll WaitForSingleObjectEx
752f118f +3e kernel32.dll WaitForSingleObjectEx
752f1143 +0d kernel32.dll WaitForSingleObject
752f3368 +10 kernel32.dll BaseThreadInitThunk
thread $10c0:
773a0166 +0e ntdll.dll NtWaitForMultipleObjects
752f3368 +10 kernel32.dll BaseThreadInitThunk
thread $cf8:
773a0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
752f3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($10b0) at:
730e2713 +24f netbios.dll Netbios
thread $4a0:
7739f8da +0e ntdll.dll NtWaitForSingleObject
763115c8 +92 KERNELBASE.dll WaitForSingleObjectEx
752f118f +3e kernel32.dll WaitForSingleObjectEx
752f1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
752f3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($10b0) at:
73284c95 +00 winspool.drv
thread $d40:
773a1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
752f3368 +10 kernel32.dll BaseThreadInitThunk
modules:
002d0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06260000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6eac0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
6f8d0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
70630000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70640000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70da0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70db0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70de0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
71060000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
710b0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71240000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71280000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
712a0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71890000 webio.dll 6.1.7601.23375 C:\Windows\
system32
718e0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71940000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
721a0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
721c0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72260000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
722a0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72450000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72470000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72480000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73060000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
730b0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
730e0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
730f0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73100000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73110000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73170000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73270000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73900000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73970000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73d30000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73d80000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73dc0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73df0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73e30000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73e50000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73e60000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73e70000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73ed0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73f40000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
740e0000 version.dll 6.1.7600.16385 C:\Windows\
system32
740f0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74c10000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74c20000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74c80000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74ce0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
74d60000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
74d80000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75030000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
750d0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750e0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750f0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75180000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75210000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
752e0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
753f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
754f0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76140000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76150000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76160000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
762c0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
762d0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
762e0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
762f0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76300000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76350000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
763f0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76420000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76430000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76440000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76680000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
766b0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
767a0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
767c0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76910000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76ad0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76be0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76c40000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76c80000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76ca0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76ce0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76d30000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ed0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
77350000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77380000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0340 svchost.exe 0 0 0
038c svchost.exe 0 0 0
03e4 MsMpEng.exe 0 0 0
0164 RapportMgmtService.exe 0 0 0
02b4 svchost.exe 0 0 0
030c svchost.exe 0 0 0
0404 svchost.exe 0 0 0
042c svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f0 OSPPSVC.EXE 0 0 0
05c0 svchost.exe 0 0 0
0488 scpbradserv.exe 0 0 0
0410 svchost.exe 0 0 0
0830 core.exe 0 0 0
09a0 RapportInjService_x64.exe 0 0 0
0a48 fbserver.exe 0 0 0
0b90 taskhost.exe 1 26 23 normal
0ba8 core.exe 1 9 22 normal
08ec dwm.exe 1 17 4 high
08d0 explorer.exe 1 664 416 normal
0c78 PresentationFontCache.exe 0 0 0
0d20 scpbradguard.exe 1 31 11 normal C:\Program Files
(x86)\scpbrad
0d30 WUDFHost.exe 0 0 0
0e38 RapportService.exe 1 14 18 normal C:\Program Files
(x86)\Trusteer\Rapport\bin
0f60 NisSrv.exe 0 0 0
0fd8 igfxEM.exe 1 14 13 normal
0fe4 igfxHK.exe 1 14 12 normal
0d70 msseces.exe 1 143 60 normal
0e44 PrnStatusMX.exe 1 23 20 normal
1148 SearchIndexer.exe 0 0 0
1174 RapportInjService_x64.exe 1 4 3 normal
13d4 WmiPrvSE.exe 0 0 0
1308 svchost.exe 0 0 0
1348 GoogleCrashHandler.exe 0 0 0
1030 GoogleCrashHandler64.exe 0 0 0
10a8 Store.exe 1 2128 539 normal C:\Program Files
(x86)\Store
1678 wuauclt.exe 1 12 5 normal
1244 OIS.EXE 1 131 55 normal
0764 DeviceDisplayObjectProvider.exe 1 9 6 normal
0648 Store.exe 1 666 239 normal C:\Program Files
(x86)\Store
1664 splwow64.exe 1 9 5 normal
1450 chrome.exe 1 27 50 normal
0ae4 chrome.exe 1 9 4 normal
0cf0 chrome.exe 1 13 7 above normal
13c0 chrome.exe 1 4 1 normal
0eb0 chrome.exe 1 4 1 idle
0888 chrome.exe 1 4 1 idle
12b4 chrome.exe 1 4 3 normal
15bc OIS.EXE 1 88 38 normal
1628 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
0718 audiodg.exe 0 0 0
0ef4 Store.exe 1 93 65 normal C:\Program Files
(x86)\Store
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0640eae0
ebx = 0640eae0
ecx = 0018ae1c
edx = 00000000
esi = 0060ca8c
edi = 0018ae14
eip = 0060ba97
esp = 0018ad78
ebp = ffffffec
stack dump:
0018ad78 82 ba 60 00 e0 ea 40 06 - d6 e2 60 00 01 00 00 00 ..`...@...`.....
0018ad88 00 00 00 00 00 00 00 00 - 4c ad 18 00 f4 ad 18 00 ........L.......
0018ad98 f4 ad 18 00 b6 a6 46 75 - 22 6e 24 ce fe ff ff ff ......Fu"n$.....
0018ada8 51 6d 40 75 e8 6d 40 75 - 00 00 00 00 e0 ae 18 00 [email protected]@u........
0018adb8 e0 ea 40 06 e0 ea 40 06 - e0 ea 40 06 3c 34 53 00 ..@...@...@.<4S.
0018adc8 10 b1 18 00 0c 89 40 00 - e0 ae 18 00 00 00 00 00 ......@.........
0018add8 e0 ea 40 06 e0 ea 40 06 - 00 00 00 00 48 8e 83 00 ..@[email protected]...
0018ade8 00 00 00 00 d0 ad 18 00 - 00 00 00 00 50 ae 18 00 ............P...
0018adf8 b6 a6 46 75 82 6e 24 ce - fe ff ff ff f3 6d 40 75 ..Fu.n$......m@u
0018ae08 44 6e 40 75 70 ae b9 02 - fa f8 39 77 84 1c 0f 06 [email protected]....
0018ae18 00 00 cf 07 00 00 01 00 - f8 ff ff ff f8 ff ff ff ................
0018ae28 50 06 00 00 6c 03 00 00 - ca 01 02 00 00 00 00 00 P...l...........
0018ae38 08 00 00 00 30 2f 41 00 - 00 00 00 00 00 00 00 00 ....0/A.........
0018ae48 00 00 40 00 00 00 00 00 - 03 00 01 00 00 00 00 00 ..@.............
0018ae58 00 00 00 00 00 00 00 00 - 54 00 51 00 52 00 53 00 ........T.Q.R.S.
0018ae68 74 00 61 00 6e 00 64 00 - 61 00 72 00 64 00 50 00 t.a.n.d.a.r.d.P.
0018ae78 72 00 65 00 76 00 69 00 - 65 00 77 00 00 00 00 00 r.e.v.i.e.w.....
0018ae88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ae98 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018aea8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
006f97c2 pop ecx
006f97c3 pop ecx
006f97c4 mov fs:[eax], edx
006f97c7 jmp loc_6f97dd
006f97c9 jmp -$2f11f6 ($4085d8) ; System.@HandleAnyException
006f97ce 172 mov eax, [ebp-8]
006f97d1 mov dword ptr [eax+4], $28
006f97d8 call -$2f0ce9 ($408af4) ; System.@DoneExcept
006f97dd 175 mov edx, [ebp-8]
006f97e0 mov eax, [ebp-4]
006f97e3 > call -$ed898 ($60bf50) ; Vcl.Forms.TCustomForm.WndProc
006f97e8 176 pop edi
006f97e9 pop esi
006f97ea pop ebx
006f97eb pop ecx
006f97ec pop ecx
006f97ed pop ebp
006f97ee ret
thread $120c:
776cf8da +0e ntdll.dll NtWaitForSingleObject
772715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75ed118f +3e kernel32.dll WaitForSingleObjectEx
75ed1143 +0d kernel32.dll WaitForSingleObject
75ed3368 +10 kernel32.dll BaseThreadInitThunk
thread $1210:
776d0166 +0e ntdll.dll NtWaitForMultipleObjects
75ed3368 +10 kernel32.dll BaseThreadInitThunk
thread $121c:
776d0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
75ed3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1200) at:
73d42713 +24f netbios.dll Netbios
thread $1268:
776cf8da +0e ntdll.dll NtWaitForSingleObject
772715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75ed118f +3e kernel32.dll WaitForSingleObjectEx
75ed1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
75ed3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1200) at:
73d84c95 +00 winspool.drv
thread $df4:
776d1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75ed3368 +10 kernel32.dll BaseThreadInitThunk
modules:
002b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00390000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06230000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06300000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6ec00000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70390000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70410000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70420000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70440000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
71050000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
71390000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71510000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71570000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
715b0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
715d0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71bc0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71c10000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71c70000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
724d0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
724f0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72590000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
725d0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72780000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
727a0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
727b0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72e10000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
72e90000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73720000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73a60000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73ab0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73ac0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73af0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73b50000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73d40000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73d50000 security.dll 6.1.7600.16385 C:\Windows\
system32
73d60000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73d70000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73dd0000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73e10000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
74070000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
740c0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
740f0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74120000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74160000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74180000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74190000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
741a0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74200000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74270000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74410000 version.dll 6.1.7600.16385 C:\Windows\
system32
74420000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74f40000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74f50000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74fb0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75060000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
750e0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75210000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75240000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75480000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75560000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75600000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75610000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75620000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75780000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75920000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75bd0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75c10000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75c60000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75d60000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75d70000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75ec0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75fd0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76070000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76100000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76130000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76200000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76220000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76230000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76e80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e90000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76ea0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76f00000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76f90000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76fa0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
770f0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77110000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77120000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77150000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77160000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
771c0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
77260000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77680000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
776b0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0290 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
01e4 svchost.exe 0 0 0
0200 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0520 igfxCUIService.exe 0 0 0
0574 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0654 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07e8 OSPPSVC.EXE 0 0 0
05b8 svchost.exe 0 0 0
0430 scpbradserv.exe 0 0 0
0704 svchost.exe 0 0 0
0804 core.exe 0 0 0
098c RapportInjService_x64.exe 0 0 0
0a30 fbserver.exe 0 0 0
0ba4 WUDFHost.exe 0 0 0
0b3c NisSrv.exe 0 0 0
0f00 WmiPrvSE.exe 0 0 0
0d1c taskhost.exe 1 26 22 normal
0d40 core.exe 1 9 22 normal
0db4 PresentationFontCache.exe 0 0 0
0dc4 dwm.exe 1 17 4 high
0de8 explorer.exe 1 879 591 normal
0f74 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0ff0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0fa0 igfxEM.exe 1 14 13 normal
076c igfxHK.exe 1 14 13 normal
0a98 msseces.exe 1 143 60 normal
0a84 PrnStatusMX.exe 1 23 18 normal
05d0 RapportInjService_x64.exe 1 4 3 normal
0de4 GoogleCrashHandler.exe 0 0 0
0e0c svchost.exe 0 0 0
0174 SearchIndexer.exe 0 0 0
10f4 GoogleCrashHandler64.exe 0 0 0
11fc Store.exe 1 4468 826 normal C:\Program Files (x86)\Store
12ac wuauclt.exe 1 12 6 normal
0670 OIS.EXE 1 81 37 normal
0ff8 OIS.EXE 1 131 109 normal
1050 splwow64.exe 1 9 4 normal
0458 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
0e78 OIS.EXE 1 88 38 normal
1614 OIS.EXE 1 101 49 normal
1368 Store.exe 1 379 222 normal C:\Program Files (x86)\Store
1698 OIS.EXE 1 88 38 normal
13b4 chrome.exe 1 27 55 normal
1124 chrome.exe 1 9 4 normal
0bec chrome.exe 1 7 7 above normal
1544 chrome.exe 1 4 1 normal
1590 chrome.exe 1 4 1 normal
1494 OIS.EXE 1 93 46 normal
1720 chrome.exe 1 4 1 idle
12cc chrome.exe 1 4 3 normal
0c60 RdrCEF.exe 1 9 19 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
05e4 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
13a0 audiodg.exe 0 0 0
0434 taskhost.exe 0 0 0
17e0 PDFCreator.exe 1 27 29 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0dfe4fd8
ebx = 00003303
ecx = 00000000
edx = 025b2ac8
esi = 0018ebb8
edi = 0066cb50
eip = 0066ea6e
esp = 0018eb7c
ebp = 0018ebe4
stack dump:
0018eb7c 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018eb8c 90 eb 18 00 6e ea 66 00 - d8 4f fe 0d 03 33 00 00 ....n.f..O...3..
0018eb9c b8 eb 18 00 50 cb 66 00 - e4 eb 18 00 ac eb 18 00 ....P.f.........
0018ebac 50 56 49 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 PVI.z.f...g.....
0018ebbc 50 56 49 06 00 00 00 00 - 9b e8 67 00 f0 eb 18 00 PVI.......g.....
0018ebcc 0c 89 40 00 e4 eb 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018ebdc d5 e9 67 01 50 56 49 06 - 0c ec 18 00 f3 e8 67 00 ..g.PVI.......g.
0018ebec 12 4d 67 00 24 ec 18 00 - 0c 89 40 00 0c ec 18 00 .Mg.$.....@.....
0018ebfc 50 56 49 06 00 00 00 00 - 00 00 00 00 50 56 49 06 PVI.........PVI.
0018ec0c 38 ec 18 00 b6 92 67 00 - 09 00 00 00 18 3c 62 00 8.....g......<b.
0018ec1c 01 00 00 00 e3 73 65 00 - 44 ec 18 00 0c 89 40 00 .....se.D.....@.
0018ec2c 38 ec 18 00 b0 30 4b 04 - 50 56 49 06 08 ed 18 00 8....0K.PVI.....
0018ec3c 2a 72 65 00 e8 eb 12 01 - 10 ed 18 00 0c 89 40 00 *re...........@.
0018ec4c 08 ed 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ec5c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ec6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ec7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ec8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ec9c 00 00 00 00 00 00 00 00 - a0 79 e5 40 d0 2c 42 06 .........y.@.,B.
0018ecac 00 00 00 00 fa a4 4f fa - ff 8b e5 40 00 00 00 00 ......O....@....
disassembling:
[...]
0112ebbf mov eax, [ebp-$18]
0112ebc2 mov eax, [eax+$250]
0112ebc8 mov ecx, [eax]
0112ebca call dword ptr [ecx+$38]
0112ebcd 425 mov edx, $112fc20
0112ebd2 mov eax, [ebp-$18]
0112ebd5 mov eax, [eax+$250]
0112ebdb mov ecx, [eax]
0112ebdd call dword ptr [ecx+$38]
0112ebe0 427 mov eax, [ebp-$18]
0112ebe3 > call -$ad79c8 ($657220) ; Data.DB.TDataSet.Open
0112ebe8 428 mov eax, [ebp-$18]
0112ebeb call -$ad5108 ($659ae8) ; Data.DB.TDataSet.First
0112ebf0 429 mov eax, [ebp-$18]
0112ebf3 cmp byte ptr [eax+$a9], 0
0112ebfa jz loc_112ec08
0112ebfc mov eax, [ebp-$18]
0112ebff cmp byte ptr [eax+$a8], 0
0112ec06 jnz loc_112ec17
0112ec08 431 mov eax, [ebp-4]
0112ec0b call +$33080 ($1161c90) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $524:
77e1f8da +0e ntdll.dll NtWaitForSingleObject
757115c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7735118f +3e kernel32.dll WaitForSingleObjectEx
77351143 +0d kernel32.dll WaitForSingleObject
77353368 +10 kernel32.dll BaseThreadInitThunk
thread $12a0:
77e20166 +0e ntdll.dll NtWaitForMultipleObjects
77353368 +10 kernel32.dll BaseThreadInitThunk
thread $d80:
77e20166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
77353368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($c18) at:
73cd2713 +24f netbios.dll Netbios
thread $774:
77e1f8da +0e ntdll.dll NtWaitForSingleObject
757115c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7735118f +3e kernel32.dll WaitForSingleObjectEx
77351143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
77353368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($c18) at:
741f4c95 +00 winspool.drv
thread $17d0:
77e21f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
77353368 +10 kernel32.dll BaseThreadInitThunk
modules:
002c0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003a0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06250000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062b0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70c50000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70dc0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
71010000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
713e0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
71400000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
71420000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
71520000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
717e0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
71830000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
718e0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71b40000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71b80000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71ba0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71cd0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
72070000 webio.dll 6.1.7601.23375 C:\Windows\
system32
720c0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72120000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72c20000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72c40000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72ce0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72d20000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72ed0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72ef0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72f00000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73ca0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73cd0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73ce0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73dc0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
74070000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
74080000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
740e0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
741e0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
747c0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74810000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74840000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74870000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
748b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
748d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
748e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
748f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74950000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
749c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74b60000 version.dll 6.1.7600.16385 C:\Windows\
system32
74b70000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75690000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
756a0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75700000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75750000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75880000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75a20000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75a30000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75a50000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75b50000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
767a0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
767b0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76970000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76980000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
769b0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
769c0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76a10000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76a20000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76c60000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76c70000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76d10000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76d20000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76fd0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77000000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
770f0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77100000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77110000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
77190000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
771b0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
77280000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
772e0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
772f0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77330000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77340000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
77450000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
774e0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
77590000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
775b0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
77640000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
776f0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77750000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
778b0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77dd0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77e00000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0314 svchost.exe 0 0 0
03f0 svchost.exe 0 0 0
0424 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f0 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0790 NetExpressUpdater.exe 0 0 0
07e4 OSPPSVC.EXE 0 0 0
05b0 svchost.exe 0 0 0
0688 scpbradserv.exe 0 0 0
0704 svchost.exe 0 0 0
0810 core.exe 0 0 0
096c RapportInjService_x64.exe 0 0 0
0a10 fbserver.exe 0 0 0
0ba8 WUDFHost.exe 0 0 0
087c NisSrv.exe 0 0 0
0cc4 WmiPrvSE.exe 0 0 0
0c2c svchost.exe 0 0 0
0dd0 GoogleCrashHandler.exe 0 0 0
0410 GoogleCrashHandler64.exe 0 0 0
0e78 SearchIndexer.exe 0 0 0
0d60 taskhost.exe 1 26 22 normal
0768 core.exe 1 9 21 normal
0a54 PresentationFontCache.exe 0 0 0
0590 dwm.exe 1 17 4 high
0d94 explorer.exe 1 443 278 normal
0f54 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
05f0 igfxEM.exe 1 14 13 normal
00a4 igfxHK.exe 1 14 12 normal
08a4 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0dc8 msseces.exe 1 143 59 normal
0e68 PrnStatusMX.exe 1 23 18 normal
10b8 RapportInjService_x64.exe 1 4 3 normal
00a8 wuauclt.exe 1 12 7 normal
0ba4 Store.exe 1 1237 382 normal C:\Program Files (x86)\Store
0c74 chrome.exe 1 28 57 normal
1254 chrome.exe 1 9 4 normal
0f08 chrome.exe 1 7 7 above normal
139c chrome.exe 1 4 1 normal
1504 chrome.exe 1 4 1 normal
1510 chrome.exe 1 4 1 idle
15bc chrome.exe 1 4 3 normal
14b0 splwow64.exe 1 9 2 normal
16ac OIS.EXE 1 131 109 normal
043c OIS.EXE 1 84 38 normal
102c DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
1698 OIS.EXE 1 118 51 normal
1790 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 05bd4cd8
ebx = 00002e36
ecx = 00000000
edx = 025c2ac8
esi = 044f9d00
edi = 0066cb50
eip = 0066ea6e
esp = 0018e338
ebp = 0018e398
stack dump:
0018e338 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e348 4c e3 18 00 6e ea 66 00 - d8 4c bd 05 36 2e 00 00 L...n.f..L..6...
0018e358 00 9d 4f 04 50 cb 66 00 - 98 e3 18 00 68 e3 18 00 ..O.P.f.....h...
0018e368 36 2e 00 00 96 93 67 00 - 00 9d 4f 04 8c 86 bf 05 6.....g...O.....
0018e378 a5 eb 67 00 a8 e3 18 00 - eb 8a 40 00 98 e3 18 00 ..g.......@.....
0018e388 50 cb 66 00 00 9d 4f 04 - 01 9d 4f 04 00 9d 4f 04 P.f...O...O...O.
0018e398 c8 e3 18 00 79 ea 67 00 - 00 9d 4f 04 62 e6 67 00 ....y.g...O.b.g.
0018e3a8 d0 e3 18 00 0c 89 40 00 - c8 e3 18 00 00 9d 4f 04 [email protected].
0018e3b8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e3c8 f8 e3 18 00 59 e8 67 00 - dc e3 18 00 0c 89 40 00 ....Y.g.......@.
0018e3d8 f8 e3 18 00 04 e4 18 00 - 0c 89 40 00 f8 e3 18 00 ..........@.....
0018e3e8 00 00 00 00 00 00 00 00 - d5 e9 67 01 00 9d 4f 04 ..........g...O.
0018e3f8 20 e4 18 00 f3 e8 67 00 - 12 4d 67 00 38 e4 18 00 .....g..Mg.8...
0018e408 0c 89 40 00 20 e4 18 00 - 00 9d 4f 04 00 00 00 00 ..@. .....O.....
0018e418 00 00 00 00 00 9d 4f 04 - 4c e4 18 00 b6 92 67 00 ......O.L.....g.
0018e428 00 00 00 00 38 5d 53 00 - 01 00 00 00 e3 73 65 00 ....8]S......se.
0018e438 58 e4 18 00 0c 89 40 00 - 4c e4 18 00 40 d5 4c 06 [email protected][email protected].
0018e448 00 9d 4f 04 8c e4 18 00 - 2a 72 65 00 d0 fe 12 01 ..O.....*re.....
0018e458 a4 e4 18 00 0c 89 40 00 - 8c e4 18 00 00 00 00 00 ......@.........
0018e468 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
0112fea5 push $1130034
0112feaa lea eax, [ebp-$20]
0112fead mov edx, 3
0112feb2 call -$d256ef ($40a7c8) ; System.@UStrCatN
0112feb7 mov edx, [ebp-$20]
0112feba mov eax, [ebp-8]
0112febd mov eax, [eax+$250]
0112fec3 mov ecx, [eax]
0112fec5 call dword ptr [ecx+$38]
0112fec8 463 mov eax, [ebp-8]
0112fecb > call -$ad8cb0 ($657220) ; Data.DB.TDataSet.Open
0112fed0 464 mov eax, [ebp-8]
0112fed3 cmp byte ptr [eax+$a8], 0
0112feda jz loc_112fefd
0112fedc mov eax, [ebp-8]
0112fedf cmp byte ptr [eax+$a9], 0
0112fee6 jz loc_112fefd
0112fee8 465 mov edx, $1130048
0112feed mov eax, [ebp-4]
0112fef0 mov eax, [eax+$4f4]
0112fef6 call -$c01837 ($52e6c4) ; Vcl.Controls.TControl.SetText
[...]
thread $11c0:
77b0f8da +0e ntdll.dll NtWaitForSingleObject
773d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
769d118f +3e kernel32.dll WaitForSingleObjectEx
769d1143 +0d kernel32.dll WaitForSingleObject
769d3368 +10 kernel32.dll BaseThreadInitThunk
thread $1038:
77b10166 +0e ntdll.dll NtWaitForMultipleObjects
769d3368 +10 kernel32.dll BaseThreadInitThunk
thread $cec:
77b0f8da +0e ntdll.dll NtWaitForSingleObject
773d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
769d118f +3e kernel32.dll WaitForSingleObjectEx
769d1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
769d3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($7c4) at:
74194c95 +00 winspool.drv
thread $880:
77b11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
769d3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003a0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06290000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063d0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f230000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70c20000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70f10000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70f30000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70f50000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70f60000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70f70000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70fc0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71490000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71580000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
717d0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71810000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71890000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71a10000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
72000000 webio.dll 6.1.7601.23375 C:\Windows\
system32
72050000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
720b0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72910000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72930000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
729d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a10000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72bc0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72be0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72bf0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
734e0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73e90000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
740e0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74120000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
74180000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
74270000 security.dll 6.1.7600.16385 C:\Windows\
system32
743e0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
744b0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74500000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74530000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74560000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
745a0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
745c0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
745d0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
745e0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74640000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
746b0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74850000 version.dll 6.1.7600.16385 C:\Windows\
system32
74860000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75380000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75390000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
753f0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75410000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75480000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75770000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
757a0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75830000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75890000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
758e0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75980000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75b20000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75c70000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
768c0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
769b0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
769c0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76ad0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76d80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76f80000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77020000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77030000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77130000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77140000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77150000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
77220000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77230000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
77250000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
772f0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
773a0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
773b0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
773c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77410000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77440000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77450000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77490000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
774b0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
775e0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
77660000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77ac0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77af0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03cc MsMpEng.exe 0 0 0
0128 RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02cc svchost.exe 0 0 0
03ec svchost.exe 0 0 0
041c svchost.exe 0 0 0
049c svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d0 armsvc.exe 0 0 0
06e8 atkexComSvc.exe 0 0 0
0728 svchost.exe 0 0 0
0750 fbguard.exe 0 0 0
0770 svchost.exe 0 0 0
0788 NetExpressUpdater.exe 0 0 0
07dc OSPPSVC.EXE 0 0 0
0550 svchost.exe 0 0 0
063c scpbradserv.exe 0 0 0
080c core.exe 0 0 0
0984 RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b24 WUDFHost.exe 0 0 0
07d8 NisSrv.exe 0 0 0
0ec0 WmiPrvSE.exe 0 0 0
092c svchost.exe 0 0 0
0e34 GoogleCrashHandler.exe 0 0 0
0f14 GoogleCrashHandler64.exe 0 0 0
075c SearchIndexer.exe 0 0 0
0fd8 taskhost.exe 1 26 24 normal
0a28 core.exe 1 9 21 normal
0e74 PresentationFontCache.exe 0 0 0
0d00 dwm.exe 1 17 4 high
059c explorer.exe 1 663 408 normal
0c88 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0170 RapportService.exe 1 14 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0a6c igfxEM.exe 1 14 13 normal
05cc igfxHK.exe 1 14 12 normal
07cc msseces.exe 1 143 60 normal
04e0 PrnStatusMX.exe 1 23 18 normal
116c RapportInjService_x64.exe 1 4 3 normal
1304 wuauclt.exe 1 12 7 normal
10bc Store.exe 1 2541 294 normal C:\Program Files (x86)\Store
04ac splwow64.exe 1 9 5 normal
0a60 OIS.EXE 1 83 45 normal
0e08 Store.exe 1 598 233 normal C:\Program Files (x86)\Store
0ba4 AcroRd32.exe 1 15 20 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader
13c0 AcroRd32.exe 1 312 177 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader
12b0 RdrCEF.exe 1 9 24 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
1470 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
1494 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
15d4 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
05fc RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
029c chrome.exe 1 74 59 normal
0e4c chrome.exe 1 9 4 normal
0ed0 chrome.exe 1 7 8 above normal
0164 chrome.exe 1 4 1 normal
16f0 chrome.exe 1 4 1 idle
1628 chrome.exe 1 4 3 normal
15bc svchost.exe 0 0 0
176c OIS.EXE 1 81 36 normal
139c chrome.exe 1 4 1 idle
15a0 chrome.exe 1 4 1 idle
14a0 audiodg.exe 0 0 0
13fc rundll32.exe 1 116 49 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 0018dc01
ecx = 00700398
edx = 0018dc01
esi = 00593bec
edi = 044b4e80
eip = 00705bfa
esp = 0018d990
ebp = 0018d9b8
stack dump:
0018d990 67 58 70 00 34 db 18 00 - ec 3b 59 00 f0 86 d5 0a gXp.4....;Y.....
0018d9a0 f7 75 40 00 a8 30 6f 00 - e2 30 6f 00 70 4f 4b 04 [email protected].
0018d9b0 d0 43 44 04 30 42 43 04 - 28 db 18 00 d4 a3 6f 00 .CD.0BC.(.....o.
0018d9c0 ec 3b 59 00 d0 3b 41 0a - ed 04 53 00 d0 3b 41 0a .;Y..;A...S..;A.
0018d9d0 f1 3b 59 00 96 09 53 00 - 08 00 0e 00 08 00 00 00 .;Y...S.........
0018d9e0 0e 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
0018d9f0 16 00 00 00 08 00 0e 00 - d0 3b 41 0a 34 db 18 00 .........;A.4...
0018da00 94 ff 52 00 08 00 0e 00 - 30 dc 18 00 d0 3b 41 0a ..R.....0....;A.
0018da10 d0 3b 41 0a c1 01 00 00 - 0e 00 00 00 00 00 00 00 .;A.............
0018da20 9c da 18 00 1f b0 93 72 - c8 a6 6f 02 08 07 20 00 .......r..o... .
0018da30 02 02 00 00 0f 00 00 00 - c1 01 0e 00 00 00 00 00 ................
0018da40 bb 80 93 72 8e 81 93 72 - 10 31 44 04 c1 01 0e 00 ...r...r.1D.....
0018da50 08 07 20 00 00 00 00 00 - 10 31 44 04 00 00 00 00 .. ......1D.....
0018da60 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018da70 00 00 00 00 00 00 00 00 - bb 80 93 72 01 00 00 00 ...........r....
0018da80 18 db 18 00 00 00 00 00 - 00 00 01 00 00 00 00 01 ................
0018da90 07 00 00 00 00 00 00 00 - bf 5b 31 40 c8 da 18 00 .........[1@....
0018daa0 fa 62 04 77 08 07 20 00 - 02 02 00 00 00 00 00 00 .b.w.. .........
0018dab0 c1 01 0e 00 bb 80 93 72 - cd ab ba dc 00 00 00 00 .......r........
0018dac0 00 00 00 00 e0 da 18 00 - cf fb 52 00 d0 3b 41 0a ..........R..;A.
disassembling:
00705bf4 public QRPrntr.TQRPrinter.GetUseStandardPrinter: ; function entry
point
00705bf4 3462 mov eax, [eax+$b8]
00705bfa > movzx eax, byte ptr [eax+$22]
00705bfe 3463 ret
thread $11c0:
77b0f8da +0e ntdll.dll NtWaitForSingleObject
773d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
769d118f +3e kernel32.dll WaitForSingleObjectEx
769d1143 +0d kernel32.dll WaitForSingleObject
769d3368 +10 kernel32.dll BaseThreadInitThunk
thread $1038:
77b10166 +0e ntdll.dll NtWaitForMultipleObjects
769d3368 +10 kernel32.dll BaseThreadInitThunk
thread $cec:
77b0f8da +0e ntdll.dll NtWaitForSingleObject
773d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
769d118f +3e kernel32.dll WaitForSingleObjectEx
769d1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
769d3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($7c4) at:
74194c95 +00 winspool.drv
thread $880:
77b11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
769d3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003a0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06290000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063d0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f230000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70c20000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70f10000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70f30000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70f50000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70f60000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70f70000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70fc0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71490000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71580000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
717d0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71810000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71890000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71a10000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
72000000 webio.dll 6.1.7601.23375 C:\Windows\
system32
72050000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
720b0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72910000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72930000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
729d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a10000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72bc0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72be0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72bf0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
734e0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73e90000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
740e0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74120000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
74180000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
74270000 security.dll 6.1.7600.16385 C:\Windows\
system32
743e0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
744b0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74500000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74530000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74560000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
745a0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
745c0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
745d0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
745e0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74640000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
746b0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74850000 version.dll 6.1.7600.16385 C:\Windows\
system32
74860000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75380000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75390000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
753f0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75410000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75470000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75480000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75770000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
757a0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75830000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75890000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
758e0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75980000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75b20000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75c70000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
768c0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
769b0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
769c0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76ad0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76d80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76f80000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77020000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77030000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77130000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77140000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77150000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
77220000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77230000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
77250000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
772f0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
773a0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
773b0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
773c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77410000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77440000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77450000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77490000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
774b0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
775e0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
77660000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77ac0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77af0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03cc MsMpEng.exe 0 0 0
0128 RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02cc svchost.exe 0 0 0
03ec svchost.exe 0 0 0
041c svchost.exe 0 0 0
049c svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d0 armsvc.exe 0 0 0
06e8 atkexComSvc.exe 0 0 0
0728 svchost.exe 0 0 0
0750 fbguard.exe 0 0 0
0770 svchost.exe 0 0 0
0788 NetExpressUpdater.exe 0 0 0
07dc OSPPSVC.EXE 0 0 0
0550 svchost.exe 0 0 0
063c scpbradserv.exe 0 0 0
080c core.exe 0 0 0
0984 RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b24 WUDFHost.exe 0 0 0
07d8 NisSrv.exe 0 0 0
0ec0 WmiPrvSE.exe 0 0 0
092c svchost.exe 0 0 0
0e34 GoogleCrashHandler.exe 0 0 0
0f14 GoogleCrashHandler64.exe 0 0 0
075c SearchIndexer.exe 0 0 0
0fd8 taskhost.exe 1 26 24 normal
0a28 core.exe 1 9 21 normal
0e74 PresentationFontCache.exe 0 0 0
0d00 dwm.exe 1 17 4 high
059c explorer.exe 1 663 407 normal
0c88 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0170 RapportService.exe 1 14 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0a6c igfxEM.exe 1 14 13 normal
05cc igfxHK.exe 1 14 12 normal
07cc msseces.exe 1 143 60 normal
04e0 PrnStatusMX.exe 1 23 18 normal
116c RapportInjService_x64.exe 1 4 3 normal
1304 wuauclt.exe 1 12 7 normal
10bc Store.exe 1 2541 294 normal C:\Program Files (x86)\Store
04ac splwow64.exe 1 9 5 normal
0a60 OIS.EXE 1 83 45 normal
0e08 Store.exe 1 600 240 normal C:\Program Files (x86)\Store
0ba4 AcroRd32.exe 1 15 20 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader
13c0 AcroRd32.exe 1 312 177 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader
12b0 RdrCEF.exe 1 9 24 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
1470 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
1494 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
15d4 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
05fc RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
029c chrome.exe 1 74 59 normal
0e4c chrome.exe 1 9 4 normal
0ed0 chrome.exe 1 7 8 above normal
0164 chrome.exe 1 4 1 normal
16f0 chrome.exe 1 4 1 idle
1628 chrome.exe 1 4 3 normal
15bc svchost.exe 0 0 0
176c OIS.EXE 1 81 36 normal
139c chrome.exe 1 4 1 idle
15a0 chrome.exe 1 4 1 idle
14a0 audiodg.exe 0 0 0
13fc rundll32.exe 1 116 48 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0047002e
ebx = 044b4e80
ecx = 8b000001
edx = 00000000
esi = 04434230
edi = 00000000
eip = 00487029
esp = 00189530
ebp = 00189538
stack dump:
00189530 00 00 00 00 00 00 00 00 - 90 d5 18 00 ca 00 6d 00 ..............m.
00189540 00 00 00 00 00 00 00 00 - 94 d5 18 00 0c 89 40 00 ..............@.
00189550 90 d5 18 00 30 42 43 04 - 80 4e 4b 04 7c 51 e3 07 ....0BC..NK.|Q..
00189560 1b 00 00 00 e0 da d5 0a - 22 b6 18 00 ef 5e 67 00 ........"....^g.
00189570 00 00 00 00 e0 da d5 0a - 80 4e 4b 04 60 af 4e 04 .........NK.`.N.
00189580 2e 00 47 00 31 5f 67 00 - 22 b6 18 00 01 00 00 00 ..G.1_g.".......
00189590 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
001895a0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
001895b0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
001895c0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
001895d0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
001895e0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
001895f0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00189600 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00189610 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00189620 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00189630 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00189640 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00189650 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00189660 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
006d00a3 push ebp
006d00a4 push $6d0414 ; System.@HandleFinally
006d00a9 push dword ptr fs:[eax]
006d00ac mov fs:[eax], esp
006d00af 339 call -$277ea8 ($45820c) ; System.SysUtils.Now
006d00b4 fstp qword ptr [$15c4828]
006d00ba wait
006d00bb 340 push 0
006d00bd push 0
006d00bf mov eax, [ebp-$4010]
006d00c5 > call -$2490ae ($48701c) ; System.Classes.TStream.SetPosition
006d00ca 341 xor eax, eax
006d00cc mov [ebp-$400c], eax
006d00d2 342 xor eax, eax
006d00d4 mov [ebp-$4014], eax
006d00da 343 push ebp
006d00db call -$21c ($6cfec4) ; LZW.InitTable
006d00e0 pop ecx
006d00e1 344 push ebp
006d00e2 call -$1bb ($6cff2c) ; LZW.ReadCode
006d00e7 pop ecx
[...]
thread $11c0:
77b0f8da +0e ntdll.dll NtWaitForSingleObject
773d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
769d118f +3e kernel32.dll WaitForSingleObjectEx
769d1143 +0d kernel32.dll WaitForSingleObject
769d3368 +10 kernel32.dll BaseThreadInitThunk
thread $1038:
77b10166 +0e ntdll.dll NtWaitForMultipleObjects
769d3368 +10 kernel32.dll BaseThreadInitThunk
thread $cec:
77b0f8da +0e ntdll.dll NtWaitForSingleObject
773d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
769d118f +3e kernel32.dll WaitForSingleObjectEx
769d1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
769d3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($7c4) at:
74194c95 +00 winspool.drv
thread $880:
77b11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
769d3368 +10 kernel32.dll BaseThreadInitThunk
thread $1510:
77b11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
769d3368 +10 kernel32.dll BaseThreadInitThunk
thread $1734:
77b11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
769d3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003a0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06290000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063d0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f230000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70c20000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70f10000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70f30000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70f50000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70f60000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70f70000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70fc0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71490000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71580000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
717d0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71810000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71890000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71a10000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
72000000 webio.dll 6.1.7601.23375 C:\Windows\
system32
72050000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
720b0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72910000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72930000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
729d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a10000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72bc0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72be0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72bf0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
734e0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73e90000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
740e0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74120000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
74180000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
74270000 security.dll 6.1.7600.16385 C:\Windows\
system32
743e0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
744b0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74500000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74530000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74560000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
745a0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
745c0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
745d0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
745e0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74640000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
746b0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74850000 version.dll 6.1.7600.16385 C:\Windows\
system32
74860000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75380000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75390000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
753f0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75410000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75470000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75480000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75770000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
757a0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75830000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75890000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
758e0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75980000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75b20000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75c70000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
768c0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
769b0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
769c0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76ad0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76d80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76f80000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77020000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77030000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77130000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77140000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77150000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
77220000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77230000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
77250000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
772f0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
773a0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
773b0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
773c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77410000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77440000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77450000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77490000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
774b0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
775e0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
77660000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77ac0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77af0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03cc MsMpEng.exe 0 0 0
0128 RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02cc svchost.exe 0 0 0
03ec svchost.exe 0 0 0
041c svchost.exe 0 0 0
049c svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d0 armsvc.exe 0 0 0
06e8 atkexComSvc.exe 0 0 0
0728 svchost.exe 0 0 0
0750 fbguard.exe 0 0 0
0770 svchost.exe 0 0 0
0788 NetExpressUpdater.exe 0 0 0
07dc OSPPSVC.EXE 0 0 0
0550 svchost.exe 0 0 0
063c scpbradserv.exe 0 0 0
080c core.exe 0 0 0
0984 RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b24 WUDFHost.exe 0 0 0
07d8 NisSrv.exe 0 0 0
0ec0 WmiPrvSE.exe 0 0 0
092c svchost.exe 0 0 0
0e34 GoogleCrashHandler.exe 0 0 0
0f14 GoogleCrashHandler64.exe 0 0 0
075c SearchIndexer.exe 0 0 0
0fd8 taskhost.exe 1 26 22 normal
0a28 core.exe 1 9 21 normal
0e74 PresentationFontCache.exe 0 0 0
0d00 dwm.exe 1 17 4 high
059c explorer.exe 1 663 406 normal
0c88 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0170 RapportService.exe 1 14 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0a6c igfxEM.exe 1 14 13 normal
05cc igfxHK.exe 1 14 12 normal
07cc msseces.exe 1 143 60 normal
04e0 PrnStatusMX.exe 1 23 18 normal
116c RapportInjService_x64.exe 1 4 3 normal
1304 wuauclt.exe 1 12 7 normal
10bc Store.exe 1 2541 294 normal C:\Program Files (x86)\Store
04ac splwow64.exe 1 9 5 normal
0a60 OIS.EXE 1 83 45 normal
0e08 Store.exe 1 583 230 normal C:\Program Files (x86)\Store
0ba4 AcroRd32.exe 1 15 20 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader
13c0 AcroRd32.exe 1 312 177 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader
12b0 RdrCEF.exe 1 9 24 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
1470 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
1494 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
15d4 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
05fc RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\
Adobe\Acrobat Reader DC\Reader\AcroCEF
029c chrome.exe 1 74 61 normal
0e4c chrome.exe 1 9 4 normal
0ed0 chrome.exe 1 7 8 above normal
0164 chrome.exe 1 4 1 normal
16f0 chrome.exe 1 4 1 normal
1628 chrome.exe 1 4 3 normal
15bc svchost.exe 0 0 0
176c OIS.EXE 1 81 36 normal
139c chrome.exe 1 4 1 idle
15a0 chrome.exe 1 4 1 idle
14a0 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 044b4e80
ebx = 00000100
ecx = 000204b0
edx = 044a5d01
esi = 04434230
edi = 0adca940
eip = 00353f48
esp = 0018dd90
ebp = 0018de04
stack dump:
0018dd90 f7 75 40 00 f5 1d 6f 00 - 30 42 43 04 01 01 00 00 [email protected].....
0018dda0 53 55 6f 00 40 a9 dc 0a - 40 a9 dc 0a f7 75 40 00 SUo.@[email protected]@.
0018ddb0 87 fa e9 00 0c de 18 00 - 0c 89 40 00 04 de 18 00 ..........@.....
0018ddc0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ddd0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dde0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ddf0 00 00 00 00 00 00 00 00 - 00 00 00 00 c0 8c 35 0a ..............5.
0018de00 d0 14 43 04 88 de 18 00 - 09 92 e9 00 5c e5 18 00 ..C.........\...
0018de10 0c 89 40 00 88 de 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018de20 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018de30 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018de40 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018de50 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018de60 00 00 00 00 40 a9 dc 0a - 20 95 4e 04 c0 97 4e 04 ....@... .N...N.
0018de70 60 9a 4e 04 60 af 4e 04 - 80 7d 4e 04 c0 82 4e 04 `.N.`.N..}N...N.
0018de80 20 80 4e 04 d0 14 43 04 - a8 e3 18 00 ed 04 53 00 .N...C.......S.
0018de90 40 a9 dc 0a 33 35 55 00 - a8 e3 18 00 62 44 62 00 @...35U.....bDb.
0018dea0 b8 43 62 00 a8 e3 18 00 - b9 40 55 00 e0 df 18 00 .Cb......@U.....
0018deb0 a8 e3 18 00 40 a9 dc 0a - 94 ff 52 00 a8 e3 18 00 [email protected].....
0018dec0 a8 e3 18 00 40 a9 dc 0a - 17 1b 01 aa f4 08 b4 06 ....@...........
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $11c0:
77b0f8da +0e ntdll.dll NtWaitForSingleObject
773d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
769d118f +3e kernel32.dll WaitForSingleObjectEx
769d1143 +0d kernel32.dll WaitForSingleObject
769d3368 +10 kernel32.dll BaseThreadInitThunk
thread $1038:
77b10166 +0e ntdll.dll NtWaitForMultipleObjects
769d3368 +10 kernel32.dll BaseThreadInitThunk
thread $cec:
77b0f8da +0e ntdll.dll NtWaitForSingleObject
773d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
769d118f +3e kernel32.dll WaitForSingleObjectEx
769d1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
769d3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($7c4) at:
74194c95 +00 winspool.drv
thread $1714:
77b11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
769d3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003a0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06290000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063d0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f230000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70c20000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70f10000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70f30000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70f50000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70f60000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70f70000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70fc0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71490000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71580000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
717d0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71810000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71890000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71a10000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
72000000 webio.dll 6.1.7601.23375 C:\Windows\
system32
72050000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
720b0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72910000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72930000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
729d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72a10000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72bc0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72be0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72bf0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
734e0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73e90000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
740e0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74120000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
74180000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
74270000 security.dll 6.1.7600.16385 C:\Windows\
system32
743e0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
744b0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74500000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74530000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74560000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
745a0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
745c0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
745d0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
745e0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74640000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
746b0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74850000 version.dll 6.1.7600.16385 C:\Windows\
system32
74860000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75380000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75390000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
753f0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75410000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75470000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75480000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75530000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75770000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
757a0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75830000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75890000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
758e0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75980000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75b20000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75c70000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
768c0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
769b0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
769c0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76ad0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76d80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e20000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76f80000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
77020000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77030000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77130000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77140000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77150000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
77220000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77230000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
77250000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
772f0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
773a0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
773b0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
773c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
77410000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77440000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77450000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77490000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
774b0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
775e0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
77660000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77ac0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77af0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03cc MsMpEng.exe 0 0 0
0128 RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02cc svchost.exe 0 0 0
03ec svchost.exe 0 0 0
041c svchost.exe 0 0 0
049c svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06d0 armsvc.exe 0 0 0
06e8 atkexComSvc.exe 0 0 0
0728 svchost.exe 0 0 0
0750 fbguard.exe 0 0 0
0770 svchost.exe 0 0 0
0788 NetExpressUpdater.exe 0 0 0
07dc OSPPSVC.EXE 0 0 0
0550 svchost.exe 0 0 0
063c scpbradserv.exe 0 0 0
080c core.exe 0 0 0
0984 RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0b24 WUDFHost.exe 0 0 0
07d8 NisSrv.exe 0 0 0
0ec0 WmiPrvSE.exe 0 0 0
092c svchost.exe 0 0 0
0e34 GoogleCrashHandler.exe 0 0 0
0f14 GoogleCrashHandler64.exe 0 0 0
075c SearchIndexer.exe 0 0 0
0fd8 taskhost.exe 1 26 23 normal
0a28 core.exe 1 9 21 normal
0e74 PresentationFontCache.exe 0 0 0
0d00 dwm.exe 1 18 4 high
059c explorer.exe 1 619 426 normal
0c88 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\scpbrad
0170 RapportService.exe 1 14 17 normal C:\Program Files (x86)\Trusteer\
Rapport\bin
0a6c igfxEM.exe 1 14 13 normal
05cc igfxHK.exe 1 14 12 normal
07cc msseces.exe 1 143 60 normal
04e0 PrnStatusMX.exe 1 23 18 normal
116c RapportInjService_x64.exe 1 4 3 normal
1304 wuauclt.exe 1 12 7 normal
04ac splwow64.exe 1 9 3 normal
0a60 OIS.EXE 1 83 45 normal
0e08 Store.exe 1 901 95 normal C:\Program Files (x86)\Store
0ba4 AcroRd32.exe 1 15 20 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader
13c0 AcroRd32.exe 1 312 177 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader
12b0 RdrCEF.exe 1 9 24 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
1470 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
1494 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
15d4 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
05fc RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
15bc svchost.exe 0 0 0
176c OIS.EXE 1 81 36 normal
0574 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0018fe14
ebx = 004075b1
ecx = 00000007
edx = 00000000
esi = 004075b1
edi = 04434230
eip = 773cc54f
esp = 0018fe14
ebp = 0018fe64
stack dump:
0018fe14 de fa ed 0e 01 00 00 00 - 00 00 00 00 4f c5 3c 77 ............O.<w
0018fe24 07 00 00 00 b1 75 40 00 - 58 80 52 04 b1 75 40 00 [email protected]@.
0018fe34 b1 75 40 00 30 42 43 04 - b0 fe 18 00 98 fe 18 00 [email protected].........
0018fe44 df 61 4d 00 30 42 43 04 - b1 75 40 00 b0 fe 18 00 .aM.0BC..u@.....
0018fe54 68 fe 18 00 b1 75 40 00 - 38 fe 18 00 a4 db 44 00 [email protected].
0018fe64 b0 fe 18 00 b1 75 40 00 - de fa ed 0e 01 00 00 00 .....u@.........
0018fe74 07 00 00 00 7c fe 18 00 - b1 75 40 00 58 80 52 04 ....|[email protected].
0018fe84 b1 75 40 00 b1 75 40 00 - 30 42 43 04 b0 fe 18 00 [email protected]@.0BC.....
0018fe94 98 fe 18 00 02 00 00 00 - f4 4c 40 00 f0 c0 4e 06 [email protected].
0018fea4 f0 c0 4e 06 37 4d 40 00 - f0 c0 4e 02 40 ff 18 00 [email protected].@...
0018feb4 b1 75 40 00 f0 c0 4e 06 - 5c 77 4d 00 01 17 01 87 [email protected].\wM.....
0018fec4 f6 48 50 00 70 02 44 0a - 00 17 01 87 f7 75 40 00 .HP.p.D......u@.
0018fed4 2e 5a 50 00 70 02 44 0a - 01 17 01 87 11 cc 52 00 .ZP.p.D.......R.
0018fee4 30 42 43 04 00 43 47 00 - f7 75 40 00 8e 1d 6f 00 [email protected].
0018fef4 30 42 43 04 01 43 47 00 - 53 55 6f 00 00 af 3d 0a 0BC..CG.SUo...=.
0018ff04 02 00 00 00 a9 1c 53 00 - 00 75 47 06 f8 a1 51 04 ......S..uG...Q.
0018ff14 00 af 3d 0a 00 00 00 00 - 98 a0 60 00 00 af 3d 0a ..=.......`...=.
0018ff24 50 f6 4d 04 72 b2 60 00 - 78 ff 18 00 0c 89 40 00 P.M.r.`.x.....@.
0018ff34 40 ff 18 00 f8 a1 51 01 - 00 af 3d 0a 88 ff 18 00 @.....Q...=.....
0018ff44 56 04 49 00 54 e0 5b 01 - 18 0b 5c 01 34 8e 60 00 V.I.T.[...\.4.`.
disassembling:
004075a0 public System.TObject.FreeInstance: ; function entry point
004075a0 35 push ebx
004075a1 mov ebx, eax
004075a3 mov eax, ebx
004075a5 call +$a6 ($407650) ; System.TObject.CleanupInstance
004075aa mov eax, ebx
004075ac call -$29fd ($404bb4) ; System.@FreeMem
004075b1 > pop ebx
004075b2 ret
thread $1190:
7778f8da +0e ntdll.dll NtWaitForSingleObject
753015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75ce118f +3e kernel32.dll WaitForSingleObjectEx
75ce1143 +0d kernel32.dll WaitForSingleObject
75ce3368 +10 kernel32.dll BaseThreadInitThunk
thread $1198:
77790166 +0e ntdll.dll NtWaitForMultipleObjects
75ce3368 +10 kernel32.dll BaseThreadInitThunk
thread $11a0:
77791f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75ce3368 +10 kernel32.dll BaseThreadInitThunk
thread $1378:
77790166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
75ce3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($112c) at:
73252713 +24f netbios.dll Netbios
thread $1388:
77791f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75ce3368 +10 kernel32.dll BaseThreadInitThunk
thread $1398:
77791f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75ce3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00350000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00380000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
04580000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06320000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
09b00000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6ed90000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
6eee0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
706c0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70b70000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70b80000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70ba0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
71100000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
71260000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
712a0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
712e0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71300000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71630000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
719d0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71a20000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71a80000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72580000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
725a0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72640000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72680000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72830000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72850000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72860000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73150000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73250000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73260000 security.dll 6.1.7600.16385 C:\Windows\
system32
73270000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
736e0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
738c0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73c10000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73ce0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73d50000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74160000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
741b0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
741e0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74220000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74240000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74250000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74260000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
742c0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74330000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
744d0000 version.dll 6.1.7600.16385 C:\Windows\
system32
744e0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75000000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75010000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75070000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75100000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75150000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75280000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
752e0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
752f0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75340000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75490000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75590000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
755a0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
757e0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75840000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75850000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75890000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75910000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75920000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75940000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75a10000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75cc0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75cd0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75de0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76a30000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76ad0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ae0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76b90000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ba0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76c90000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76cc0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76cd0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ce0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76d70000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76d80000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76e20000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76ed0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76ee0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76f40000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76ff0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
771b0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77350000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77740000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77770000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02d0 lsass.exe 0 0 0
02d8 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
02b4 svchost.exe 0 0 0
0344 svchost.exe 0 0 0
025c svchost.exe 0 0 0
0420 svchost.exe 0 0 0
0478 audiodg.exe 0 0 0
04ac svchost.exe 0 0 0
0524 igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
07ec OSPPSVC.EXE 0 0 0
0690 svchost.exe 0 0 0
0674 scpbradserv.exe 0 0 0
0740 svchost.exe 0 0 0
0808 core.exe 0 0 0
095c RapportInjService_x64.exe 0 0 0
0a18 fbserver.exe 0 0 0
0bac WUDFHost.exe 0 0 0
0b30 NisSrv.exe 0 0 0
0c30 taskhost.exe 1 26 23 normal
0c7c core.exe 1 9 19 normal
0cdc PresentationFontCache.exe 0 0 0
0ce4 dwm.exe 1 16 4 high
0d14 explorer.exe 1 338 225 normal
0e40 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\scpbrad
0f20 igfxEM.exe 1 14 13 normal
0f48 igfxHK.exe 1 14 12 normal
0d30 RapportService.exe 1 14 17 normal C:\Program Files (x86)\Trusteer\
Rapport\bin
0d60 msseces.exe 1 143 60 normal
0e34 PrnStatusMX.exe 1 23 18 normal
0fc0 svchost.exe 0 0 0
015c GoogleCrashHandler.exe 0 0 0
0994 RapportInjService_x64.exe 1 4 3 normal
03dc SearchIndexer.exe 0 0 0
10dc SearchProtocolHost.exe 0 0 0
1120 SearchFilterHost.exe 0 0 0 idle
11dc GoogleCrashHandler64.exe 0 0 0
11f8 WmiPrvSE.exe 0 0 0
1244 svchost.exe 0 0 0
1288 sppsvc.exe 0 0 0
133c VSSVC.exe 0 0 0
1380 svchost.exe 0 0 0
13a4 WmiPrvSE.exe 0 0 0
1128 Store.exe 1 107 86 normal C:\Program Files (x86)\Store
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 044bb2f8
ebx = 00003303
ecx = 00000000
edx = 02962ac8
esi = 00000000
edi = 00000000
eip = 0066ea6e
esp = 0018f0d0
ebp = 0018f1ac
stack dump:
0018f0d0 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018f0e0 e4 f0 18 00 6e ea 66 00 - f8 b2 4b 04 03 33 00 00 ....n.f...K..3..
0018f0f0 00 00 00 00 00 00 00 00 - ac f1 18 00 00 f1 18 00 ................
0018f100 00 00 00 00 7a ea 66 00 - 0b 46 67 00 18 f1 18 00 ....z.f..Fg.....
0018f110 eb 8a 40 00 ac f1 18 00 - 24 f1 18 00 0c 89 40 00 ..@.....$.....@.
0018f120 ac f1 18 00 30 f1 18 00 - 0c 89 40 00 ac f1 18 00 ....0.....@.....
0018f130 c4 f1 18 00 0c 89 40 00 - ac f1 18 00 00 00 00 00 ......@.........
0018f140 70 8d 46 04 01 fa 53 06 - 00 00 00 00 00 00 00 00 p.F...S.........
0018f150 00 00 00 00 00 00 00 00 - 00 00 00 00 0c 46 4f 06 .............FO.
0018f160 64 23 45 00 00 04 00 00 - 01 00 00 00 34 ce 4b 04 d#E.........4.K.
0018f170 08 00 00 00 0c 46 4f 06 - 08 00 00 00 30 44 44 04 .....FO.....0DD.
0018f180 00 00 00 00 01 00 00 00 - 70 8d 46 04 f1 fd 66 00 ........p.F...f.
0018f190 0c 46 4f 06 01 00 00 00 - 00 00 00 00 00 00 00 07 .FO.............
0018f1a0 70 8d 46 04 00 00 00 00 - 00 00 00 00 f4 f1 18 00 p.F.............
0018f1b0 10 56 64 00 b0 fa 53 06 - 0c 46 4f 06 cb 55 64 00 .Vd...S..FO..Ud.
0018f1c0 47 1e 67 00 d0 f1 18 00 - eb 8a 40 00 f4 f1 18 00 G.g.......@.....
0018f1d0 60 f2 18 00 0c 89 40 00 - f4 f1 18 00 00 00 00 00 `.....@.........
0018f1e0 40 20 48 04 40 20 48 04 - 00 00 00 00 70 8d 46 04 @ H.@ H.....p.F.
0018f1f0 30 44 44 04 74 f2 18 00 - 2d 94 67 00 00 cb 66 00 0DD.t...-.g...f.
0018f200 2e 95 67 00 01 cb 66 00 - 74 f2 18 00 00 00 00 00 ..g...f.t.......
disassembling:
[...]
009a1389 push $9a1c78
009a138e lea eax, [ebp-$2c]
009a1391 mov edx, 5
009a1396 call -$596bd3 ($40a7c8) ; System.@UStrCatN
009a139b mov edx, [ebp-$2c]
009a139e mov eax, [ebp-$18]
009a13a1 mov eax, [eax+$250]
009a13a7 mov ecx, [eax]
009a13a9 call dword ptr [ecx+$38]
009a13ac 639 mov eax, [ebp-$18]
009a13af > call -$34a194 ($657220) ; Data.DB.TDataSet.Open
009a13b4 641 mov eax, [$15bcdf0]
009a13b9 mov eax, [eax]
009a13bb mov eax, [eax+$e60]
009a13c1 cmp byte ptr [eax+$a8], 0
009a13c8 jz loc_9a13e4
009a13ca mov eax, [$15bcdf0]
009a13cf mov eax, [eax]
009a13d1 mov eax, [eax+$e60]
009a13d7 cmp byte ptr [eax+$a9], 0
009a13de jnz loc_9a194c
[...]
thread $1010:
7728f8da +0e ntdll.dll NtWaitForSingleObject
767c15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
764e118f +3e kernel32.dll WaitForSingleObjectEx
764e1143 +0d kernel32.dll WaitForSingleObject
764e3368 +10 kernel32.dll BaseThreadInitThunk
thread $12f0:
77290166 +0e ntdll.dll NtWaitForMultipleObjects
764e3368 +10 kernel32.dll BaseThreadInitThunk
thread $ddc:
77290166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
764e3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($e44) at:
73872713 +24f netbios.dll Netbios
thread $11f4:
7728f8da +0e ntdll.dll NtWaitForSingleObject
767c15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
764e118f +3e kernel32.dll WaitForSingleObjectEx
764e1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
764e3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($e44) at:
72bb4c95 +00 winspool.drv
thread $d9c:
77291f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
764e3368 +10 kernel32.dll BaseThreadInitThunk
modules:
001c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00280000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
003c0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
025b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
06240000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6edb0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70230000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70860000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70870000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70880000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
708a0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70af0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70cb0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70d70000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70fb0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70ff0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71170000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71190000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
714d0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71520000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71580000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72090000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
720b0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72150000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72190000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72340000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72360000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72370000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72900000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72940000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
72a40000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
72aa0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72ba0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73870000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73880000 security.dll 6.1.7600.16385 C:\Windows\
system32
73a80000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73ab0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73c30000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73c80000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73cb0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73ce0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73d20000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73d40000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73d50000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73d60000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73dc0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73e30000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73fd0000 version.dll 6.1.7600.16385 C:\Windows\
system32
73fe0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74b00000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74b10000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74b70000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
74b90000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
74c40000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
74da0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
74e00000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74e10000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
74f60000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75000000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75c50000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75c60000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75ea0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75eb0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f20000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75fc0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75ff0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76000000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76060000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76190000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76440000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
764c0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
764d0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
765e0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
766b0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
766c0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
766d0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
766f0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76700000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
767b0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76800000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
768f0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76a90000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76b30000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76b50000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76b90000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76c20000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c30000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76c90000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76d90000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76de0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77240000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77270000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0290 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03e0 MsMpEng.exe 0 0 0
0148 RapportMgmtService.exe 0 0 0
0314 svchost.exe 0 0 0
0374 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
042c svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
0564 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
07e0 OSPPSVC.EXE 0 0 0
0578 svchost.exe 0 0 0
0428 scpbradserv.exe 0 0 0
05b4 core.exe 0 0 0
0984 RapportInjService_x64.exe 0 0 0
0a10 fbserver.exe 0 0 0
0bac WUDFHost.exe 0 0 0
08e4 NisSrv.exe 0 0 0
0c80 WmiPrvSE.exe 0 0 0
0cd8 svchost.exe 0 0 0
0db0 GoogleCrashHandler.exe 0 0 0
0888 GoogleCrashHandler64.exe 0 0 0
0948 SearchIndexer.exe 0 0 0
08fc taskhost.exe 1 26 22 normal
0df0 core.exe 1 9 21 normal
049c PresentationFontCache.exe 0 0 0
0878 dwm.exe 1 18 4 high
0170 explorer.exe 1 425 292 normal
0f60 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\scpbrad
0fe0 RapportService.exe 1 32 25 normal C:\Program Files (x86)\Trusteer\
Rapport\bin
00bc igfxEM.exe 1 14 13 normal
1004 igfxHK.exe 1 14 13 normal
1088 msseces.exe 1 143 59 normal
10c0 PrnStatusMX.exe 1 23 18 normal
125c RapportInjService_x64.exe 1 4 3 normal
11b0 wuauclt.exe 1 12 6 normal
0930 Store.exe 1 1611 449 normal C:\Program Files (x86)\Store
1144 splwow64.exe 1 9 3 normal
0f5c AcroRd32.exe 1 15 20 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader
0f90 AcroRd32.exe 1 260 134 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader
0bf4 RdrCEF.exe 1 9 23 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
1448 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
1480 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
1600 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
1338 OIS.EXE 1 88 38 normal
17dc OIS.EXE 1 88 38 normal
1118 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0c50 OIS.EXE 1 81 38 normal
1428 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0ccbbe70
ebx = 00003303
ecx = 00000000
edx = 002c2ac8
esi = 0018e3d4
edi = 0066cb50
eip = 0066ea6e
esp = 0018e398
ebp = 0018e400
stack dump:
0018e398 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e3a8 ac e3 18 00 6e ea 66 00 - 70 be cb 0c 03 33 00 00 ....n.f.p....3..
0018e3b8 d4 e3 18 00 50 cb 66 00 - 00 e4 18 00 c8 e3 18 00 ....P.f.........
0018e3c8 00 88 4b 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 ..K.z.f...g.....
0018e3d8 00 88 4b 04 00 00 00 00 - 9b e8 67 00 0c e4 18 00 ..K.......g.....
0018e3e8 0c 89 40 00 00 e4 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e3f8 d5 e9 67 01 00 88 4b 04 - 28 e4 18 00 f3 e8 67 00 ..g...K.(.....g.
0018e408 12 4d 67 00 40 e4 18 00 - 0c 89 40 00 28 e4 18 00 .Mg.@.....@.(...
0018e418 00 88 4b 04 00 00 00 00 - 00 00 00 00 00 88 4b 04 ..K...........K.
0018e428 54 e4 18 00 b6 92 67 00 - 00 00 00 00 38 5d 53 00 T.....g.....8]S.
0018e438 01 00 00 00 e3 73 65 00 - 60 e4 18 00 0c 89 40 00 .....se.`.....@.
0018e448 54 e4 18 00 60 a4 4f 06 - 00 88 4b 04 8c e4 18 00 T...`.O...K.....
0018e458 2a 72 65 00 7d d3 1b 01 - a4 e4 18 00 0c 89 40 00 *re.}.........@.
0018e468 8c e4 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e478 00 00 00 00 00 00 00 00 - 60 a4 4f 06 00 88 4b 04 ........`.O...K.
0018e488 d0 4a 29 05 d0 e4 18 00 - 53 5d 53 00 80 e6 18 00 .J).....S]S.....
0018e498 06 6a 53 00 80 e6 18 00 - 1f f9 54 00 b0 e4 18 00 .jS.......T.....
0018e4a8 eb 8a 40 00 d0 e4 18 00 - 50 e6 18 00 0c 89 40 00 [email protected].....@.
0018e4b8 d0 e4 18 00 00 00 00 00 - 60 a4 4f 06 80 e6 18 00 ........`.O.....
0018e4c8 00 00 00 00 60 a4 4f 06 - fc e5 18 00 94 ff 52 00 ....`.O.......R.
disassembling:
[...]
011bd354 mov ecx, [ebp-$18]
011bd357 lea eax, [ebp-$14]
011bd35a mov edx, $11bd448
011bd35f call -$db2c24 ($40a740) ; System.@UStrCat3
011bd364 mov edx, [ebp-$14]
011bd367 mov eax, [ebp-8]
011bd36a mov eax, [eax+$250]
011bd370 mov ecx, [eax]
011bd372 call dword ptr [ecx+$38]
011bd375 734 mov eax, [ebp-8]
011bd378 > call -$b6615d ($657220) ; Data.DB.TDataSet.Open
011bd37d 735 mov eax, [ebp-8]
011bd380 cmp byte ptr [eax+$a8], 0
011bd387 jz loc_11bd3aa
011bd389 mov eax, [ebp-8]
011bd38c cmp byte ptr [eax+$a9], 0
011bd393 jz loc_11bd3aa
011bd395 736 mov edx, $11bd4b0
011bd39a mov eax, [ebp-4]
011bd39d mov eax, [eax+$3ec]
011bd3a3 call -$c8ece4 ($52e6c4) ; Vcl.Controls.TControl.SetText
[...]
thread $1010:
7728f8da +0e ntdll.dll NtWaitForSingleObject
767c15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
764e118f +3e kernel32.dll WaitForSingleObjectEx
764e1143 +0d kernel32.dll WaitForSingleObject
764e3368 +10 kernel32.dll BaseThreadInitThunk
thread $12f0:
77290166 +0e ntdll.dll NtWaitForMultipleObjects
764e3368 +10 kernel32.dll BaseThreadInitThunk
thread $ddc:
77290166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
764e3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($e44) at:
73872713 +24f netbios.dll Netbios
thread $11f4:
7728f8da +0e ntdll.dll NtWaitForSingleObject
767c15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
764e118f +3e kernel32.dll WaitForSingleObjectEx
764e1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
764e3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($e44) at:
72bb4c95 +00 winspool.drv
thread $d9c:
77291f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
764e3368 +10 kernel32.dll BaseThreadInitThunk
modules:
001c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00280000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
003c0000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
025b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
06240000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6edb0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70230000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70860000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70870000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70880000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
708a0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70af0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70cb0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70d70000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70fb0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70ff0000 rooksbas.DLL 3.6.0.2 C:\Program
Files (x86)\Trusteer\Rapport\bin
71170000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71190000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
714d0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71520000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71580000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72090000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
720b0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72150000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72190000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72340000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72360000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72370000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72900000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72940000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
72a40000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
72aa0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72ba0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73870000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73880000 security.dll 6.1.7600.16385 C:\Windows\
system32
73a80000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73ab0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
73c30000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73c80000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73cb0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73ce0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73d20000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73d40000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73d50000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73d60000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73dc0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73e30000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73fd0000 version.dll 6.1.7600.16385 C:\Windows\
system32
73fe0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74b00000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74b10000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74b70000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
74b90000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
74c40000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
74da0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
74e00000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74e10000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
74f60000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75000000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75c50000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75c60000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75ea0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75eb0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f20000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75fc0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75ff0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76000000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76060000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76190000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76440000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
764c0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
764d0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
765e0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
766b0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
766c0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
766d0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
766f0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76700000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
767b0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76800000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
768f0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76a90000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76b30000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76b50000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76b90000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76c20000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76c30000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76c90000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76d90000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76de0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77240000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77270000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0290 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03e0 MsMpEng.exe 0 0 0
0148 RapportMgmtService.exe 0 0 0
0314 svchost.exe 0 0 0
0374 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
042c svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
0564 svchost.exe 0 0 0
0624 spoolsv.exe 0 0 0
062c taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
07e0 OSPPSVC.EXE 0 0 0
0578 svchost.exe 0 0 0
0428 scpbradserv.exe 0 0 0
05b4 core.exe 0 0 0
0984 RapportInjService_x64.exe 0 0 0
0a10 fbserver.exe 0 0 0
0bac WUDFHost.exe 0 0 0
08e4 NisSrv.exe 0 0 0
0c80 WmiPrvSE.exe 0 0 0
0cd8 svchost.exe 0 0 0
0db0 GoogleCrashHandler.exe 0 0 0
0888 GoogleCrashHandler64.exe 0 0 0
0948 SearchIndexer.exe 0 0 0
08fc taskhost.exe 1 26 23 normal
0df0 core.exe 1 9 21 normal
049c PresentationFontCache.exe 0 0 0
0878 dwm.exe 1 18 4 high
0170 explorer.exe 1 425 292 normal
0f60 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\scpbrad
0fe0 RapportService.exe 1 32 25 normal C:\Program Files (x86)\Trusteer\
Rapport\bin
00bc igfxEM.exe 1 14 13 normal
1004 igfxHK.exe 1 14 13 normal
1088 msseces.exe 1 143 59 normal
10c0 PrnStatusMX.exe 1 23 18 normal
125c RapportInjService_x64.exe 1 4 3 normal
11b0 wuauclt.exe 1 12 6 normal
0930 Store.exe 1 1611 451 normal C:\Program Files (x86)\Store
1144 splwow64.exe 1 9 3 normal
0f5c AcroRd32.exe 1 15 20 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader
0f90 AcroRd32.exe 1 260 134 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader
0bf4 RdrCEF.exe 1 9 23 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
1448 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
1480 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
1600 RdrCEF.exe 1 4 1 normal C:\Program Files (x86)\Adobe\
Acrobat Reader DC\Reader\AcroCEF
1338 OIS.EXE 1 88 38 normal
17dc OIS.EXE 1 88 38 normal
1118 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0c50 OIS.EXE 1 81 38 normal
1428 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0ccbbe70
ebx = 00003303
ecx = 00000000
edx = 002c2ac8
esi = 0018e864
edi = 0066cb50
eip = 0066ea6e
esp = 0018e828
ebp = 0018e890
stack dump:
0018e828 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e838 3c e8 18 00 6e ea 66 00 - 70 be cb 0c 03 33 00 00 <...n.f.p....3..
0018e848 64 e8 18 00 50 cb 66 00 - 90 e8 18 00 58 e8 18 00 d...P.f.....X...
0018e858 00 88 4b 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 ..K.z.f...g.....
0018e868 00 88 4b 04 00 00 00 00 - 9b e8 67 00 9c e8 18 00 ..K.......g.....
0018e878 0c 89 40 00 90 e8 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e888 d5 e9 67 01 00 88 4b 04 - b8 e8 18 00 f3 e8 67 00 ..g...K.......g.
0018e898 12 4d 67 00 d0 e8 18 00 - 0c 89 40 00 b8 e8 18 00 .Mg.......@.....
0018e8a8 00 88 4b 04 00 00 00 00 - 00 00 00 00 00 88 4b 04 ..K...........K.
0018e8b8 e4 e8 18 00 b6 92 67 00 - 00 00 00 00 38 5d 53 00 ......g.....8]S.
0018e8c8 01 00 00 00 e3 73 65 00 - f0 e8 18 00 0c 89 40 00 .....se.......@.
0018e8d8 e4 e8 18 00 60 a4 4f 06 - 00 88 4b 04 1c e9 18 00 ....`.O...K.....
0018e8e8 2a 72 65 00 7d d3 1b 01 - 34 e9 18 00 0c 89 40 00 *re.}...4.....@.
0018e8f8 1c e9 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e908 00 00 00 00 00 00 00 00 - 60 a4 4f 06 00 88 4b 04 ........`.O...K.
0018e918 d0 4a 29 05 60 e9 18 00 - 53 5d 53 00 10 eb 18 00 .J).`...S]S.....
0018e928 06 6a 53 00 10 eb 18 00 - 1f f9 54 00 40 e9 18 00 .jS.......T.@...
0018e938 eb 8a 40 00 60 e9 18 00 - e0 ea 18 00 0c 89 40 00 ..@.`.........@.
0018e948 60 e9 18 00 00 00 00 00 - 60 a4 4f 06 10 eb 18 00 `.......`.O.....
0018e958 00 00 00 00 60 a4 4f 06 - 8c ea 18 00 94 ff 52 00 ....`.O.......R.
disassembling:
[...]
011bd354 mov ecx, [ebp-$18]
011bd357 lea eax, [ebp-$14]
011bd35a mov edx, $11bd448
011bd35f call -$db2c24 ($40a740) ; System.@UStrCat3
011bd364 mov edx, [ebp-$14]
011bd367 mov eax, [ebp-8]
011bd36a mov eax, [eax+$250]
011bd370 mov ecx, [eax]
011bd372 call dword ptr [ecx+$38]
011bd375 734 mov eax, [ebp-8]
011bd378 > call -$b6615d ($657220) ; Data.DB.TDataSet.Open
011bd37d 735 mov eax, [ebp-8]
011bd380 cmp byte ptr [eax+$a8], 0
011bd387 jz loc_11bd3aa
011bd389 mov eax, [ebp-8]
011bd38c cmp byte ptr [eax+$a9], 0
011bd393 jz loc_11bd3aa
011bd395 736 mov edx, $11bd4b0
011bd39a mov eax, [ebp-4]
011bd39d mov eax, [eax+$3ec]
011bd3a3 call -$c8ece4 ($52e6c4) ; Vcl.Controls.TControl.SetText
[...]
thread $14a8:
77cef8da +0e ntdll.dll NtWaitForSingleObject
778715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f8118f +3e kernel32.dll WaitForSingleObjectEx
76f81143 +0d kernel32.dll WaitForSingleObject
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $1104:
77cf0166 +0e ntdll.dll NtWaitForMultipleObjects
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $b24:
77cef8da +0e ntdll.dll NtWaitForSingleObject
778715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f8118f +3e kernel32.dll WaitForSingleObjectEx
76f81143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76f83368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($165c) at:
74574c95 +00 winspool.drv
thread $1668:
77cf1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f83368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06240000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062b0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70be0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70ff0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71060000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
716a0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
717d0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71870000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71890000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71de0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71f60000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71fb0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72010000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72b00000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72b20000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72bc0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72c00000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72db0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72dd0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72de0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73bf0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73cf0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73e70000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74120000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74150000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
74550000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
74560000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
745f0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74610000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
74620000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
74650000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
74660000 security.dll 6.1.7600.16385 C:\Windows\
system32
74670000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
746a0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
746f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74720000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74750000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74790000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
747b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
747c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
747d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74830000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
748a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74a40000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a50000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75560000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75570000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75660000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75670000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75690000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75740000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
757c0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75890000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
759f0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76640000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76880000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76910000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ab0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76ac0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76b50000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76cb0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76d50000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76e80000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76ea0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76eb0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ec0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76f70000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
77080000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77330000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
773d0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77430000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77530000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77540000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77570000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
775c0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77620000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77630000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
776a0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
776b0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
776c0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
776f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77840000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77850000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77860000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
778b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77ca0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77cd0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02d0 lsass.exe 0 0 0
02d8 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02d4 svchost.exe 0 0 0
0210 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0668 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07e8 OSPPSVC.EXE 0 0 0
05b4 svchost.exe 0 0 0
0698 scpbradserv.exe 0 0 0
0750 svchost.exe 0 0 0
0814 core.exe 0 0 0
0964 RapportInjService_x64.exe 0 0 0
0a04 fbserver.exe 0 0 0
0b08 taskhost.exe 1 26 23 normal
0b1c core.exe 1 9 22 normal
0b98 dwm.exe 1 18 4 high
0bb8 explorer.exe 1 521 308 normal
0ce0 PresentationFontCache.exe 0 0 0
0d30 WUDFHost.exe 0 0 0
0d68 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0da0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e40 msseces.exe 1 143 60 normal
0e64 PrnStatusMX.exe 1 23 18 normal
0d2c NisSrv.exe 0 0 0
0164 igfxEM.exe 1 14 14 normal
0204 igfxHK.exe 1 14 13 normal
0f94 SearchIndexer.exe 0 0 0
120c RapportInjService_x64.exe 1 4 3 normal
1134 svchost.exe 0 0 0
0f80 GoogleCrashHandler.exe 0 0 0
110c GoogleCrashHandler64.exe 0 0 0
12c0 WmiPrvSE.exe 0 0 0
0ab4 wuauclt.exe 1 12 6 normal
0cf4 OIS.EXE 1 91 44 normal
11b4 OIS.EXE 1 101 49 normal
0bfc OIS.EXE 1 100 49 normal
0de0 OIS.EXE 1 104 51 normal
1780 Store.exe 1 479 361 normal C:\Program Files (x86)\Store
13e0 splwow64.exe 1 9 3 normal
111c chrome.exe 1 26 54 normal
1730 chrome.exe 1 9 4 normal
0c9c chrome.exe 1 7 6 above normal
1160 chrome.exe 1 4 1 normal
147c chrome.exe 1 4 1 normal
1744 chrome.exe 1 4 1 normal
04f8 chrome.exe 1 4 1 idle
17c4 chrome.exe 1 4 3 normal
0470 audiodg.exe 0 0 0
1444 rundll32.exe 1 116 47 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a1a4fa8
ebx = 00003303
ecx = 00000000
edx = 026d2ac8
esi = 0018da4c
edi = 0066cb50
eip = 0066ea6e
esp = 0018da10
ebp = 0018da78
stack dump:
0018da10 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018da20 24 da 18 00 6e ea 66 00 - a8 4f 1a 0a 03 33 00 00 $...n.f..O...3..
0018da30 4c da 18 00 50 cb 66 00 - 78 da 18 00 40 da 18 00 L...P.f.x...@...
0018da40 30 34 44 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 04D.z.f...g.....
0018da50 30 34 44 06 00 00 00 00 - 9b e8 67 00 84 da 18 00 04D.......g.....
0018da60 0c 89 40 00 78 da 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018da70 d5 e9 67 01 30 34 44 06 - a0 da 18 00 f3 e8 67 00 ..g.04D.......g.
0018da80 12 4d 67 00 b8 da 18 00 - 0c 89 40 00 a0 da 18 00 .Mg.......@.....
0018da90 30 34 44 06 00 00 00 00 - 00 00 00 00 30 34 44 06 04D.........04D.
0018daa0 cc da 18 00 b6 92 67 00 - 00 00 00 00 38 5d 53 00 ......g.....8]S.
0018dab0 01 00 00 00 e3 73 65 00 - d8 da 18 00 0c 89 40 00 .....se.......@.
0018dac0 cc da 18 00 70 71 20 0a - 30 34 44 06 3c e0 18 00 ....pq .04D.<...
0018dad0 2a 72 65 00 ce c2 ed 00 - 44 e0 18 00 0c 89 40 00 *re.....D.....@.
0018dae0 3c e0 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 <...............
0018daf0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db00 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db10 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db20 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db30 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db40 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00edc29d push $edd4f8
00edc2a2 lea eax, [ebp-$4bc]
00edc2a8 mov edx, 3
00edc2ad call -$ad1aea ($40a7c8) ; System.@UStrCatN
00edc2b2 mov edx, [ebp-$4bc]
00edc2b8 mov eax, [ebp-$34]
00edc2bb mov eax, [eax+$250]
00edc2c1 mov ecx, [eax]
00edc2c3 call dword ptr [ecx+$38]
00edc2c6 4111 mov eax, [ebp-$34]
00edc2c9 > call -$8850ae ($657220) ; Data.DB.TDataSet.Open
00edc2ce 4113 mov eax, [$15bcdf0]
00edc2d3 mov eax, [eax]
00edc2d5 mov eax, [eax+$1710]
00edc2db cmp byte ptr [eax+$a9], 0
00edc2e2 jz loc_edc89e
00edc2e8 mov eax, [$15bcdf0]
00edc2ed mov eax, [eax]
00edc2ef mov eax, [eax+$1710]
00edc2f5 cmp byte ptr [eax+$a8], 0
00edc2fc jz loc_edc89e
[...]
thread $14a8:
77cef8da +0e ntdll.dll NtWaitForSingleObject
778715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f8118f +3e kernel32.dll WaitForSingleObjectEx
76f81143 +0d kernel32.dll WaitForSingleObject
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $1104:
77cf0166 +0e ntdll.dll NtWaitForMultipleObjects
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $b24:
77cef8da +0e ntdll.dll NtWaitForSingleObject
778715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f8118f +3e kernel32.dll WaitForSingleObjectEx
76f81143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76f83368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($165c) at:
74574c95 +00 winspool.drv
thread $1668:
77cf1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $8c0:
77cf1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $1364:
77cf1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f83368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06240000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062b0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70be0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70ff0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71060000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
716a0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
717d0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71870000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71890000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71de0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71f60000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71fb0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72010000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72b00000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72b20000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72bc0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72c00000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72db0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72dd0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72de0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73bf0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73cf0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73e70000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74120000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74150000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
74550000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
74560000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
745f0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74610000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
74620000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
74650000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
74660000 security.dll 6.1.7600.16385 C:\Windows\
system32
74670000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
746a0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
746f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74720000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74750000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74790000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
747b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
747c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
747d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74830000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
748a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74a40000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a50000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75560000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75570000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75660000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75670000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75690000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75740000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
757c0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75890000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75980000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
759f0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76640000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76880000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76910000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ab0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76ac0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76b50000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76cb0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76d50000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76e80000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76ea0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76eb0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ec0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76f70000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
77080000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77330000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
773d0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77430000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77530000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77540000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77570000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
775c0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77620000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77630000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
776a0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
776b0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
776c0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
776f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77840000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77850000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77860000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
778b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77ca0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77cd0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02d0 lsass.exe 0 0 0
02d8 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02d4 svchost.exe 0 0 0
0210 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0668 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07e8 OSPPSVC.EXE 0 0 0
05b4 svchost.exe 0 0 0
0698 scpbradserv.exe 0 0 0
0750 svchost.exe 0 0 0
0814 core.exe 0 0 0
0964 RapportInjService_x64.exe 0 0 0
0a04 fbserver.exe 0 0 0
0b08 taskhost.exe 1 26 23 normal
0b1c core.exe 1 9 22 normal
0b98 dwm.exe 1 18 4 high
0bb8 explorer.exe 1 509 309 normal
0ce0 PresentationFontCache.exe 0 0 0
0d30 WUDFHost.exe 0 0 0
0d68 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0da0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e40 msseces.exe 1 143 60 normal
0e64 PrnStatusMX.exe 1 23 18 normal
0d2c NisSrv.exe 0 0 0
0164 igfxEM.exe 1 14 14 normal
0204 igfxHK.exe 1 14 13 normal
0f94 SearchIndexer.exe 0 0 0
120c RapportInjService_x64.exe 1 4 3 normal
1134 svchost.exe 0 0 0
0f80 GoogleCrashHandler.exe 0 0 0
110c GoogleCrashHandler64.exe 0 0 0
12c0 WmiPrvSE.exe 0 0 0
0ab4 wuauclt.exe 1 12 6 normal
0cf4 OIS.EXE 1 91 44 normal
11b4 OIS.EXE 1 101 49 normal
0bfc OIS.EXE 1 100 49 normal
0de0 OIS.EXE 1 104 51 normal
1780 Store.exe 1 480 362 normal C:\Program Files (x86)\Store
13e0 splwow64.exe 1 9 3 normal
111c chrome.exe 1 26 54 normal
1730 chrome.exe 1 9 4 normal
0c9c chrome.exe 1 7 6 above normal
1160 chrome.exe 1 4 1 normal
147c chrome.exe 1 4 1 normal
1744 chrome.exe 1 4 1 normal
04f8 chrome.exe 1 4 1 idle
17c4 chrome.exe 1 4 3 normal
0470 audiodg.exe 0 0 0
1444 rundll32.exe 1 116 47 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a1a4fa8
ebx = 00003303
ecx = 00000000
edx = 026d2ac8
esi = 0018daec
edi = 0066cb50
eip = 0066ea6e
esp = 0018dab0
ebp = 0018db18
stack dump:
0018dab0 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018dac0 c4 da 18 00 6e ea 66 00 - a8 4f 1a 0a 03 33 00 00 ....n.f..O...3..
0018dad0 ec da 18 00 50 cb 66 00 - 18 db 18 00 e0 da 18 00 ....P.f.........
0018dae0 30 34 44 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 04D.z.f...g.....
0018daf0 30 34 44 06 00 00 00 00 - 9b e8 67 00 24 db 18 00 04D.......g.$...
0018db00 0c 89 40 00 18 db 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018db10 d5 e9 67 01 30 34 44 06 - 40 db 18 00 f3 e8 67 00 [email protected].
0018db20 12 4d 67 00 58 db 18 00 - 0c 89 40 00 40 db 18 00 .Mg.X.....@.@...
0018db30 30 34 44 06 00 00 00 00 - 00 00 00 00 30 34 44 06 04D.........04D.
0018db40 6c db 18 00 b6 92 67 00 - 00 00 00 00 38 5d 53 00 l.....g.....8]S.
0018db50 01 00 00 00 e3 73 65 00 - 78 db 18 00 0c 89 40 00 .....se.x.....@.
0018db60 6c db 18 00 70 71 20 0a - 30 34 44 06 dc e0 18 00 l...pq .04D.....
0018db70 2a 72 65 00 ce c2 ed 00 - e4 e0 18 00 0c 89 40 00 *re...........@.
0018db80 dc e0 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db90 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dba0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dbb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dbc0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dbd0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dbe0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00edc29d push $edd4f8
00edc2a2 lea eax, [ebp-$4bc]
00edc2a8 mov edx, 3
00edc2ad call -$ad1aea ($40a7c8) ; System.@UStrCatN
00edc2b2 mov edx, [ebp-$4bc]
00edc2b8 mov eax, [ebp-$34]
00edc2bb mov eax, [eax+$250]
00edc2c1 mov ecx, [eax]
00edc2c3 call dword ptr [ecx+$38]
00edc2c6 4111 mov eax, [ebp-$34]
00edc2c9 > call -$8850ae ($657220) ; Data.DB.TDataSet.Open
00edc2ce 4113 mov eax, [$15bcdf0]
00edc2d3 mov eax, [eax]
00edc2d5 mov eax, [eax+$1710]
00edc2db cmp byte ptr [eax+$a9], 0
00edc2e2 jz loc_edc89e
00edc2e8 mov eax, [$15bcdf0]
00edc2ed mov eax, [eax]
00edc2ef mov eax, [eax+$1710]
00edc2f5 cmp byte ptr [eax+$a8], 0
00edc2fc jz loc_edc89e
[...]
thread $14a8:
77cef8da +0e ntdll.dll NtWaitForSingleObject
778715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f8118f +3e kernel32.dll WaitForSingleObjectEx
76f81143 +0d kernel32.dll WaitForSingleObject
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $1104:
77cf0166 +0e ntdll.dll NtWaitForMultipleObjects
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $b24:
77cef8da +0e ntdll.dll NtWaitForSingleObject
778715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f8118f +3e kernel32.dll WaitForSingleObjectEx
76f81143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76f83368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($165c) at:
74574c95 +00 winspool.drv
thread $1668:
77cf1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $8c0:
77cf1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $1364:
77cf1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f83368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06240000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062b0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70be0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70ff0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71060000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
716a0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
717d0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71870000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71890000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71de0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71f60000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71fb0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72010000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72b00000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72b20000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72bc0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72c00000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72db0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72dd0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72de0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73bf0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73cf0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73e70000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74120000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74150000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
74550000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
74560000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
745f0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74610000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
74620000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
74650000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
74660000 security.dll 6.1.7600.16385 C:\Windows\
system32
74670000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
746a0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
746f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74720000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74750000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74790000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
747b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
747c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
747d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74830000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
748a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74a40000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a50000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75560000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75570000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75660000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75670000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75690000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75740000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
757c0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75890000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75980000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
759f0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76640000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76880000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76910000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ab0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76ac0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76b50000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76cb0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76d50000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76e80000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76ea0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76eb0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ec0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76f70000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
77080000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77330000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
773d0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77430000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77530000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77540000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77570000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
775c0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77620000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77630000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
776a0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
776b0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
776c0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
776f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77840000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77850000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77860000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
778b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77ca0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77cd0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02d0 lsass.exe 0 0 0
02d8 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02d4 svchost.exe 0 0 0
0210 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0668 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07e8 OSPPSVC.EXE 0 0 0
05b4 svchost.exe 0 0 0
0698 scpbradserv.exe 0 0 0
0750 svchost.exe 0 0 0
0814 core.exe 0 0 0
0964 RapportInjService_x64.exe 0 0 0
0a04 fbserver.exe 0 0 0
0b08 taskhost.exe 1 26 23 normal
0b1c core.exe 1 9 22 normal
0b98 dwm.exe 1 18 4 high
0bb8 explorer.exe 1 509 308 normal
0ce0 PresentationFontCache.exe 0 0 0
0d30 WUDFHost.exe 0 0 0
0d68 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0da0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e40 msseces.exe 1 143 60 normal
0e64 PrnStatusMX.exe 1 23 18 normal
0d2c NisSrv.exe 0 0 0
0164 igfxEM.exe 1 14 14 normal
0204 igfxHK.exe 1 14 13 normal
0f94 SearchIndexer.exe 0 0 0
120c RapportInjService_x64.exe 1 4 3 normal
1134 svchost.exe 0 0 0
0f80 GoogleCrashHandler.exe 0 0 0
110c GoogleCrashHandler64.exe 0 0 0
12c0 WmiPrvSE.exe 0 0 0
0ab4 wuauclt.exe 1 12 6 normal
0cf4 OIS.EXE 1 91 44 normal
11b4 OIS.EXE 1 101 49 normal
0bfc OIS.EXE 1 100 49 normal
0de0 OIS.EXE 1 104 51 normal
1780 Store.exe 1 479 363 normal C:\Program Files (x86)\Store
13e0 splwow64.exe 1 9 3 normal
111c chrome.exe 1 26 54 normal
1730 chrome.exe 1 9 4 normal
0c9c chrome.exe 1 7 6 above normal
1160 chrome.exe 1 4 1 normal
147c chrome.exe 1 4 1 normal
1744 chrome.exe 1 4 1 normal
04f8 chrome.exe 1 4 1 idle
17c4 chrome.exe 1 4 3 normal
0470 audiodg.exe 0 0 0
1444 rundll32.exe 1 116 46 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a1a4fa8
ebx = 00003303
ecx = 00000000
edx = 026d2ac8
esi = 0018decc
edi = 0066cb50
eip = 0066ea6e
esp = 0018de90
ebp = 0018def8
stack dump:
0018de90 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018dea0 a4 de 18 00 6e ea 66 00 - a8 4f 1a 0a 03 33 00 00 ....n.f..O...3..
0018deb0 cc de 18 00 50 cb 66 00 - f8 de 18 00 c0 de 18 00 ....P.f.........
0018dec0 30 34 44 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 04D.z.f...g.....
0018ded0 30 34 44 06 00 00 00 00 - 9b e8 67 00 04 df 18 00 04D.......g.....
0018dee0 0c 89 40 00 f8 de 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018def0 d5 e9 67 01 30 34 44 06 - 20 df 18 00 f3 e8 67 00 ..g.04D. .....g.
0018df00 12 4d 67 00 38 df 18 00 - 0c 89 40 00 20 df 18 00 .Mg.8.....@. ...
0018df10 30 34 44 06 00 00 00 00 - 00 00 00 00 30 34 44 06 04D.........04D.
0018df20 4c df 18 00 b6 92 67 00 - 00 00 00 00 38 5d 53 00 L.....g.....8]S.
0018df30 01 00 00 00 e3 73 65 00 - 58 df 18 00 0c 89 40 00 .....se.X.....@.
0018df40 4c df 18 00 70 71 20 0a - 30 34 44 06 bc e4 18 00 L...pq .04D.....
0018df50 2a 72 65 00 ce c2 ed 00 - c4 e4 18 00 0c 89 40 00 *re...........@.
0018df60 bc e4 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018df70 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018df80 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018df90 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dfa0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dfb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dfc0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00edc29d push $edd4f8
00edc2a2 lea eax, [ebp-$4bc]
00edc2a8 mov edx, 3
00edc2ad call -$ad1aea ($40a7c8) ; System.@UStrCatN
00edc2b2 mov edx, [ebp-$4bc]
00edc2b8 mov eax, [ebp-$34]
00edc2bb mov eax, [eax+$250]
00edc2c1 mov ecx, [eax]
00edc2c3 call dword ptr [ecx+$38]
00edc2c6 4111 mov eax, [ebp-$34]
00edc2c9 > call -$8850ae ($657220) ; Data.DB.TDataSet.Open
00edc2ce 4113 mov eax, [$15bcdf0]
00edc2d3 mov eax, [eax]
00edc2d5 mov eax, [eax+$1710]
00edc2db cmp byte ptr [eax+$a9], 0
00edc2e2 jz loc_edc89e
00edc2e8 mov eax, [$15bcdf0]
00edc2ed mov eax, [eax]
00edc2ef mov eax, [eax+$1710]
00edc2f5 cmp byte ptr [eax+$a8], 0
00edc2fc jz loc_edc89e
[...]
thread $14a8:
77cef8da +0e ntdll.dll NtWaitForSingleObject
778715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f8118f +3e kernel32.dll WaitForSingleObjectEx
76f81143 +0d kernel32.dll WaitForSingleObject
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $1104:
77cf0166 +0e ntdll.dll NtWaitForMultipleObjects
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $b24:
77cef8da +0e ntdll.dll NtWaitForSingleObject
778715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f8118f +3e kernel32.dll WaitForSingleObjectEx
76f81143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76f83368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($165c) at:
74574c95 +00 winspool.drv
thread $101c:
77cf1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f83368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06240000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062b0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70be0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70ff0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71060000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
716a0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
717d0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71870000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71890000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71de0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71f60000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71fb0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72010000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72b00000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72b20000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72bc0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72c00000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72db0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72dd0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72de0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73bf0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73cf0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73e70000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74120000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74150000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
74550000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
74560000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
745f0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74610000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
74620000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
74650000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
74660000 security.dll 6.1.7600.16385 C:\Windows\
system32
74670000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
746a0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
746f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74720000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74750000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74790000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
747b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
747c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
747d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74830000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
748a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74a40000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a50000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75560000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75570000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75660000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75670000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75690000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75740000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
757c0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75890000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75980000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
759f0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76640000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76880000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76910000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ab0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76ac0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76b50000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76cb0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76d50000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76e80000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76ea0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76eb0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ec0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76f70000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
77080000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77330000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
773d0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77430000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77530000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77540000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77570000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
775c0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77620000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77630000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
776a0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
776b0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
776c0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
776f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77840000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77850000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77860000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
778b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77ca0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77cd0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02d0 lsass.exe 0 0 0
02d8 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02d4 svchost.exe 0 0 0
0210 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0668 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07e8 OSPPSVC.EXE 0 0 0
05b4 svchost.exe 0 0 0
0698 scpbradserv.exe 0 0 0
0750 svchost.exe 0 0 0
0814 core.exe 0 0 0
0964 RapportInjService_x64.exe 0 0 0
0a04 fbserver.exe 0 0 0
0b08 taskhost.exe 1 26 23 normal
0b1c core.exe 1 9 22 normal
0b98 dwm.exe 1 18 4 high
0bb8 explorer.exe 1 489 308 normal
0ce0 PresentationFontCache.exe 0 0 0
0d30 WUDFHost.exe 0 0 0
0d68 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0da0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e40 msseces.exe 1 143 60 normal
0e64 PrnStatusMX.exe 1 23 18 normal
0d2c NisSrv.exe 0 0 0
0164 igfxEM.exe 1 14 14 normal
0204 igfxHK.exe 1 14 13 normal
0f94 SearchIndexer.exe 0 0 0
120c RapportInjService_x64.exe 1 4 3 normal
1134 svchost.exe 0 0 0
0f80 GoogleCrashHandler.exe 0 0 0
110c GoogleCrashHandler64.exe 0 0 0
12c0 WmiPrvSE.exe 0 0 0
0ab4 wuauclt.exe 1 12 6 normal
0cf4 OIS.EXE 1 91 44 normal
11b4 OIS.EXE 1 101 49 normal
0bfc OIS.EXE 1 100 49 normal
0de0 OIS.EXE 1 104 51 normal
1780 Store.exe 1 771 346 normal C:\Program Files (x86)\Store
13e0 splwow64.exe 1 9 3 normal
111c chrome.exe 1 26 54 normal
1730 chrome.exe 1 9 4 normal
0c9c chrome.exe 1 7 6 above normal
1160 chrome.exe 1 4 1 normal
147c chrome.exe 1 4 1 normal
1744 chrome.exe 1 4 1 idle
04f8 chrome.exe 1 4 1 idle
17c4 chrome.exe 1 4 3 normal
0470 audiodg.exe 0 0 0
0324 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
044c rundll32.exe 1 116 45 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 0018df01
ecx = 00700398
edx = 0018df01
esi = 00593bec
edi = 04513880
eip = 00705bfa
esp = 0018dcbc
ebp = 0018dce4
stack dump:
0018dcbc 67 58 70 00 60 de 18 00 - ec 3b 59 00 d0 fb 3f 06 gXp.`....;Y...?.
0018dccc f7 75 40 00 a8 30 6f 00 - e2 30 6f 00 e0 fe 21 05 [email protected]...!.
0018dcdc 10 39 4a 04 30 63 49 04 - 54 de 18 00 d4 a3 6f 00 .9J.0cI.T.....o.
0018dcec ec 3b 59 00 10 1a 1c 0a - ed 04 53 00 10 1a 1c 0a .;Y.......S.....
0018dcfc f1 3b 59 00 96 09 53 00 - 13 00 14 00 13 00 00 00 .;Y...S.........
0018dd0c 14 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
0018dd1c 16 00 00 00 13 00 14 00 - 10 1a 1c 0a 60 de 18 00 ............`...
0018dd2c 94 ff 52 00 13 00 14 00 - 5c df 18 00 10 1a 1c 0a ..R.....\.......
0018dd3c 10 1a 1c 0a cc 01 00 00 - 14 00 00 00 00 00 00 00 ................
0018dd4c c8 dd 18 00 1f b0 b2 72 - b8 85 1e 06 5c 02 2d 00 .......r....\.-.
0018dd5c 02 02 00 00 0f 00 00 00 - cc 01 14 00 00 00 00 00 ................
0018dd6c bb 80 b2 72 8e 81 b2 72 - 50 26 4a 04 cc 01 14 00 ...r...rP&J.....
0018dd7c 5c 02 2d 00 00 00 00 00 - 50 26 4a 04 cf fb 52 00 \.-.....P&J...R.
0018dd8c 90 80 21 05 40 b0 00 00 - 00 00 00 00 90 80 21 05 ..!.@.........!.
0018dd9c 00 00 00 00 00 00 00 00 - bb 80 b2 72 01 00 00 00 ...........r....
0018ddac 44 de 18 00 00 00 00 00 - 28 de 18 00 00 00 00 00 D.......(.......
0018ddbc e2 0f 05 04 40 b0 00 00 - 30 c7 81 e1 f4 dd 18 00 [email protected].......
0018ddcc fa 62 44 77 5c 02 2d 00 - 02 02 00 00 00 00 00 00 .bDw\.-.........
0018dddc cc 01 14 00 bb 80 b2 72 - cd ab ba dc 00 00 00 00 .......r........
0018ddec 00 00 00 00 0c de 18 00 - cf fb 52 00 10 1a 1c 0a ..........R.....
disassembling:
00705bf4 public QRPrntr.TQRPrinter.GetUseStandardPrinter: ; function entry
point
00705bf4 3462 mov eax, [eax+$b8]
00705bfa > movzx eax, byte ptr [eax+$22]
00705bfe 3463 ret
thread $14a8:
77cef8da +0e ntdll.dll NtWaitForSingleObject
778715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f8118f +3e kernel32.dll WaitForSingleObjectEx
76f81143 +0d kernel32.dll WaitForSingleObject
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $1104:
77cf0166 +0e ntdll.dll NtWaitForMultipleObjects
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $b24:
77cef8da +0e ntdll.dll NtWaitForSingleObject
778715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f8118f +3e kernel32.dll WaitForSingleObjectEx
76f81143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76f83368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($165c) at:
74574c95 +00 winspool.drv
thread $1294:
77cf1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $1204:
77cf1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f83368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06240000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062b0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70be0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70ff0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71060000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
716a0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
717d0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71870000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71890000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71de0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71f60000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71fb0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72010000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72b00000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72b20000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72bc0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72c00000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72db0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72dd0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72de0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73bf0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73cf0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73e70000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74120000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74150000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
74550000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
74560000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
745f0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74610000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
74620000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
74650000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
74660000 security.dll 6.1.7600.16385 C:\Windows\
system32
74670000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
746a0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
746f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74720000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74750000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74790000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
747b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
747c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
747d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74830000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
748a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74a40000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a50000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75560000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75570000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75660000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75670000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75690000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75740000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
757c0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75890000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75980000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
759f0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76640000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76880000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76910000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ab0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76ac0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76b50000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76cb0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76d50000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76e80000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76ea0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76eb0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ec0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76f70000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
77080000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77330000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
773d0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77430000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77530000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77540000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77570000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
775c0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77620000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77630000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
776a0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
776b0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
776c0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
776f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77840000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77850000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77860000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
778b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77ca0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77cd0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02d0 lsass.exe 0 0 0
02d8 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02d4 svchost.exe 0 0 0
0210 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0668 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07e8 OSPPSVC.EXE 0 0 0
05b4 svchost.exe 0 0 0
0698 scpbradserv.exe 0 0 0
0750 svchost.exe 0 0 0
0814 core.exe 0 0 0
0964 RapportInjService_x64.exe 0 0 0
0a04 fbserver.exe 0 0 0
0b08 taskhost.exe 1 26 23 normal
0b1c core.exe 1 9 22 normal
0b98 dwm.exe 1 18 4 high
0bb8 explorer.exe 1 487 308 normal
0ce0 PresentationFontCache.exe 0 0 0
0d30 WUDFHost.exe 0 0 0
0d68 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0da0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e40 msseces.exe 1 143 60 normal
0e64 PrnStatusMX.exe 1 23 18 normal
0d2c NisSrv.exe 0 0 0
0164 igfxEM.exe 1 14 14 normal
0204 igfxHK.exe 1 14 13 normal
0f94 SearchIndexer.exe 0 0 0
120c RapportInjService_x64.exe 1 4 3 normal
1134 svchost.exe 0 0 0
0f80 GoogleCrashHandler.exe 0 0 0
110c GoogleCrashHandler64.exe 0 0 0
12c0 WmiPrvSE.exe 0 0 0
0ab4 wuauclt.exe 1 12 6 normal
0cf4 OIS.EXE 1 91 44 normal
11b4 OIS.EXE 1 101 49 normal
0bfc OIS.EXE 1 100 49 normal
0de0 OIS.EXE 1 104 51 normal
1780 Store.exe 1 768 345 normal C:\Program Files (x86)\Store
13e0 splwow64.exe 1 9 3 normal
111c chrome.exe 1 26 54 normal
1730 chrome.exe 1 9 4 normal
0c9c chrome.exe 1 7 6 above normal
1160 chrome.exe 1 4 1 normal
147c chrome.exe 1 4 1 normal
1744 chrome.exe 1 4 1 idle
04f8 chrome.exe 1 4 1 idle
17c4 chrome.exe 1 4 3 normal
0470 audiodg.exe 0 0 0
0324 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 04513880
ebx = 77440100
ecx = 00000000
edx = 04504701
esi = 04496330
edi = 0018e36c
eip = 004075f4
esp = 0018e0c0
ebp = 0018e130
stack dump:
0018e0c0 f5 1d 6f 00 30 63 49 04 - 01 01 44 77 53 55 6f 00 ..o.0cI...DwSUo.
0018e0d0 10 93 1f 0a 10 93 1f 0a - f7 75 40 00 87 fa e9 00 .........u@.....
0018e0e0 38 e1 18 00 0c 89 40 00 - 30 e1 18 00 00 00 00 00 [email protected].......
0018e0f0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e100 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e110 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e120 00 00 00 00 00 00 00 00 - 80 82 1d 0a 10 3e 49 04 .............>I.
0018e130 b4 e1 18 00 09 92 e9 00 - 1c e5 18 00 0c 89 40 00 ..............@.
0018e140 b4 e1 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e150 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e160 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e170 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e180 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e190 10 93 1f 0a 20 7f 54 04 - c0 81 54 04 60 84 54 04 .... .T...T.`.T.
0018e1a0 60 99 54 04 80 67 54 04 - c0 6c 54 04 20 6a 54 04 `.T..gT..lT. jT.
0018e1b0 10 3e 49 04 04 e3 18 00 - ed 04 53 00 10 93 1f 0a .>I.......S.....
0018e1c0 33 35 55 00 6c e3 18 00 - 62 44 62 00 b8 43 62 00 35U.l...bDb..Cb.
0018e1d0 6c e3 18 00 61 40 55 00 - 10 93 1f 0a 94 ff 52 00 [email protected].
0018e1e0 6c e3 18 00 4c e5 18 00 - 10 93 1f 0a f3 00 00 00 l...L...........
0018e1f0 05 8b 46 77 68 74 44 77 - b3 0f 01 7b 3b 00 00 00 ..FwhtDw...{;...
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $14a8:
77cef8da +0e ntdll.dll NtWaitForSingleObject
778715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f8118f +3e kernel32.dll WaitForSingleObjectEx
76f81143 +0d kernel32.dll WaitForSingleObject
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $1104:
77cf0166 +0e ntdll.dll NtWaitForMultipleObjects
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $b24:
77cef8da +0e ntdll.dll NtWaitForSingleObject
778715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f8118f +3e kernel32.dll WaitForSingleObjectEx
76f81143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76f83368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($165c) at:
74574c95 +00 winspool.drv
thread $1294:
77cf1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $1204:
77cf1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f83368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06240000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062b0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70be0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70ff0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71060000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
716a0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
717d0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71870000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71890000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71de0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71f60000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71fb0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72010000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72b00000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72b20000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72bc0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72c00000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72db0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72dd0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72de0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73bf0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73cf0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73e70000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74120000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74150000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
74550000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
74560000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
745f0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74610000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
74620000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
74650000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
74660000 security.dll 6.1.7600.16385 C:\Windows\
system32
74670000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
746a0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
746f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74720000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74750000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74790000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
747b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
747c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
747d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74830000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
748a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74a40000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a50000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75560000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75570000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75660000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75670000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75690000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75740000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
757c0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75890000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75980000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
759f0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76640000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76880000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76910000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ab0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76ac0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76b50000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76cb0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76d50000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76e80000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76ea0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76eb0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ec0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76f70000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
77080000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77330000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
773d0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77430000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77530000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77540000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77570000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
775c0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77620000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77630000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
776a0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
776b0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
776c0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
776f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77840000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77850000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77860000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
778b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77ca0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77cd0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02d0 lsass.exe 0 0 0
02d8 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02d4 svchost.exe 0 0 0
0210 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0668 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07e8 OSPPSVC.EXE 0 0 0
05b4 svchost.exe 0 0 0
0698 scpbradserv.exe 0 0 0
0750 svchost.exe 0 0 0
0814 core.exe 0 0 0
0964 RapportInjService_x64.exe 0 0 0
0a04 fbserver.exe 0 0 0
0b08 taskhost.exe 1 26 24 normal
0b1c core.exe 1 9 22 normal
0b98 dwm.exe 1 18 4 high
0bb8 explorer.exe 1 487 308 normal
0ce0 PresentationFontCache.exe 0 0 0
0d30 WUDFHost.exe 0 0 0
0d68 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0da0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e40 msseces.exe 1 143 60 normal
0e64 PrnStatusMX.exe 1 23 18 normal
0d2c NisSrv.exe 0 0 0
0164 igfxEM.exe 1 14 14 normal
0204 igfxHK.exe 1 14 13 normal
0f94 SearchIndexer.exe 0 0 0
120c RapportInjService_x64.exe 1 4 3 normal
1134 svchost.exe 0 0 0
0f80 GoogleCrashHandler.exe 0 0 0
110c GoogleCrashHandler64.exe 0 0 0
12c0 WmiPrvSE.exe 0 0 0
0ab4 wuauclt.exe 1 12 6 normal
0cf4 OIS.EXE 1 91 44 normal
11b4 OIS.EXE 1 101 49 normal
0bfc OIS.EXE 1 100 49 normal
0de0 OIS.EXE 1 104 51 normal
1780 Store.exe 1 770 351 normal C:\Program Files (x86)\Store
13e0 splwow64.exe 1 9 2 normal
111c chrome.exe 1 26 54 normal
1730 chrome.exe 1 9 4 normal
0c9c chrome.exe 1 7 6 above normal
1160 chrome.exe 1 4 1 normal
147c chrome.exe 1 4 1 normal
1744 chrome.exe 1 4 1 idle
04f8 chrome.exe 1 4 1 idle
17c4 chrome.exe 1 4 3 normal
0470 audiodg.exe 0 0 0
0324 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 04513880
ebx = 04496330
ecx = 00000000
edx = 0018da01
esi = 04496330
edi = 00000000
eip = 004075f4
esp = 0018d8b8
ebp = 0018d9e8
stack dump:
0018d8b8 26 32 6f 00 6c da 18 00 - 94 ff 52 00 00 00 00 00 &2o.l.....R.....
0018d8c8 05 02 05 04 30 63 49 04 - 30 63 49 04 84 da 18 00 ....0cI.0cI.....
0018d8d8 94 ff 52 00 01 00 00 00 - 05 02 05 04 30 63 49 04 ..R.........0cI.
0018d8e8 a4 d8 18 00 01 00 00 00 - 20 db 18 00 b6 a6 4a 77 ........ .....Jw
0018d8f8 c3 60 dd 96 fe ff ff ff - 51 6d 44 77 3f 0d 45 77 .`......QmDw?.Ew
0018d908 00 00 00 00 30 2f 41 00 - 7a 05 0f 00 30 00 00 00 ....0/A.z...0...
0018d918 a4 0e 0a 57 01 00 00 00 - 00 00 00 00 00 00 00 00 ...W............
0018d928 30 00 00 00 30 63 49 04 - 68 99 6e 00 00 00 00 00 0...0cI.h.n.....
0018d938 58 d9 18 00 65 0d 45 77 - 30 2f 41 00 7a 05 0f 00 X...e.Ew0/A.z...
0018d948 30 00 00 00 a4 0e 0a 57 - 01 00 00 00 00 00 00 00 0......W........
0018d958 ac da 18 00 f1 49 53 00 - 30 2f 41 00 7a 05 0f 00 .....IS.0/A.z...
0018d968 30 00 00 00 a4 0e 0a 57 - 01 00 00 00 ac da 18 00 0......W........
0018d978 30 63 49 04 30 63 49 04 - 04 db 18 00 94 ff 52 00 0cI.0cI.......R.
0018d988 30 63 49 04 30 63 49 04 - 30 63 49 04 ef 47 d0 77 0cI.0cI.0cI..G.w
0018d998 01 00 00 00 00 00 40 00 - 00 00 00 00 00 00 00 00 ......@.........
0018d9a8 ac d9 18 00 2b d4 81 e1 - 64 da 18 00 44 aa 44 77 ....+...d...D.Dw
0018d9b8 00 00 01 00 1c da 18 00 - 00 00 00 00 00 00 00 46 ...............F
0018d9c8 2f 01 00 00 b2 00 00 00 - 1a 03 00 00 63 04 00 00 /...........c...
0018d9d8 0a 03 13 00 00 00 00 00 - 00 00 40 00 00 00 00 00 ..........@.....
0018d9e8 34 da 18 00 f4 48 53 00 - 05 02 05 04 30 63 49 04 4....HS.....0cI.
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $14a8:
77cef8da +0e ntdll.dll NtWaitForSingleObject
778715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f8118f +3e kernel32.dll WaitForSingleObjectEx
76f81143 +0d kernel32.dll WaitForSingleObject
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $1104:
77cf0166 +0e ntdll.dll NtWaitForMultipleObjects
76f83368 +10 kernel32.dll BaseThreadInitThunk
thread $b24:
77cef8da +0e ntdll.dll NtWaitForSingleObject
778715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76f8118f +3e kernel32.dll WaitForSingleObjectEx
76f81143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76f83368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($165c) at:
74574c95 +00 winspool.drv
thread $12d0:
77447908 +26 USER32.dll GetMessageW
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76f83368 +10 kernel32.dll BaseThreadInitThunk
>> created by thread $1674 at:
773e450f +00 SHLWAPI.dll
thread $740:
77cf1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76f83368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06240000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062b0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6e340000 ieframe.DLL 11.0.9600.18817 C:\Windows\
system32
6f060000 GrooveIntlResource.dll 14.0.6017.1000 C:\Program
Files (x86)\Microsoft Office\Office14\1046
6f8e0000 office.odf 14.0.7109.5000 C:\Program
Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures
6fd00000 GROOVEEX.DLL 14.0.7113.5005 C:\Program
Files (x86)\Microsoft Office\Office14
70be0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70e30000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
70eb0000 WindowsCodecs.dll 6.2.9200.21830 C:\Windows\
system32
70ff0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71060000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
712d0000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
713b0000 SearchFolder.dll 6.1.7601.17514 C:\Windows\
system32
71450000 ntshrui.dll 6.1.7601.17755 C:\Windows\
system32
716a0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
717d0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71870000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71890000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71de0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71f60000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71fb0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72010000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72b00000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72b20000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72bb0000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\
system32
72bc0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72c00000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72db0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72dd0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72de0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72f80000 SHDOCVW.dll 6.1.7601.23896 C:\Windows\
system32
72fb0000 StructuredQuery.dll 7.0.7601.23451 C:\Windows\
System32
73010000 MSVCP90.dll 9.0.30729.4940 C:\Windows\
WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_50916076bcb9a742
730a0000 MSVCR90.dll 9.0.30729.4940 C:\Windows\
WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_50916076bcb9a742
73150000 EhStorShell.dll 6.1.7600.16385 C:\Windows\
system32
73190000 tiptsf.dll 6.1.7601.18984 C:\Program
Files (x86)\Common Files\microsoft shared\ink
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
735c0000 thumbcache.dll 6.1.7601.17514 C:\Windows\
SysWOW64
73bf0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73cf0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73df0000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73e30000 XmlLite.dll 1.3.1001.0 C:\Windows\
system32
73e70000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
740b0000 api-ms-win-downlevel-shell32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
system32
74120000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74150000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
744e0000 mssprxy.dll 7.0.7601.23914 C:\Windows\
system32
744f0000 LINKINFO.dll 6.1.7600.16385 C:\Windows\
system32
74530000 slc.dll 6.1.7600.16385 C:\Windows\
system32
74540000 cscapi.dll 6.1.7601.17514 C:\Windows\
system32
74550000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
74560000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
745c0000 ATL90.DLL 9.0.30729.4148 C:\Windows\
WinSxS\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.4148_none_51ca66a2bbe76806
745f0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
74610000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
74620000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
74650000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
74660000 security.dll 6.1.7600.16385 C:\Windows\
system32
74670000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
746a0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
746f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74720000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74750000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74790000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
747b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
747c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
747d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74830000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
748a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74a40000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a50000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75560000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75570000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75660000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75670000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75690000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75740000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
757c0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75890000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75980000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
759f0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76640000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76880000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76910000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ab0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76ac0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76b50000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76cb0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76d50000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76e80000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76ea0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76eb0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ec0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76f70000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
77080000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77330000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
773d0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77430000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77530000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77540000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77570000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
775c0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77620000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77630000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
776a0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
776b0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
776c0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
776f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
77840000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
77850000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77860000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
778b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77ca0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
77cd0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02bc services.exe 0 0 0
02d0 lsass.exe 0 0 0
02d8 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02d4 svchost.exe 0 0 0
0210 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
049c svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
056c svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0668 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07e8 OSPPSVC.EXE 0 0 0
05b4 svchost.exe 0 0 0
0698 scpbradserv.exe 0 0 0
0750 svchost.exe 0 0 0
0814 core.exe 0 0 0
0964 RapportInjService_x64.exe 0 0 0
0a04 fbserver.exe 0 0 0
0b08 taskhost.exe 1 26 19 normal
0b1c core.exe 1 9 22 normal
0b98 dwm.exe 1 18 4 high
0bb8 explorer.exe 1 601 388 normal
0ce0 PresentationFontCache.exe 0 0 0
0d30 WUDFHost.exe 0 0 0
0d68 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0da0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e40 msseces.exe 1 143 60 normal
0e64 PrnStatusMX.exe 1 23 18 normal
0d2c NisSrv.exe 0 0 0
0164 igfxEM.exe 1 14 14 normal
0204 igfxHK.exe 1 14 13 normal
0f94 SearchIndexer.exe 0 0 0
120c RapportInjService_x64.exe 1 4 3 normal
1134 svchost.exe 0 0 0
0f80 GoogleCrashHandler.exe 0 0 0
110c GoogleCrashHandler64.exe 0 0 0
12c0 WmiPrvSE.exe 0 0 0
0ab4 wuauclt.exe 1 12 6 normal
0cf4 OIS.EXE 1 91 44 normal
11b4 OIS.EXE 1 101 49 normal
0bfc OIS.EXE 1 100 49 normal
0de0 OIS.EXE 1 104 51 normal
1780 Store.exe 1 2097 221 normal C:\Program Files (x86)\Store
13e0 splwow64.exe 1 9 3 normal
0324 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
158c OIS.EXE 1 101 49 normal
0fc8 OIS.EXE 1 107 50 normal
0fcc Store.exe 1 191 184 normal C:\Program Files (x86)\Store
083c OIS.EXE 1 81 37 normal
113c OIS.EXE 1 109 41 normal
1488 chrome.exe 1 22 54 normal
174c chrome.exe 1 9 4 normal
0f64 chrome.exe 1 7 6 above normal
13fc chrome.exe 1 4 1 normal
0e88 chrome.exe 1 4 1 normal
1600 chrome.exe 1 4 1 normal
0da8 chrome.exe 1 4 1 idle
1734 chrome.exe 1 4 3 normal
0e90 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a8316e0
ebx = 00474300
ecx = 00000001
edx = c7010f01
esi = 04496330
edi = 04496330
eip = 004075f4
esp = 0018fef0
ebp = 0018ff40
stack dump:
0018fef0 8e 1d 6f 00 30 63 49 04 - 01 43 47 00 53 55 6f 00 ..o.0cI..CG.SUo.
0018ff00 60 f4 a5 05 02 00 00 00 - a9 1c 53 00 00 56 42 06 `.........S..VB.
0018ff10 f8 a1 57 04 60 f4 a5 05 - 00 00 00 00 98 a0 60 00 ..W.`.........`.
0018ff20 60 f4 a5 05 50 e0 53 04 - 72 b2 60 00 78 ff 18 00 `...P.S.r.`.x...
0018ff30 0c 89 40 00 40 ff 18 00 - f8 a1 57 01 60 f4 a5 05 ..@[email protected].`...
0018ff40 88 ff 18 00 56 04 49 00 - 54 e0 5b 01 18 0b 5c 01 ....V.I.T.[...\.
0018ff50 34 8e 60 00 6e 8e 60 00 - d4 1e 45 00 ac 1e 45 00 4.`.n.`...E...E.
0018ff60 af 90 40 00 88 ff 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018ff70 00 e0 fd 7e 14 20 59 01 - c4 ff 18 00 dc 8b 40 00 ...~. Y.......@.
0018ff80 88 ff 18 00 00 00 00 00 - 94 ff 18 00 6a 33 f8 76 ............j3.v
0018ff90 00 e0 fd 7e d4 ff 18 00 - f2 98 d0 77 00 e0 fd 7e ...~.......w...~
0018ffa0 ac 48 d6 76 00 00 00 00 - 00 00 00 00 00 e0 fd 7e .H.v...........~
0018ffb0 00 00 00 00 b9 6c b2 77 - 00 00 00 00 a0 ff 18 00 .....l.w........
0018ffc0 00 00 00 00 ff ff ff ff - 45 58 d4 77 58 71 01 01 ........EX.wXq..
0018ffd0 00 00 00 00 ec ff 18 00 - c5 98 d0 77 44 1f 59 01 ...........wD.Y.
0018ffe0 00 e0 fd 7e 00 00 00 00 - 00 00 00 00 00 00 00 00 ...~............
0018fff0 00 00 00 00 44 1f 59 01 - 00 e0 fd 7e 00 00 00 00 ....D.Y....~....
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $13b0:
771df8da +0e ntdll.dll NtWaitForSingleObject
755615c8 +92 KERNELBASE.dll WaitForSingleObjectEx
74ad118f +3e kernel32.dll WaitForSingleObjectEx
74ad1143 +0d kernel32.dll WaitForSingleObject
74ad3368 +10 kernel32.dll BaseThreadInitThunk
thread $13b4:
771e0166 +0e ntdll.dll NtWaitForMultipleObjects
74ad3368 +10 kernel32.dll BaseThreadInitThunk
thread $13c0:
771e0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
74ad3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13a4) at:
737e2713 +24f netbios.dll Netbios
thread $1228:
771df8da +0e ntdll.dll NtWaitForSingleObject
755615c8 +92 KERNELBASE.dll WaitForSingleObjectEx
74ad118f +3e kernel32.dll WaitForSingleObjectEx
74ad1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
74ad3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13a4) at:
73974c95 +00 winspool.drv
thread $f10:
771e1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
74ad3368 +10 kernel32.dll BaseThreadInitThunk
thread $dc8:
771e1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
74ad3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00330000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
044c0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6e4c0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
707b0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
707c0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
707e0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
707f0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70810000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
708c0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70c20000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70ce0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70d20000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
70f30000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70f70000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
712d0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71450000 webio.dll 6.1.7601.23375 C:\Windows\
system32
714a0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71500000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71ff0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72010000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
720b0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
720f0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
722a0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
722c0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
722d0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
725a0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
72980000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
737b0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
737e0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
737f0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73800000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73860000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73960000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73ac0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73b90000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73be0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73c10000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73c40000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73c80000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73ca0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73cb0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73cc0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73d20000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73d90000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73f30000 version.dll 6.1.7600.16385 C:\Windows\
system32
73f40000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74a50000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74a60000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74ac0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
74bd0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74c50000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
74ce0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
74de0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
74e00000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
74eb0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75000000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75030000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
750b0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
750c0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750e0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75110000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
752b0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75310000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75320000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75530000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75540000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75550000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75600000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75620000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75630000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75670000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75700000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75710000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
757b0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76400000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76530000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76770000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76780000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76790000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
767a0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76870000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76910000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76a00000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76d40000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76da0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77190000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
771c0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0344 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0524 igfxCUIService.exe 0 0 0
0578 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
066c svchost.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
0760 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
079c NetExpressUpdater.exe 0 0 0
07ec OSPPSVC.EXE 0 0 0
058c svchost.exe 0 0 0
0424 scpbradserv.exe 0 0 0
0808 core.exe 0 0 0
0968 RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0bc0 WUDFHost.exe 0 0 0
0980 NisSrv.exe 0 0 0
0fc4 WmiPrvSE.exe 0 0 0
0cfc svchost.exe 0 0 0
071c GoogleCrashHandler.exe 0 0 0
0d90 GoogleCrashHandler64.exe 0 0 0
0ddc SearchIndexer.exe 0 0 0
0644 taskhost.exe 1 26 22 normal
0f70 core.exe 1 9 20 normal
0de8 PresentationFontCache.exe 0 0 0
0298 dwm.exe 1 17 4 high
01a4 explorer.exe 1 451 271 normal
0dc4 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0ea8 igfxEM.exe 1 14 14 normal
0b64 igfxHK.exe 1 14 13 normal
0ea4 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
094c msseces.exe 1 143 60 normal
0d3c PrnStatusMX.exe 1 23 18 normal
1158 RapportInjService_x64.exe 1 4 3 normal
135c wuauclt.exe 1 12 6 normal
13a0 Store.exe 1 1481 373 normal C:\Program Files (x86)\Store
1390 splwow64.exe 1 9 4 normal
0db8 chrome.exe 1 73 57 normal
12d0 chrome.exe 1 9 4 normal
1204 chrome.exe 1 7 7 above normal
0820 chrome.exe 1 4 1 normal
10f4 chrome.exe 1 4 1 normal
15f4 armsvc.exe 0 0 0
1490 OIS.EXE 1 96 46 normal
15a0 chrome.exe 1 4 1 normal
14e8 chrome.exe 1 4 1 idle
15e4 chrome.exe 1 4 3 normal
1220 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0724 OIS.EXE 1 88 38 normal
1674 svchost.exe 0 0 0
149c audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 04478058
ebx = 00454e3a
ecx = 0044dba4
edx = 0018dffc
esi = 00454e3a
edi = 0ba599c0
eip = 00454e3a
esp = 0018e02c
ebp = 0018e074
stack dump:
0018e02c 3a 4e 45 00 de fa ed 0e - 01 00 00 00 07 00 00 00 :NE.............
0018e03c 40 e0 18 00 3a 4e 45 00 - 58 80 47 04 3a 4e 45 00 @...:NE.X.G.:NE.
0018e04c 3a 4e 45 00 c0 99 a5 0b - 74 e0 18 00 5c e0 18 00 :NE.....t...\...
0018e05c 02 00 00 00 f4 4c 40 00 - c0 99 a5 0b 00 00 00 00 .....L@.........
0018e06c 37 4d 40 00 10 aa 51 02 - d4 e0 18 00 3a 4e 45 00 [email protected].....:NE.
0018e07c af d4 52 00 49 67 61 00 - f4 01 02 00 21 00 00 00 ..R.Iga.....!...
0018e08c 90 3d 50 06 6c e3 18 00 - c0 99 a5 0b 00 00 00 00 .=P.l...........
0018e09c 11 1d 53 00 00 00 00 00 - 6c e3 18 00 c0 99 a5 0b ..S.....l.......
0018e0ac 00 00 00 00 98 a0 60 00 - f0 44 a2 0a f0 44 a2 0a ......`..D...D..
0018e0bc 72 b2 60 00 e0 e0 18 00 - 0c 89 40 00 d4 e0 18 00 r.`.......@.....
0018e0cc f0 44 a2 01 c0 99 a5 0b - 30 e1 18 00 f7 75 40 00 .D......0....u@.
0018e0dc 93 fa e9 00 38 e1 18 00 - 0c 89 40 00 30 e1 18 00 [email protected]...
0018e0ec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0fc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e10c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e11c 00 00 00 00 00 00 00 00 - 00 00 00 00 20 5e 3e 0a ............ ^>.
0018e12c d0 14 38 04 b4 e1 18 00 - 09 92 e9 00 1c e5 18 00 ..8.............
0018e13c 0c 89 40 00 b4 e1 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e14c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e15c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $13b0:
771df8da +0e ntdll.dll NtWaitForSingleObject
755615c8 +92 KERNELBASE.dll WaitForSingleObjectEx
74ad118f +3e kernel32.dll WaitForSingleObjectEx
74ad1143 +0d kernel32.dll WaitForSingleObject
74ad3368 +10 kernel32.dll BaseThreadInitThunk
thread $13b4:
771e0166 +0e ntdll.dll NtWaitForMultipleObjects
74ad3368 +10 kernel32.dll BaseThreadInitThunk
thread $13c0:
771e0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
74ad3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13a4) at:
737e2713 +24f netbios.dll Netbios
thread $1228:
771df8da +0e ntdll.dll NtWaitForSingleObject
755615c8 +92 KERNELBASE.dll WaitForSingleObjectEx
74ad118f +3e kernel32.dll WaitForSingleObjectEx
74ad1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
74ad3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13a4) at:
73974c95 +00 winspool.drv
thread $f10:
771e1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
74ad3368 +10 kernel32.dll BaseThreadInitThunk
thread $dc8:
771e1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
74ad3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00330000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
044c0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6e4c0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
707b0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
707c0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
707e0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
707f0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70810000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
708c0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70c20000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70ce0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70d20000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
70f30000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70f70000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
712d0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71450000 webio.dll 6.1.7601.23375 C:\Windows\
system32
714a0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71500000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71ff0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72010000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
720b0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
720f0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
722a0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
722c0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
722d0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
725a0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
72980000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
737b0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
737e0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
737f0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73800000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73860000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73960000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73ac0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73b90000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73be0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73c10000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73c40000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73c80000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73ca0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73cb0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73cc0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73d20000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73d90000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73f30000 version.dll 6.1.7600.16385 C:\Windows\
system32
73f40000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74a50000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74a60000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74ac0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
74bd0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74c50000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
74ce0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
74de0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
74e00000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
74eb0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75000000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75030000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
750b0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
750c0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750d0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
750e0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75110000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
752b0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75310000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75320000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75530000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75540000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75550000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75600000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75620000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75630000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75670000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75700000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75710000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
757b0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76400000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76530000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76770000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76780000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76790000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
767a0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76870000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76910000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76a00000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76d40000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76da0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77190000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
771c0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0344 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0524 igfxCUIService.exe 0 0 0
0578 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
066c svchost.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
0760 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
079c NetExpressUpdater.exe 0 0 0
07ec OSPPSVC.EXE 0 0 0
058c svchost.exe 0 0 0
0424 scpbradserv.exe 0 0 0
0808 core.exe 0 0 0
0968 RapportInjService_x64.exe 0 0 0
09fc fbserver.exe 0 0 0
0bc0 WUDFHost.exe 0 0 0
0980 NisSrv.exe 0 0 0
0fc4 WmiPrvSE.exe 0 0 0
0cfc svchost.exe 0 0 0
071c GoogleCrashHandler.exe 0 0 0
0d90 GoogleCrashHandler64.exe 0 0 0
0ddc SearchIndexer.exe 0 0 0
0644 taskhost.exe 1 26 23 normal
0f70 core.exe 1 9 20 normal
0de8 PresentationFontCache.exe 0 0 0
0298 dwm.exe 1 17 4 high
01a4 explorer.exe 1 431 270 normal
0dc4 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0ea8 igfxEM.exe 1 14 14 normal
0b64 igfxHK.exe 1 14 13 normal
0ea4 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
094c msseces.exe 1 143 60 normal
0d3c PrnStatusMX.exe 1 23 18 normal
1158 RapportInjService_x64.exe 1 4 3 normal
135c wuauclt.exe 1 12 6 normal
13a0 Store.exe 1 1479 354 normal C:\Program Files (x86)\Store
1390 splwow64.exe 1 9 4 normal
0db8 chrome.exe 1 73 57 normal
12d0 chrome.exe 1 9 4 normal
1204 chrome.exe 1 7 7 above normal
0820 chrome.exe 1 4 1 normal
10f4 chrome.exe 1 4 1 normal
15f4 armsvc.exe 0 0 0
1490 OIS.EXE 1 96 46 normal
15a0 chrome.exe 1 4 1 normal
14e8 chrome.exe 1 4 1 idle
15e4 chrome.exe 1 4 3 normal
1220 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0724 OIS.EXE 1 88 38 normal
1674 svchost.exe 0 0 0
149c audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0aa44550
ebx = 00000578
ecx = 00000000
edx = 02632ac8
esi = 0b1351e0
edi = 0b1351e0
eip = 0045d04d
esp = 0018ec38
ebp = 0018ec8c
stack dump:
0018ec38 4d d0 45 00 de fa ed 0e - 01 00 00 00 07 00 00 00 M.E.............
0018ec48 4c ec 18 00 4d d0 45 00 - 50 45 a4 0a 78 05 00 00 L...M.E.PE..x...
0018ec58 e0 51 13 0b e0 51 13 0b - 8c ec 18 00 68 ec 18 00 .Q...Q......h...
0018ec68 98 ec 18 00 0c 89 40 00 - 8c ec 18 00 01 43 47 00 [email protected].
0018ec78 00 00 00 00 78 05 00 00 - 00 af 40 00 9c 65 40 05 [email protected]@.
0018ec88 11 58 47 00 a8 ec 18 00 - d6 cf 45 00 fe 38 53 00 .XG.......E..8S.
0018ec98 f0 ec 18 00 0c 89 40 00 - a8 ec 18 00 e0 51 13 0b [email protected]..
0018eca8 04 ed 18 00 7e 1c 53 00 - 00 36 53 06 e0 51 13 0b ....~.S..6S..Q..
0018ecb8 e0 51 13 0b 01 43 47 00 - 99 ff 54 00 d0 14 38 04 .Q...CG...T...8.
0018ecc8 09 00 00 00 a9 1c 53 00 - 00 45 5a 06 0a 00 00 00 ......S..EZ.....
0018ecd8 d0 14 38 04 00 00 00 00 - 98 a0 60 00 18 3c 62 00 ..8.......`..<b.
0018ece8 70 41 48 0a 72 b2 60 00 - 10 ed 18 00 0c 89 40 00 pAH.r.`.......@.
0018ecf8 04 ed 18 00 20 c1 2a 01 - d0 14 38 04 38 ed 18 00 .... .*...8.8...
0018ed08 f7 75 40 00 43 7b 13 01 - 6c ef 18 00 0c 89 40 00 [email protected]{..l.....@.
0018ed18 38 ed 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 8...............
0018ed28 00 00 00 00 70 41 48 0a - 60 99 43 04 d0 2c 4d 06 ....pAH.`.C..,M.
0018ed38 5c ed 18 00 ed 04 53 00 - 70 41 48 0a 1d 3c 62 00 \.....S.pAH..<b.
0018ed48 07 3c 62 00 d8 ee 18 00 - 18 3b 62 00 70 41 48 0a .<b......;b.pAH.
0018ed58 01 00 00 00 cc ee 18 00 - 25 09 53 00 0a 00 00 00 ........%.S.....
0018ed68 03 00 00 00 00 00 00 00 - d8 ee 18 00 70 41 48 0a ............pAH.
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $1210:
7769f8da +0e ntdll.dll NtWaitForSingleObject
769d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76ff118f +3e kernel32.dll WaitForSingleObjectEx
76ff1143 +0d kernel32.dll WaitForSingleObject
76ff3368 +10 kernel32.dll BaseThreadInitThunk
thread $1228:
776a0166 +0e ntdll.dll NtWaitForMultipleObjects
76ff3368 +10 kernel32.dll BaseThreadInitThunk
thread $1230:
776a0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76ff3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d48) at:
73e42713 +24f netbios.dll Netbios
thread $15d4:
7769f8da +0e ntdll.dll NtWaitForSingleObject
769d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76ff118f +3e kernel32.dll WaitForSingleObjectEx
76ff1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76ff3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d48) at:
73fe4c95 +00 winspool.drv
thread $12b0:
776a1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76ff3368 +10 kernel32.dll BaseThreadInitThunk
thread $1200:
776a1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76ff3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06240000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06350000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70b70000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70c30000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
71060000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
710d0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71130000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
71390000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
713e0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71420000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71440000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71450000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71460000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71910000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71960000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
719c0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
724b0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
724d0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72570000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
725b0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72760000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72780000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72790000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73240000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
73250000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
73270000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
73280000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73a70000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73be0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73c60000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73da0000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73db0000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73dc0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73e10000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73e40000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73e50000 security.dll 6.1.7600.16385 C:\Windows\
system32
73e60000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73e70000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73ed0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73fd0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
74030000 slc.dll 6.1.7600.16385 C:\Windows\
system32
74050000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
740a0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
740d0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74100000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74140000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74160000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74170000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74180000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74190000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
741e0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74220000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74230000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
74250000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
743f0000 version.dll 6.1.7600.16385 C:\Windows\
system32
74400000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74f10000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74f20000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74f80000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75230000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
753d0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75520000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75550000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75580000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75590000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
755b0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
755c0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
755d0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
756d0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75730000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75820000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75830000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75870000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75900000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
765e0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76740000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
767a0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76850000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76900000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76910000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76920000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
769c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76a10000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76a20000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76a40000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76b10000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76ba0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76de0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76df0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76ea0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76eb0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76f00000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76f20000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76f40000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76fe0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
77150000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77650000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
77680000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
02b0 svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
0570 svchost.exe 0 0 0
0630 spoolsv.exe 0 0 0
0638 taskeng.exe 0 0 0
0670 svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
0760 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f0 OSPPSVC.EXE 0 0 0
05c0 svchost.exe 0 0 0
06c8 scpbradserv.exe 0 0 0
074c svchost.exe 0 0 0
0818 core.exe 0 0 0
0978 RapportInjService_x64.exe 0 0 0
0a30 fbserver.exe 0 0 0
0bd0 WUDFHost.exe 0 0 0
0c34 NisSrv.exe 0 0 0
0e44 taskhost.exe 1 26 22 normal
0e68 core.exe 1 9 21 normal
0ecc PresentationFontCache.exe 0 0 0
0f2c dwm.exe 1 17 4 high
0f3c explorer.exe 1 503 355 normal
0c94 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
093c RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0f20 igfxEM.exe 1 14 14 normal
0fd8 igfxHK.exe 1 14 12 normal
0dc0 msseces.exe 1 143 60 normal
0754 PrnStatusMX.exe 1 23 18 normal
0ffc WmiPrvSE.exe 0 0 0
0cdc GoogleCrashHandler.exe 0 0 0
0938 RapportInjService_x64.exe 1 4 3 normal
0180 GoogleCrashHandler64.exe 0 0 0
1068 SearchIndexer.exe 0 0 0
12f8 svchost.exe 0 0 0
0c20 Store.exe 1 3428 466 normal C:\Program Files (x86)\Store
1784 wuauclt.exe 1 12 6 normal
08b8 splwow64.exe 1 9 4 normal
14a0 chrome.exe 1 74 60 normal
15c4 chrome.exe 1 9 4 normal
0144 chrome.exe 1 7 6 above normal
13f4 chrome.exe 1 4 1 normal
15b8 chrome.exe 1 4 1 normal
1344 chrome.exe 1 4 1 normal
162c chrome.exe 1 4 1 idle
1350 chrome.exe 1 4 3 normal
11f0 Store.exe 1 272 211 normal C:\Program Files (x86)\Store
1724 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
127c audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0cde1568
ebx = 00003303
ecx = 00000000
edx = 026d2ac8
esi = 0018e70c
edi = 0066cb50
eip = 0066ea6e
esp = 0018e6d0
ebp = 0018e738
stack dump:
0018e6d0 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e6e0 e4 e6 18 00 6e ea 66 00 - 68 15 de 0c 03 33 00 00 ....n.f.h....3..
0018e6f0 0c e7 18 00 50 cb 66 00 - 38 e7 18 00 00 e7 18 00 ....P.f.8.......
0018e700 60 99 41 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 `.A.z.f...g.....
0018e710 60 99 41 04 00 00 00 00 - 9b e8 67 00 44 e7 18 00 `.A.......g.D...
0018e720 0c 89 40 00 38 e7 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018e730 d5 e9 67 01 60 99 41 04 - 60 e7 18 00 f3 e8 67 00 ..g.`.A.`.....g.
0018e740 12 4d 67 00 78 e7 18 00 - 0c 89 40 00 60 e7 18 00 .Mg.x.....@.`...
0018e750 60 99 41 04 00 00 00 00 - 00 00 00 00 60 99 41 04 `.A.........`.A.
0018e760 8c e7 18 00 b6 92 67 00 - 10 b6 cf 0a 00 00 00 00 ......g.........
0018e770 01 00 00 00 e3 73 65 00 - 98 e7 18 00 0c 89 40 00 .....se.......@.
0018e780 8c e7 18 00 b0 04 2f 0a - 60 99 41 04 68 e8 18 00 ....../.`.A.h...
0018e790 2a 72 65 00 91 91 15 01 - 7c e8 18 00 0c 89 40 00 *re.....|.....@.
0018e7a0 68 e8 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 h...............
0018e7b0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e7c0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e7d0 b0 04 2f 0a 00 00 00 00 - 00 00 00 00 00 00 00 00 ../.............
0018e7e0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e7f0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e800 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
01159160 push $115961c
01159165 lea eax, [ebp-$9c]
0115916b mov edx, 3
01159170 call -$d4e9ad ($40a7c8) ; System.@UStrCatN
01159175 mov edx, [ebp-$9c]
0115917b mov eax, [ebp-$1c]
0115917e mov eax, [eax+$250]
01159184 mov ecx, [eax]
01159186 call dword ptr [ecx+$38]
01159189 2870 mov eax, [ebp-$1c]
0115918c > call -$b01f71 ($657220) ; Data.DB.TDataSet.Open
01159191 2872 mov eax, [$15bcdf0]
01159196 mov eax, [eax]
01159198 mov eax, [eax+$27c]
0115919e mov edx, $1159630
011591a3 call -$b00c08 ($6585a0) ; Data.DB.TDataSet.FieldByName
011591a8 lea edx, [ebp-$a0]
011591ae mov ecx, [eax]
011591b0 call dword ptr [ecx+$80]
011591b6 mov eax, [ebp-$a0]
011591bc mov edx, $1159654
[...]
thread $1048:
7756f8da +0e ntdll.dll NtWaitForSingleObject
759d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75e7118f +3e kernel32.dll WaitForSingleObjectEx
75e71143 +0d kernel32.dll WaitForSingleObject
75e73368 +10 kernel32.dll BaseThreadInitThunk
thread $1264:
77570166 +0e ntdll.dll NtWaitForMultipleObjects
75e73368 +10 kernel32.dll BaseThreadInitThunk
thread $d84:
77570166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
75e73368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($10ec) at:
73d12713 +24f netbios.dll Netbios
thread $10e0:
7756f8da +0e ntdll.dll NtWaitForSingleObject
759d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75e7118f +3e kernel32.dll WaitForSingleObjectEx
75e71143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
75e73368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($10ec) at:
73ea4c95 +00 winspool.drv
thread $1034:
77571f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75e73368 +10 kernel32.dll BaseThreadInitThunk
thread $1444:
77571f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75e73368 +10 kernel32.dll BaseThreadInitThunk
thread $1714:
77571f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75e73368 +10 kernel32.dll BaseThreadInitThunk
thread $1688:
77571f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75e73368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00350000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00380000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
04280000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06300000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6ed30000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
707c0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70840000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70b90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70bb0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70bd0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70be0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70ca0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70f60000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
70fa0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71000000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71040000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
712b0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71430000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71440000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71450000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71490000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71a80000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71ad0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71b30000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72380000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
723a0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72440000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72480000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72630000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72650000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72660000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73920000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73b20000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73b80000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73d10000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73d20000 security.dll 6.1.7600.16385 C:\Windows\
system32
73d30000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73d90000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73e90000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73f00000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73f20000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73f70000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73fa0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73fd0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74010000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74030000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74040000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74050000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74060000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
740b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
740f0000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74100000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
74120000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
742c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
742d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74de0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74df0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74e50000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
74e90000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74ea0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75150000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
751e0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
751f0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75320000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75380000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75430000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75440000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75450000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75550000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75560000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75600000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75620000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75860000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75870000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
758a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75900000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75910000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
759c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75a10000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75b70000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b80000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75cd0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75da0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75db0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75e60000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75fd0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76010000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76020000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76050000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
760a0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76240000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
762c0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76350000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76fa0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
77090000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
77130000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77520000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77550000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02cc svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0410 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0760 fbguard.exe 0 0 0
0788 svchost.exe 0 0 0
07a0 NetExpressUpdater.exe 0 0 0
07f4 OSPPSVC.EXE 0 0 0
05bc svchost.exe 0 0 0
0434 scpbradserv.exe 0 0 0
0710 svchost.exe 0 0 0
0808 core.exe 0 0 0
0980 RapportInjService_x64.exe 0 0 0
09f4 fbserver.exe 0 0 0
0b70 WUDFHost.exe 0 0 0
05dc NisSrv.exe 0 0 0
0efc WmiPrvSE.exe 0 0 0
0fe0 svchost.exe 0 0 0
0d38 GoogleCrashHandler.exe 0 0 0
0c34 GoogleCrashHandler64.exe 0 0 0
0614 SearchIndexer.exe 0 0 0
0c0c taskhost.exe 1 26 24 normal
0ebc core.exe 1 9 22 normal
0fa8 PresentationFontCache.exe 0 0 0
0298 dwm.exe 1 17 4 high
0674 explorer.exe 1 465 253 normal
0e20 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0e38 igfxEM.exe 1 14 14 normal
0e30 igfxHK.exe 1 14 13 normal
0534 msseces.exe 1 143 60 normal
0e1c RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e28 PrnStatusMX.exe 1 23 18 normal
10c4 RapportInjService_x64.exe 1 4 3 normal
11f4 wuauclt.exe 1 12 6 normal
03e4 Store.exe 1 938 268 normal C:\Program Files (x86)\Store
103c splwow64.exe 1 9 3 normal
0cec chrome.exe 1 74 59 normal
0f5c chrome.exe 1 9 4 normal
0474 chrome.exe 1 8 8 above normal
0724 chrome.exe 1 4 1 normal
0178 chrome.exe 1 4 1 normal
1288 chrome.exe 1 4 1 idle
0678 chrome.exe 1 4 1 idle
1198 chrome.exe 1 4 3 normal
1294 OIS.EXE 1 111 50 normal
0c10 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
0a2c OIS.EXE 1 101 50 normal
0eb4 audiodg.exe 0 0 0
1020 OIS.EXE 1 130 111 normal
1370 EXCEL.EXE 1 339 112 normal
105c WMIC.exe 0 0 0
0300 conhost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 05e19b20
ebx = 00003303
ecx = 00000000
edx = 02982ac8
esi = 0018ec90
edi = 0066cb50
eip = 0066ea6e
esp = 0018ec54
ebp = 0018ecbc
stack dump:
0018ec54 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018ec64 68 ec 18 00 6e ea 66 00 - 20 9b e1 05 03 33 00 00 h...n.f. ....3..
0018ec74 90 ec 18 00 50 cb 66 00 - bc ec 18 00 84 ec 18 00 ....P.f.........
0018ec84 30 25 56 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 0%V.z.f...g.....
0018ec94 30 25 56 04 00 00 00 00 - 9b e8 67 00 c8 ec 18 00 0%V.......g.....
0018eca4 0c 89 40 00 bc ec 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018ecb4 d5 e9 67 01 30 25 56 04 - e4 ec 18 00 f3 e8 67 00 ..g.0%V.......g.
0018ecc4 12 4d 67 00 fc ec 18 00 - 0c 89 40 00 e4 ec 18 00 .Mg.......@.....
0018ecd4 30 25 56 04 00 00 00 00 - 00 00 00 00 30 25 56 04 0%V.........0%V.
0018ece4 10 ed 18 00 b6 92 67 00 - 0c 00 00 00 18 3c 62 00 ......g......<b.
0018ecf4 01 00 00 00 e3 73 65 00 - 1c ed 18 00 0c 89 40 00 .....se.......@.
0018ed04 10 ed 18 00 50 f3 a2 0b - 30 25 56 04 38 ed 18 00 ....P...0%V.8...
0018ed14 2a 72 65 00 1b 8f 13 01 - 6c ef 18 00 0c 89 40 00 *re.....l.....@.
0018ed24 38 ed 18 00 00 00 00 00 - 50 f3 a2 0b 30 25 56 04 8.......P...0%V.
0018ed34 10 ee 37 05 5c ed 18 00 - ed 04 53 00 50 f3 a2 0b ..7.\.....S.P...
0018ed44 1d 3c 62 00 07 3c 62 00 - d8 ee 18 00 18 3b 62 00 .<b..<b......;b.
0018ed54 50 f3 a2 0b 01 00 00 00 - cc ee 18 00 25 09 53 00 P...........%.S.
0018ed64 0c 00 00 00 18 00 00 00 - 00 00 00 00 d8 ee 18 00 ................
0018ed74 50 f3 a2 0b a1 09 53 00 - 18 00 0c 00 d8 ee 18 00 P.....S.........
0018ed84 b0 02 03 00 01 ee 18 00 - 2c e9 52 00 50 00 00 00 ........,.R.P...
disassembling:
[...]
01138ef0 push $1139140
01138ef5 lea eax, [ebp-$10]
01138ef8 mov edx, 3
01138efd call -$d2e73a ($40a7c8) ; System.@UStrCatN
01138f02 mov edx, [ebp-$10]
01138f05 mov eax, [ebp-8]
01138f08 mov eax, [eax+$250]
01138f0e mov ecx, [eax]
01138f10 call dword ptr [ecx+$38]
01138f13 1150 mov eax, [ebp-8]
01138f16 > call -$ae1cfb ($657220) ; Data.DB.TDataSet.Open
01138f1b 1152 mov eax, [ebp-4]
01138f1e mov eax, [eax+$598]
01138f24 xor edx, edx
01138f26 mov [eax+$c], edx
01138f29 1153 mov ecx, [$15bc3ac]
01138f2f mov eax, [$15bcc10]
01138f34 mov eax, [eax]
01138f36 mov edx, [$eb7cf4]
01138f3c call -$b2369d ($6158a4) ; Vcl.Forms.TApplication.CreateForm
01138f41 1154 mov eax, [ebp-4]
[...]
thread $14e0:
7756f8da +0e ntdll.dll NtWaitForSingleObject
759d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75e7118f +3e kernel32.dll WaitForSingleObjectEx
75e71143 +0d kernel32.dll WaitForSingleObject
75e73368 +10 kernel32.dll BaseThreadInitThunk
thread $8e8:
77570166 +0e ntdll.dll NtWaitForMultipleObjects
75e73368 +10 kernel32.dll BaseThreadInitThunk
thread $1638:
7756f8da +0e ntdll.dll NtWaitForSingleObject
759d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75e7118f +3e kernel32.dll WaitForSingleObjectEx
75e71143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
75e73368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1724) at:
73ea4c95 +00 winspool.drv
thread $934:
77571f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75e73368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00350000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00380000 BCLW32.dll C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
04300000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
062e0000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6ed30000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
707c0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70840000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70b90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70bb0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70bd0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70be0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70ca0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70fa0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71000000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
712b0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71430000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71450000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71490000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71a80000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71ad0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71b30000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72380000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
723a0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72440000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72480000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72630000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72650000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72660000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73b20000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73be0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73d20000 security.dll 6.1.7600.16385 C:\Windows\
system32
73d30000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73d90000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73e90000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73f00000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73f20000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73f70000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73fa0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73fd0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74010000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74030000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74040000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74050000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
740b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74120000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
742c0000 version.dll 6.1.7600.16385 C:\Windows\
system32
742d0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74de0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74df0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74e50000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
74e90000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74ea0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75150000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
751e0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
751f0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75320000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75380000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75430000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75440000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75450000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75550000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75560000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75600000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75620000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75860000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75870000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
758a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75900000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75910000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
759c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75a10000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75b70000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b80000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75cd0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75da0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75db0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75e60000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75fd0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76020000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76050000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
760a0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76240000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
762c0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76350000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76fa0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
77090000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
77130000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
77520000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77550000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02cc svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0410 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06d8 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0760 fbguard.exe 0 0 0
0788 svchost.exe 0 0 0
07a0 NetExpressUpdater.exe 0 0 0
07f4 OSPPSVC.EXE 0 0 0
05bc svchost.exe 0 0 0
0434 scpbradserv.exe 0 0 0
0710 svchost.exe 0 0 0
0808 core.exe 0 0 0
0980 RapportInjService_x64.exe 0 0 0
09f4 fbserver.exe 0 0 0
0b70 WUDFHost.exe 0 0 0
05dc NisSrv.exe 0 0 0
0efc WmiPrvSE.exe 0 0 0
0fe0 svchost.exe 0 0 0
0d38 GoogleCrashHandler.exe 0 0 0
0c34 GoogleCrashHandler64.exe 0 0 0
0614 SearchIndexer.exe 0 0 0
0c0c taskhost.exe 1 26 21 normal
0ebc core.exe 1 9 22 normal
0fa8 PresentationFontCache.exe 0 0 0
0298 dwm.exe 1 17 4 high
0674 explorer.exe 1 732 435 normal
0e20 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0e38 igfxEM.exe 1 14 14 normal
0e30 igfxHK.exe 1 14 13 normal
0534 msseces.exe 1 143 60 normal
0e1c RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e28 PrnStatusMX.exe 1 23 18 normal
10c4 RapportInjService_x64.exe 1 4 3 normal
11f4 wuauclt.exe 1 12 6 normal
103c splwow64.exe 1 9 2 normal
1294 OIS.EXE 1 111 51 normal
0c10 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0a2c OIS.EXE 1 101 50 normal
1020 OIS.EXE 1 130 111 normal
1370 EXCEL.EXE 1 335 113 normal
044c Store.exe 1 1207 345 normal C:\Program Files (x86)\Store
0480 OIS.EXE 1 81 37 normal
11c4 chrome.exe 1 78 62 normal
1014 chrome.exe 1 9 4 normal
170c chrome.exe 1 7 9 above normal
0f88 chrome.exe 1 4 1 normal
0ee4 chrome.exe 1 4 1 normal
0f58 chrome.exe 1 4 1 idle
11e4 chrome.exe 1 4 1 idle
0ea4 chrome.exe 1 4 3 normal
1244 OIS.EXE 1 93 46 normal
0b64 OIS.EXE 1 88 37 normal
0bb8 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 05ec5660
ebx = 00002e36
ecx = 00000000
edx = 02962ac8
esi = 045e1030
edi = 0066cb50
eip = 0066ea6e
esp = 0018e338
ebp = 0018e398
stack dump:
0018e338 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e348 4c e3 18 00 6e ea 66 00 - 60 56 ec 05 36 2e 00 00 L...n.f.`V..6...
0018e358 30 10 5e 04 50 cb 66 00 - 98 e3 18 00 68 e3 18 00 0.^.P.f.....h...
0018e368 36 2e 00 00 96 93 67 00 - 30 10 5e 04 d4 6a 3f 0a 6.....g.0.^..j?.
0018e378 a5 eb 67 00 a8 e3 18 00 - eb 8a 40 00 98 e3 18 00 ..g.......@.....
0018e388 50 cb 66 00 30 10 5e 04 - 01 10 5e 04 30 10 5e 04 P.f.0.^...^.0.^.
0018e398 c8 e3 18 00 79 ea 67 00 - 30 10 5e 04 62 e6 67 00 ....y.g.0.^.b.g.
0018e3a8 d0 e3 18 00 0c 89 40 00 - c8 e3 18 00 30 10 5e 04 [email protected].^.
0018e3b8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e3c8 f8 e3 18 00 59 e8 67 00 - dc e3 18 00 0c 89 40 00 ....Y.g.......@.
0018e3d8 f8 e3 18 00 04 e4 18 00 - 0c 89 40 00 f8 e3 18 00 ..........@.....
0018e3e8 00 00 00 00 00 00 00 00 - d5 e9 67 01 30 10 5e 04 ..........g.0.^.
0018e3f8 20 e4 18 00 f3 e8 67 00 - 12 4d 67 00 38 e4 18 00 .....g..Mg.8...
0018e408 0c 89 40 00 20 e4 18 00 - 30 10 5e 04 00 00 00 00 ..@. ...0.^.....
0018e418 00 00 00 00 30 10 5e 04 - 4c e4 18 00 b6 92 67 00 ....0.^.L.....g.
0018e428 00 00 00 00 38 5d 53 00 - 01 1c 54 00 e3 73 65 00 ....8]S...T..se.
0018e438 58 e4 18 00 0c 89 40 00 - 4c e4 18 00 40 d5 5d 06 [email protected]...@.].
0018e448 30 10 5e 04 8c e4 18 00 - 2a 72 65 00 d0 fe 12 01 0.^.....*re.....
0018e458 a4 e4 18 00 0c 89 40 00 - 8c e4 18 00 00 00 00 00 ......@.........
0018e468 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
0112fea5 push $1130034
0112feaa lea eax, [ebp-$20]
0112fead mov edx, 3
0112feb2 call -$d256ef ($40a7c8) ; System.@UStrCatN
0112feb7 mov edx, [ebp-$20]
0112feba mov eax, [ebp-8]
0112febd mov eax, [eax+$250]
0112fec3 mov ecx, [eax]
0112fec5 call dword ptr [ecx+$38]
0112fec8 463 mov eax, [ebp-8]
0112fecb > call -$ad8cb0 ($657220) ; Data.DB.TDataSet.Open
0112fed0 464 mov eax, [ebp-8]
0112fed3 cmp byte ptr [eax+$a8], 0
0112feda jz loc_112fefd
0112fedc mov eax, [ebp-8]
0112fedf cmp byte ptr [eax+$a9], 0
0112fee6 jz loc_112fefd
0112fee8 465 mov edx, $1130048
0112feed mov eax, [ebp-4]
0112fef0 mov eax, [eax+$4f4]
0112fef6 call -$c01837 ($52e6c4) ; Vcl.Controls.TControl.SetText
[...]
thread $1350:
777bf8da +0e ntdll.dll NtWaitForSingleObject
766215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76c8118f +3e kernel32.dll WaitForSingleObjectEx
76c81143 +0d kernel32.dll WaitForSingleObject
76c83368 +10 kernel32.dll BaseThreadInitThunk
thread $1358:
777c0166 +0e ntdll.dll NtWaitForMultipleObjects
76c83368 +10 kernel32.dll BaseThreadInitThunk
thread $136c:
777c0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76c83368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1328) at:
73ee2713 +24f netbios.dll Netbios
thread $1568:
777bf8da +0e ntdll.dll NtWaitForSingleObject
766215c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76c8118f +3e kernel32.dll WaitForSingleObjectEx
76c81143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76c83368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1328) at:
74084c95 +00 winspool.drv
thread $1454:
777c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76c83368 +10 kernel32.dll BaseThreadInitThunk
thread $122c:
777c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76c83368 +10 kernel32.dll BaseThreadInitThunk
modules:
001c0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00270000 BCLW32.dll C:\Program
Files (x86)\Store
003a0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
025b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
06250000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06390000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6ff00000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
6ff80000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
6ff90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
6ffb0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70220000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70e80000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
712a0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71500000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71540000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71560000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71580000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71a30000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71a80000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71ae0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
725d0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
725f0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72690000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
726d0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72880000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
728a0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
728b0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73820000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73d10000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73eb0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73ee0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73ef0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73f00000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73f10000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73f70000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
74070000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
740f0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
74140000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
74170000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
741c0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
741f0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74220000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74260000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74280000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74290000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
742a0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74300000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74370000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74510000 version.dll 6.1.7600.16385 C:\Windows\
system32
74520000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75030000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75040000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
750a0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
751d0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
751e0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75210000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75250000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75300000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75450000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75690000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
756a0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75700000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75720000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75750000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
757f0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75800000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75810000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
759b0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
759c0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76610000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76660000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
766e0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76730000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76800000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76810000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76820000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
768b0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
768d0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
769c0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76c70000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76d80000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76e40000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76ed0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76f80000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
770b0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77100000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
77200000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77210000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77230000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
77390000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77770000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
777a0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
0148 RapportMgmtService.exe 0 0 0
0314 svchost.exe 0 0 0
036c svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0524 igfxCUIService.exe 0 0 0
0578 svchost.exe 0 0 0
0638 spoolsv.exe 0 0 0
0640 taskeng.exe 0 0 0
0678 svchost.exe 0 0 0
06ec armsvc.exe 0 0 0
0704 atkexComSvc.exe 0 0 0
0740 svchost.exe 0 0 0
0764 fbguard.exe 0 0 0
0788 svchost.exe 0 0 0
07a0 NetExpressUpdater.exe 0 0 0
07ec OSPPSVC.EXE 0 0 0
0650 svchost.exe 0 0 0
06e4 scpbradserv.exe 0 0 0
07e8 svchost.exe 0 0 0
0824 core.exe 0 0 0
0980 RapportInjService_x64.exe 0 0 0
0a2c fbserver.exe 0 0 0
0ba8 WUDFHost.exe 0 0 0
0878 NisSrv.exe 0 0 0
0cb0 taskhost.exe 1 26 21 normal
0d14 core.exe 1 9 20 normal
0d68 PresentationFontCache.exe 0 0 0
0d80 dwm.exe 1 17 4 high
0da8 explorer.exe 1 425 241 normal
0950 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0f68 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0f8c igfxEM.exe 1 14 13 normal
0bd4 igfxHK.exe 1 14 13 normal
0128 msseces.exe 1 143 60 normal
0c2c PrnStatusMX.exe 1 23 18 normal
0318 RapportInjService_x64.exe 1 4 3 normal
0f74 GoogleCrashHandler.exe 0 0 0
0fe0 svchost.exe 0 0 0
01a0 SearchIndexer.exe 0 0 0
11f0 GoogleCrashHandler64.exe 0 0 0
126c wuauclt.exe 1 12 6 normal
0db0 Store.exe 1 619 248 normal C:\Program Files (x86)\Store
10dc chrome.exe 1 27 53 normal
11d8 chrome.exe 1 9 4 normal
1344 chrome.exe 1 8 7 above normal
029c chrome.exe 1 4 1 normal
0880 chrome.exe 1 4 1 normal
125c chrome.exe 1 4 1 idle
1518 chrome.exe 1 4 3 normal
159c WmiPrvSE.exe 0 0 0
1730 splwow64.exe 1 9 4 normal
14dc audiodg.exe 0 0 0
17ac chrome.exe 1 4 1 idle
14b0 Store.exe 1 206 184 normal C:\Program Files (x86)\Store
0f5c Store.exe 1 91 69 normal C:\Program Files (x86)\Store
05e0 rundll32.exe 1 116 44 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 06413d90
ecx = 04392650
edx = 0438e670
esi = 00593bec
edi = 0018de20
eip = 006fa3da
esp = 0018dcac
ebp = 0018de14
stack dump:
0018dcac ec 3b 59 00 d0 4a 81 0a - ed 04 53 00 d0 4a 81 0a .;Y..J....S..J..
0018dcbc f1 3b 59 00 96 09 53 00 - 13 00 0a 00 13 00 00 00 .;Y...S.........
0018dccc 0a 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
0018dcdc 16 00 00 00 13 00 0a 00 - d0 4a 81 0a 20 de 18 00 .........J.. ...
0018dcec 94 ff 52 00 13 00 0a 00 - 1c df 18 00 d0 4a 81 0a ..R..........J..
0018dcfc d0 4a 81 0a cc 01 00 00 - 0a 00 00 00 00 00 00 00 .J..............
0018dd0c 88 dd 18 00 1f b0 5f 72 - 40 6c 89 0a ac 04 0a 00 ......_r@l......
0018dd1c 02 02 00 00 0f 00 00 00 - cc 01 0a 00 00 00 00 00 ................
0018dd2c bb 80 5f 72 8e 81 5f 72 - 10 39 39 04 cc 01 0a 00 .._r.._r.99.....
0018dd3c ac 04 0a 00 00 00 00 00 - 10 39 39 04 00 00 00 00 .........99.....
0018dd4c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd5c 00 00 00 00 00 00 00 00 - bb 80 5f 72 01 00 00 00 .........._r....
0018dd6c 04 de 18 00 00 00 00 00 - 00 00 01 00 00 00 00 01 ................
0018dd7c 07 00 00 00 00 00 00 00 - 9b 82 11 6d b4 dd 18 00 ...........m....
0018dd8c fa 62 11 77 ac 04 0a 00 - 02 02 00 00 00 00 00 00 .b.w............
0018dd9c cc 01 0a 00 bb 80 5f 72 - cd ab ba dc 00 00 00 00 ......_r........
0018ddac 00 00 00 00 cc dd 18 00 - cf fb 52 00 d0 4a 81 0a ..........R..J..
0018ddbc 0a b0 00 00 00 00 00 00 - 13 00 0a 00 01 00 00 00 ................
0018ddcc 00 de 18 00 41 40 53 00 - 13 00 0a 00 10 39 39 04 [email protected].
0018dddc 00 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
disassembling:
[...]
006fa3ae mov edx, [$6e9910]
006fa3b4 call -$2f2b11 ($4078a8) ; System.@IsClass
006fa3b9 test al, al
006fa3bb jnz loc_6fa3ca
006fa3bd 402 mov eax, [ebx+$460]
006fa3c3 call +$cd78 ($707140) ; QRPrntr.TQRPrinter.Print
006fa3c8 jmp loc_6fa3f4
006fa3ca 405 mov eax, [$15c48cc]
006fa3cf call -$741c ($6f2fb8) ; QuickRpt.TCustomQuickRep.Print
006fa3d4 407 mov eax, [ebx+$3cc]
006fa3da > cmp dword ptr [eax+$2b8], 0
006fa3e1 jnz loc_6fa3f4
006fa3e3 409 mov edx, [$15c48cc]
006fa3e9 mov edx, [edx+$36c]
006fa3ef call +$9920 ($703d14) ; QRPrntr.TQRPreview.SetQRPrinter
006fa3f4 412 pop esi
006fa3f5 pop ebx
006fa3f6 ret
thread $1268:
76f0f8da +0e ntdll.dll NtWaitForSingleObject
75db15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75be118f +3e kernel32.dll WaitForSingleObjectEx
75be1143 +0d kernel32.dll WaitForSingleObject
75be3368 +10 kernel32.dll BaseThreadInitThunk
thread $126c:
76f10166 +0e ntdll.dll NtWaitForMultipleObjects
75be3368 +10 kernel32.dll BaseThreadInitThunk
thread $1278:
76f10166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
75be3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1254) at:
73152713 +24f netbios.dll Netbios
thread $1090:
76f0f8da +0e ntdll.dll NtWaitForSingleObject
75db15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
75be118f +3e kernel32.dll WaitForSingleObjectEx
75be1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
75be3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1254) at:
73184c95 +00 winspool.drv
thread $74c:
76f11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75be3368 +10 kernel32.dll BaseThreadInitThunk
modules:
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02620000 WINPPLA.DLL C:\Program
Files (x86)\Store
02660000 BCLW32.dll C:\Program
Files (x86)\Store
04580000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06390000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6e370000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
6fc30000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70320000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70330000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70350000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
708b0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70a10000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70a50000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70a90000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70ab0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71000000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71180000 webio.dll 6.1.7601.23375 C:\Windows\
system32
711d0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71230000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71d20000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71d40000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71de0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71e20000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
71fd0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
71ff0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72000000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72bc0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
72ef0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
72f50000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73050000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
730a0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73110000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73120000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73150000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73160000 security.dll 6.1.7600.16385 C:\Windows\
system32
73170000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73200000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73500000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
73580000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73670000 slc.dll 6.1.7600.16385 C:\Windows\
system32
738c0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73910000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73940000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73970000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
739b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
739d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
739e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
739f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73a50000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73ac0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73c60000 version.dll 6.1.7600.16385 C:\Windows\
system32
73c70000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74780000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74790000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
747f0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
74800000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
74ab0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
74be0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
74cb0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74d00000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
74d30000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
74e80000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74e90000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
74ec0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74ed0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75b20000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75b30000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75b40000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75bd0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75ce0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75cf0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75da0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75df0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75e10000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75eb0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75f40000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75f50000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75fb0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76030000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76190000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76230000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76250000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76340000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76380000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76390000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76490000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
764f0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76690000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
766b0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76760000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76810000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76a50000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76ec0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ef0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
014c RapportMgmtService.exe 0 0 0
02b4 svchost.exe 0 0 0
0344 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0514 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0638 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06e8 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0760 fbguard.exe 0 0 0
0788 svchost.exe 0 0 0
07a0 NetExpressUpdater.exe 0 0 0
07f8 OSPPSVC.EXE 0 0 0
0690 svchost.exe 0 0 0
042c scpbradserv.exe 0 0 0
0750 svchost.exe 0 0 0
0818 core.exe 0 0 0
0968 RapportInjService_x64.exe 0 0 0
0a24 fbserver.exe 0 0 0
0bc0 WUDFHost.exe 0 0 0
0860 NisSrv.exe 0 0 0
0c28 WmiPrvSE.exe 0 0 0
0df4 taskhost.exe 1 26 21 normal
0e28 core.exe 1 9 22 normal
0e94 PresentationFontCache.exe 0 0 0
0ec0 dwm.exe 1 17 4 high
0f78 explorer.exe 1 394 284 normal
06f4 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0b94 igfxEM.exe 1 14 13 normal
0bb0 igfxHK.exe 1 14 12 normal
03f0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0d84 msseces.exe 1 143 59 normal
0c24 PrnStatusMX.exe 1 23 18 normal
0a98 GoogleCrashHandler.exe 0 0 0
0fdc RapportInjService_x64.exe 1 4 3 normal
03d0 GoogleCrashHandler64.exe 0 0 0
0e50 SearchIndexer.exe 0 0 0
0d3c svchost.exe 0 0 0
1250 Store.exe 1 2660 669 normal C:\Program Files (x86)\Store
1244 wuauclt.exe 1 12 6 normal
11ac splwow64.exe 1 9 4 normal
12ac chrome.exe 1 76 62 normal
0940 chrome.exe 1 9 4 normal
106c chrome.exe 1 9 6 above normal
1248 chrome.exe 1 4 1 normal
1154 chrome.exe 1 4 1 normal
12e0 chrome.exe 1 4 1 normal
170c chrome.exe 1 4 1 idle
17b0 chrome.exe 1 4 3 normal
1234 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1480 chrome.exe 1 4 1 idle
037c chrome.exe 1 4 1 idle
159c audiodg.exe 0 0 0
14b8 rundll32.exe 1 116 46 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 064e5150
ecx = 043d0fd0
edx = 043ce670
esi = 00593bec
edi = 0018de20
eip = 006fa3da
esp = 0018dcac
ebp = 0018de14
stack dump:
0018dcac ec 3b 59 00 b0 10 38 0a - ed 04 53 00 b0 10 38 0a .;Y...8...S...8.
0018dcbc f1 3b 59 00 96 09 53 00 - 10 00 02 00 10 00 00 00 .;Y...S.........
0018dccc 02 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
0018dcdc 16 00 00 00 10 00 02 00 - b0 10 38 0a 20 de 18 00 ..........8. ...
0018dcec 94 ff 52 00 10 00 02 00 - 1c df 18 00 b0 10 38 0a ..R...........8.
0018dcfc b0 10 38 0a c9 01 00 00 - 02 00 00 00 00 00 00 00 ..8.............
0018dd0c 88 dd 18 00 1f b0 d4 71 - 38 77 a1 0a 2e 05 31 00 .......q8w....1.
0018dd1c 02 02 00 00 0f 00 00 00 - c9 01 02 00 00 00 00 00 ................
0018dd2c bb 80 d4 71 8e 81 d4 71 - 00 00 00 00 c9 01 02 00 ...q...q........
0018dd3c 2e 05 31 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ..1.............
0018dd4c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 01 ................
0018dd5c 00 00 00 00 00 00 00 00 - bb 80 d4 71 01 00 00 00 ...........q....
0018dd6c 04 de 18 00 00 00 00 00 - 00 00 01 00 00 00 00 01 ................
0018dd7c 07 00 00 00 00 00 00 00 - 7f 42 9c 7d b4 dd 18 00 .........B.}....
0018dd8c fa 62 3a 76 2e 05 31 00 - 02 02 00 00 00 00 00 00 .b:v..1.........
0018dd9c c9 01 02 00 bb 80 d4 71 - cd ab ba dc 00 00 00 00 .......q........
0018ddac 00 00 00 00 cc dd 18 00 - cf fb 52 00 b0 10 38 0a ..........R...8.
0018ddbc 0a b0 00 00 00 00 00 00 - 10 00 02 00 01 00 00 00 ................
0018ddcc 00 de 18 00 41 40 53 00 - 10 00 02 00 50 17 3d 04 [email protected].=.
0018dddc 00 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
disassembling:
[...]
006fa3ae mov edx, [$6e9910]
006fa3b4 call -$2f2b11 ($4078a8) ; System.@IsClass
006fa3b9 test al, al
006fa3bb jnz loc_6fa3ca
006fa3bd 402 mov eax, [ebx+$460]
006fa3c3 call +$cd78 ($707140) ; QRPrntr.TQRPrinter.Print
006fa3c8 jmp loc_6fa3f4
006fa3ca 405 mov eax, [$15c48cc]
006fa3cf call -$741c ($6f2fb8) ; QuickRpt.TCustomQuickRep.Print
006fa3d4 407 mov eax, [ebx+$3cc]
006fa3da > cmp dword ptr [eax+$2b8], 0
006fa3e1 jnz loc_6fa3f4
006fa3e3 409 mov edx, [$15c48cc]
006fa3e9 mov edx, [edx+$36c]
006fa3ef call +$9920 ($703d14) ; QRPrntr.TQRPreview.SetQRPrinter
006fa3f4 412 pop esi
006fa3f5 pop ebx
006fa3f6 ret
thread $139c:
7720f8da +0e ntdll.dll NtWaitForSingleObject
76a515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
758a118f +3e kernel32.dll WaitForSingleObjectEx
758a1143 +0d kernel32.dll WaitForSingleObject
758a3368 +10 kernel32.dll BaseThreadInitThunk
thread $13a0:
77210166 +0e ntdll.dll NtWaitForMultipleObjects
758a3368 +10 kernel32.dll BaseThreadInitThunk
thread $13a4:
77211f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
758a3368 +10 kernel32.dll BaseThreadInitThunk
thread $13bc:
77210166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
758a3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1368) at:
73852713 +24f netbios.dll Netbios
thread $450:
77211f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
758a3368 +10 kernel32.dll BaseThreadInitThunk
thread $1184:
77211f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
758a3368 +10 kernel32.dll BaseThreadInitThunk
modules:
002d0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06230000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06360000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70060000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
701d0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
701e0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70200000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70210000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70670000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70740000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70890000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
708a0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70ce0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70f20000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71090000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
710b0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71300000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71480000 webio.dll 6.1.7601.23375 C:\Windows\
system32
714d0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71530000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72020000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72040000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
720e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72120000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
722d0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
722f0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72300000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72990000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73670000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
736a0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73850000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73860000 security.dll 6.1.7600.16385 C:\Windows\
system32
73870000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73880000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73980000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73c10000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73c40000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73c70000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73cb0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73cd0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73ce0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73cf0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73d50000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73dc0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73f60000 version.dll 6.1.7600.16385 C:\Windows\
system32
73f70000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74a80000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74a90000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74af0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
74d30000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
74d50000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
74d60000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
74e60000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74e70000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
74ea0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75000000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
750d0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750e0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750f0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
751a0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
751c0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75230000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75460000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75470000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75480000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75490000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
754a0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75570000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
756a0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
756d0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75760000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75850000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75890000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
759a0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75c50000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
768a0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76930000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76990000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76a40000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76a90000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76ae0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76af0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76b00000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76b60000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76be0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76c00000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76d50000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
771c0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
771f0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0304 svchost.exe 0 0 0
03f4 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0570 svchost.exe 0 0 0
0630 spoolsv.exe 0 0 0
0638 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f0 OSPPSVC.EXE 0 0 0
05bc svchost.exe 0 0 0
069c scpbradserv.exe 0 0 0
0774 svchost.exe 0 0 0
080c core.exe 0 0 0
095c RapportInjService_x64.exe 0 0 0
0a20 fbserver.exe 0 0 0
0bcc WUDFHost.exe 0 0 0
086c NisSrv.exe 0 0 0
0f70 WmiPrvSE.exe 0 0 0
0e7c svchost.exe 0 0 0
0f3c GoogleCrashHandler.exe 0 0 0
0f28 GoogleCrashHandler64.exe 0 0 0
0880 sppsvc.exe 0 0 0
0fe0 SearchIndexer.exe 0 0 0
0648 taskhost.exe 1 26 20 normal
0d14 core.exe 1 9 19 normal
0d98 PresentationFontCache.exe 0 0 0
0da4 dwm.exe 1 16 4 high
0e34 explorer.exe 1 356 210 normal
0594 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\scpbrad
067c RapportService.exe 1 14 18 normal C:\Program Files (x86)\Trusteer\
Rapport\bin
0a6c igfxEM.exe 1 14 13 normal
0a54 igfxHK.exe 1 14 13 normal
050c msseces.exe 1 143 60 normal
0720 PrnStatusMX.exe 1 23 18 normal
10a4 RapportInjService_x64.exe 1 4 3 normal
12ec TrustedInstaller.exe 0 0 0
1334 wuauclt.exe 1 12 7 normal
1364 Store.exe 1 185 200 normal C:\Program Files (x86)\Store
13e0 WmiPrvSE.exe 0 0 0
1b98 WmiPrvSE.exe 0 0 0
1bf0 VSSVC.exe 0 0 0
0cb4 svchost.exe 0 0 0
10e0 MpCmdRun.exe 0 0 0
1078 MpCmdRun.exe 0 0 0
0374 conhost.exe 0 0 0
11d8 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a2e5c08
ebx = 00003303
ecx = 00000000
edx = 025d2ac8
esi = 0018ee88
edi = 0066cb50
eip = 0066ea6e
esp = 0018ee4c
ebp = 0018eeb4
stack dump:
0018ee4c 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018ee5c 60 ee 18 00 6e ea 66 00 - 08 5c 2e 0a 03 33 00 00 `...n.f..\...3..
0018ee6c 88 ee 18 00 50 cb 66 00 - b4 ee 18 00 7c ee 18 00 ....P.f.....|...
0018ee7c 30 73 42 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 0sB.z.f...g.....
0018ee8c 30 73 42 06 00 00 00 00 - 9b e8 67 00 c0 ee 18 00 0sB.......g.....
0018ee9c 0c 89 40 00 b4 ee 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018eeac d5 e9 67 01 30 73 42 06 - dc ee 18 00 f3 e8 67 00 ..g.0sB.......g.
0018eebc 12 4d 67 00 f4 ee 18 00 - 0c 89 40 00 dc ee 18 00 .Mg.......@.....
0018eecc 30 73 42 06 00 00 00 00 - 00 00 00 00 30 73 42 06 0sB.........0sB.
0018eedc 08 ef 18 00 b6 92 67 00 - 00 00 00 00 3c 9a 5b 00 ......g.....<.[.
0018eeec 01 00 00 00 e3 73 65 00 - 14 ef 18 00 0c 89 40 00 .....se.......@.
0018eefc 08 ef 18 00 20 96 42 06 - 30 73 42 06 68 ef 18 00 .... .B.0sB.h...
0018ef0c 2a 72 65 00 78 5a 56 01 - 20 ef 18 00 64 89 40 00 *re.xZV. ...d.@.
0018ef1c 68 ef 18 00 78 ef 18 00 - 0c 89 40 00 68 ef 18 00 [email protected]...
0018ef2c 00 00 00 00 3c 9a 5b 00 - 20 96 42 06 00 00 00 00 ....<.[. .B.....
0018ef3c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ef4c 00 00 00 00 20 96 42 06 - 01 00 00 00 00 00 00 00 .... .B.........
0018ef5c 00 00 00 00 30 73 42 06 - 40 86 31 0a 94 ef 18 00 [email protected].....
0018ef6c 4e 9a 5b 00 9c ef 18 00 - 34 99 5b 00 40 f0 18 00 N.[.....4.[.@...
0018ef7c dc 86 40 00 94 ef 18 00 - 00 00 00 00 fd 0c 0f 04 ..@.............
disassembling:
[...]
01565a4f 884 mov eax, [ebp-8]
01565a52 mov eax, [eax+$250]
01565a58 mov edx, [eax]
01565a5a call dword ptr [edx+$44]
01565a5d 885 mov eax, [ebp-8]
01565a60 mov eax, [eax+$250]
01565a66 mov edx, $1565c40
01565a6b mov ecx, [eax]
01565a6d call dword ptr [ecx+$38]
01565a70 886 mov eax, [ebp-8]
01565a73 > call -$f0e858 ($657220) ; Data.DB.TDataSet.Open
01565a78 xor eax, eax
01565a7a pop edx
01565a7b pop ecx
01565a7c pop ecx
01565a7d mov fs:[eax], edx
01565a80 jmp loc_1565c0b
01565a85 jmp -$115d4b2 ($4085d8) ; System.@HandleAnyException
01565a8a 890 mov eax, [$15bcdf0]
01565a8f mov eax, [eax]
01565a91 mov eax, [eax+$60]
[...]
thread $13a0:
77210166 +0e ntdll.dll NtWaitForMultipleObjects
758a3368 +10 kernel32.dll BaseThreadInitThunk
thread $13bc:
77210166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
758a3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1368) at:
73852713 +24f netbios.dll Netbios
thread $1834:
7720f8da +0e ntdll.dll NtWaitForSingleObject
76a515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
758a118f +3e kernel32.dll WaitForSingleObjectEx
758a1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
758a3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1368) at:
73994c95 +00 winspool.drv
thread $1098:
77211f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
758a3368 +10 kernel32.dll BaseThreadInitThunk
thread $1234:
77211f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
758a3368 +10 kernel32.dll BaseThreadInitThunk
thread $f80:
77211f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
758a3368 +10 kernel32.dll BaseThreadInitThunk
modules:
002d0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06230000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06360000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70060000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
701d0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
701e0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70200000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70210000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70670000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70740000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70890000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
708a0000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70ce0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70f20000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71090000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
710b0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71300000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71480000 webio.dll 6.1.7601.23375 C:\Windows\
system32
714d0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71530000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72020000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72040000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
720e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72120000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
722d0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
722f0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72300000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72990000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73670000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
736a0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73850000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73860000 security.dll 6.1.7600.16385 C:\Windows\
system32
73870000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73880000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73980000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73bc0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73c10000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73c40000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73c70000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73cb0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73cd0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73ce0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73cf0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73d50000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73dc0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73f60000 version.dll 6.1.7600.16385 C:\Windows\
system32
73f70000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74a80000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74a90000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74af0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
74d30000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
74d50000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
74d60000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
74e60000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74e70000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
74ea0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75000000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
750d0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750e0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
750f0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
751a0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
751c0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75230000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75460000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75470000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75480000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75490000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
754a0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75570000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
756a0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
756d0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75760000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75850000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75890000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
759a0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75c50000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
768a0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76930000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76990000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76a40000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76a90000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76ae0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76af0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76b00000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76b60000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76be0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76c00000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76d50000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
771c0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
771f0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0304 svchost.exe 0 0 0
03f4 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
051c igfxCUIService.exe 0 0 0
0570 svchost.exe 0 0 0
0630 spoolsv.exe 0 0 0
0638 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f0 OSPPSVC.EXE 0 0 0
05bc svchost.exe 0 0 0
069c scpbradserv.exe 0 0 0
0774 svchost.exe 0 0 0
080c core.exe 0 0 0
095c RapportInjService_x64.exe 0 0 0
0a20 fbserver.exe 0 0 0
0bcc WUDFHost.exe 0 0 0
086c NisSrv.exe 0 0 0
0f70 WmiPrvSE.exe 0 0 0
0e7c svchost.exe 0 0 0
0f3c GoogleCrashHandler.exe 0 0 0
0f28 GoogleCrashHandler64.exe 0 0 0
0fe0 SearchIndexer.exe 0 0 0
0648 taskhost.exe 1 26 23 normal
0d14 core.exe 1 9 21 normal
0d98 PresentationFontCache.exe 0 0 0
0da4 dwm.exe 1 17 4 high
0e34 explorer.exe 1 429 259 normal
0594 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
067c RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0a6c igfxEM.exe 1 14 13 normal
0a54 igfxHK.exe 1 14 13 normal
050c msseces.exe 1 143 59 normal
0720 PrnStatusMX.exe 1 23 18 normal
10a4 RapportInjService_x64.exe 1 4 3 normal
1334 wuauclt.exe 1 12 7 normal
1364 Store.exe 1 1322 481 normal C:\Program Files (x86)\Store
0e88 splwow64.exe 1 9 4 normal
1b7c OIS.EXE 1 119 50 normal
0604 chrome.exe 1 27 60 normal
11c0 chrome.exe 1 9 4 normal
1180 chrome.exe 1 7 5 above normal
0e04 chrome.exe 1 4 1 normal
1ae4 chrome.exe 1 4 1 normal
1884 chrome.exe 1 4 1 normal
14c0 chrome.exe 1 4 1 idle
17f4 chrome.exe 1 4 3 normal
19a4 OIS.EXE 1 101 49 normal
13dc audiodg.exe 0 0 0
16e0 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0888 rundll32.exe 1 117 47 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0c3d5510
ebx = 00003303
ecx = 00000000
edx = 025d2ac8
esi = 0018da4c
edi = 0066cb50
eip = 0066ea6e
esp = 0018da10
ebp = 0018da78
stack dump:
0018da10 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018da20 24 da 18 00 6e ea 66 00 - 10 55 3d 0c 03 33 00 00 $...n.f..U=..3..
0018da30 4c da 18 00 50 cb 66 00 - 78 da 18 00 40 da 18 00 L...P.f.x...@...
0018da40 30 34 42 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 04B.z.f...g.....
0018da50 30 34 42 06 00 00 00 00 - 9b e8 67 00 84 da 18 00 04B.......g.....
0018da60 0c 89 40 00 78 da 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018da70 d5 e9 67 01 30 34 42 06 - a0 da 18 00 f3 e8 67 00 ..g.04B.......g.
0018da80 12 4d 67 00 b8 da 18 00 - 0c 89 40 00 a0 da 18 00 .Mg.......@.....
0018da90 30 34 42 06 00 00 00 00 - 00 00 00 00 30 34 42 06 04B.........04B.
0018daa0 cc da 18 00 b6 92 67 00 - 00 00 00 00 38 5d 53 00 ......g.....8]S.
0018dab0 01 00 00 00 e3 73 65 00 - d8 da 18 00 0c 89 40 00 .....se.......@.
0018dac0 cc da 18 00 f0 1a 0e 0c - 30 34 42 06 3c e0 18 00 ........04B.<...
0018dad0 2a 72 65 00 ce c2 ed 00 - 44 e0 18 00 0c 89 40 00 *re.....D.....@.
0018dae0 3c e0 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 <...............
0018daf0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db00 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db10 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db20 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db30 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db40 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00edc29d push $edd4f8
00edc2a2 lea eax, [ebp-$4bc]
00edc2a8 mov edx, 3
00edc2ad call -$ad1aea ($40a7c8) ; System.@UStrCatN
00edc2b2 mov edx, [ebp-$4bc]
00edc2b8 mov eax, [ebp-$34]
00edc2bb mov eax, [eax+$250]
00edc2c1 mov ecx, [eax]
00edc2c3 call dword ptr [ecx+$38]
00edc2c6 4111 mov eax, [ebp-$34]
00edc2c9 > call -$8850ae ($657220) ; Data.DB.TDataSet.Open
00edc2ce 4113 mov eax, [$15bcdf0]
00edc2d3 mov eax, [eax]
00edc2d5 mov eax, [eax+$1710]
00edc2db cmp byte ptr [eax+$a9], 0
00edc2e2 jz loc_edc89e
00edc2e8 mov eax, [$15bcdf0]
00edc2ed mov eax, [eax]
00edc2ef mov eax, [eax+$1710]
00edc2f5 cmp byte ptr [eax+$a8], 0
00edc2fc jz loc_edc89e
[...]
thread $1064:
776ef8da +0e ntdll.dll NtWaitForSingleObject
76f015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7530118f +3e kernel32.dll WaitForSingleObjectEx
75301143 +0d kernel32.dll WaitForSingleObject
75303368 +10 kernel32.dll BaseThreadInitThunk
thread $1068:
776f0166 +0e ntdll.dll NtWaitForMultipleObjects
75303368 +10 kernel32.dll BaseThreadInitThunk
thread $112c:
776f0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
75303368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13f8) at:
734a2713 +24f netbios.dll Netbios
thread $1074:
776ef8da +0e ntdll.dll NtWaitForSingleObject
76f015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7530118f +3e kernel32.dll WaitForSingleObjectEx
75301143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
75303368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13f8) at:
73644c95 +00 winspool.drv
thread $458:
776f1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75303368 +10 kernel32.dll BaseThreadInitThunk
thread $a64:
776f1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75303368 +10 kernel32.dll BaseThreadInitThunk
thread $a70:
776f1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75303368 +10 kernel32.dll BaseThreadInitThunk
modules:
001c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00290000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
025b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02690000 BCLW32.dll C:\Program
Files (x86)\Store
045e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06390000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70760000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70c30000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70c90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70cb0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70cd0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
710f0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
71130000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
711f0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71430000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71470000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71490000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
717e0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71960000 webio.dll 6.1.7601.23375 C:\Windows\
system32
719b0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71a10000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72500000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72520000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725c0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72600000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
727b0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
727d0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
727e0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72ec0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
72f40000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73420000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73470000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
734a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
734b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
734c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
734d0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73530000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73630000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73910000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73d10000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73f20000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
740a0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
740f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74120000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74150000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74190000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
741b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
741c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
741d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74230000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
742a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74440000 version.dll 6.1.7600.16385 C:\Windows\
system32
74450000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74f60000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74f70000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74fd0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
74ff0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75000000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75020000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75100000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
751f0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75200000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
752a0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
752f0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75400000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75410000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
754a0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75750000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75880000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75890000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
764e0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76630000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76730000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76740000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
767c0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76a00000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76a60000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76b00000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76b90000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76cf0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76d30000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76d60000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76d70000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76e20000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76ef0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76f40000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76fb0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76fc0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76fd0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77000000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77230000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77250000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
772b0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
776a0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
776d0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0340 svchost.exe 0 0 0
038c svchost.exe 0 0 0
03e0 MsMpEng.exe 0 0 0
0170 RapportMgmtService.exe 0 0 0
02b0 svchost.exe 0 0 0
0308 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
04b0 svchost.exe 0 0 0
0514 igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
0760 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f4 OSPPSVC.EXE 0 0 0
0688 svchost.exe 0 0 0
04a4 scpbradserv.exe 0 0 0
00bc svchost.exe 0 0 0
080c core.exe 0 0 0
0978 RapportInjService_x64.exe 0 0 0
0a28 fbserver.exe 0 0 0
0ba0 WUDFHost.exe 0 0 0
0858 NisSrv.exe 0 0 0
0da4 taskhost.exe 1 26 24 normal
0dc0 core.exe 1 9 21 normal
0e04 PresentationFontCache.exe 0 0 0
0e38 dwm.exe 1 17 4 high
0e88 explorer.exe 1 512 338 normal
0a1c scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0d5c RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0940 msseces.exe 1 143 59 normal
0fa4 PrnStatusMX.exe 1 23 18 normal
0f44 igfxEM.exe 1 14 14 normal
0d80 igfxHK.exe 1 14 12 normal
021c SearchIndexer.exe 0 0 0
1034 RapportInjService_x64.exe 1 4 3 normal
1090 GoogleCrashHandler.exe 0 0 0
10a0 GoogleCrashHandler64.exe 0 0 0
10ac WmiPrvSE.exe 0 0 0
126c svchost.exe 0 0 0
13f4 Store.exe 1 3328 649 normal C:\Program Files (x86)\Store
11b8 wuauclt.exe 1 12 6 normal
0d54 splwow64.exe 1 9 5 normal
0a90 Store.exe 1 209 185 normal C:\Program Files (x86)\Store
0a0c DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0bd0 OIS.EXE 1 99 47 normal
0954 OIS.EXE 1 109 41 normal
04f4 OIS.EXE 1 88 38 normal
0534 chrome.exe 1 81 62 normal
152c chrome.exe 1 9 4 normal
14c4 chrome.exe 1 7 9 above normal
0450 chrome.exe 1 4 1 normal
0cec chrome.exe 1 4 1 normal
1084 chrome.exe 1 4 1 normal
1178 chrome.exe 1 4 3 normal
0c60 OIS.EXE 1 108 106 normal
115c OIS.EXE 1 81 39 normal
0df0 chrome.exe 1 4 1 idle
1420 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a2eca70
ebx = 00003303
ecx = 00000000
edx = 002e2ac8
esi = 0018d174
edi = 0066cb50
eip = 0066ea6e
esp = 0018d138
ebp = 0018d1a0
stack dump:
0018d138 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018d148 4c d1 18 00 6e ea 66 00 - 70 ca 2e 0a 03 33 00 00 L...n.f.p....3..
0018d158 74 d1 18 00 50 cb 66 00 - a0 d1 18 00 68 d1 18 00 t...P.f.....h...
0018d168 20 d8 51 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 .Q.z.f...g.....
0018d178 20 d8 51 06 00 00 00 00 - 9b e8 67 00 ac d1 18 00 .Q.......g.....
0018d188 0c 89 40 00 a0 d1 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018d198 d5 e9 67 01 20 d8 51 06 - c8 d1 18 00 f3 e8 67 00 ..g. .Q.......g.
0018d1a8 12 4d 67 00 e0 d1 18 00 - 0c 89 40 00 c8 d1 18 00 .Mg.......@.....
0018d1b8 20 d8 51 06 00 00 00 00 - 00 00 00 00 20 d8 51 06 .Q......... .Q.
0018d1c8 f4 d1 18 00 b6 92 67 00 - b8 d7 18 00 e0 a1 73 05 ......g.......s.
0018d1d8 01 00 00 00 e3 73 65 00 - 00 d2 18 00 0c 89 40 00 .....se.......@.
0018d1e8 f4 d1 18 00 e0 a1 73 05 - 20 d8 51 06 c4 d2 18 00 ......s. .Q.....
0018d1f8 2a 72 65 00 e8 eb 12 01 - cc d2 18 00 0c 89 40 00 *re...........@.
0018d208 c4 d2 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d218 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d228 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d238 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d248 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d258 00 00 00 00 00 00 00 00 - 00 92 e5 40 a0 b9 4a 06 [email protected].
0018d268 00 00 00 00 fa a4 4f fa - 1f 92 e5 40 00 00 00 00 ......O....@....
disassembling:
[...]
0112ebbf mov eax, [ebp-$18]
0112ebc2 mov eax, [eax+$250]
0112ebc8 mov ecx, [eax]
0112ebca call dword ptr [ecx+$38]
0112ebcd 425 mov edx, $112fc20
0112ebd2 mov eax, [ebp-$18]
0112ebd5 mov eax, [eax+$250]
0112ebdb mov ecx, [eax]
0112ebdd call dword ptr [ecx+$38]
0112ebe0 427 mov eax, [ebp-$18]
0112ebe3 > call -$ad79c8 ($657220) ; Data.DB.TDataSet.Open
0112ebe8 428 mov eax, [ebp-$18]
0112ebeb call -$ad5108 ($659ae8) ; Data.DB.TDataSet.First
0112ebf0 429 mov eax, [ebp-$18]
0112ebf3 cmp byte ptr [eax+$a9], 0
0112ebfa jz loc_112ec08
0112ebfc mov eax, [ebp-$18]
0112ebff cmp byte ptr [eax+$a8], 0
0112ec06 jnz loc_112ec17
0112ec08 431 mov eax, [ebp-4]
0112ec0b call +$33080 ($1161c90) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $1064:
776ef8da +0e ntdll.dll NtWaitForSingleObject
76f015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7530118f +3e kernel32.dll WaitForSingleObjectEx
75301143 +0d kernel32.dll WaitForSingleObject
75303368 +10 kernel32.dll BaseThreadInitThunk
thread $1068:
776f0166 +0e ntdll.dll NtWaitForMultipleObjects
75303368 +10 kernel32.dll BaseThreadInitThunk
thread $112c:
776f0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
75303368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13f8) at:
734a2713 +24f netbios.dll Netbios
thread $1074:
776ef8da +0e ntdll.dll NtWaitForSingleObject
76f015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7530118f +3e kernel32.dll WaitForSingleObjectEx
75301143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
75303368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13f8) at:
73644c95 +00 winspool.drv
thread $a64:
776f1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75303368 +10 kernel32.dll BaseThreadInitThunk
thread $a70:
776f1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75303368 +10 kernel32.dll BaseThreadInitThunk
modules:
001c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00290000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
025b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02690000 BCLW32.dll C:\Program
Files (x86)\Store
045e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06390000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70760000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70c30000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70c90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70cb0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70cd0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
710f0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
71130000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
711f0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71430000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71470000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71490000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
717e0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71960000 webio.dll 6.1.7601.23375 C:\Windows\
system32
719b0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71a10000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72500000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72520000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725c0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72600000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
727b0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
727d0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
727e0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72ec0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
72f40000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73420000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73470000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
734a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
734b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
734c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
734d0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73530000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73630000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73910000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73d10000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73f20000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
740a0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
740f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74120000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74150000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74190000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
741b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
741c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
741d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74230000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
742a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74440000 version.dll 6.1.7600.16385 C:\Windows\
system32
74450000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74f60000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74f70000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74fd0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
74ff0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75000000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75010000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75020000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75100000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
751f0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75200000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
752a0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
752f0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75400000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75410000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
754a0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75750000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75880000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75890000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
764e0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76630000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76730000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76740000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
767c0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76a00000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76a60000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76b00000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76b90000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76cf0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76d30000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76d60000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76d70000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76e20000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76ef0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76f40000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76fb0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76fc0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76fd0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77000000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77230000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77250000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
772b0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
776a0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
776d0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0340 svchost.exe 0 0 0
038c svchost.exe 0 0 0
03e0 MsMpEng.exe 0 0 0
0170 RapportMgmtService.exe 0 0 0
02b0 svchost.exe 0 0 0
0308 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
04b0 svchost.exe 0 0 0
0514 igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
0760 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f4 OSPPSVC.EXE 0 0 0
0688 svchost.exe 0 0 0
04a4 scpbradserv.exe 0 0 0
00bc svchost.exe 0 0 0
080c core.exe 0 0 0
0978 RapportInjService_x64.exe 0 0 0
0a28 fbserver.exe 0 0 0
0ba0 WUDFHost.exe 0 0 0
0858 NisSrv.exe 0 0 0
0da4 taskhost.exe 1 26 23 normal
0dc0 core.exe 1 9 21 normal
0e04 PresentationFontCache.exe 0 0 0
0e38 dwm.exe 1 17 4 high
0e88 explorer.exe 1 514 339 normal
0a1c scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0d5c RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0940 msseces.exe 1 143 59 normal
0fa4 PrnStatusMX.exe 1 23 18 normal
0f44 igfxEM.exe 1 14 14 normal
0d80 igfxHK.exe 1 14 12 normal
021c SearchIndexer.exe 0 0 0
1034 RapportInjService_x64.exe 1 4 3 normal
1090 GoogleCrashHandler.exe 0 0 0
10a0 GoogleCrashHandler64.exe 0 0 0
10ac WmiPrvSE.exe 0 0 0
126c svchost.exe 0 0 0
13f4 Store.exe 1 3341 513 normal C:\Program Files (x86)\Store
11b8 wuauclt.exe 1 12 6 normal
0d54 splwow64.exe 1 9 6 normal
0a90 Store.exe 1 209 185 normal C:\Program Files (x86)\Store
0a0c DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0bd0 OIS.EXE 1 99 47 normal
0954 OIS.EXE 1 109 41 normal
04f4 OIS.EXE 1 88 38 normal
0534 chrome.exe 1 81 62 normal
152c chrome.exe 1 9 4 normal
14c4 chrome.exe 1 7 9 above normal
0450 chrome.exe 1 4 1 normal
0cec chrome.exe 1 4 1 normal
1084 chrome.exe 1 4 1 normal
1178 chrome.exe 1 4 3 normal
0c60 OIS.EXE 1 108 106 normal
115c OIS.EXE 1 81 39 normal
0df0 chrome.exe 1 4 1 idle
1420 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 064eec98
ebx = 00003303
ecx = 00000000
edx = 002e2ac8
esi = 0018ea0c
edi = 0066cb50
eip = 0066ea6e
esp = 0018e9d0
ebp = 0018ea38
stack dump:
0018e9d0 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e9e0 e4 e9 18 00 6e ea 66 00 - 98 ec 4e 06 03 33 00 00 ....n.f...N..3..
0018e9f0 0c ea 18 00 50 cb 66 00 - 38 ea 18 00 00 ea 18 00 ....P.f.8.......
0018ea00 20 d8 51 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 .Q.z.f...g.....
0018ea10 20 d8 51 06 00 00 00 00 - 9b e8 67 00 44 ea 18 00 .Q.......g.D...
0018ea20 0c 89 40 00 38 ea 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018ea30 d5 e9 67 01 20 d8 51 06 - 60 ea 18 00 f3 e8 67 00 ..g. .Q.`.....g.
0018ea40 12 4d 67 00 78 ea 18 00 - 0c 89 40 00 60 ea 18 00 .Mg.x.....@.`...
0018ea50 20 d8 51 06 00 00 00 00 - 00 00 00 00 20 d8 51 06 .Q......... .Q.
0018ea60 8c ea 18 00 b6 92 67 00 - b0 95 3a 0c 00 00 00 00 ......g...:.....
0018ea70 01 00 00 00 e3 73 65 00 - 98 ea 18 00 0c 89 40 00 .....se.......@.
0018ea80 8c ea 18 00 40 d6 49 04 - 20 d8 51 06 5c eb 18 00 [email protected]. .Q.\...
0018ea90 2a 72 65 00 e8 eb 12 01 - 64 eb 18 00 0c 89 40 00 *re.....d.....@.
0018eaa0 5c eb 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 \...............
0018eab0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eac0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ead0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eae0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eaf0 00 00 00 00 00 00 00 00 - 00 92 e5 40 a0 b9 4a 06 [email protected].
0018eb00 00 00 00 00 fa a4 4f fa - 1f 92 e5 40 00 00 00 00 ......O....@....
disassembling:
[...]
0112ebbf mov eax, [ebp-$18]
0112ebc2 mov eax, [eax+$250]
0112ebc8 mov ecx, [eax]
0112ebca call dword ptr [ecx+$38]
0112ebcd 425 mov edx, $112fc20
0112ebd2 mov eax, [ebp-$18]
0112ebd5 mov eax, [eax+$250]
0112ebdb mov ecx, [eax]
0112ebdd call dword ptr [ecx+$38]
0112ebe0 427 mov eax, [ebp-$18]
0112ebe3 > call -$ad79c8 ($657220) ; Data.DB.TDataSet.Open
0112ebe8 428 mov eax, [ebp-$18]
0112ebeb call -$ad5108 ($659ae8) ; Data.DB.TDataSet.First
0112ebf0 429 mov eax, [ebp-$18]
0112ebf3 cmp byte ptr [eax+$a9], 0
0112ebfa jz loc_112ec08
0112ebfc mov eax, [ebp-$18]
0112ebff cmp byte ptr [eax+$a8], 0
0112ec06 jnz loc_112ec17
0112ec08 431 mov eax, [ebp-4]
0112ec0b call +$33080 ($1161c90) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $1064:
776ef8da +0e ntdll.dll NtWaitForSingleObject
76f015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7530118f +3e kernel32.dll WaitForSingleObjectEx
75301143 +0d kernel32.dll WaitForSingleObject
75303368 +10 kernel32.dll BaseThreadInitThunk
thread $1068:
776f0166 +0e ntdll.dll NtWaitForMultipleObjects
75303368 +10 kernel32.dll BaseThreadInitThunk
thread $112c:
776f0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
75303368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13f8) at:
734a2713 +24f netbios.dll Netbios
thread $1074:
776ef8da +0e ntdll.dll NtWaitForSingleObject
76f015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7530118f +3e kernel32.dll WaitForSingleObjectEx
75301143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
75303368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13f8) at:
73644c95 +00 winspool.drv
thread $1744:
776f1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75303368 +10 kernel32.dll BaseThreadInitThunk
modules:
001c0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00290000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
025b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02690000 BCLW32.dll C:\Program
Files (x86)\Store
045e0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06390000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70760000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70c30000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70c90000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70cb0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70cd0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
710f0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
71130000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
711f0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71430000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71470000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71490000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
717e0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71960000 webio.dll 6.1.7601.23375 C:\Windows\
system32
719b0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71a10000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72500000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72520000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725c0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72600000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
727b0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
727d0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
727e0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72ec0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
72f40000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73420000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73470000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
734a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
734b0000 security.dll 6.1.7600.16385 C:\Windows\
system32
734c0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
734d0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73530000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73630000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73910000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
73d10000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73f20000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
740a0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
740f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74120000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74150000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74190000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
741b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
741c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
741d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74230000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
742a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74440000 version.dll 6.1.7600.16385 C:\Windows\
system32
74450000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74f60000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74f70000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74fd0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
74ff0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75000000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75010000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75020000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75100000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
751f0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75200000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
752a0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
752f0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75400000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75410000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
754a0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75750000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
75880000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75890000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
764e0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76630000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76730000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76740000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
767c0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76a00000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76a60000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76b00000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76b90000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76cf0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76d30000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76d60000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76d70000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76e20000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76ef0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76f40000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76fb0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76fc0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76fd0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
77000000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77230000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77250000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
772b0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
776a0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
776d0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0340 svchost.exe 0 0 0
038c svchost.exe 0 0 0
03e0 MsMpEng.exe 0 0 0
0170 RapportMgmtService.exe 0 0 0
02b0 svchost.exe 0 0 0
0308 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0420 svchost.exe 0 0 0
04b0 svchost.exe 0 0 0
0514 igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f8 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
0760 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f4 OSPPSVC.EXE 0 0 0
0688 svchost.exe 0 0 0
04a4 scpbradserv.exe 0 0 0
00bc svchost.exe 0 0 0
080c core.exe 0 0 0
0978 RapportInjService_x64.exe 0 0 0
0a28 fbserver.exe 0 0 0
0ba0 WUDFHost.exe 0 0 0
0858 NisSrv.exe 0 0 0
0da4 taskhost.exe 1 26 22 normal
0dc0 core.exe 1 9 21 normal
0e04 PresentationFontCache.exe 0 0 0
0e38 dwm.exe 1 17 4 high
0e88 explorer.exe 1 526 350 normal
0a1c scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0d5c RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0940 msseces.exe 1 143 59 normal
0fa4 PrnStatusMX.exe 1 23 18 normal
0f44 igfxEM.exe 1 14 14 normal
0d80 igfxHK.exe 1 14 12 normal
021c SearchIndexer.exe 0 0 0
1034 RapportInjService_x64.exe 1 4 3 normal
1090 GoogleCrashHandler.exe 0 0 0
10a0 GoogleCrashHandler64.exe 0 0 0
10ac WmiPrvSE.exe 0 0 0
126c svchost.exe 0 0 0
13f4 Store.exe 1 3693 536 normal C:\Program Files (x86)\Store
11b8 wuauclt.exe 1 12 6 normal
0d54 splwow64.exe 1 9 3 normal
0a90 Store.exe 1 226 185 normal C:\Program Files (x86)\Store
0a0c DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0bd0 OIS.EXE 1 99 47 normal
0954 OIS.EXE 1 109 41 normal
04f4 OIS.EXE 1 88 38 normal
0534 chrome.exe 1 82 64 normal
152c chrome.exe 1 9 4 normal
14c4 chrome.exe 1 8 9 above normal
0450 chrome.exe 1 4 1 normal
0cec chrome.exe 1 4 1 normal
1084 chrome.exe 1 4 1 normal
1178 chrome.exe 1 4 3 normal
0c60 OIS.EXE 1 108 106 normal
115c OIS.EXE 1 81 39 normal
0f08 chrome.exe 1 4 1 idle
17dc chrome.exe 1 4 1 idle
0e98 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 065f6480
ebx = 0a2d9a40
ecx = 00000000
edx = 002e2ac8
esi = 00000006
edi = 0ac37760
eip = 00610d9a
esp = 0018ddfc
ebp = 0018de40
stack dump:
0018ddfc 9a 0d 61 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..a.............
0018de0c 10 de 18 00 9a 0d 61 00 - 80 64 5f 06 40 9a 2d 0a [email protected].
0018de1c 06 00 00 00 60 77 c3 0a - 40 de 18 00 2c de 18 00 ....`w..@...,...
0018de2c 90 de 18 00 0c 89 40 00 - 40 de 18 00 00 00 00 00 ......@.@.......
0018de3c 00 00 00 00 40 9a 2d 0a - 46 ea 60 00 70 de 18 00 [email protected].`.p...
0018de4c 11 00 00 00 06 00 00 00 - 60 77 c3 0a b7 77 53 00 ........`w...wS.
0018de5c 90 b8 5f 06 34 86 0e 01 - 06 00 00 00 90 b8 5f 06 .._.4........._.
0018de6c 40 9a 2d 0a 84 de 18 00 - 95 0f 6a 00 3c 4e 0a 0b @.-.......j.<N..
0018de7c 11 00 00 00 00 00 00 00 - b0 de 18 00 45 38 6a 00 ............E8j.
0018de8c 3c 4e 0a 0b ec de 18 00 - 0c 89 40 00 b0 de 18 00 <N........@.....
0018de9c 3c 4e 0a 0b 00 00 00 00 - 11 00 00 00 06 00 00 00 <N..............
0018deac 90 b8 5f 06 c0 de 18 00 - 85 8d 7b 00 3c 4e 0a 0b .._.......{.<N..
0018debc 90 b8 5f 06 e0 de 18 00 - 50 cf 89 00 3c 4e 0a 0b .._.....P...<N..
0018decc 00 00 00 00 f8 ce 89 00 - 90 b8 5f 06 06 00 00 00 .........._.....
0018dedc 11 00 00 00 04 df 18 00 - f4 04 6a 00 3c 4e 0a 0b ..........j.<N..
0018deec 0c df 18 00 0c 89 40 00 - 04 df 18 00 30 e1 18 00 [email protected]...
0018defc 90 b8 5f 06 00 00 00 00 - 1c df 18 00 11 03 6a 00 .._...........j.
0018df0c 34 df 18 00 0c 89 40 00 - 1c df 18 00 90 b8 5f 06 4.....@......._.
0018df1c 6c df 18 00 40 9d 69 00 - eb 03 8a 00 90 b8 5f 06 [email protected]......._.
0018df2c b5 27 84 00 dd 27 84 00 - 00 e1 18 00 0c 89 40 00 .'...'........@.
disassembling:
010e8614 public UnitStatusProducao.TfrmStatusProducao.GridSetEditText: ;
function entry point
010e8614 853 push ebp
010e8615 mov ebp, esp
010e8617 add esp, -$c
010e861a mov [ebp-$c], ecx
010e861d mov [ebp-8], edx
010e8620 mov [ebp-4], eax
010e8623 854 mov eax, [ebp-4]
010e8626 mov eax, [eax+$3d0]
010e862c mov edx, [eax]
010e862e > call dword ptr [edx+$f4]
010e8634 856 mov esp, ebp
010e8636 pop ebp
010e8637 ret 8
thread $13e4:
773ff8da +0e ntdll.dll NtWaitForSingleObject
76af15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76bd118f +3e kernel32.dll WaitForSingleObjectEx
76bd1143 +0d kernel32.dll WaitForSingleObject
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $13e8:
77400166 +0e ntdll.dll NtWaitForMultipleObjects
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $13f4:
77400166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76bd3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13d8) at:
73882713 +24f netbios.dll Netbios
thread $fec:
77401f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $1178:
77401f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $11b4:
77401f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $1188:
77401e27 +0b ntdll.dll NtTraceControl
77439fc9 +40 ntdll.dll EtwpNotificationThread
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $1084:
77401f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $b1c:
773ff8da +0e ntdll.dll NtWaitForSingleObject
76af15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76bd118f +3e kernel32.dll WaitForSingleObjectEx
76bd1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76bd3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($13d8) at:
73ba4c95 +00 winspool.drv
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00310000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
043c0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06310000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6e680000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
6fdb0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
6fdc0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
6fde0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
6fdf0000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
6fe10000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70690000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70a80000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70ae0000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
70db0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70e90000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
710e0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71280000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
712c0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71300000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71320000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71330000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71910000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71960000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
719c0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72210000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72230000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
722d0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72310000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
724c0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
724e0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
724f0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73530000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73630000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73660000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
736c0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73870000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73880000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73890000 security.dll 6.1.7600.16385 C:\Windows\
system32
738a0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73b90000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73db0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73e00000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73e30000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73e60000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73ea0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73ec0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73ed0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73ee0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73ef0000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
73f40000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73f80000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
73f90000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
73fb0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74150000 version.dll 6.1.7600.16385 C:\Windows\
system32
74160000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74c70000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74c80000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74ce0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
74d80000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
74ed0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75110000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75170000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75270000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75310000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75400000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
75490000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
754b0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75560000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
75580000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75590000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
755b0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
756e0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75760000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
757a0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75850000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
764a0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76530000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76540000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76820000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76830000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
768d0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76900000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76920000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76930000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ad0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76ae0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76b90000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76bc0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76cd0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76e30000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e40000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76e50000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76e60000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76f30000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76f80000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
773b0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
773e0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
032c svchost.exe 0 0 0
0378 svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0304 svchost.exe 0 0 0
03f4 svchost.exe 0 0 0
041c svchost.exe 0 0 0
0474 audiodg.exe 0 0 0
04a4 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0668 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0730 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
0778 svchost.exe 0 0 0
078c NetExpressUpdater.exe 0 0 0
07e4 OSPPSVC.EXE 0 0 0
05a0 svchost.exe 0 0 0
0690 scpbradserv.exe 0 0 0
06a4 svchost.exe 0 0 0
04fc core.exe 0 0 0
0990 RapportInjService_x64.exe 0 0 0
0a30 fbserver.exe 0 0 0
0bd4 WUDFHost.exe 0 0 0
0868 NisSrv.exe 0 0 0
0f34 WmiPrvSE.exe 0 0 0
0f08 taskhost.exe 1 26 24 normal
0f28 core.exe 1 9 19 normal
0fe0 PresentationFontCache.exe 0 0 0
0ff0 dwm.exe 1 16 2 high
0c88 explorer.exe 1 361 223 normal
0d70 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\scpbrad
0a94 RapportService.exe 1 14 18 normal C:\Program Files (x86)\Trusteer\
Rapport\bin
07e0 igfxEM.exe 1 14 13 normal
0b38 igfxHK.exe 1 14 12 normal
0784 svchost.exe 0 0 0
0928 msseces.exe 1 143 59 normal
0ee8 PrnStatusMX.exe 1 23 18 normal
0de8 RapportInjService_x64.exe 1 4 3 normal
0704 GoogleCrashHandler.exe 0 0 0
0408 GoogleCrashHandler64.exe 0 0 0
0f5c SearchIndexer.exe 0 0 0
0f88 WmiPrvSE.exe 0 0 0
0df8 sppsvc.exe 0 0 0
112c SearchProtocolHost.exe 0 0 0
1140 SearchFilterHost.exe 0 0 0 idle
1204 VSSVC.exe 0 0 0
122c svchost.exe 0 0 0
1388 TrustedInstaller.exe 0 0 0
13d4 Store.exe 1 189 227 normal C:\Program Files (x86)\Store
0fe8 wuauclt.exe 1 12 6 normal
1358 WMIADAP.exe 0 0 0
03d0 WmiPrvSE.exe 0 0 0
1008 splwow64.exe 1 9 3 normal
0ef8 rundll32.exe 1 116 46 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 0645c390
ecx = 04453890
edx = 0444fc70
esi = 00593bec
edi = 0018de60
eip = 006fa3da
esp = 0018dcec
ebp = 0018de54
stack dump:
0018dcec ec 3b 59 00 d0 5b 82 0a - ed 04 53 00 d0 5b 82 0a .;Y..[....S..[..
0018dcfc f1 3b 59 00 96 09 53 00 - 08 00 05 00 08 00 00 00 .;Y...S.........
0018dd0c 05 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
0018dd1c 16 00 00 00 08 00 05 00 - d0 5b 82 0a 60 de 18 00 .........[..`...
0018dd2c 94 ff 52 00 08 00 05 00 - 5c df 18 00 d0 5b 82 0a ..R.....\....[..
0018dd3c d0 5b 82 0a c1 01 00 00 - 05 00 00 00 00 00 00 00 .[..............
0018dd4c c8 dd 18 00 1f b0 23 72 - 80 76 67 02 f0 02 03 00 ......#r.vg.....
0018dd5c 02 02 00 00 0f 00 00 00 - c1 01 05 00 00 00 00 00 ................
0018dd6c bb 80 23 72 8e 81 23 72 - 00 00 00 00 c1 01 05 00 ..#r..#r........
0018dd7c f0 02 03 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd9c 00 00 00 00 00 00 00 00 - bb 80 23 72 01 00 00 00 ..........#r....
0018ddac 44 de 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 D...............
0018ddbc 00 00 00 00 00 00 00 00 - f2 7a 7b e7 f4 dd 18 00 .........z{.....
0018ddcc fa 62 18 75 f0 02 03 00 - 02 02 00 00 00 00 00 00 .b.u............
0018dddc c1 01 05 00 bb 80 23 72 - cd ab ba dc 00 00 00 00 ......#r........
0018ddec 00 00 00 00 0c de 18 00 - cf fb 52 00 d0 5b 82 0a ..........R..[..
0018ddfc 0a b0 00 00 00 00 00 00 - 08 00 05 00 01 00 00 00 ................
0018de0c 40 de 18 00 41 40 53 00 - 08 00 05 00 d0 34 45 04 @[email protected].
0018de1c 00 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
disassembling:
[...]
006fa3ae mov edx, [$6e9910]
006fa3b4 call -$2f2b11 ($4078a8) ; System.@IsClass
006fa3b9 test al, al
006fa3bb jnz loc_6fa3ca
006fa3bd 402 mov eax, [ebx+$460]
006fa3c3 call +$cd78 ($707140) ; QRPrntr.TQRPrinter.Print
006fa3c8 jmp loc_6fa3f4
006fa3ca 405 mov eax, [$15c48cc]
006fa3cf call -$741c ($6f2fb8) ; QuickRpt.TCustomQuickRep.Print
006fa3d4 407 mov eax, [ebx+$3cc]
006fa3da > cmp dword ptr [eax+$2b8], 0
006fa3e1 jnz loc_6fa3f4
006fa3e3 409 mov edx, [$15c48cc]
006fa3e9 mov edx, [edx+$36c]
006fa3ef call +$9920 ($703d14) ; QRPrntr.TQRPreview.SetQRPrinter
006fa3f4 412 pop esi
006fa3f5 pop ebx
006fa3f6 ret
thread $750:
770c0166 +0e ntdll.dll NtWaitForMultipleObjects
752d3368 +10 kernel32.dll BaseThreadInitThunk
thread $125c:
770c0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
752d3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d48) at:
734a2713 +24f netbios.dll Netbios
thread $328:
770bf8da +0e ntdll.dll NtWaitForSingleObject
75a915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
752d118f +3e kernel32.dll WaitForSingleObjectEx
752d1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
752d3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d48) at:
73624c95 +00 winspool.drv
thread $47c:
770c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
752d3368 +10 kernel32.dll BaseThreadInitThunk
modules:
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02620000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02650000 BCLW32.dll C:\Program
Files (x86)\Store
06270000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06300000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6e520000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70410000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70420000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70740000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70760000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70770000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70da0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70de0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70e10000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70e60000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
70f80000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71330000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71380000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
713e0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71ed0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71ef0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71f90000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71fd0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72180000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
721a0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
721b0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
729c0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73470000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
734a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
734b0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73510000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73610000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73670000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
736c0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
737d0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73810000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73860000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73a70000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73ac0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73af0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73b20000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73b60000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73b80000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73b90000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73ba0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73c00000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73c70000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73e10000 version.dll 6.1.7600.16385 C:\Windows\
system32
73e20000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74930000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74940000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
749b0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
74a60000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
74a80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74a90000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74c30000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
74cc0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
74d20000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
74dd0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
74f20000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74fa0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
74fc0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
74fd0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74fe0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75050000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75120000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75280000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
752c0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
753f0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
756a0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
758e0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75980000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75a80000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75b60000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75c50000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75cf0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75d00000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d10000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d20000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76970000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
769a0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76a30000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76a40000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76a50000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ab0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76ae0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76af0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76b70000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77070000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
770a0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
01a4 svchost.exe 0 0 0
041c svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
0514 igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0630 spoolsv.exe 0 0 0
0638 taskeng.exe 0 0 0
0670 svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0784 svchost.exe 0 0 0
079c NetExpressUpdater.exe 0 0 0
07ec OSPPSVC.EXE 0 0 0
05b8 svchost.exe 0 0 0
06a4 scpbradserv.exe 0 0 0
0778 svchost.exe 0 0 0
0828 core.exe 0 0 0
097c RapportInjService_x64.exe 0 0 0
0a24 fbserver.exe 0 0 0
0bc8 WUDFHost.exe 0 0 0
0bf0 NisSrv.exe 0 0 0
0f44 WmiPrvSE.exe 0 0 0
0de8 taskhost.exe 1 26 23 normal
0e10 core.exe 1 9 21 normal
0e84 PresentationFontCache.exe 0 0 0
095c dwm.exe 1 17 4 high
0eb0 explorer.exe 1 488 269 normal
0fa0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0960 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0a58 igfxEM.exe 1 14 13 normal
05e0 igfxHK.exe 1 14 13 normal
0c94 msseces.exe 1 143 59 normal
0ca4 PrnStatusMX.exe 1 23 18 normal
0fe8 RapportInjService_x64.exe 1 4 3 normal
0658 GoogleCrashHandler.exe 0 0 0
0e90 svchost.exe 0 0 0
0954 SearchIndexer.exe 0 0 0
11ac GoogleCrashHandler64.exe 0 0 0
1124 wuauclt.exe 1 12 7 normal
11d0 Store.exe 1 416 233 normal C:\Program Files (x86)\Store
0740 OIS.EXE 1 95 47 normal
1174 Store.exe 1 138 185 normal C:\Program Files (x86)\Store
07e0 OIS.EXE 1 102 52 normal
1110 chrome.exe 1 77 66 normal
10fc chrome.exe 1 9 4 normal
0d5c chrome.exe 1 7 7 above normal
0ba0 chrome.exe 1 4 1 normal
13b4 chrome.exe 1 4 1 normal
112c chrome.exe 1 4 1 idle
10c4 chrome.exe 1 4 1 idle
1028 chrome.exe 1 4 3 normal
0680 splwow64.exe 1 9 3 normal
0410 audiodg.exe 0 0 0
11e0 SearchProtocolHost.exe 0 0 0
0d00 SearchFilterHost.exe 0 0 0 idle
10d0 OIS.EXE 1 109 39 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 0018de01
ecx = 00700398
edx = 0018de01
esi = 00593bec
edi = 043c3790
eip = 00705bfa
esp = 0018dc7c
ebp = 0018dca4
stack dump:
0018dc7c 67 58 70 00 20 de 18 00 - ec 3b 59 00 80 42 45 06 gXp. ....;Y..BE.
0018dc8c f7 75 40 00 a8 30 6f 00 - e2 30 6f 00 70 39 3c 04 [email protected]<.
0018dc9c 50 26 35 04 b0 10 34 04 - 14 de 18 00 d4 a3 6f 00 P&5...4.......o.
0018dcac ec 3b 59 00 50 25 5f 0a - ed 04 53 00 50 25 5f 0a .;Y.P%_...S.P%_.
0018dcbc f1 3b 59 00 96 09 53 00 - 08 00 0a 00 08 00 00 00 .;Y...S.........
0018dccc 0a 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
0018dcdc 16 00 00 00 08 00 0a 00 - 50 25 5f 0a 20 de 18 00 ........P%_. ...
0018dcec 94 ff 52 00 08 00 0a 00 - 1c df 18 00 50 25 5f 0a ..R.........P%_.
0018dcfc 50 25 5f 0a c1 01 00 00 - 0a 00 00 00 00 00 00 00 P%_.............
0018dd0c 88 dd 18 00 1f b0 ef 71 - f0 ab 29 00 18 05 02 00 .......q..).....
0018dd1c 02 02 00 00 0f 00 00 00 - c1 01 0a 00 00 00 00 00 ................
0018dd2c bb 80 ef 71 8e 81 ef 71 - d0 0f 35 04 c1 01 0a 00 ...q...q..5.....
0018dd3c 18 05 02 00 00 00 00 00 - d0 0f 35 04 00 00 00 00 ..........5.....
0018dd4c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd5c 00 00 00 00 00 00 00 00 - bb 80 ef 71 01 00 00 00 ...........q....
0018dd6c 04 de 18 00 00 00 00 00 - 00 00 01 00 00 00 00 01 ................
0018dd7c 07 00 00 00 00 00 00 00 - d3 f4 50 1d b4 dd 18 00 ..........P.....
0018dd8c fa 62 99 75 18 05 02 00 - 02 02 00 00 00 00 00 00 .b.u............
0018dd9c c1 01 0a 00 bb 80 ef 71 - cd ab ba dc 00 00 00 00 .......q........
0018ddac 00 00 00 00 cc dd 18 00 - cf fb 52 00 50 25 5f 0a ..........R.P%_.
disassembling:
00705bf4 public QRPrntr.TQRPrinter.GetUseStandardPrinter: ; function entry
point
00705bf4 3462 mov eax, [eax+$b8]
00705bfa > movzx eax, byte ptr [eax+$22]
00705bfe 3463 ret
thread $1284:
770bf8da +0e ntdll.dll NtWaitForSingleObject
75a915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
752d118f +3e kernel32.dll WaitForSingleObjectEx
752d1143 +0d kernel32.dll WaitForSingleObject
752d3368 +10 kernel32.dll BaseThreadInitThunk
thread $750:
770c0166 +0e ntdll.dll NtWaitForMultipleObjects
752d3368 +10 kernel32.dll BaseThreadInitThunk
thread $125c:
770c0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
752d3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d48) at:
734a2713 +24f netbios.dll Netbios
thread $328:
770bf8da +0e ntdll.dll NtWaitForSingleObject
75a915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
752d118f +3e kernel32.dll WaitForSingleObjectEx
752d1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
752d3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d48) at:
73624c95 +00 winspool.drv
thread $47c:
770c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
752d3368 +10 kernel32.dll BaseThreadInitThunk
modules:
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02620000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02650000 BCLW32.dll C:\Program
Files (x86)\Store
06270000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06300000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6e520000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70410000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70420000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70740000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70760000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70770000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70da0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70de0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70e10000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70e60000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
70f80000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71330000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71380000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
713e0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71ed0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71ef0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71f90000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71fd0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72180000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
721a0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
721b0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
729c0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73470000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
734a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
734b0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73510000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73610000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73670000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
736c0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
737d0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73810000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73860000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73a70000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73ac0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73af0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73b20000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73b60000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73b80000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73b90000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73ba0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73c00000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73c70000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73e10000 version.dll 6.1.7600.16385 C:\Windows\
system32
73e20000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74930000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74940000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
749a0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
749b0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
74a60000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
74a80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74a90000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74c30000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
74cc0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
74d20000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
74dd0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
74f20000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74fa0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
74fc0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
74fd0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74fe0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75050000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75120000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75280000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
752c0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
753f0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
756a0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
758e0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75980000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75a80000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75b60000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75c50000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75cf0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75d00000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d10000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d20000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76970000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
769a0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76a30000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76a40000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76a50000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ab0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76ae0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76af0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76b70000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77070000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
770a0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
01a4 svchost.exe 0 0 0
041c svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
0514 igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0630 spoolsv.exe 0 0 0
0638 taskeng.exe 0 0 0
0670 svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0784 svchost.exe 0 0 0
079c NetExpressUpdater.exe 0 0 0
07ec OSPPSVC.EXE 0 0 0
05b8 svchost.exe 0 0 0
06a4 scpbradserv.exe 0 0 0
0778 svchost.exe 0 0 0
0828 core.exe 0 0 0
097c RapportInjService_x64.exe 0 0 0
0a24 fbserver.exe 0 0 0
0bc8 WUDFHost.exe 0 0 0
0bf0 NisSrv.exe 0 0 0
0f44 WmiPrvSE.exe 0 0 0
0de8 taskhost.exe 1 26 24 normal
0e10 core.exe 1 9 21 normal
0e84 PresentationFontCache.exe 0 0 0
095c dwm.exe 1 17 4 high
0eb0 explorer.exe 1 476 267 normal
0fa0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0960 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0a58 igfxEM.exe 1 14 13 normal
05e0 igfxHK.exe 1 14 13 normal
0c94 msseces.exe 1 143 59 normal
0ca4 PrnStatusMX.exe 1 23 18 normal
0fe8 RapportInjService_x64.exe 1 4 3 normal
0658 GoogleCrashHandler.exe 0 0 0
0e90 svchost.exe 0 0 0
0954 SearchIndexer.exe 0 0 0
11ac GoogleCrashHandler64.exe 0 0 0
1124 wuauclt.exe 1 12 7 normal
11d0 Store.exe 1 418 238 normal C:\Program Files (x86)\Store
0740 OIS.EXE 1 95 47 normal
1174 Store.exe 1 138 185 normal C:\Program Files (x86)\Store
07e0 OIS.EXE 1 102 52 normal
1110 chrome.exe 1 77 66 normal
10fc chrome.exe 1 9 4 normal
0d5c chrome.exe 1 7 7 above normal
0ba0 chrome.exe 1 4 1 normal
13b4 chrome.exe 1 4 1 normal
112c chrome.exe 1 4 1 idle
10c4 chrome.exe 1 4 1 idle
1028 chrome.exe 1 4 3 normal
0680 splwow64.exe 1 9 3 normal
0410 audiodg.exe 0 0 0
10d0 OIS.EXE 1 109 39 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0047002e
ebx = 043c3790
ecx = 8b000001
edx = 00000000
esi = 043410b0
edi = 00000000
eip = 00487029
esp = 00188c0c
ebp = 00188c14
stack dump:
00188c0c 00 00 00 00 00 00 00 00 - 6c cc 18 00 ca 00 6d 00 ........l.....m.
00188c1c 00 00 00 00 00 00 00 00 - 70 cc 18 00 0c 89 40 00 ........p.....@.
00188c2c 6c cc 18 00 b0 10 34 04 - 90 37 3c 04 00 00 00 00 l.....4..7<.....
00188c3c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188c4c 00 00 00 00 00 00 00 00 - 90 37 3c 04 00 00 00 00 .........7<.....
00188c5c 2e 00 47 00 00 00 00 00 - 00 00 00 00 01 00 00 00 ..G.............
00188c6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188c7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188c8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188c9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188cac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188cbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188ccc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188cdc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188cec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188cfc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d2c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d3c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
006d00a3 push ebp
006d00a4 push $6d0414 ; System.@HandleFinally
006d00a9 push dword ptr fs:[eax]
006d00ac mov fs:[eax], esp
006d00af 339 call -$277ea8 ($45820c) ; System.SysUtils.Now
006d00b4 fstp qword ptr [$15c4828]
006d00ba wait
006d00bb 340 push 0
006d00bd push 0
006d00bf mov eax, [ebp-$4010]
006d00c5 > call -$2490ae ($48701c) ; System.Classes.TStream.SetPosition
006d00ca 341 xor eax, eax
006d00cc mov [ebp-$400c], eax
006d00d2 342 xor eax, eax
006d00d4 mov [ebp-$4014], eax
006d00da 343 push ebp
006d00db call -$21c ($6cfec4) ; LZW.InitTable
006d00e0 pop ecx
006d00e1 344 push ebp
006d00e2 call -$1bb ($6cff2c) ; LZW.ReadCode
006d00e7 pop ecx
[...]
thread $1284:
770bf8da +0e ntdll.dll NtWaitForSingleObject
75a915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
752d118f +3e kernel32.dll WaitForSingleObjectEx
752d1143 +0d kernel32.dll WaitForSingleObject
752d3368 +10 kernel32.dll BaseThreadInitThunk
thread $750:
770c0166 +0e ntdll.dll NtWaitForMultipleObjects
752d3368 +10 kernel32.dll BaseThreadInitThunk
thread $125c:
770c0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
752d3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d48) at:
734a2713 +24f netbios.dll Netbios
thread $328:
770bf8da +0e ntdll.dll NtWaitForSingleObject
75a915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
752d118f +3e kernel32.dll WaitForSingleObjectEx
752d1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
752d3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d48) at:
73624c95 +00 winspool.drv
thread $47c:
770c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
752d3368 +10 kernel32.dll BaseThreadInitThunk
modules:
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02620000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02650000 BCLW32.dll C:\Program
Files (x86)\Store
06270000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06300000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6e520000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70410000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70420000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70740000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70760000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70770000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70da0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70de0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70e10000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70e60000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
70f80000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71330000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71380000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
713e0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71ed0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71ef0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71f90000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71fd0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72180000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
721a0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
721b0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
729c0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73470000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
734a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
734b0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73510000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73610000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73670000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
736c0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
737d0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73810000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73860000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73a70000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73ac0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73af0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73b20000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73b60000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73b80000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73b90000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73ba0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73c00000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73c70000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73e10000 version.dll 6.1.7600.16385 C:\Windows\
system32
73e20000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74930000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74940000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
749a0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
749b0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
74a60000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
74a80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74a90000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74c30000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
74cc0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
74d20000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
74dd0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
74f20000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74fa0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
74fc0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
74fd0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74fe0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75050000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75120000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75280000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
752c0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
753f0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
756a0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
758e0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75980000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75a80000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75b60000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75c50000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75cf0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75d00000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d10000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d20000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76970000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
769a0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76a30000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76a40000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76a50000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ab0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76ae0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76af0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76b70000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77070000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
770a0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
01a4 svchost.exe 0 0 0
041c svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
0514 igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0630 spoolsv.exe 0 0 0
0638 taskeng.exe 0 0 0
0670 svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0784 svchost.exe 0 0 0
079c NetExpressUpdater.exe 0 0 0
07ec OSPPSVC.EXE 0 0 0
05b8 svchost.exe 0 0 0
06a4 scpbradserv.exe 0 0 0
0778 svchost.exe 0 0 0
0828 core.exe 0 0 0
097c RapportInjService_x64.exe 0 0 0
0a24 fbserver.exe 0 0 0
0bc8 WUDFHost.exe 0 0 0
0bf0 NisSrv.exe 0 0 0
0f44 WmiPrvSE.exe 0 0 0
0de8 taskhost.exe 1 26 23 normal
0e10 core.exe 1 9 21 normal
0e84 PresentationFontCache.exe 0 0 0
095c dwm.exe 1 17 4 high
0eb0 explorer.exe 1 476 267 normal
0fa0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0960 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0a58 igfxEM.exe 1 14 13 normal
05e0 igfxHK.exe 1 14 13 normal
0c94 msseces.exe 1 143 59 normal
0ca4 PrnStatusMX.exe 1 23 18 normal
0fe8 RapportInjService_x64.exe 1 4 3 normal
0658 GoogleCrashHandler.exe 0 0 0
0e90 svchost.exe 0 0 0
0954 SearchIndexer.exe 0 0 0
11ac GoogleCrashHandler64.exe 0 0 0
1124 wuauclt.exe 1 12 7 normal
11d0 Store.exe 1 401 231 normal C:\Program Files (x86)\Store
0740 OIS.EXE 1 95 47 normal
1174 Store.exe 1 138 185 normal C:\Program Files (x86)\Store
07e0 OIS.EXE 1 102 52 normal
1110 chrome.exe 1 77 66 normal
10fc chrome.exe 1 9 4 normal
0d5c chrome.exe 1 7 7 above normal
0ba0 chrome.exe 1 4 1 normal
13b4 chrome.exe 1 4 1 normal
112c chrome.exe 1 4 1 idle
10c4 chrome.exe 1 4 1 idle
1028 chrome.exe 1 4 3 normal
0680 splwow64.exe 1 9 3 normal
0410 audiodg.exe 0 0 0
10d0 OIS.EXE 1 109 39 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 7e3f77ee
ebx = 00180100
ecx = 000204c0
edx = 043b4701
esi = 043410b0
edi = 0018e36c
eip = 0034005f
esp = 0018e07c
ebp = 0018e1b4
stack dump:
0018e07c f7 75 40 00 f5 1d 6f 00 - b0 10 34 04 01 01 18 00 [email protected].....
0018e08c 53 55 6f 00 70 f0 58 0a - 70 f0 58 0a f7 75 40 00 SUo.p.X.p.X..u@.
0018e09c 27 ab e9 00 1c e5 18 00 - 0c 89 40 00 b4 e1 18 00 '.........@.....
0018e0ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0dc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0ec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0fc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e10c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e11c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e12c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e13c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e14c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e15c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e16c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e17c 00 00 00 00 70 f0 58 0a - 00 00 00 00 60 e1 57 0a ....p.X.....`.W.
0018e18c 50 56 49 06 20 7f 3f 04 - c0 81 3f 04 60 84 3f 04 PVI. .?...?.`.?.
0018e19c 00 9c 3f 04 60 99 3f 04 - 80 67 3f 04 c0 6c 3f 04 ..?.`.?..g?..l?.
0018e1ac 20 6a 3f 04 10 1d 34 04 - 04 e3 18 00 ed 04 53 00 j?...4.......S.
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $1284:
770bf8da +0e ntdll.dll NtWaitForSingleObject
75a915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
752d118f +3e kernel32.dll WaitForSingleObjectEx
752d1143 +0d kernel32.dll WaitForSingleObject
752d3368 +10 kernel32.dll BaseThreadInitThunk
thread $750:
770c0166 +0e ntdll.dll NtWaitForMultipleObjects
752d3368 +10 kernel32.dll BaseThreadInitThunk
thread $125c:
770c0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
752d3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d48) at:
734a2713 +24f netbios.dll Netbios
thread $328:
770bf8da +0e ntdll.dll NtWaitForSingleObject
75a915c8 +92 KERNELBASE.dll WaitForSingleObjectEx
752d118f +3e kernel32.dll WaitForSingleObjectEx
752d1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
752d3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d48) at:
73624c95 +00 winspool.drv
thread $165c:
770c1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
752d3368 +10 kernel32.dll BaseThreadInitThunk
modules:
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02620000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02650000 BCLW32.dll C:\Program
Files (x86)\Store
06270000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06300000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6e520000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70410000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70420000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70740000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70760000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70770000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70da0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70de0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70e10000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70e60000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
70f80000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71330000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71380000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
713e0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71ed0000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71ef0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71f90000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71fd0000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72180000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
721a0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
721b0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72850000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
728d0000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
729c0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73420000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73470000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
734a0000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
734b0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73510000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73610000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73670000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
736c0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
737d0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73810000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73860000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73a70000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73ac0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73af0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73b20000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73b60000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73b80000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73b90000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73ba0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73c00000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73c70000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73e10000 version.dll 6.1.7600.16385 C:\Windows\
system32
73e20000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74930000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74940000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
749a0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
749b0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
74a60000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
74a80000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74a90000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
74c30000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
74cc0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
74d20000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
74dd0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
74f20000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
74fa0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
74fc0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
74fd0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74fe0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75050000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75120000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75280000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
752c0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
753d0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
753f0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
756a0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
758e0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75980000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75a80000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75b60000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75c50000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75cf0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75d00000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d10000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d20000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76970000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
769a0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76a30000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76a40000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76a50000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ab0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76ae0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76af0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76b70000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
77070000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
770a0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d8 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
01a4 svchost.exe 0 0 0
041c svchost.exe 0 0 0
04a4 svchost.exe 0 0 0
0514 igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0630 spoolsv.exe 0 0 0
0638 taskeng.exe 0 0 0
0670 svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0784 svchost.exe 0 0 0
079c NetExpressUpdater.exe 0 0 0
07ec OSPPSVC.EXE 0 0 0
05b8 svchost.exe 0 0 0
06a4 scpbradserv.exe 0 0 0
0778 svchost.exe 0 0 0
0828 core.exe 0 0 0
097c RapportInjService_x64.exe 0 0 0
0a24 fbserver.exe 0 0 0
0bc8 WUDFHost.exe 0 0 0
0bf0 NisSrv.exe 0 0 0
0f44 WmiPrvSE.exe 0 0 0
0de8 taskhost.exe 1 26 21 normal
0e10 core.exe 1 9 21 normal
0e84 PresentationFontCache.exe 0 0 0
095c dwm.exe 1 17 4 high
0eb0 explorer.exe 1 573 368 normal
0fa0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0960 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0a58 igfxEM.exe 1 14 13 normal
05e0 igfxHK.exe 1 14 13 normal
0c94 msseces.exe 1 143 59 normal
0ca4 PrnStatusMX.exe 1 23 18 normal
0fe8 RapportInjService_x64.exe 1 4 3 normal
0658 GoogleCrashHandler.exe 0 0 0
0e90 svchost.exe 0 0 0
0954 SearchIndexer.exe 0 0 0
11ac GoogleCrashHandler64.exe 0 0 0
1124 wuauclt.exe 1 12 7 normal
11d0 Store.exe 1 3819 105 normal C:\Program Files (x86)\Store
0740 OIS.EXE 1 95 47 normal
1174 Store.exe 1 694 237 normal C:\Program Files (x86)\Store
07e0 OIS.EXE 1 102 52 normal
0680 splwow64.exe 1 9 3 normal
10d0 OIS.EXE 1 109 40 normal
0cb8 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
1090 OIS.EXE 1 81 37 normal
1118 OIS.EXE 1 101 48 normal
0ddc OIS.EXE 1 101 47 normal
1434 OIS.EXE 1 93 46 normal
15e8 chrome.exe 1 27 57 normal
05c8 chrome.exe 1 9 4 normal
05a0 chrome.exe 1 7 6 above normal
0650 chrome.exe 1 4 1 normal
138c chrome.exe 1 4 1 normal
0b18 chrome.exe 1 4 1 normal
17c4 chrome.exe 1 4 1 idle
1680 chrome.exe 1 4 3 normal
1020 OIS.EXE 1 127 82 normal
15a4 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0018fe20
ebx = 004075b1
ecx = 00000007
edx = 00000000
esi = 004075b1
edi = 043410b0
eip = 75a8c54f
esp = 0018fe20
ebp = 0018fe70
stack dump:
0018fe20 de fa ed 0e 01 00 00 00 - 00 00 00 00 4f c5 a8 75 ............O..u
0018fe30 07 00 00 00 b1 75 40 00 - 58 80 43 04 b1 75 40 00 [email protected]@.
0018fe40 b1 75 40 00 b0 10 34 04 - bc fe 18 00 a4 fe 18 00 [email protected].........
0018fe50 df 61 4d 00 b0 10 34 04 - b1 75 40 00 bc fe 18 00 .aM...4..u@.....
0018fe60 74 fe 18 00 b1 75 40 00 - 44 fe 18 00 a4 db 44 00 [email protected].
0018fe70 bc fe 18 00 b1 75 40 00 - de fa ed 0e 01 00 00 00 .....u@.........
0018fe80 07 00 00 00 88 fe 18 00 - b1 75 40 00 58 80 43 04 [email protected].
0018fe90 b1 75 40 00 b1 75 40 00 - b0 10 34 04 bc fe 18 00 [email protected]@...4.....
0018fea0 a4 fe 18 00 02 00 00 00 - f4 4c 40 00 a0 1e 45 06 [email protected].
0018feb0 a0 1e 45 06 37 4d 40 00 - a0 1e 45 02 40 ff 18 00 [email protected].@...
0018fec0 b1 75 40 00 a0 1e 45 06 - 5c 77 4d 00 01 b6 9b 0a [email protected].\wM.....
0018fed0 f6 48 50 00 f0 ae 61 0a - 01 b6 9b 0a f7 75 40 00 .HP...a......u@.
0018fee0 93 39 7b 00 b0 10 34 04 - 00 aa 58 0a f7 75 40 00 .9{...4...X..u@.
0018fef0 99 1d 6f 00 b0 10 34 04 - 01 aa 58 0a 53 55 6f 00 ..o...4...X.SUo.
0018ff00 60 fe 44 06 01 00 00 00 - a9 1c 53 00 00 56 47 06 `.D.......S..VG.
0018ff10 f8 a1 42 04 60 fe 44 06 - 00 00 00 00 98 a0 60 00 ..B.`.D.......`.
0018ff20 60 fe 44 06 50 e0 3e 04 - 72 b2 60 00 78 ff 18 00 `.D.P.>.r.`.x...
0018ff30 0c 89 40 00 40 ff 18 00 - f8 a1 42 01 60 fe 44 06 ..@[email protected].`.D.
0018ff40 88 ff 18 00 56 04 49 00 - 54 e0 5b 01 18 0b 5c 01 ....V.I.T.[...\.
0018ff50 34 8e 60 00 6e 8e 60 00 - d4 1e 45 00 ac 1e 45 00 4.`.n.`...E...E.
disassembling:
004075a0 public System.TObject.FreeInstance: ; function entry point
004075a0 35 push ebx
004075a1 mov ebx, eax
004075a3 mov eax, ebx
004075a5 call +$a6 ($407650) ; System.TObject.CleanupInstance
004075aa mov eax, ebx
004075ac call -$29fd ($404bb4) ; System.@FreeMem
004075b1 > pop ebx
004075b2 ret
thread $2a0:
77cef8da +0e ntdll.dll NtWaitForSingleObject
75a415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
763c118f +3e kernel32.dll WaitForSingleObjectEx
763c1143 +0d kernel32.dll WaitForSingleObject
763c3368 +10 kernel32.dll BaseThreadInitThunk
thread $13bc:
77cf0166 +0e ntdll.dll NtWaitForMultipleObjects
763c3368 +10 kernel32.dll BaseThreadInitThunk
thread $170:
77cf1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
763c3368 +10 kernel32.dll BaseThreadInitThunk
thread $b64:
77cef8da +0e ntdll.dll NtWaitForSingleObject
75a415c8 +92 KERNELBASE.dll WaitForSingleObjectEx
763c118f +3e kernel32.dll WaitForSingleObjectEx
763c1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
763c3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($b58) at:
74044c95 +00 winspool.drv
thread $12c0:
77cf1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
763c3368 +10 kernel32.dll BaseThreadInitThunk
thread $fd4:
77cf1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
763c3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00310000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06290000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
063a0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f110000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
71370000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
713f0000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
71690000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
716b0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
716c0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
717d0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71820000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71a70000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71a90000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71de0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71f60000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71fb0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
72010000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72b00000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72b20000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72bc0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72c00000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72db0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72dd0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72de0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73ab0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73b00000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73b30000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73c80000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73c90000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
73f10000 security.dll 6.1.7600.16385 C:\Windows\
system32
73f20000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73f30000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
74030000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
74340000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
746f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74720000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74750000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74790000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
747b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
747c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
747d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74830000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
748a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74a40000 version.dll 6.1.7600.16385 C:\Windows\
system32
74a50000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75560000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75570000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
755d0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75610000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75640000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75900000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75980000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75990000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75a30000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75a80000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75a90000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75ae0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75b00000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75d40000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75e90000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75f40000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
75f50000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75f60000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
760c0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
760d0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76170000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76180000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76190000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76200000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
763a0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
763b0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76580000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76610000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76710000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76770000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
768a0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76970000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
769d0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77620000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
776d0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
77700000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
777f0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77800000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
77890000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
778b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
77ca0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77cd0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0344 svchost.exe 0 0 0
0200 svchost.exe 0 0 0
041c svchost.exe 0 0 0
04ac svchost.exe 0 0 0
0518 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0628 spoolsv.exe 0 0 0
0630 taskeng.exe 0 0 0
0658 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07f0 OSPPSVC.EXE 0 0 0
05bc svchost.exe 0 0 0
04a4 scpbradserv.exe 0 0 0
0778 svchost.exe 0 0 0
0814 core.exe 0 0 0
095c RapportInjService_x64.exe 0 0 0
0a28 fbserver.exe 0 0 0
0bb4 WUDFHost.exe 0 0 0
0978 NisSrv.exe 0 0 0
0ef4 WmiPrvSE.exe 0 0 0
0e94 svchost.exe 0 0 0
0fb4 GoogleCrashHandler.exe 0 0 0
0fc8 GoogleCrashHandler64.exe 0 0 0
0c9c SearchIndexer.exe 0 0 0
0e3c taskhost.exe 1 26 22 normal
0e80 core.exe 1 9 20 normal
0dd0 PresentationFontCache.exe 0 0 0
0f90 dwm.exe 1 17 4 high
0d48 explorer.exe 1 394 261 normal
0b10 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\scpbrad
0764 igfxEM.exe 1 14 13 normal
0898 igfxHK.exe 1 14 13 normal
08e8 RapportService.exe 1 14 18 normal C:\Program Files (x86)\Trusteer\
Rapport\bin
08b8 msseces.exe 1 143 60 normal
0de8 PrnStatusMX.exe 1 23 18 normal
110c RapportInjService_x64.exe 1 4 3 normal
1250 wuauclt.exe 1 12 6 normal
0c84 Store.exe 1 976 311 normal C:\Program Files (x86)\Store
0b00 splwow64.exe 1 9 4 normal
12dc DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1004 Store.exe 1 187 223 normal C:\Program Files (x86)\Store
0950 rundll32.exe 1 116 47 normal
0434 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0000000b
ebx = 0a2e6320
ecx = 043c2290
edx = 043be670
esi = 00593bec
edi = 0018de60
eip = 006fa3da
esp = 0018dcec
ebp = 0018de54
stack dump:
0018dcec ec 3b 59 00 b0 2e 36 0a - ed 04 53 00 b0 2e 36 0a .;Y...6...S...6.
0018dcfc f1 3b 59 00 96 09 53 00 - 1a 00 0a 00 1a 00 00 00 .;Y...S.........
0018dd0c 0a 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
0018dd1c 16 00 00 00 1a 00 0a 00 - b0 2e 36 0a 60 de 18 00 ..........6.`...
0018dd2c 94 ff 52 00 1a 00 0a 00 - 5c df 18 00 b0 2e 36 0a ..R.....\.....6.
0018dd3c b0 2e 36 0a d3 01 00 00 - 0a 00 00 00 00 00 00 00 ..6.............
0018dd4c c8 dd 18 00 1f b0 b2 72 - 20 fb 67 02 0a 04 13 00 .......r .g.....
0018dd5c 02 02 00 00 0f 00 00 00 - d3 01 0a 00 00 00 00 00 ................
0018dd6c bb 80 b2 72 8e 81 b2 72 - 00 00 00 00 d3 01 0a 00 ...r...r........
0018dd7c 0a 04 13 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd9c 00 00 00 00 00 00 00 00 - bb 80 b2 72 01 00 00 00 ...........r....
0018ddac 44 de 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 D...............
0018ddbc 00 00 00 00 00 00 00 00 - 1a 45 00 89 f4 dd 18 00 .........E......
0018ddcc fa 62 62 76 0a 04 13 00 - 02 02 00 00 00 00 00 00 .bbv............
0018dddc d3 01 0a 00 bb 80 b2 72 - cd ab ba dc 00 00 00 00 .......r........
0018ddec 00 00 00 00 0c de 18 00 - cf fb 52 00 b0 2e 36 0a ..........R...6.
0018ddfc 0a b0 00 00 00 00 00 00 - 1a 00 0a 00 01 00 00 00 ................
0018de0c 40 de 18 00 41 40 53 00 - 1a 00 0a 00 d0 1e 3c 04 @...A@S.......<.
0018de1c 00 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
disassembling:
[...]
006fa3ae mov edx, [$6e9910]
006fa3b4 call -$2f2b11 ($4078a8) ; System.@IsClass
006fa3b9 test al, al
006fa3bb jnz loc_6fa3ca
006fa3bd 402 mov eax, [ebx+$460]
006fa3c3 call +$cd78 ($707140) ; QRPrntr.TQRPrinter.Print
006fa3c8 jmp loc_6fa3f4
006fa3ca 405 mov eax, [$15c48cc]
006fa3cf call -$741c ($6f2fb8) ; QuickRpt.TCustomQuickRep.Print
006fa3d4 407 mov eax, [ebx+$3cc]
006fa3da > cmp dword ptr [eax+$2b8], 0
006fa3e1 jnz loc_6fa3f4
006fa3e3 409 mov edx, [$15c48cc]
006fa3e9 mov edx, [edx+$36c]
006fa3ef call +$9920 ($703d14) ; QRPrntr.TQRPreview.SetQRPrinter
006fa3f4 412 pop esi
006fa3f5 pop ebx
006fa3f6 ret
thread $13bc:
775ef8da +0e ntdll.dll NtWaitForSingleObject
761015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76ce118f +3e kernel32.dll WaitForSingleObjectEx
76ce1143 +0d kernel32.dll WaitForSingleObject
76ce3368 +10 kernel32.dll BaseThreadInitThunk
thread $13f4:
775f0166 +0e ntdll.dll NtWaitForMultipleObjects
76ce3368 +10 kernel32.dll BaseThreadInitThunk
thread $10a4:
775f0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76ce3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($139c) at:
73622713 +24f netbios.dll Netbios
thread $630:
775ef8da +0e ntdll.dll NtWaitForSingleObject
761015c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76ce118f +3e kernel32.dll WaitForSingleObjectEx
76ce1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76ce3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($139c) at:
737a4c95 +00 winspool.drv
thread $530:
775f1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76ce3368 +10 kernel32.dll BaseThreadInitThunk
modules:
002c0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003a0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06240000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06350000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6eb40000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70490000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
709f0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70a00000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70a20000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70c10000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
710d0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71330000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71370000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71390000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
716e0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71860000 webio.dll 6.1.7601.23375 C:\Windows\
system32
718b0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71910000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72400000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72420000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
724c0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72500000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
726b0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
726d0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
726e0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72900000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
735f0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73620000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73630000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73690000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73790000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
737f0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
73840000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
73980000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
739c0000 security.dll 6.1.7600.16385 C:\Windows\
system32
739e0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73fa0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73ff0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74020000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74050000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74090000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
740b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
740c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
740d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74130000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
741a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74340000 version.dll 6.1.7600.16385 C:\Windows\
system32
74350000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74e60000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74e70000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74ed0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74ee0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
74f40000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74f50000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
750f0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
753a0000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
753b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
753d0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
753e0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76030000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76060000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
760f0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
76140000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76210000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76230000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76260000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
762c0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
763d0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
763f0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76490000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
764a0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
764f0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76640000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76650000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76660000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76670000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76700000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76780000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76830000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76840000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76850000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
769b0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76aa0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76ba0000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76cd0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76de0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76e80000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76e90000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76ed0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
775a0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
775d0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
0258 csrss.exe 1 0 0
0260 wininit.exe 0 0 0
0288 winlogon.exe 1 0 0
02c4 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0254 svchost.exe 0 0 0
02d0 svchost.exe 0 0 0
03f0 svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0554 svchost.exe 0 0 0
0618 spoolsv.exe 0 0 0
0620 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06d0 armsvc.exe 0 0 0
06e4 atkexComSvc.exe 0 0 0
0728 svchost.exe 0 0 0
0754 fbguard.exe 0 0 0
077c svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07e4 OSPPSVC.EXE 0 0 0
0590 svchost.exe 0 0 0
0688 scpbradserv.exe 0 0 0
06fc svchost.exe 0 0 0
0810 core.exe 0 0 0
0958 RapportInjService_x64.exe 0 0 0
0a0c fbserver.exe 0 0 0
0b90 WUDFHost.exe 0 0 0
08cc NisSrv.exe 0 0 0
0ef0 WmiPrvSE.exe 0 0 0
0e08 taskhost.exe 1 26 23 normal
0e2c core.exe 1 9 21 normal
0e88 PresentationFontCache.exe 0 0 0
0eac dwm.exe 1 17 4 high
0f70 explorer.exe 1 559 343 normal
02b4 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
08a4 igfxEM.exe 1 14 14 normal
08b8 igfxHK.exe 1 14 13 normal
0d08 RapportService.exe 1 14 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0c4c msseces.exe 1 143 59 normal
0d44 PrnStatusMX.exe 1 23 18 normal
0d20 RapportInjService_x64.exe 1 4 3 normal
0d00 GoogleCrashHandler.exe 0 0 0
0d84 GoogleCrashHandler64.exe 0 0 0
04e4 SearchIndexer.exe 0 0 0
0c1c svchost.exe 0 0 0
1398 Store.exe 1 1299 507 normal C:\Program Files (x86)\Store
1178 wuauclt.exe 1 12 6 normal
1338 splwow64.exe 1 9 3 normal
132c OIS.EXE 1 104 49 normal
1584 OIS.EXE 1 73 37 normal
0f9c DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
0858 chrome.exe 1 79 67 normal
0924 chrome.exe 1 9 4 normal
07d4 chrome.exe 1 9 8 above normal
1150 chrome.exe 1 4 1 normal
13fc chrome.exe 1 4 1 normal
1588 chrome.exe 1 4 1 idle
13d4 chrome.exe 1 4 3 normal
0834 chrome.exe 1 4 1 idle
15a8 chrome.exe 1 4 1 idle
0e38 chrome.exe 1 4 1 idle
12e8 chrome.exe 1 4 1 idle
1530 chrome.exe 1 4 1 idle
177c chrome.exe 1 4 1 idle
1538 OIS.EXE 1 90 49 normal
156c OIS.EXE 1 115 109 normal
158c POWERPNT.EXE 1 84 77 normal
13ac POWERPNT.EXE 1 92 72 normal
0aac OIS.EXE 1 101 49 normal
16d8 audiodg.exe 0 0 0
0b20 OIS.EXE 1 97 46 normal
159c OIS.EXE 1 88 32 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 063c3e70
ebx = 00003303
ecx = 00000000
edx = 025c2ac8
esi = 0018df14
edi = 0066cb50
eip = 0066ea6e
esp = 0018ded8
ebp = 0018df40
stack dump:
0018ded8 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018dee8 ec de 18 00 6e ea 66 00 - 70 3e 3c 06 03 33 00 00 ....n.f.p><..3..
0018def8 14 df 18 00 50 cb 66 00 - 40 df 18 00 08 df 18 00 ....P.f.@.......
0018df08 c0 97 30 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 ..0.z.f...g.....
0018df18 c0 97 30 04 00 00 00 00 - 9b e8 67 00 4c df 18 00 ..0.......g.L...
0018df28 0c 89 40 00 40 df 18 00 - 00 00 00 00 00 00 00 00 ..@.@...........
0018df38 d5 e9 67 01 c0 97 30 04 - 68 df 18 00 f3 e8 67 00 ..g...0.h.....g.
0018df48 12 4d 67 00 80 df 18 00 - 0c 89 40 00 68 df 18 00 [email protected]...
0018df58 c0 97 30 04 00 00 00 00 - 00 00 00 00 c0 97 30 04 ..0...........0.
0018df68 94 df 18 00 b6 92 67 00 - 00 00 00 00 38 5d 53 00 ......g.....8]S.
0018df78 01 00 00 00 e3 73 65 00 - a0 df 18 00 0c 89 40 00 .....se.......@.
0018df88 94 df 18 00 20 22 c4 0a - c0 97 30 04 c8 df 18 00 .... "....0.....
0018df98 2a 72 65 00 2f e9 bb 00 - e0 df 18 00 0c 89 40 00 *re./.........@.
0018dfa8 c8 df 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dfb8 00 00 00 00 20 22 c4 0a - c0 97 30 04 70 8c 26 04 .... "....0.p.&.
0018dfc8 0c e0 18 00 53 5d 53 00 - bc e1 18 00 06 6a 53 00 ....S]S......jS.
0018dfd8 bc e1 18 00 1f f9 54 00 - ec df 18 00 eb 8a 40 00 ......T.......@.
0018dfe8 0c e0 18 00 8c e1 18 00 - 0c 89 40 00 0c e0 18 00 ..........@.....
0018dff8 00 00 00 00 20 22 c4 0a - bc e1 18 00 00 00 00 00 .... "..........
0018e008 20 22 c4 0a 38 e1 18 00 - 94 ff 52 00 00 00 00 00 "..8.....R.....
disassembling:
[...]
00bbe906 mov ecx, [ebp-$18]
00bbe909 lea eax, [ebp-$14]
00bbe90c mov edx, $bbe9cc
00bbe911 call -$7b41d6 ($40a740) ; System.@UStrCat3
00bbe916 mov edx, [ebp-$14]
00bbe919 mov eax, [ebp-8]
00bbe91c mov eax, [eax+$250]
00bbe922 mov ecx, [eax]
00bbe924 call dword ptr [ecx+$38]
00bbe927 474 mov eax, [ebp-8]
00bbe92a > call -$56770f ($657220) ; Data.DB.TDataSet.Open
00bbe92f 475 mov eax, [ebp-8]
00bbe932 cmp byte ptr [eax+$a8], 0
00bbe939 jz loc_bbe95c
00bbe93b mov eax, [ebp-8]
00bbe93e cmp byte ptr [eax+$a9], 0
00bbe945 jz loc_bbe95c
00bbe947 476 mov edx, $bbea44
00bbe94c mov eax, [ebp-4]
00bbe94f mov eax, [eax+$3a8]
00bbe955 call -$690296 ($52e6c4) ; Vcl.Controls.TControl.SetText
[...]
thread $15ac:
77d6f8da +0e ntdll.dll NtWaitForSingleObject
764715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7566118f +3e kernel32.dll WaitForSingleObjectEx
75661143 +0d kernel32.dll WaitForSingleObject
75663368 +10 kernel32.dll BaseThreadInitThunk
thread $18ec:
77d70166 +0e ntdll.dll NtWaitForMultipleObjects
75663368 +10 kernel32.dll BaseThreadInitThunk
thread $18fc:
77d70166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
75663368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($18c0) at:
74522713 +24f netbios.dll Netbios
thread $1264:
77d6f8da +0e ntdll.dll NtWaitForSingleObject
764715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7566118f +3e kernel32.dll WaitForSingleObjectEx
75661143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
75663368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($18c0) at:
746c4c95 +00 winspool.drv
thread $7ec:
77d71f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75663368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06230000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06340000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f510000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70d30000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70f00000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
71360000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
71370000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
71380000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
713a0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
71410000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
715e0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71620000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71640000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
717d0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
718f0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71e60000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71eb0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71f10000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71f50000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
72b80000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72ba0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72c40000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72c80000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72e30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72e50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72e60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
74390000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
744f0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74520000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
74530000 security.dll 6.1.7600.16385 C:\Windows\
system32
74540000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
74550000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
745b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
746b0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
74720000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74770000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
747a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
747d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74810000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74830000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74840000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74850000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
748b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74920000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74ac0000 version.dll 6.1.7600.16385 C:\Windows\
system32
74ad0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
755e0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
755f0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75650000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75760000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75900000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75930000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75940000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75950000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
759e0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75a80000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75bd0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75bf0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75c40000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75cf0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d00000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75d10000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d20000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75d30000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d40000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75ea0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75f40000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75fa0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76020000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76040000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76050000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76150000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76460000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
764b0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76550000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76570000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76580000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76590000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
765c0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76690000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76780000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
769c0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76a50000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76ae0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76b20000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76c50000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76d00000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77d20000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77d50000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03c8 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0340 svchost.exe 0 0 0
0214 svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0768 fbguard.exe 0 0 0
078c svchost.exe 0 0 0
07a0 NetExpressUpdater.exe 0 0 0
07fc OSPPSVC.EXE 0 0 0
069c svchost.exe 0 0 0
06d0 scpbradserv.exe 0 0 0
082c core.exe 0 0 0
096c RapportInjService_x64.exe 0 0 0
0a3c fbserver.exe 0 0 0
0be4 WUDFHost.exe 0 0 0
0898 NisSrv.exe 0 0 0
0f94 WmiPrvSE.exe 0 0 0
0ea4 svchost.exe 0 0 0
0f64 GoogleCrashHandler.exe 0 0 0
0f7c GoogleCrashHandler64.exe 0 0 0
08bc SearchIndexer.exe 0 0 0
0c08 taskhost.exe 1 26 21 normal
0ab8 core.exe 1 9 21 normal
06dc PresentationFontCache.exe 0 0 0
0aac dwm.exe 1 17 4 high
093c explorer.exe 1 601 401 normal
0f58 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c4c RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
052c igfxEM.exe 1 14 13 normal
0fe0 igfxHK.exe 1 14 12 normal
0aa0 msseces.exe 1 143 59 normal
0ba0 PrnStatusMX.exe 1 23 18 normal
110c RapportInjService_x64.exe 1 4 3 normal
12a0 wuauclt.exe 1 12 6 normal
18bc Store.exe 1 2153 689 normal C:\Program Files (x86)\Store
17d8 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1a08 splwow64.exe 1 9 3 normal
136c svchost.exe 0 0 0
1980 OIS.EXE 1 92 46 normal
1a9c chrome.exe 1 77 62 normal
0298 chrome.exe 1 9 4 normal
1bc4 chrome.exe 1 7 7 above normal
1214 chrome.exe 1 4 1 normal
016c chrome.exe 1 4 1 normal
1bd8 chrome.exe 1 4 1 normal
1a98 chrome.exe 1 4 1 idle
11a0 chrome.exe 1 4 3 normal
1084 taskhost.exe 0 0 0
1a1c audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0ac455c8
ebx = 00003303
ecx = 00000000
edx = 026b2ac8
esi = 0018d174
edi = 0066cb50
eip = 0066ea6e
esp = 0018d138
ebp = 0018d1a0
stack dump:
0018d138 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018d148 4c d1 18 00 6e ea 66 00 - c8 55 c4 0a 03 33 00 00 L...n.f..U...3..
0018d158 74 d1 18 00 50 cb 66 00 - a0 d1 18 00 68 d1 18 00 t...P.f.....h...
0018d168 a0 d6 43 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 ..C.z.f...g.....
0018d178 a0 d6 43 06 00 00 00 00 - 9b e8 67 00 ac d1 18 00 ..C.......g.....
0018d188 0c 89 40 00 a0 d1 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018d198 d5 e9 67 01 a0 d6 43 06 - c8 d1 18 00 f3 e8 67 00 ..g...C.......g.
0018d1a8 12 4d 67 00 e0 d1 18 00 - 0c 89 40 00 c8 d1 18 00 .Mg.......@.....
0018d1b8 a0 d6 43 06 00 00 00 00 - 00 00 00 00 a0 d6 43 06 ..C...........C.
0018d1c8 f4 d1 18 00 b6 92 67 00 - b8 d7 18 00 10 6a 3f 0c ......g......j?.
0018d1d8 01 00 00 00 e3 73 65 00 - 00 d2 18 00 0c 89 40 00 .....se.......@.
0018d1e8 f4 d1 18 00 10 6a 3f 0c - a0 d6 43 06 c4 d2 18 00 .....j?...C.....
0018d1f8 2a 72 65 00 e8 eb 12 01 - cc d2 18 00 0c 89 40 00 *re...........@.
0018d208 c4 d2 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d218 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d228 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d238 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d248 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d258 00 00 00 00 00 00 00 00 - 80 8c e5 40 a0 b9 3b 06 ...........@..;.
0018d268 00 00 00 00 fa a4 4f fa - ff 97 e5 40 00 00 00 00 ......O....@....
disassembling:
[...]
0112ebbf mov eax, [ebp-$18]
0112ebc2 mov eax, [eax+$250]
0112ebc8 mov ecx, [eax]
0112ebca call dword ptr [ecx+$38]
0112ebcd 425 mov edx, $112fc20
0112ebd2 mov eax, [ebp-$18]
0112ebd5 mov eax, [eax+$250]
0112ebdb mov ecx, [eax]
0112ebdd call dword ptr [ecx+$38]
0112ebe0 427 mov eax, [ebp-$18]
0112ebe3 > call -$ad79c8 ($657220) ; Data.DB.TDataSet.Open
0112ebe8 428 mov eax, [ebp-$18]
0112ebeb call -$ad5108 ($659ae8) ; Data.DB.TDataSet.First
0112ebf0 429 mov eax, [ebp-$18]
0112ebf3 cmp byte ptr [eax+$a9], 0
0112ebfa jz loc_112ec08
0112ebfc mov eax, [ebp-$18]
0112ebff cmp byte ptr [eax+$a8], 0
0112ec06 jnz loc_112ec17
0112ec08 431 mov eax, [ebp-4]
0112ec0b call +$33080 ($1161c90) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $15ac:
77d6f8da +0e ntdll.dll NtWaitForSingleObject
764715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7566118f +3e kernel32.dll WaitForSingleObjectEx
75661143 +0d kernel32.dll WaitForSingleObject
75663368 +10 kernel32.dll BaseThreadInitThunk
thread $18ec:
77d70166 +0e ntdll.dll NtWaitForMultipleObjects
75663368 +10 kernel32.dll BaseThreadInitThunk
thread $18fc:
77d70166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
75663368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($18c0) at:
74522713 +24f netbios.dll Netbios
thread $1264:
77d6f8da +0e ntdll.dll NtWaitForSingleObject
764715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7566118f +3e kernel32.dll WaitForSingleObjectEx
75661143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
75663368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($18c0) at:
746c4c95 +00 winspool.drv
thread $1984:
77d71f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75663368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06230000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06340000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f510000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70d30000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70f00000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
71360000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
71370000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
71380000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
713a0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
71410000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
715e0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71620000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71640000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
717d0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
718f0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71e60000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71eb0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71f10000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71f50000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
72b80000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72ba0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72c40000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72c80000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72e30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72e50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72e60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
74390000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
744f0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74520000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
74530000 security.dll 6.1.7600.16385 C:\Windows\
system32
74540000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
74550000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
745b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
746b0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
74720000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74770000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
747a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
747d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74810000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74830000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74840000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74850000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
748b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74920000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74ac0000 version.dll 6.1.7600.16385 C:\Windows\
system32
74ad0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
755e0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
755f0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75650000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75760000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75900000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75930000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75940000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75950000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
759e0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75a80000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75bd0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75bf0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75c40000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75cf0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d00000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75d10000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d20000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75d30000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d40000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75ea0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75f40000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75fa0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76020000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76040000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76050000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76150000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76460000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
764b0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76550000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76570000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76580000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76590000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
765c0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76690000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76780000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
769c0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76a50000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76ae0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76b20000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76c50000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76d00000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77d20000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77d50000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03c8 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0340 svchost.exe 0 0 0
0214 svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0768 fbguard.exe 0 0 0
078c svchost.exe 0 0 0
07a0 NetExpressUpdater.exe 0 0 0
07fc OSPPSVC.EXE 0 0 0
069c svchost.exe 0 0 0
06d0 scpbradserv.exe 0 0 0
082c core.exe 0 0 0
096c RapportInjService_x64.exe 0 0 0
0a3c fbserver.exe 0 0 0
0be4 WUDFHost.exe 0 0 0
0898 NisSrv.exe 0 0 0
0f94 WmiPrvSE.exe 0 0 0
0ea4 svchost.exe 0 0 0
0f64 GoogleCrashHandler.exe 0 0 0
0f7c GoogleCrashHandler64.exe 0 0 0
08bc SearchIndexer.exe 0 0 0
0c08 taskhost.exe 1 26 22 normal
0ab8 core.exe 1 9 21 normal
06dc PresentationFontCache.exe 0 0 0
0aac dwm.exe 1 17 4 high
093c explorer.exe 1 601 411 normal
0f58 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c4c RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
052c igfxEM.exe 1 14 13 normal
0fe0 igfxHK.exe 1 14 12 normal
0aa0 msseces.exe 1 143 59 normal
0ba0 PrnStatusMX.exe 1 23 18 normal
110c RapportInjService_x64.exe 1 4 3 normal
12a0 wuauclt.exe 1 12 6 normal
18bc Store.exe 1 2436 596 normal C:\Program Files (x86)\Store
17d8 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1a08 splwow64.exe 1 9 2 normal
136c svchost.exe 0 0 0
1980 OIS.EXE 1 93 46 normal
1a9c chrome.exe 1 78 56 normal
0298 chrome.exe 1 9 4 normal
1bc4 chrome.exe 1 7 7 above normal
1214 chrome.exe 1 4 1 normal
016c chrome.exe 1 4 1 normal
1bd8 chrome.exe 1 4 1 idle
1a98 chrome.exe 1 4 1 idle
11a0 chrome.exe 1 4 3 normal
1a1c audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0bda0e68
ebx = 00003303
ecx = 00000000
edx = 026b2ac8
esi = 0018e3cc
edi = 0066cb50
eip = 0066ea6e
esp = 0018e390
ebp = 0018e3f8
stack dump:
0018e390 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e3a0 a4 e3 18 00 6e ea 66 00 - 68 0e da 0b 03 33 00 00 ....n.f.h....3..
0018e3b0 cc e3 18 00 50 cb 66 00 - f8 e3 18 00 c0 e3 18 00 ....P.f.........
0018e3c0 30 1c 50 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 0.P.z.f...g.....
0018e3d0 30 1c 50 04 00 00 00 00 - 9b e8 67 00 04 e4 18 00 0.P.......g.....
0018e3e0 0c 89 40 00 f8 e3 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e3f0 d5 e9 67 01 30 1c 50 04 - 20 e4 18 00 f3 e8 67 00 ..g.0.P. .....g.
0018e400 12 4d 67 00 38 e4 18 00 - 0c 89 40 00 20 e4 18 00 .Mg.8.....@. ...
0018e410 30 1c 50 04 00 00 00 00 - 00 00 00 00 30 1c 50 04 0.P.........0.P.
0018e420 4c e4 18 00 b6 92 67 00 - 00 00 00 00 38 5d 53 00 L.....g.....8]S.
0018e430 01 00 00 00 e3 73 65 00 - 58 e4 18 00 0c 89 40 00 .....se.X.....@.
0018e440 4c e4 18 00 e0 f4 4b 06 - 30 1c 50 04 8c e4 18 00 L.....K.0.P.....
0018e450 2a 72 65 00 d0 fe 12 01 - a4 e4 18 00 0c 89 40 00 *re...........@.
0018e460 8c e4 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e470 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e480 e0 f4 4b 06 30 1c 50 04 - a0 b9 3b 06 d0 e4 18 00 ..K.0.P...;.....
0018e490 53 5d 53 00 80 e6 18 00 - 06 6a 53 00 80 e6 18 00 S]S......jS.....
0018e4a0 1f f9 54 00 b0 e4 18 00 - eb 8a 40 00 d0 e4 18 00 ..T.......@.....
0018e4b0 50 e6 18 00 0c 89 40 00 - d0 e4 18 00 00 00 00 00 P.....@.........
0018e4c0 e0 f4 4b 06 80 e6 18 00 - 00 00 00 00 e0 f4 4b 06 ..K...........K.
disassembling:
[...]
0112fea5 push $1130034
0112feaa lea eax, [ebp-$20]
0112fead mov edx, 3
0112feb2 call -$d256ef ($40a7c8) ; System.@UStrCatN
0112feb7 mov edx, [ebp-$20]
0112feba mov eax, [ebp-8]
0112febd mov eax, [eax+$250]
0112fec3 mov ecx, [eax]
0112fec5 call dword ptr [ecx+$38]
0112fec8 463 mov eax, [ebp-8]
0112fecb > call -$ad8cb0 ($657220) ; Data.DB.TDataSet.Open
0112fed0 464 mov eax, [ebp-8]
0112fed3 cmp byte ptr [eax+$a8], 0
0112feda jz loc_112fefd
0112fedc mov eax, [ebp-8]
0112fedf cmp byte ptr [eax+$a9], 0
0112fee6 jz loc_112fefd
0112fee8 465 mov edx, $1130048
0112feed mov eax, [ebp-4]
0112fef0 mov eax, [eax+$4f4]
0112fef6 call -$c01837 ($52e6c4) ; Vcl.Controls.TControl.SetText
[...]
thread $15ac:
77d6f8da +0e ntdll.dll NtWaitForSingleObject
764715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7566118f +3e kernel32.dll WaitForSingleObjectEx
75661143 +0d kernel32.dll WaitForSingleObject
75663368 +10 kernel32.dll BaseThreadInitThunk
thread $18ec:
77d70166 +0e ntdll.dll NtWaitForMultipleObjects
75663368 +10 kernel32.dll BaseThreadInitThunk
thread $18fc:
77d70166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
75663368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($18c0) at:
74522713 +24f netbios.dll Netbios
thread $1264:
77d6f8da +0e ntdll.dll NtWaitForSingleObject
764715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7566118f +3e kernel32.dll WaitForSingleObjectEx
75661143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
75663368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($18c0) at:
746c4c95 +00 winspool.drv
thread $1984:
77d71f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75663368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06230000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06340000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f510000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70d30000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70f00000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
71360000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
71370000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
71380000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
713a0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
71410000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
715e0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71620000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71640000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
717d0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
718f0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71e60000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71eb0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71f10000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71f50000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
72b80000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72ba0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72c40000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72c80000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72e30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72e50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72e60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
74390000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
744f0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74520000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
74530000 security.dll 6.1.7600.16385 C:\Windows\
system32
74540000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
74550000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
745b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
746b0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
74720000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74770000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
747a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
747d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74810000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74830000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74840000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74850000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
748b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74920000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74ac0000 version.dll 6.1.7600.16385 C:\Windows\
system32
74ad0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
755e0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
755f0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75650000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75760000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75900000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75930000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75940000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75950000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
759e0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75a80000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75bd0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75bf0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75c40000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75cf0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d00000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75d10000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d20000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75d30000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d40000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75ea0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75f40000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75fa0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76020000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76040000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76050000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76150000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76460000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
764b0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76550000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76570000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76580000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76590000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
765c0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76690000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76780000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
769c0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76a50000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76ae0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76b20000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76c50000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76d00000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77d20000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77d50000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03c8 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0340 svchost.exe 0 0 0
0214 svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0768 fbguard.exe 0 0 0
078c svchost.exe 0 0 0
07a0 NetExpressUpdater.exe 0 0 0
07fc OSPPSVC.EXE 0 0 0
069c svchost.exe 0 0 0
06d0 scpbradserv.exe 0 0 0
082c core.exe 0 0 0
096c RapportInjService_x64.exe 0 0 0
0a3c fbserver.exe 0 0 0
0be4 WUDFHost.exe 0 0 0
0898 NisSrv.exe 0 0 0
0f94 WmiPrvSE.exe 0 0 0
0ea4 svchost.exe 0 0 0
0f64 GoogleCrashHandler.exe 0 0 0
0f7c GoogleCrashHandler64.exe 0 0 0
08bc SearchIndexer.exe 0 0 0
0c08 taskhost.exe 1 26 23 normal
0ab8 core.exe 1 9 21 normal
06dc PresentationFontCache.exe 0 0 0
0aac dwm.exe 1 17 4 high
093c explorer.exe 1 601 414 normal
0f58 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c4c RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
052c igfxEM.exe 1 14 13 normal
0fe0 igfxHK.exe 1 14 12 normal
0aa0 msseces.exe 1 143 59 normal
0ba0 PrnStatusMX.exe 1 23 18 normal
110c RapportInjService_x64.exe 1 4 3 normal
12a0 wuauclt.exe 1 12 6 normal
18bc Store.exe 1 2436 596 normal C:\Program Files (x86)\Store
17d8 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
1a08 splwow64.exe 1 9 2 normal
136c svchost.exe 0 0 0
1980 OIS.EXE 1 93 46 normal
1a9c chrome.exe 1 78 56 normal
0298 chrome.exe 1 9 4 normal
1bc4 chrome.exe 1 7 7 above normal
1214 chrome.exe 1 4 1 normal
016c chrome.exe 1 4 1 normal
1bd8 chrome.exe 1 4 1 idle
1a98 chrome.exe 1 4 1 idle
11a0 chrome.exe 1 4 3 normal
1a1c audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0bda0e68
ebx = 00003303
ecx = 00000000
edx = 026b2ac8
esi = 0018e3cc
edi = 0066cb50
eip = 0066ea6e
esp = 0018e390
ebp = 0018e3f8
stack dump:
0018e390 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e3a0 a4 e3 18 00 6e ea 66 00 - 68 0e da 0b 03 33 00 00 ....n.f.h....3..
0018e3b0 cc e3 18 00 50 cb 66 00 - f8 e3 18 00 c0 e3 18 00 ....P.f.........
0018e3c0 30 1c 50 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 0.P.z.f...g.....
0018e3d0 30 1c 50 04 00 00 00 00 - 9b e8 67 00 04 e4 18 00 0.P.......g.....
0018e3e0 0c 89 40 00 f8 e3 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e3f0 d5 e9 67 01 30 1c 50 04 - 20 e4 18 00 f3 e8 67 00 ..g.0.P. .....g.
0018e400 12 4d 67 00 38 e4 18 00 - 0c 89 40 00 20 e4 18 00 .Mg.8.....@. ...
0018e410 30 1c 50 04 00 00 00 00 - 00 00 00 00 30 1c 50 04 0.P.........0.P.
0018e420 4c e4 18 00 b6 92 67 00 - 00 00 00 00 38 5d 53 00 L.....g.....8]S.
0018e430 01 00 00 00 e3 73 65 00 - 58 e4 18 00 0c 89 40 00 .....se.X.....@.
0018e440 4c e4 18 00 e0 f4 4b 06 - 30 1c 50 04 8c e4 18 00 L.....K.0.P.....
0018e450 2a 72 65 00 d0 fe 12 01 - a4 e4 18 00 0c 89 40 00 *re...........@.
0018e460 8c e4 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e470 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e480 e0 f4 4b 06 30 1c 50 04 - a0 b9 3b 06 d0 e4 18 00 ..K.0.P...;.....
0018e490 53 5d 53 00 80 e6 18 00 - 06 6a 53 00 80 e6 18 00 S]S......jS.....
0018e4a0 1f f9 54 00 b0 e4 18 00 - eb 8a 40 00 d0 e4 18 00 ..T.......@.....
0018e4b0 50 e6 18 00 0c 89 40 00 - d0 e4 18 00 00 00 00 00 P.....@.........
0018e4c0 e0 f4 4b 06 80 e6 18 00 - 00 00 00 00 e0 f4 4b 06 ..K...........K.
disassembling:
[...]
0112fea5 push $1130034
0112feaa lea eax, [ebp-$20]
0112fead mov edx, 3
0112feb2 call -$d256ef ($40a7c8) ; System.@UStrCatN
0112feb7 mov edx, [ebp-$20]
0112feba mov eax, [ebp-8]
0112febd mov eax, [eax+$250]
0112fec3 mov ecx, [eax]
0112fec5 call dword ptr [ecx+$38]
0112fec8 463 mov eax, [ebp-8]
0112fecb > call -$ad8cb0 ($657220) ; Data.DB.TDataSet.Open
0112fed0 464 mov eax, [ebp-8]
0112fed3 cmp byte ptr [eax+$a8], 0
0112feda jz loc_112fefd
0112fedc mov eax, [ebp-8]
0112fedf cmp byte ptr [eax+$a9], 0
0112fee6 jz loc_112fefd
0112fee8 465 mov edx, $1130048
0112feed mov eax, [ebp-4]
0112fef0 mov eax, [eax+$4f4]
0112fef6 call -$c01837 ($52e6c4) ; Vcl.Controls.TControl.SetText
[...]
thread $15ac:
77d6f8da +0e ntdll.dll NtWaitForSingleObject
764715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7566118f +3e kernel32.dll WaitForSingleObjectEx
75661143 +0d kernel32.dll WaitForSingleObject
75663368 +10 kernel32.dll BaseThreadInitThunk
thread $18ec:
77d70166 +0e ntdll.dll NtWaitForMultipleObjects
75663368 +10 kernel32.dll BaseThreadInitThunk
thread $18fc:
77d70166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
75663368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($18c0) at:
74522713 +24f netbios.dll Netbios
thread $1264:
77d6f8da +0e ntdll.dll NtWaitForSingleObject
764715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7566118f +3e kernel32.dll WaitForSingleObjectEx
75661143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
75663368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($18c0) at:
746c4c95 +00 winspool.drv
thread $c8c:
77d71f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75663368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06230000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06340000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6f510000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70d30000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70f00000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
71360000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
71370000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
71380000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
713a0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
71410000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
715e0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71620000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71640000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
717d0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71880000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
718f0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71e60000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71eb0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71f10000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71f50000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
72b80000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72ba0000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72c40000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72c80000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72e30000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72e50000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72e60000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
74390000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
744c0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
74520000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
74530000 security.dll 6.1.7600.16385 C:\Windows\
system32
74540000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
74550000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
745b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
746b0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
74720000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74770000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
747a0000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
747d0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74810000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74830000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74840000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74850000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
748b0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74920000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74ac0000 version.dll 6.1.7600.16385 C:\Windows\
system32
74ad0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
755e0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
755f0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75650000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75760000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75900000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75930000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75940000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75950000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
759e0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75a80000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75bd0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75bf0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
75c40000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75cf0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d00000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75d10000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d20000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75d30000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75d40000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75ea0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75f40000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75fa0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
76020000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76040000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76050000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76150000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76460000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
764b0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76550000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76570000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76580000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76590000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
765c0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76690000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76780000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
769c0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76a50000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
76ae0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76b20000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76c50000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76d00000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77d20000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77d50000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03c8 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0340 svchost.exe 0 0 0
0214 svchost.exe 0 0 0
0418 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
0558 svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0634 taskeng.exe 0 0 0
065c svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0768 fbguard.exe 0 0 0
078c svchost.exe 0 0 0
07a0 NetExpressUpdater.exe 0 0 0
07fc OSPPSVC.EXE 0 0 0
069c svchost.exe 0 0 0
06d0 scpbradserv.exe 0 0 0
082c core.exe 0 0 0
096c RapportInjService_x64.exe 0 0 0
0a3c fbserver.exe 0 0 0
0be4 WUDFHost.exe 0 0 0
0898 NisSrv.exe 0 0 0
0f94 WmiPrvSE.exe 0 0 0
0ea4 svchost.exe 0 0 0
0f64 GoogleCrashHandler.exe 0 0 0
0f7c GoogleCrashHandler64.exe 0 0 0
08bc SearchIndexer.exe 0 0 0
0c08 taskhost.exe 1 26 23 normal
0ab8 core.exe 1 9 21 normal
06dc PresentationFontCache.exe 0 0 0
0aac dwm.exe 1 17 4 high
093c explorer.exe 1 607 412 normal
0f58 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c4c RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
052c igfxEM.exe 1 14 13 normal
0fe0 igfxHK.exe 1 14 12 normal
0aa0 msseces.exe 1 143 59 normal
0ba0 PrnStatusMX.exe 1 23 18 normal
110c RapportInjService_x64.exe 1 4 3 normal
12a0 wuauclt.exe 1 12 6 normal
18bc Store.exe 1 2955 659 normal C:\Program Files (x86)\Store
17d8 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
1a08 splwow64.exe 1 9 2 normal
136c svchost.exe 0 0 0
1980 OIS.EXE 1 93 45 normal
1a9c chrome.exe 1 80 67 normal
0298 chrome.exe 1 9 4 normal
1bc4 chrome.exe 1 8 7 above normal
1214 chrome.exe 1 4 1 normal
016c chrome.exe 1 4 1 normal
1bd8 chrome.exe 1 4 1 normal
1a98 chrome.exe 1 4 1 idle
11a0 chrome.exe 1 4 3 normal
0ea0 audiodg.exe 0 0 0
1558 svchost.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0afb6c80
ebx = 00003303
ecx = 00000000
edx = 026b2ac8
esi = 0018de48
edi = 0066cb50
eip = 0066ea6e
esp = 0018de0c
ebp = 0018de74
stack dump:
0018de0c 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018de1c 20 de 18 00 6e ea 66 00 - 80 6c fb 0a 03 33 00 00 ...n.f..l...3..
0018de2c 48 de 18 00 50 cb 66 00 - 74 de 18 00 3c de 18 00 H...P.f.t...<...
0018de3c 80 f3 43 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 ..C.z.f...g.....
0018de4c 80 f3 43 06 00 00 00 00 - 9b e8 67 00 80 de 18 00 ..C.......g.....
0018de5c 0c 89 40 00 74 de 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018de6c d5 e9 67 01 80 f3 43 06 - 9c de 18 00 f3 e8 67 00 ..g...C.......g.
0018de7c 12 4d 67 00 b4 de 18 00 - 0c 89 40 00 9c de 18 00 .Mg.......@.....
0018de8c 80 f3 43 06 00 00 00 00 - 00 00 00 00 80 f3 43 06 ..C...........C.
0018de9c c8 de 18 00 b6 92 67 00 - 00 00 00 00 3c 9a 5b 00 ......g.....<.[.
0018deac 01 00 00 00 e3 73 65 00 - d4 de 18 00 0c 89 40 00 .....se.......@.
0018debc c8 de 18 00 f0 17 43 06 - 80 f3 43 06 28 df 18 00 ......C...C.(...
0018decc 2a 72 65 00 78 5a 56 01 - e0 de 18 00 64 89 40 00 *re.xZV.....d.@.
0018dedc 28 df 18 00 38 df 18 00 - 0c 89 40 00 28 df 18 00 (...8.....@.(...
0018deec 00 00 00 00 3c 9a 5b 00 - f0 17 43 06 00 00 00 00 ....<.[...C.....
0018defc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018df0c 00 00 00 00 f0 17 43 06 - 01 00 00 00 00 00 00 00 ......C.........
0018df1c 00 00 00 00 80 f3 43 06 - 40 86 55 0a 54 df 18 00 [email protected]...
0018df2c 4e 9a 5b 00 5c df 18 00 - 34 99 5b 00 00 e0 18 00 N.[.\...4.[.....
0018df3c dc 86 40 00 54 df 18 00 - 00 00 00 00 fd 0c 8d 02 [email protected]...........
disassembling:
[...]
01565a4f 884 mov eax, [ebp-8]
01565a52 mov eax, [eax+$250]
01565a58 mov edx, [eax]
01565a5a call dword ptr [edx+$44]
01565a5d 885 mov eax, [ebp-8]
01565a60 mov eax, [eax+$250]
01565a66 mov edx, $1565c40
01565a6b mov ecx, [eax]
01565a6d call dword ptr [ecx+$38]
01565a70 886 mov eax, [ebp-8]
01565a73 > call -$f0e858 ($657220) ; Data.DB.TDataSet.Open
01565a78 xor eax, eax
01565a7a pop edx
01565a7b pop ecx
01565a7c pop ecx
01565a7d mov fs:[eax], edx
01565a80 jmp loc_1565c0b
01565a85 jmp -$115d4b2 ($4085d8) ; System.@HandleAnyException
01565a8a 890 mov eax, [$15bcdf0]
01565a8f mov eax, [eax]
01565a91 mov eax, [eax+$60]
[...]
thread $52c:
7700f8da +0e ntdll.dll NtWaitForSingleObject
75c715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7585118f +3e kernel32.dll WaitForSingleObjectEx
75851143 +0d kernel32.dll WaitForSingleObject
75853368 +10 kernel32.dll BaseThreadInitThunk
thread $1590:
77010166 +0e ntdll.dll NtWaitForMultipleObjects
75853368 +10 kernel32.dll BaseThreadInitThunk
thread $15c0:
7700f8da +0e ntdll.dll NtWaitForSingleObject
75c715c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7585118f +3e kernel32.dll WaitForSingleObjectEx
75851143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
75853368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($168c) at:
72f64c95 +00 winspool.drv
thread $1120:
77011f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75853368 +10 kernel32.dll BaseThreadInitThunk
thread $10e0:
77011f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75853368 +10 kernel32.dll BaseThreadInitThunk
thread $ca8:
77011f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75853368 +10 kernel32.dll BaseThreadInitThunk
thread $11c0:
77011f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
75853368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00310000 WINPPLA.DLL C:\Program
Files (x86)\Store
00350000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06230000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06340000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
702c0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70410000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70600000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70620000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70630000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70640000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70740000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70a00000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
70a40000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70ab0000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
70b00000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
70b40000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
70d90000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
70db0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
70dc0000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
70ee0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71280000 webio.dll 6.1.7601.23375 C:\Windows\
system32
712d0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71330000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
71e20000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
71e40000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
71ee0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
71f20000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
720d0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
720f0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72100000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72910000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
72990000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
72d20000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72d50000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
72e50000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72f50000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
72fb0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73080000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
730c0000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
733c0000 security.dll 6.1.7600.16385 C:\Windows\
system32
733e0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
735e0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
739c0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
73a10000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
73a40000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
73a70000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
73ab0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
73ad0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
73ae0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
73af0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
73b00000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
73b50000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
73b90000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
73ba0000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
73bc0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
73d60000 version.dll 6.1.7600.16385 C:\Windows\
system32
73d70000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74880000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74890000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
748f0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
749f0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
74ae0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74af0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
74b10000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
74b30000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74b40000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
74bc0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
74bd0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74be0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
74bf0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75840000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
75950000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
759f0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75c30000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75c40000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75c50000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75c60000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75cb0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
75cf0000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75d80000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
76030000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76160000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
76190000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
761a0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
761b0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
76210000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76220000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76420000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
764d0000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
765f0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76640000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76660000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
767b0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76880000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76930000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76960000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76a00000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76a90000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76fc0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
76ff0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0334 svchost.exe 0 0 0
0380 svchost.exe 0 0 0
03d0 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
024c svchost.exe 0 0 0
0304 svchost.exe 0 0 0
03ec svchost.exe 0 0 0
0418 svchost.exe 0 0 0
049c svchost.exe 0 0 0
0508 igfxCUIService.exe 0 0 0
0554 svchost.exe 0 0 0
0630 spoolsv.exe 0 0 0
0638 taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06e0 armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0738 svchost.exe 0 0 0
075c fbguard.exe 0 0 0
0784 svchost.exe 0 0 0
0798 NetExpressUpdater.exe 0 0 0
07f0 OSPPSVC.EXE 0 0 0
0688 svchost.exe 0 0 0
0694 scpbradserv.exe 0 0 0
00bc svchost.exe 0 0 0
0828 core.exe 0 0 0
0968 RapportInjService_x64.exe 0 0 0
0a0c fbserver.exe 0 0 0
0bac WUDFHost.exe 0 0 0
0af0 NisSrv.exe 0 0 0
0f50 WmiPrvSE.exe 0 0 0
0f38 svchost.exe 0 0 0
0c44 GoogleCrashHandler.exe 0 0 0
0cd0 GoogleCrashHandler64.exe 0 0 0
095c SearchIndexer.exe 0 0 0
0ea0 taskhost.exe 1 26 23 normal
04ac core.exe 1 9 21 normal
0fe8 PresentationFontCache.exe 0 0 0
0fcc dwm.exe 1 18 4 high
0390 explorer.exe 1 473 345 normal
0938 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0d2c igfxEM.exe 1 14 13 normal
04c8 igfxHK.exe 1 14 13 normal
0ad0 RapportService.exe 1 14 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0dac msseces.exe 1 143 60 normal
09a8 PrnStatusMX.exe 1 23 18 normal
11d4 RapportInjService_x64.exe 1 4 3 normal
0414 wuauclt.exe 1 12 6 normal
1324 Store.exe 1 2898 631 normal C:\Program Files (x86)\Store
1200 OIS.EXE 1 81 36 normal
0ccc splwow64.exe 1 9 3 normal
0e04 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
0fbc OIS.EXE 1 161 55 normal
154c chrome.exe 1 75 60 normal
131c chrome.exe 1 9 4 normal
1380 chrome.exe 1 8 6 above normal
1398 chrome.exe 1 4 1 normal
128c chrome.exe 1 4 1 normal
0584 chrome.exe 1 4 1 normal
16fc chrome.exe 1 4 1 idle
1318 chrome.exe 1 4 3 normal
17ec OIS.EXE 1 97 45 normal
1338 EXCEL.EXE 1 383 140 normal
1758 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0b3ad150
ebx = 00003303
ecx = 00000000
edx = 02702ac8
esi = 0018da4c
edi = 0066cb50
eip = 0066ea6e
esp = 0018da10
ebp = 0018da78
stack dump:
0018da10 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018da20 24 da 18 00 6e ea 66 00 - 50 d1 3a 0b 03 33 00 00 $...n.f.P.:..3..
0018da30 4c da 18 00 50 cb 66 00 - 78 da 18 00 40 da 18 00 L...P.f.x...@...
0018da40 30 34 43 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 04C.z.f...g.....
0018da50 30 34 43 06 00 00 00 00 - 9b e8 67 00 84 da 18 00 04C.......g.....
0018da60 0c 89 40 00 78 da 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018da70 d5 e9 67 01 30 34 43 06 - a0 da 18 00 f3 e8 67 00 ..g.04C.......g.
0018da80 12 4d 67 00 b8 da 18 00 - 0c 89 40 00 a0 da 18 00 .Mg.......@.....
0018da90 30 34 43 06 00 00 00 00 - 00 00 00 00 30 34 43 06 04C.........04C.
0018daa0 cc da 18 00 b6 92 67 00 - 00 00 00 00 38 5d 53 00 ......g.....8]S.
0018dab0 01 00 00 00 e3 73 65 00 - d8 da 18 00 0c 89 40 00 .....se.......@.
0018dac0 cc da 18 00 70 80 ab 0b - 30 34 43 06 3c e0 18 00 ....p...04C.<...
0018dad0 2a 72 65 00 ce c2 ed 00 - 44 e0 18 00 0c 89 40 00 *re.....D.....@.
0018dae0 3c e0 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 <...............
0018daf0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db00 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db10 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db20 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db30 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018db40 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
00edc29d push $edd4f8
00edc2a2 lea eax, [ebp-$4bc]
00edc2a8 mov edx, 3
00edc2ad call -$ad1aea ($40a7c8) ; System.@UStrCatN
00edc2b2 mov edx, [ebp-$4bc]
00edc2b8 mov eax, [ebp-$34]
00edc2bb mov eax, [eax+$250]
00edc2c1 mov ecx, [eax]
00edc2c3 call dword ptr [ecx+$38]
00edc2c6 4111 mov eax, [ebp-$34]
00edc2c9 > call -$8850ae ($657220) ; Data.DB.TDataSet.Open
00edc2ce 4113 mov eax, [$15bcdf0]
00edc2d3 mov eax, [eax]
00edc2d5 mov eax, [eax+$1710]
00edc2db cmp byte ptr [eax+$a9], 0
00edc2e2 jz loc_edc89e
00edc2e8 mov eax, [$15bcdf0]
00edc2ed mov eax, [eax]
00edc2ef mov eax, [eax+$1710]
00edc2f5 cmp byte ptr [eax+$a8], 0
00edc2fc jz loc_edc89e
[...]
thread $1258:
7770f8da +0e ntdll.dll NtWaitForSingleObject
754515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76bd118f +3e kernel32.dll WaitForSingleObjectEx
76bd1143 +0d kernel32.dll WaitForSingleObject
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $1250:
77710166 +0e ntdll.dll NtWaitForMultipleObjects
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $cc8:
77710166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76bd3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($614) at:
72c32713 +24f netbios.dll Netbios
thread $42c:
7770f8da +0e ntdll.dll NtWaitForSingleObject
754515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76bd118f +3e kernel32.dll WaitForSingleObjectEx
76bd1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76bd3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($614) at:
72dc4c95 +00 winspool.drv
thread $da4:
77711f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $1428:
77711f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $105c:
77711f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76bd3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
062a0000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06330000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
703c0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
707c0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70d50000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70d60000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70d80000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70d90000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70db0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70e00000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70e40000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
713f0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71450000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71490000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
714b0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
715e0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71980000 webio.dll 6.1.7601.23375 C:\Windows\
system32
719d0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71a30000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72520000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72540000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72620000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
727d0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
727f0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72800000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72c00000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72c30000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
72c40000 security.dll 6.1.7600.16385 C:\Windows\
system32
72c50000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
72cb0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
72db0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73930000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73fb0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
740c0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74110000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74140000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74170000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
741b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
741d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
741e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
741f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74250000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
742c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74460000 version.dll 6.1.7600.16385 C:\Windows\
system32
74470000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74f80000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74f90000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74ff0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75070000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75210000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
752e0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75430000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75440000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75490000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
754c0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
755c0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75670000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75720000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
759d0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
759e0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75a80000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75a90000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75af0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75b90000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75bb0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76800000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76880000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
768c0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
768d0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76960000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
769f0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76a00000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76b60000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76b70000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76bc0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76cd0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ce0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76d10000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76d30000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76e60000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76f00000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76f50000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76f60000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
771a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77200000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
776c0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
776f0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0340 svchost.exe 0 0 0
0218 svchost.exe 0 0 0
0414 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
055c svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0638 taskeng.exe 0 0 0
0660 svchost.exe 0 0 0
06e8 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0764 fbguard.exe 0 0 0
0788 svchost.exe 0 0 0
07a0 NetExpressUpdater.exe 0 0 0
07f8 OSPPSVC.EXE 0 0 0
0688 svchost.exe 0 0 0
06cc scpbradserv.exe 0 0 0
0824 core.exe 0 0 0
0978 RapportInjService_x64.exe 0 0 0
0a28 fbserver.exe 0 0 0
0be0 WUDFHost.exe 0 0 0
0b30 NisSrv.exe 0 0 0
0f14 WmiPrvSE.exe 0 0 0
0e74 svchost.exe 0 0 0
0f0c GoogleCrashHandler.exe 0 0 0
0c28 GoogleCrashHandler64.exe 0 0 0
07e4 SearchIndexer.exe 0 0 0
0a44 taskhost.exe 1 26 23 normal
0a54 core.exe 1 9 21 normal
0c8c PresentationFontCache.exe 0 0 0
0bd0 dwm.exe 1 17 4 high
0d48 explorer.exe 1 430 255 normal
0ee0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
033c igfxEM.exe 1 14 13 normal
0a58 igfxHK.exe 1 14 12 normal
0fc8 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e90 msseces.exe 1 143 59 normal
07ec PrnStatusMX.exe 1 23 18 normal
1144 RapportInjService_x64.exe 1 4 3 normal
1304 wuauclt.exe 1 12 7 normal
0e00 Store.exe 1 771 331 normal C:\Program Files (x86)\Store
0ea4 Store.exe 1 276 184 normal C:\Program Files (x86)\Store
17c0 chrome.exe 1 28 64 normal
1044 chrome.exe 1 9 4 normal
1020 chrome.exe 1 8 7 above normal
178c chrome.exe 1 4 1 normal
17f8 chrome.exe 1 4 1 normal
1058 chrome.exe 1 4 1 normal
0b10 chrome.exe 1 4 3 normal
1184 chrome.exe 1 4 1 idle
03e8 splwow64.exe 1 9 4 normal
121c OIS.EXE 1 81 37 normal
165c chrome.exe 1 4 1 idle
1128 chrome.exe 1 4 1 idle
1718 audiodg.exe 0 0 0
05a8 rundll32.exe 1 117 48 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 06483d90
ecx = 044e2290
edx = 044de670
esi = 00593bec
edi = 0018de60
eip = 006fa3da
esp = 0018dcec
ebp = 0018de54
stack dump:
0018dcec ec 3b 59 00 d0 2c 59 0a - ed 04 53 00 d0 2c 59 0a .;Y..,Y...S..,Y.
0018dcfc f1 3b 59 00 96 09 53 00 - 15 00 0d 00 15 00 00 00 .;Y...S.........
0018dd0c 0d 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
0018dd1c 16 00 00 00 15 00 0d 00 - d0 2c 59 0a 60 de 18 00 .........,Y.`...
0018dd2c 94 ff 52 00 15 00 0d 00 - 5c df 18 00 d0 2c 59 0a ..R.....\....,Y.
0018dd3c d0 2c 59 0a ce 01 00 00 - 0d 00 00 00 00 00 00 00 .,Y.............
0018dd4c c8 dd 18 00 1f b0 54 72 - 78 e7 b5 0a 12 06 08 00 ......Trx.......
0018dd5c 02 02 00 00 0f 00 00 00 - ce 01 0d 00 00 00 00 00 ................
0018dd6c bb 80 54 72 8e 81 54 72 - 90 13 4e 04 ce 01 0d 00 ..Tr..Tr..N.....
0018dd7c 12 06 08 00 00 00 00 00 - 90 13 4e 04 58 47 7c 04 ..........N.XG|.
0018dd8c 07 00 00 00 1c 00 00 00 - 50 e0 57 04 98 de 18 00 ........P.W.....
0018dd9c 00 00 00 00 00 00 00 00 - bb 80 54 72 01 00 00 00 ..........Tr....
0018ddac 44 de 18 00 00 00 00 00 - 00 00 00 00 c8 dd 18 00 D...............
0018ddbc 07 00 00 00 00 00 00 00 - 79 8b 57 71 f4 dd 18 00 ........y.Wq....
0018ddcc fa 62 4d 75 12 06 08 00 - 02 02 00 00 00 00 00 00 .bMu............
0018dddc ce 01 0d 00 bb 80 54 72 - cd ab ba dc 00 00 00 00 ......Tr........
0018ddec 00 00 00 00 0c de 18 00 - cf fb 52 00 d0 2c 59 0a ..........R..,Y.
0018ddfc 0a b0 00 00 00 00 00 00 - 15 00 0d 00 01 00 00 00 ................
0018de0c 40 de 18 00 41 40 53 00 - 15 00 0d 00 90 13 4e 04 @[email protected].
0018de1c 00 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
disassembling:
[...]
006fa3ae mov edx, [$6e9910]
006fa3b4 call -$2f2b11 ($4078a8) ; System.@IsClass
006fa3b9 test al, al
006fa3bb jnz loc_6fa3ca
006fa3bd 402 mov eax, [ebx+$460]
006fa3c3 call +$cd78 ($707140) ; QRPrntr.TQRPrinter.Print
006fa3c8 jmp loc_6fa3f4
006fa3ca 405 mov eax, [$15c48cc]
006fa3cf call -$741c ($6f2fb8) ; QuickRpt.TCustomQuickRep.Print
006fa3d4 407 mov eax, [ebx+$3cc]
006fa3da > cmp dword ptr [eax+$2b8], 0
006fa3e1 jnz loc_6fa3f4
006fa3e3 409 mov edx, [$15c48cc]
006fa3e9 mov edx, [edx+$36c]
006fa3ef call +$9920 ($703d14) ; QRPrntr.TQRPreview.SetQRPrinter
006fa3f4 412 pop esi
006fa3f5 pop ebx
006fa3f6 ret
thread $1104:
7770f8da +0e ntdll.dll NtWaitForSingleObject
754515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76bd118f +3e kernel32.dll WaitForSingleObjectEx
76bd1143 +0d kernel32.dll WaitForSingleObject
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $6dc:
77710166 +0e ntdll.dll NtWaitForMultipleObjects
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $15fc:
7770f8da +0e ntdll.dll NtWaitForSingleObject
754515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76bd118f +3e kernel32.dll WaitForSingleObjectEx
76bd1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76bd3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d84) at:
74034c95 +00 winspool.drv
thread $150c:
77711f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $470:
77711f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $c90:
77711f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76bd3368 +10 kernel32.dll BaseThreadInitThunk
modules:
002b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00390000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06240000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06330000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
703c0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
707c0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70d50000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70d60000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70d80000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70d90000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70db0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70e00000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70e40000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
713f0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71450000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71490000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
714b0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
715e0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71980000 webio.dll 6.1.7601.23375 C:\Windows\
system32
719d0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71a30000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72520000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72540000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72620000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
727d0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
727f0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72800000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73160000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73e50000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73ee0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73f10000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73f20000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
74020000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
740a0000 security.dll 6.1.7600.16385 C:\Windows\
system32
740c0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74110000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74140000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74170000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
741b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
741d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
741e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
741f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74250000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
742c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74460000 version.dll 6.1.7600.16385 C:\Windows\
system32
74470000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74f80000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74f90000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74ff0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75070000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75210000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
752e0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75430000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75440000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75490000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
754c0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
755c0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75670000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75720000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
759d0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
759e0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75a80000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75a90000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75af0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75b90000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75bb0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76800000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76880000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
768c0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
768d0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76960000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
769f0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76a00000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76b60000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76b70000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76bc0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76cd0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ce0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76d10000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76d30000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76e60000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76f00000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76f50000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76f60000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
771a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77200000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
776c0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
776f0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0340 svchost.exe 0 0 0
0218 svchost.exe 0 0 0
0414 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
055c svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0638 taskeng.exe 0 0 0
0660 svchost.exe 0 0 0
06e8 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0764 fbguard.exe 0 0 0
0788 svchost.exe 0 0 0
07a0 NetExpressUpdater.exe 0 0 0
07f8 OSPPSVC.EXE 0 0 0
0688 svchost.exe 0 0 0
06cc scpbradserv.exe 0 0 0
0824 core.exe 0 0 0
0978 RapportInjService_x64.exe 0 0 0
0a28 fbserver.exe 0 0 0
0be0 WUDFHost.exe 0 0 0
0b30 NisSrv.exe 0 0 0
0f14 WmiPrvSE.exe 0 0 0
0e74 svchost.exe 0 0 0
07e4 SearchIndexer.exe 0 0 0
0a44 taskhost.exe 1 26 23 normal
0a54 core.exe 1 9 21 normal
0c8c PresentationFontCache.exe 0 0 0
0bd0 dwm.exe 1 18 4 high
0d48 explorer.exe 1 811 524 normal
0ee0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
033c igfxEM.exe 1 14 13 normal
0a58 igfxHK.exe 1 14 12 normal
0fc8 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e90 msseces.exe 1 143 59 normal
07ec PrnStatusMX.exe 1 23 18 normal
1144 RapportInjService_x64.exe 1 4 3 normal
1304 wuauclt.exe 1 12 6 normal
1640 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
1198 OIS.EXE 1 81 37 normal
1768 chrome.exe 1 28 61 normal
17d4 chrome.exe 1 9 4 normal
0364 chrome.exe 1 7 8 above normal
0128 chrome.exe 1 4 1 normal
178c chrome.exe 1 4 1 normal
0378 chrome.exe 1 4 1 normal
1764 chrome.exe 1 4 1 idle
1578 chrome.exe 1 4 3 normal
0894 Store.exe 1 1248 365 normal C:\Program Files (x86)\Store
173c Store.exe 1 227 184 normal C:\Program Files (x86)\Store
1070 splwow64.exe 1 9 5 normal
0d70 OIS.EXE 1 81 37 normal
16e8 GoogleCrashHandler.exe 0 0 0
0b84 GoogleCrashHandler64.exe 0 0 0
05c0 audiodg.exe 0 0 0
177c rundll32.exe 1 117 48 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 00000000
ebx = 06485b30
ecx = 04443190
edx = 0443e670
esi = 00593bec
edi = 0018de60
eip = 006fa3da
esp = 0018dcec
ebp = 0018de54
stack dump:
0018dcec ec 3b 59 00 50 bb 16 0a - ed 04 53 00 50 bb 16 0a .;Y.P.....S.P...
0018dcfc f1 3b 59 00 96 09 53 00 - 12 00 0e 00 12 00 00 00 .;Y...S.........
0018dd0c 0e 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
0018dd1c 16 00 00 00 12 00 0e 00 - 50 bb 16 0a 60 de 18 00 ........P...`...
0018dd2c 94 ff 52 00 12 00 0e 00 - 5c df 18 00 50 bb 16 0a ..R.....\...P...
0018dd3c 50 bb 16 0a cb 01 00 00 - 0e 00 00 00 00 00 00 00 P...............
0018dd4c c8 dd 18 00 1f b0 54 72 - 58 8c 62 02 a0 06 0b 00 ......TrX.b.....
0018dd5c 02 02 00 00 0f 00 00 00 - cb 01 0e 00 00 00 00 00 ................
0018dd6c bb 80 54 72 8e 81 54 72 - 00 00 00 00 cb 01 0e 00 ..Tr..Tr........
0018dd7c a0 06 0b 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dd9c 00 00 00 00 00 00 00 00 - bb 80 54 72 01 00 00 00 ..........Tr....
0018ddac 44 de 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 D...............
0018ddbc 00 00 00 00 00 00 00 00 - fc 64 77 3f f4 dd 18 00 .........dw?....
0018ddcc fa 62 4d 75 a0 06 0b 00 - 02 02 00 00 00 00 00 00 .bMu............
0018dddc cb 01 0e 00 bb 80 54 72 - cd ab ba dc 00 00 00 00 ......Tr........
0018ddec 00 00 00 00 0c de 18 00 - cf fb 52 00 50 bb 16 0a ..........R.P...
0018ddfc 0a b0 00 00 00 00 00 00 - 12 00 0e 00 01 00 00 00 ................
0018de0c 40 de 18 00 41 40 53 00 - 12 00 0e 00 50 26 44 04 @[email protected]&D.
0018de1c 00 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
disassembling:
[...]
006fa3ae mov edx, [$6e9910]
006fa3b4 call -$2f2b11 ($4078a8) ; System.@IsClass
006fa3b9 test al, al
006fa3bb jnz loc_6fa3ca
006fa3bd 402 mov eax, [ebx+$460]
006fa3c3 call +$cd78 ($707140) ; QRPrntr.TQRPrinter.Print
006fa3c8 jmp loc_6fa3f4
006fa3ca 405 mov eax, [$15c48cc]
006fa3cf call -$741c ($6f2fb8) ; QuickRpt.TCustomQuickRep.Print
006fa3d4 407 mov eax, [ebx+$3cc]
006fa3da > cmp dword ptr [eax+$2b8], 0
006fa3e1 jnz loc_6fa3f4
006fa3e3 409 mov edx, [$15c48cc]
006fa3e9 mov edx, [edx+$36c]
006fa3ef call +$9920 ($703d14) ; QRPrntr.TQRPreview.SetQRPrinter
006fa3f4 412 pop esi
006fa3f5 pop ebx
006fa3f6 ret
thread $1104:
7770f8da +0e ntdll.dll NtWaitForSingleObject
754515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76bd118f +3e kernel32.dll WaitForSingleObjectEx
76bd1143 +0d kernel32.dll WaitForSingleObject
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $6dc:
77710166 +0e ntdll.dll NtWaitForMultipleObjects
76bd3368 +10 kernel32.dll BaseThreadInitThunk
thread $15fc:
7770f8da +0e ntdll.dll NtWaitForSingleObject
754515c8 +92 KERNELBASE.dll WaitForSingleObjectEx
76bd118f +3e kernel32.dll WaitForSingleObjectEx
76bd1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76bd3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($d84) at:
74034c95 +00 winspool.drv
thread $c90:
77711f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76bd3368 +10 kernel32.dll BaseThreadInitThunk
modules:
002b0000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00390000 WINPPLA.DLL C:\Program
Files (x86)\Store
003d0000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06240000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06330000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
703c0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
707c0000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70d50000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70d60000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70d80000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70d90000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70db0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70e00000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70e40000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
713f0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71450000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71490000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
714b0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
715e0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71980000 webio.dll 6.1.7601.23375 C:\Windows\
system32
719d0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71a30000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72520000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72540000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
725e0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72620000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
727d0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
727f0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72800000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73160000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73e50000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73ee0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73f10000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73f20000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
74020000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
740a0000 security.dll 6.1.7600.16385 C:\Windows\
system32
740c0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74110000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74140000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74170000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
741b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
741d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
741e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
741f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74250000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
742c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74460000 version.dll 6.1.7600.16385 C:\Windows\
system32
74470000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74f80000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74f90000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
74ff0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75070000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75210000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
752e0000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
75430000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75440000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75490000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
754c0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
755c0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75670000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75720000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
759d0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
759e0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
75a80000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
75a90000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
75af0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75b90000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75bb0000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
76800000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76880000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
768c0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
768d0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76960000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
769f0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76a00000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76b60000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76b70000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76bb0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76bc0000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76cd0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76ce0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76d10000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76d30000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76e60000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76f00000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
76f50000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76f60000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
771a0000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
77200000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
776c0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
776f0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02b8 services.exe 0 0 0
02cc lsass.exe 0 0 0
02d4 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
0160 RapportMgmtService.exe 0 0 0
0168 svchost.exe 0 0 0
0340 svchost.exe 0 0 0
0218 svchost.exe 0 0 0
0414 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
050c igfxCUIService.exe 0 0 0
055c svchost.exe 0 0 0
062c spoolsv.exe 0 0 0
0638 taskeng.exe 0 0 0
0660 svchost.exe 0 0 0
06e8 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0764 fbguard.exe 0 0 0
0788 svchost.exe 0 0 0
07a0 NetExpressUpdater.exe 0 0 0
07f8 OSPPSVC.EXE 0 0 0
0688 svchost.exe 0 0 0
06cc scpbradserv.exe 0 0 0
0824 core.exe 0 0 0
0978 RapportInjService_x64.exe 0 0 0
0a28 fbserver.exe 0 0 0
0be0 WUDFHost.exe 0 0 0
0b30 NisSrv.exe 0 0 0
0f14 WmiPrvSE.exe 0 0 0
0e74 svchost.exe 0 0 0
07e4 SearchIndexer.exe 0 0 0
0a44 taskhost.exe 1 26 22 normal
0a54 core.exe 1 9 21 normal
0c8c PresentationFontCache.exe 0 0 0
0bd0 dwm.exe 1 18 4 high
0d48 explorer.exe 1 809 518 normal
0ee0 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
033c igfxEM.exe 1 14 13 normal
0a58 igfxHK.exe 1 14 12 normal
0fc8 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e90 msseces.exe 1 143 59 normal
07ec PrnStatusMX.exe 1 23 18 normal
1144 RapportInjService_x64.exe 1 4 3 normal
1304 wuauclt.exe 1 12 6 normal
1640 DllHost.exe 1 9 5 normal C:\Windows\SysWOW64
1198 OIS.EXE 1 81 37 normal
1768 chrome.exe 1 28 62 normal
17d4 chrome.exe 1 9 4 normal
0364 chrome.exe 1 7 8 above normal
0128 chrome.exe 1 4 1 normal
178c chrome.exe 1 4 1 normal
0378 chrome.exe 1 4 1 normal
1764 chrome.exe 1 4 1 idle
1578 chrome.exe 1 4 3 normal
0894 Store.exe 1 1310 474 normal C:\Program Files (x86)\Store
173c Store.exe 1 227 184 normal C:\Program Files (x86)\Store
1070 splwow64.exe 1 9 4 normal
0d70 OIS.EXE 1 81 37 normal
16e8 GoogleCrashHandler.exe 0 0 0
0b84 GoogleCrashHandler64.exe 0 0 0
1568 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a944178
ebx = 00003303
ecx = 00000000
edx = 025b2ac8
esi = 0018df20
edi = 0066cb50
eip = 0066ea6e
esp = 0018dee4
ebp = 0018df4c
stack dump:
0018dee4 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018def4 f8 de 18 00 6e ea 66 00 - 78 41 94 0a 03 33 00 00 ....n.f.xA...3..
0018df04 20 df 18 00 50 cb 66 00 - 4c df 18 00 14 df 18 00 ...P.f.L.......
0018df14 e0 e2 4e 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 ..N.z.f...g.....
0018df24 e0 e2 4e 04 00 00 00 00 - 9b e8 67 00 58 df 18 00 ..N.......g.X...
0018df34 0c 89 40 00 4c df 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018df44 d5 e9 67 01 e0 e2 4e 04 - 74 df 18 00 f3 e8 67 00 ..g...N.t.....g.
0018df54 12 4d 67 00 8c df 18 00 - 0c 89 40 00 74 df 18 00 [email protected]...
0018df64 e0 e2 4e 04 00 00 00 00 - 00 00 00 00 e0 e2 4e 04 ..N...........N.
0018df74 a0 df 18 00 b6 92 67 00 - 04 e2 18 00 38 5d 53 00 ......g.....8]S.
0018df84 01 00 00 00 e3 73 65 00 - ac df 18 00 0c 89 40 00 .....se.......@.
0018df94 a0 df 18 00 a0 f4 86 0a - e0 e2 4e 04 dc df 18 00 ..........N.....
0018dfa4 2a 72 65 00 76 26 ed 00 - f4 df 18 00 0c 89 40 00 *re.v&........@.
0018dfb4 dc df 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018dfc4 00 00 00 00 00 00 00 00 - 00 00 00 00 a0 f4 86 0a ................
0018dfd4 e0 e2 4e 04 d0 41 0c 0a - 14 e0 18 00 53 5d 53 00 ..N..A......S]S.
0018dfe4 04 e2 18 00 06 6a 53 00 - 04 e2 18 00 4e 0e 55 00 .....jS.....N.U.
0018dff4 a4 e1 18 00 0c 89 40 00 - 14 e0 18 00 04 e2 18 00 ......@.........
0018e004 a0 f4 86 0a 04 e2 18 00 - 00 00 00 00 a0 f4 86 0a ................
0018e014 40 e1 18 00 94 ff 52 00 - 04 e2 18 00 a0 f4 86 0a @.....R.........
disassembling:
[...]
00ed264b push $ed2804
00ed2650 lea eax, [ebp-$10]
00ed2653 mov edx, 3
00ed2658 call -$ac7e95 ($40a7c8) ; System.@UStrCatN
00ed265d mov edx, [ebp-$10]
00ed2660 mov eax, [ebp-8]
00ed2663 mov eax, [eax+$250]
00ed2669 mov ecx, [eax]
00ed266b call dword ptr [ecx+$38]
00ed266e 2801 mov eax, [ebp-8]
00ed2671 > call -$87b456 ($657220) ; Data.DB.TDataSet.Open
00ed2676 2802 mov eax, [ebp-8]
00ed2679 call -$878b96 ($659ae8) ; Data.DB.TDataSet.First
00ed267e 2824 lea edx, [ebp-$18]
00ed2681 mov eax, [ebp-4]
00ed2684 mov eax, [eax+$48c]
00ed268a call -$9a4027 ($52e668) ; Vcl.Controls.TControl.GetText
00ed268f mov eax, [ebp-$18]
00ed2692 mov edx, $ed2814
00ed2697 call -$ac7dc4 ($40a8d8) ; System.@UStrEqual
00ed269c jnz loc_ed26c4
[...]
thread $119c:
777ef8da +0e ntdll.dll NtWaitForSingleObject
752d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7622118f +3e kernel32.dll WaitForSingleObjectEx
76221143 +0d kernel32.dll WaitForSingleObject
76223368 +10 kernel32.dll BaseThreadInitThunk
thread $11a8:
777f0166 +0e ntdll.dll NtWaitForMultipleObjects
76223368 +10 kernel32.dll BaseThreadInitThunk
thread $1244:
777f0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76223368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1188) at:
73b92713 +24f netbios.dll Netbios
thread $8c0:
777ef8da +0e ntdll.dll NtWaitForSingleObject
752d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7622118f +3e kernel32.dll WaitForSingleObjectEx
76221143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76223368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1188) at:
73ec4c95 +00 winspool.drv
thread $1328:
777f1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76223368 +10 kernel32.dll BaseThreadInitThunk
thread $a78:
777f1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76223368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00320000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06240000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06370000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70850000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70bf0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70c00000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70c20000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70c30000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70c50000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70cb0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70e70000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70e80000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
711c0000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
71290000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
712f0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71330000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71370000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71390000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
716a0000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
716c0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71a60000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71ab0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71b10000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72600000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72620000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
726c0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72700000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
728b0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
728d0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
728e0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73a50000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73b50000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73b60000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73b90000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73ba0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73bb0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73bc0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73c20000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73eb0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
741a0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
741f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74220000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74250000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74290000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
742b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
742c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
742d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
742e0000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
74330000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74370000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74380000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
743a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74540000 version.dll 6.1.7600.16385 C:\Windows\
system32
74550000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75060000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75070000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
750d0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75170000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75180000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
752b0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
752c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75310000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
753b0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
753c0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75460000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75470000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75570000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
756c0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
757b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
757d0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75800000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75880000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75890000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75940000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
759d0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
759f0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75a30000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75a90000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75d40000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75f80000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76050000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76060000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76200000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76210000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76380000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76390000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
763e0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76410000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76420000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
764b0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
764f0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
765a0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
765c0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76720000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76780000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
777a0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
777d0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
025c csrss.exe 1 0 0
0264 wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02c8 services.exe 0 0 0
02d0 lsass.exe 0 0 0
02d8 lsm.exe 0 0 0
0338 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
0148 RapportMgmtService.exe 0 0 0
02b8 svchost.exe 0 0 0
0348 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0504 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0634 spoolsv.exe 0 0 0
063c taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0764 fbguard.exe 0 0 0
0788 svchost.exe 0 0 0
079c NetExpressUpdater.exe 0 0 0
07f8 OSPPSVC.EXE 0 0 0
0698 svchost.exe 0 0 0
06d0 scpbradserv.exe 0 0 0
082c core.exe 0 0 0
0974 RapportInjService_x64.exe 0 0 0
0a30 fbserver.exe 0 0 0
0b98 WUDFHost.exe 0 0 0
0b38 NisSrv.exe 0 0 0
0eec WmiPrvSE.exe 0 0 0
0dec svchost.exe 0 0 0
0e88 GoogleCrashHandler.exe 0 0 0
0f30 GoogleCrashHandler64.exe 0 0 0
0fcc SearchIndexer.exe 0 0 0
0c38 taskhost.exe 1 26 23 normal
0884 core.exe 1 9 20 normal
0ff8 PresentationFontCache.exe 0 0 0
0a40 dwm.exe 1 16 4 high
0fc8 explorer.exe 1 405 251 normal
03d4 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0e60 igfxEM.exe 1 14 13 normal
0ba4 igfxHK.exe 1 14 13 normal
0ca0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
07e4 msseces.exe 1 143 59 normal
0e80 PrnStatusMX.exe 1 23 18 normal
10a0 RapportInjService_x64.exe 1 4 3 normal
1360 wuauclt.exe 1 12 7 normal
1184 Store.exe 1 1140 439 normal C:\Program Files (x86)\Store
0c48 splwow64.exe 1 9 4 normal
12d8 OIS.EXE 1 84 38 normal
0e90 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
106c chrome.exe 1 22 45 normal
1090 chrome.exe 1 9 4 normal
0f0c chrome.exe 1 7 5 above normal
0490 chrome.exe 1 4 1 normal
1134 chrome.exe 1 4 1 normal
1054 chrome.exe 1 4 1 idle
1208 chrome.exe 1 4 1 idle
1164 chrome.exe 1 4 1 idle
115c audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0ba1d688
ebx = 00003303
ecx = 00000000
edx = 02622ac8
esi = 0018ea1c
edi = 0066cb50
eip = 0066ea6e
esp = 0018e9e0
ebp = 0018ea48
stack dump:
0018e9e0 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e9f0 f4 e9 18 00 6e ea 66 00 - 88 d6 a1 0b 03 33 00 00 ....n.f......3..
0018ea00 1c ea 18 00 50 cb 66 00 - 48 ea 18 00 10 ea 18 00 ....P.f.H.......
0018ea10 50 56 43 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 PVC.z.f...g.....
0018ea20 50 56 43 06 00 00 00 00 - 9b e8 67 00 54 ea 18 00 PVC.......g.T...
0018ea30 0c 89 40 00 48 ea 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018ea40 d5 e9 67 01 50 56 43 06 - 70 ea 18 00 f3 e8 67 00 ..g.PVC.p.....g.
0018ea50 12 4d 67 00 88 ea 18 00 - 0c 89 40 00 70 ea 18 00 [email protected]...
0018ea60 50 56 43 06 00 00 00 00 - 00 00 00 00 50 56 43 06 PVC.........PVC.
0018ea70 9c ea 18 00 b6 92 67 00 - a0 1e 40 04 00 00 00 00 ......g...@.....
0018ea80 01 00 00 00 e3 73 65 00 - a8 ea 18 00 0c 89 40 00 .....se.......@.
0018ea90 9c ea 18 00 80 c0 41 04 - 50 56 43 06 6c eb 18 00 ......A.PVC.l...
0018eaa0 2a 72 65 00 e8 eb 12 01 - 74 eb 18 00 0c 89 40 00 *re.....t.....@.
0018eab0 6c eb 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 l...............
0018eac0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ead0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eae0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eaf0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eb00 00 00 00 00 00 00 00 00 - c0 91 e5 40 d0 37 3c 06 [email protected]<.
0018eb10 00 00 00 00 fa a4 4f fa - 9f 99 e5 40 00 00 00 00 ......O....@....
disassembling:
[...]
0112ebbf mov eax, [ebp-$18]
0112ebc2 mov eax, [eax+$250]
0112ebc8 mov ecx, [eax]
0112ebca call dword ptr [ecx+$38]
0112ebcd 425 mov edx, $112fc20
0112ebd2 mov eax, [ebp-$18]
0112ebd5 mov eax, [eax+$250]
0112ebdb mov ecx, [eax]
0112ebdd call dword ptr [ecx+$38]
0112ebe0 427 mov eax, [ebp-$18]
0112ebe3 > call -$ad79c8 ($657220) ; Data.DB.TDataSet.Open
0112ebe8 428 mov eax, [ebp-$18]
0112ebeb call -$ad5108 ($659ae8) ; Data.DB.TDataSet.First
0112ebf0 429 mov eax, [ebp-$18]
0112ebf3 cmp byte ptr [eax+$a9], 0
0112ebfa jz loc_112ec08
0112ebfc mov eax, [ebp-$18]
0112ebff cmp byte ptr [eax+$a8], 0
0112ec06 jnz loc_112ec17
0112ec08 431 mov eax, [ebp-4]
0112ec0b call +$33080 ($1161c90) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $119c:
777ef8da +0e ntdll.dll NtWaitForSingleObject
752d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7622118f +3e kernel32.dll WaitForSingleObjectEx
76221143 +0d kernel32.dll WaitForSingleObject
76223368 +10 kernel32.dll BaseThreadInitThunk
thread $11a8:
777f0166 +0e ntdll.dll NtWaitForMultipleObjects
76223368 +10 kernel32.dll BaseThreadInitThunk
thread $1244:
777f0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76223368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1188) at:
73b92713 +24f netbios.dll Netbios
thread $8c0:
777ef8da +0e ntdll.dll NtWaitForSingleObject
752d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7622118f +3e kernel32.dll WaitForSingleObjectEx
76221143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76223368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1188) at:
73ec4c95 +00 winspool.drv
thread $cd8:
777f1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76223368 +10 kernel32.dll BaseThreadInitThunk
thread $580:
777f1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76223368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00320000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06240000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06370000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70850000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70bf0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70c00000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70c20000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70c30000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70c50000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70cb0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70e70000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70e80000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
711c0000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
71290000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
712f0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71330000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71370000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71390000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
716a0000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
716c0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71a60000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71ab0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71b10000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72600000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72620000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
726c0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72700000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
728b0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
728d0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
728e0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73a50000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73b50000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73b60000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73b90000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73ba0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73bb0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73bc0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73c20000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73eb0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
741a0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
741f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74220000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74250000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74290000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
742b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
742c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
742d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
742e0000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
74330000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74370000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74380000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
743a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74540000 version.dll 6.1.7600.16385 C:\Windows\
system32
74550000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75060000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75070000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
750d0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75170000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75180000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
752b0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
752c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75310000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
753b0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
753c0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75460000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75470000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75570000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
756c0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
757b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
757d0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75800000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75880000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75890000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75940000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
759d0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
759f0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75a30000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75a90000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75d40000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75f80000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76050000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76060000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76200000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76210000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76380000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76390000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
763e0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76410000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76420000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
764b0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
764f0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
765a0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
765c0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76720000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76780000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
777a0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
777d0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
025c csrss.exe 1 0 0
0264 wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02c8 services.exe 0 0 0
02d0 lsass.exe 0 0 0
02d8 lsm.exe 0 0 0
0338 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
0148 RapportMgmtService.exe 0 0 0
02b8 svchost.exe 0 0 0
0348 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0504 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0634 spoolsv.exe 0 0 0
063c taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0764 fbguard.exe 0 0 0
0788 svchost.exe 0 0 0
079c NetExpressUpdater.exe 0 0 0
07f8 OSPPSVC.EXE 0 0 0
0698 svchost.exe 0 0 0
06d0 scpbradserv.exe 0 0 0
082c core.exe 0 0 0
0974 RapportInjService_x64.exe 0 0 0
0a30 fbserver.exe 0 0 0
0b98 WUDFHost.exe 0 0 0
0b38 NisSrv.exe 0 0 0
0eec WmiPrvSE.exe 0 0 0
0dec svchost.exe 0 0 0
0e88 GoogleCrashHandler.exe 0 0 0
0f30 GoogleCrashHandler64.exe 0 0 0
0fcc SearchIndexer.exe 0 0 0
0c38 taskhost.exe 1 26 23 normal
0884 core.exe 1 9 21 normal
0ff8 PresentationFontCache.exe 0 0 0
0a40 dwm.exe 1 16 4 high
0fc8 explorer.exe 1 405 273 normal
03d4 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0e60 igfxEM.exe 1 14 13 normal
0ba4 igfxHK.exe 1 14 13 normal
0ca0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
07e4 msseces.exe 1 143 59 normal
0e80 PrnStatusMX.exe 1 23 18 normal
10a0 RapportInjService_x64.exe 1 4 3 normal
1360 wuauclt.exe 1 12 7 normal
1184 Store.exe 1 2282 981 normal C:\Program Files (x86)\Store
0c48 splwow64.exe 1 9 3 normal
12d8 OIS.EXE 1 84 38 normal
0e90 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
106c chrome.exe 1 23 57 normal
1090 chrome.exe 1 9 4 normal
0f0c chrome.exe 1 7 6 above normal
0490 chrome.exe 1 4 1 normal
1134 chrome.exe 1 4 1 normal
1124 chrome.exe 1 4 1 normal
0838 chrome.exe 1 4 1 idle
125c audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0c099ce0
ebx = 00003303
ecx = 00000000
edx = 02622ac8
esi = 0018d174
edi = 0066cb50
eip = 0066ea6e
esp = 0018d138
ebp = 0018d1a0
stack dump:
0018d138 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018d148 4c d1 18 00 6e ea 66 00 - e0 9c 09 0c 03 33 00 00 L...n.f......3..
0018d158 74 d1 18 00 50 cb 66 00 - a0 d1 18 00 68 d1 18 00 t...P.f.....h...
0018d168 50 56 43 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 PVC.z.f...g.....
0018d178 50 56 43 06 00 00 00 00 - 9b e8 67 00 ac d1 18 00 PVC.......g.....
0018d188 0c 89 40 00 a0 d1 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018d198 d5 e9 67 01 50 56 43 06 - c8 d1 18 00 f3 e8 67 00 ..g.PVC.......g.
0018d1a8 12 4d 67 00 e0 d1 18 00 - 0c 89 40 00 c8 d1 18 00 .Mg.......@.....
0018d1b8 50 56 43 06 00 00 00 00 - 00 00 00 00 50 56 43 06 PVC.........PVC.
0018d1c8 f4 d1 18 00 b6 92 67 00 - b8 d7 18 00 80 d8 1d 0d ......g.........
0018d1d8 01 00 00 00 e3 73 65 00 - 00 d2 18 00 0c 89 40 00 .....se.......@.
0018d1e8 f4 d1 18 00 80 d8 1d 0d - 50 56 43 06 c4 d2 18 00 ........PVC.....
0018d1f8 2a 72 65 00 e8 eb 12 01 - cc d2 18 00 0c 89 40 00 *re...........@.
0018d208 c4 d2 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d218 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d228 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d238 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d248 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018d258 00 00 00 00 00 00 00 00 - 80 99 e5 40 d0 37 3c 06 [email protected]<.
0018d268 00 00 00 00 fa a4 4f fa - 9f 99 e5 40 00 00 00 00 ......O....@....
disassembling:
[...]
0112ebbf mov eax, [ebp-$18]
0112ebc2 mov eax, [eax+$250]
0112ebc8 mov ecx, [eax]
0112ebca call dword ptr [ecx+$38]
0112ebcd 425 mov edx, $112fc20
0112ebd2 mov eax, [ebp-$18]
0112ebd5 mov eax, [eax+$250]
0112ebdb mov ecx, [eax]
0112ebdd call dword ptr [ecx+$38]
0112ebe0 427 mov eax, [ebp-$18]
0112ebe3 > call -$ad79c8 ($657220) ; Data.DB.TDataSet.Open
0112ebe8 428 mov eax, [ebp-$18]
0112ebeb call -$ad5108 ($659ae8) ; Data.DB.TDataSet.First
0112ebf0 429 mov eax, [ebp-$18]
0112ebf3 cmp byte ptr [eax+$a9], 0
0112ebfa jz loc_112ec08
0112ebfc mov eax, [ebp-$18]
0112ebff cmp byte ptr [eax+$a8], 0
0112ec06 jnz loc_112ec17
0112ec08 431 mov eax, [ebp-4]
0112ec0b call +$33080 ($1161c90) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $119c:
777ef8da +0e ntdll.dll NtWaitForSingleObject
752d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7622118f +3e kernel32.dll WaitForSingleObjectEx
76221143 +0d kernel32.dll WaitForSingleObject
76223368 +10 kernel32.dll BaseThreadInitThunk
thread $11a8:
777f0166 +0e ntdll.dll NtWaitForMultipleObjects
76223368 +10 kernel32.dll BaseThreadInitThunk
thread $1244:
777f0166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76223368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1188) at:
73b92713 +24f netbios.dll Netbios
thread $8c0:
777ef8da +0e ntdll.dll NtWaitForSingleObject
752d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7622118f +3e kernel32.dll WaitForSingleObjectEx
76221143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76223368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1188) at:
73ec4c95 +00 winspool.drv
thread $cd8:
777f1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76223368 +10 kernel32.dll BaseThreadInitThunk
thread $580:
777f1f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76223368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 WINPPLA.DLL C:\Program
Files (x86)\Store
00270000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
00320000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 BCLW32.dll C:\Program
Files (x86)\Store
06240000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06370000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
70850000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70bf0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70c00000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70c20000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70c30000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70c50000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70cb0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70e70000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70e80000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
711c0000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
71290000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
712f0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71330000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71370000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71390000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
716a0000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
716c0000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
71a60000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71ab0000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71b10000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72600000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72620000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
726c0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72700000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
728b0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
728d0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
728e0000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73a50000 PROPSYS.dll 7.0.7601.17514 C:\Windows\
system32
73b50000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
73b60000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73b90000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73ba0000 security.dll 6.1.7600.16385 C:\Windows\
system32
73bb0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73bc0000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73c20000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73eb0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
741a0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
741f0000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74220000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74250000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74290000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
742b0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
742c0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
742d0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
742e0000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
74330000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
74370000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
74380000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
743a0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74540000 version.dll 6.1.7600.16385 C:\Windows\
system32
74550000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75060000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75070000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
750d0000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
75170000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75180000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
752b0000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
752c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75310000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
753b0000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
753c0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75460000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
75470000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
75570000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
756c0000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
757b0000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
757d0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75800000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75880000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75890000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
75940000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
759d0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
759f0000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75a30000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
75a90000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75d40000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
75f80000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
76050000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76060000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76200000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76210000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76380000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76390000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
763e0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76410000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76420000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
764b0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
764f0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
765a0000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
765c0000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76720000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76780000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
777a0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
777d0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01fc csrss.exe 0 0 0
025c csrss.exe 1 0 0
0264 wininit.exe 0 0 0
028c winlogon.exe 1 0 0
02c8 services.exe 0 0 0
02d0 lsass.exe 0 0 0
02d8 lsm.exe 0 0 0
0338 svchost.exe 0 0 0
0384 svchost.exe 0 0 0
03dc MsMpEng.exe 0 0 0
0148 RapportMgmtService.exe 0 0 0
02b8 svchost.exe 0 0 0
0348 svchost.exe 0 0 0
0404 svchost.exe 0 0 0
0428 svchost.exe 0 0 0
04a8 svchost.exe 0 0 0
0504 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0634 spoolsv.exe 0 0 0
063c taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
06fc atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0764 fbguard.exe 0 0 0
0788 svchost.exe 0 0 0
079c NetExpressUpdater.exe 0 0 0
07f8 OSPPSVC.EXE 0 0 0
0698 svchost.exe 0 0 0
06d0 scpbradserv.exe 0 0 0
082c core.exe 0 0 0
0974 RapportInjService_x64.exe 0 0 0
0a30 fbserver.exe 0 0 0
0b98 WUDFHost.exe 0 0 0
0b38 NisSrv.exe 0 0 0
0eec WmiPrvSE.exe 0 0 0
0dec svchost.exe 0 0 0
0e88 GoogleCrashHandler.exe 0 0 0
0f30 GoogleCrashHandler64.exe 0 0 0
0fcc SearchIndexer.exe 0 0 0
0c38 taskhost.exe 1 26 22 normal
0884 core.exe 1 9 21 normal
0ff8 PresentationFontCache.exe 0 0 0
0a40 dwm.exe 1 16 4 high
0fc8 explorer.exe 1 405 272 normal
03d4 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0e60 igfxEM.exe 1 14 13 normal
0ba4 igfxHK.exe 1 14 13 normal
0ca0 RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
07e4 msseces.exe 1 143 59 normal
0e80 PrnStatusMX.exe 1 23 18 normal
10a0 RapportInjService_x64.exe 1 4 3 normal
1360 wuauclt.exe 1 12 7 normal
1184 Store.exe 1 2291 839 normal C:\Program Files (x86)\Store
0c48 splwow64.exe 1 9 3 normal
12d8 OIS.EXE 1 84 38 normal
0e90 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
106c chrome.exe 1 23 57 normal
1090 chrome.exe 1 9 4 normal
0f0c chrome.exe 1 7 6 above normal
0490 chrome.exe 1 4 1 normal
1134 chrome.exe 1 4 1 normal
1124 chrome.exe 1 4 1 normal
0838 chrome.exe 1 4 1 idle
125c audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0c3fde90
ebx = 00003303
ecx = 00000000
edx = 02622ac8
esi = 0018ea0c
edi = 0066cb50
eip = 0066ea6e
esp = 0018e9d0
ebp = 0018ea38
stack dump:
0018e9d0 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e9e0 e4 e9 18 00 6e ea 66 00 - 90 de 3f 0c 03 33 00 00 ....n.f...?..3..
0018e9f0 0c ea 18 00 50 cb 66 00 - 38 ea 18 00 00 ea 18 00 ....P.f.8.......
0018ea00 50 56 43 06 7a ea 66 00 - a0 e9 67 00 00 00 00 00 PVC.z.f...g.....
0018ea10 50 56 43 06 00 00 00 00 - 9b e8 67 00 44 ea 18 00 PVC.......g.D...
0018ea20 0c 89 40 00 38 ea 18 00 - 00 00 00 00 00 00 00 00 [email protected]...........
0018ea30 d5 e9 67 01 50 56 43 06 - 60 ea 18 00 f3 e8 67 00 ..g.PVC.`.....g.
0018ea40 12 4d 67 00 78 ea 18 00 - 0c 89 40 00 60 ea 18 00 .Mg.x.....@.`...
0018ea50 50 56 43 06 00 00 00 00 - 00 00 00 00 50 56 43 06 PVC.........PVC.
0018ea60 8c ea 18 00 b6 92 67 00 - 70 0a a5 0a 00 00 00 00 ......g.p.......
0018ea70 01 00 00 00 e3 73 65 00 - 98 ea 18 00 0c 89 40 00 .....se.......@.
0018ea80 8c ea 18 00 80 d2 41 04 - 50 56 43 06 5c eb 18 00 ......A.PVC.\...
0018ea90 2a 72 65 00 e8 eb 12 01 - 64 eb 18 00 0c 89 40 00 *re.....d.....@.
0018eaa0 5c eb 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 \...............
0018eab0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eac0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018ead0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eae0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018eaf0 00 00 00 00 00 00 00 00 - 80 99 e5 40 d0 37 3c 06 [email protected]<.
0018eb00 00 00 00 00 fa a4 4f fa - 9f 99 e5 40 00 00 00 00 ......O....@....
disassembling:
[...]
0112ebbf mov eax, [ebp-$18]
0112ebc2 mov eax, [eax+$250]
0112ebc8 mov ecx, [eax]
0112ebca call dword ptr [ecx+$38]
0112ebcd 425 mov edx, $112fc20
0112ebd2 mov eax, [ebp-$18]
0112ebd5 mov eax, [eax+$250]
0112ebdb mov ecx, [eax]
0112ebdd call dword ptr [ecx+$38]
0112ebe0 427 mov eax, [ebp-$18]
0112ebe3 > call -$ad79c8 ($657220) ; Data.DB.TDataSet.Open
0112ebe8 428 mov eax, [ebp-$18]
0112ebeb call -$ad5108 ($659ae8) ; Data.DB.TDataSet.First
0112ebf0 429 mov eax, [ebp-$18]
0112ebf3 cmp byte ptr [eax+$a9], 0
0112ebfa jz loc_112ec08
0112ebfc mov eax, [ebp-$18]
0112ebff cmp byte ptr [eax+$a8], 0
0112ec06 jnz loc_112ec17
0112ec08 431 mov eax, [ebp-4]
0112ec0b call +$33080 ($1161c90) ;
UnitCotacao.TfrmCotacao.GravaGridVenda
[...]
thread $1004:
7775f8da +0e ntdll.dll NtWaitForSingleObject
75d815c8 +92 KERNELBASE.dll WaitForSingleObjectEx
764a118f +3e kernel32.dll WaitForSingleObjectEx
764a1143 +0d kernel32.dll WaitForSingleObject
764a3368 +10 kernel32.dll BaseThreadInitThunk
thread $13ac:
77760166 +0e ntdll.dll NtWaitForMultipleObjects
764a3368 +10 kernel32.dll BaseThreadInitThunk
thread $1580:
77760166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
764a3368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1264) at:
73982713 +24f netbios.dll Netbios
thread $153c:
7775f8da +0e ntdll.dll NtWaitForSingleObject
75d815c8 +92 KERNELBASE.dll WaitForSingleObjectEx
764a118f +3e kernel32.dll WaitForSingleObjectEx
764a1143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
764a3368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1264) at:
73ac4c95 +00 winspool.drv
thread $fa0:
77761f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
764a3368 +10 kernel32.dll BaseThreadInitThunk
thread $cb0:
77761f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
764a3368 +10 kernel32.dll BaseThreadInitThunk
modules:
00230000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
003a0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02570000 BCLW32.dll C:\Program
Files (x86)\Store
06240000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06310000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
6ef20000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
6efd0000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
70420000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
70b60000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70b80000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
70ba0000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70dc0000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
70dd0000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
70de0000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
70e20000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
70fa0000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
71170000 api-ms-win-downlevel-advapi32-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
71230000 rasadhlp.dll 6.1.7600.16385 C:\Windows\
system32
712a0000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
712e0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
71300000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71310000 wship6.dll 6.1.7600.16385 C:\Windows\
System32
71850000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
719d0000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71a20000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71a80000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72570000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72590000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72630000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72670000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72820000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72840000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72850000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
72c30000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
72c60000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73630000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73740000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
73980000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73990000 security.dll 6.1.7600.16385 C:\Windows\
system32
739a0000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
739b0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
73ab0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
73b30000 slc.dll 6.1.7600.16385 C:\Windows\
system32
73b70000 api-ms-win-downlevel-shlwapi-l2-1-0.dll 6.2.9200.16492 C:\Windows\
system32
74110000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74160000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74190000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
741c0000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
74200000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
74220000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
74230000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
74240000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74250000 DNSAPI.dll 6.1.7601.17570 C:\Windows\
system32
742a0000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
742e0000 WINNSI.DLL 6.1.7601.23889 C:\Windows\
system32
742f0000 IPHLPAPI.DLL 6.1.7601.17514 C:\Windows\
system32
74310000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
744b0000 version.dll 6.1.7600.16385 C:\Windows\
system32
744c0000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
74fd0000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
74fe0000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75040000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
75c90000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75ca0000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75d70000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75dc0000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
75e70000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75f00000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75f80000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
75fb0000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
75fe0000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
76000000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76010000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
76160000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76290000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
762a0000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76440000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76480000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76490000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
765a0000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
765b0000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
767f0000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76890000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
768f0000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76990000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76a30000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
76a50000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76a60000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
76ac0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76b60000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
76c50000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
76db0000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76dc0000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
76dd0000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
77080000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
77090000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
770b0000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
771b0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
77240000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
772f0000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
77710000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
77740000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0258 svchost.exe 0 0 0
02cc svchost.exe 0 0 0
01e0 svchost.exe 0 0 0
0410 svchost.exe 0 0 0
04a0 svchost.exe 0 0 0
0510 igfxCUIService.exe 0 0 0
0568 svchost.exe 0 0 0
0630 spoolsv.exe 0 0 0
063c taskeng.exe 0 0 0
0664 svchost.exe 0 0 0
06e4 armsvc.exe 0 0 0
0700 atkexComSvc.exe 0 0 0
073c svchost.exe 0 0 0
0768 fbguard.exe 0 0 0
078c svchost.exe 0 0 0
07a0 NetExpressUpdater.exe 0 0 0
07fc OSPPSVC.EXE 0 0 0
0690 svchost.exe 0 0 0
0498 scpbradserv.exe 0 0 0
00bc svchost.exe 0 0 0
0824 core.exe 0 0 0
0968 RapportInjService_x64.exe 0 0 0
0a28 fbserver.exe 0 0 0
0bd8 WUDFHost.exe 0 0 0
0858 NisSrv.exe 0 0 0
0fd0 WmiPrvSE.exe 0 0 0
0ebc svchost.exe 0 0 0
0fa8 GoogleCrashHandler.exe 0 0 0
0c8c GoogleCrashHandler64.exe 0 0 0
0b0c SearchIndexer.exe 0 0 0
08bc taskhost.exe 1 26 22 normal
0b2c core.exe 1 9 22 normal
0500 PresentationFontCache.exe 0 0 0
0ef0 dwm.exe 1 21 5 high
0d8c explorer.exe 1 474 281 normal
0e28 scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0fb4 igfxEM.exe 1 14 14 normal
032c igfxHK.exe 1 14 13 normal
0584 RapportService.exe 1 14 17 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0e90 msseces.exe 1 143 60 normal
0c40 PrnStatusMX.exe 1 23 18 normal
1070 RapportInjService_x64.exe 1 4 3 normal
16dc wuauclt.exe 1 12 6 normal
1268 Store.exe 1 1012 308 normal C:\Program Files (x86)\Store
1270 Store.exe 1 91 69 normal C:\Program Files (x86)\Store
14b4 splwow64.exe 1 9 3 normal
15b0 Store.exe 1 549 213 normal C:\Program Files (x86)\Store
0f68 Store.exe 1 91 69 normal C:\Program Files (x86)\Store
0484 OIS.EXE 1 93 46 normal
1738 DllHost.exe 1 9 6 normal C:\Windows\SysWOW64
13ec OIS.EXE 1 84 38 normal
13b4 OIS.EXE 1 81 37 normal
16b8 chrome.exe 1 23 62 normal
136c chrome.exe 1 9 4 normal
1578 chrome.exe 1 7 9 above normal
1700 chrome.exe 1 4 1 normal
0a78 chrome.exe 1 4 1 normal
095c chrome.exe 1 4 1 normal
1528 chrome.exe 1 4 1 idle
14fc chrome.exe 1 4 3 normal
0d4c VSSVC.exe 0 0 0
10f4 svchost.exe 0 0 0
03a4 taskhost.exe 0 0 0
0d60 audiodg.exe 0 0 0
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0a662548
ebx = 00003303
ecx = 00000000
edx = 026a2ac8
esi = 0018e3cc
edi = 0066cb50
eip = 0066ea6e
esp = 0018e390
ebp = 0018e3f8
stack dump:
0018e390 6e ea 66 00 de fa ed 0e - 01 00 00 00 07 00 00 00 n.f.............
0018e3a0 a4 e3 18 00 6e ea 66 00 - 48 25 66 0a 03 33 00 00 ....n.f.H%f..3..
0018e3b0 cc e3 18 00 50 cb 66 00 - f8 e3 18 00 c0 e3 18 00 ....P.f.........
0018e3c0 60 84 49 04 7a ea 66 00 - a0 e9 67 00 00 00 00 00 `.I.z.f...g.....
0018e3d0 60 84 49 04 00 00 00 00 - 9b e8 67 00 04 e4 18 00 `.I.......g.....
0018e3e0 0c 89 40 00 f8 e3 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e3f0 d5 e9 67 01 60 84 49 04 - 20 e4 18 00 f3 e8 67 00 ..g.`.I. .....g.
0018e400 12 4d 67 00 38 e4 18 00 - 0c 89 40 00 20 e4 18 00 .Mg.8.....@. ...
0018e410 60 84 49 04 00 00 00 00 - 00 00 00 00 60 84 49 04 `.I.........`.I.
0018e420 4c e4 18 00 b6 92 67 00 - 00 00 00 00 38 5d 53 00 L.....g.....8]S.
0018e430 01 00 00 00 e3 73 65 00 - 58 e4 18 00 0c 89 40 00 .....se.X.....@.
0018e440 4c e4 18 00 40 d5 52 06 - 60 84 49 04 8c e4 18 00 [email protected].`.I.....
0018e450 2a 72 65 00 d0 fe 12 01 - a4 e4 18 00 0c 89 40 00 *re...........@.
0018e460 8c e4 18 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e470 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e480 40 d5 52 06 60 84 49 04 - d0 c9 42 06 d0 e4 18 00 @.R.`.I...B.....
0018e490 53 5d 53 00 80 e6 18 00 - 06 6a 53 00 80 e6 18 00 S]S......jS.....
0018e4a0 1f f9 54 00 b0 e4 18 00 - eb 8a 40 00 d0 e4 18 00 ..T.......@.....
0018e4b0 50 e6 18 00 0c 89 40 00 - d0 e4 18 00 00 00 00 00 P.....@.........
0018e4c0 40 d5 52 06 80 e6 18 00 - 00 00 00 00 40 d5 52 06 @[email protected].
disassembling:
[...]
0112fea5 push $1130034
0112feaa lea eax, [ebp-$20]
0112fead mov edx, 3
0112feb2 call -$d256ef ($40a7c8) ; System.@UStrCatN
0112feb7 mov edx, [ebp-$20]
0112feba mov eax, [ebp-8]
0112febd mov eax, [eax+$250]
0112fec3 mov ecx, [eax]
0112fec5 call dword ptr [ecx+$38]
0112fec8 463 mov eax, [ebp-8]
0112fecb > call -$ad8cb0 ($657220) ; Data.DB.TDataSet.Open
0112fed0 464 mov eax, [ebp-8]
0112fed3 cmp byte ptr [eax+$a8], 0
0112feda jz loc_112fefd
0112fedc mov eax, [ebp-8]
0112fedf cmp byte ptr [eax+$a9], 0
0112fee6 jz loc_112fefd
0112fee8 465 mov edx, $1130048
0112feed mov eax, [ebp-4]
0112fef0 mov eax, [eax+$4f4]
0112fef6 call -$c01837 ($52e6c4) ; Vcl.Controls.TControl.SetText
[...]
thread $125c:
77e10166 +0e ntdll.dll NtWaitForMultipleObjects
76043368 +10 kernel32.dll BaseThreadInitThunk
thread $1260:
77e11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76043368 +10 kernel32.dll BaseThreadInitThunk
thread $1268:
77e10166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76043368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1248) at:
73f22713 +24f netbios.dll Netbios
thread $1664:
77e0f8da +0e ntdll.dll NtWaitForSingleObject
758d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7604118f +3e kernel32.dll WaitForSingleObjectEx
76041143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76043368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1248) at:
740c4c95 +00 winspool.drv
thread $1768:
77e11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76043368 +10 kernel32.dll BaseThreadInitThunk
thread $1748:
77e11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76043368 +10 kernel32.dll BaseThreadInitThunk
modules:
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02620000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02650000 BCLW32.dll C:\Program
Files (x86)\Store
06260000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06370000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
706c0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70a20000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70c20000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70d30000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
71310000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
71410000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
71420000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
71430000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
71450000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71490000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71690000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
716d0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
716f0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71a80000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71f00000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71f50000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71fb0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72010000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
72c20000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72c40000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72ce0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72d20000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72ed0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72ef0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72f00000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73ef0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73f20000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73f30000 security.dll 6.1.7600.16385 C:\Windows\
system32
73f40000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73f50000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73fb0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
740b0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
747c0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74810000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74840000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74870000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
748b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
748d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
748e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
748f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74950000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
749c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74b60000 version.dll 6.1.7600.16385 C:\Windows\
system32
74b70000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75680000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75690000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75750000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75760000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75830000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75850000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
758b0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
758c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75940000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75950000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75960000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
759b0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75a30000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75a50000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75b40000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75df0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75e00000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75f60000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75ff0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76000000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76030000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76140000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76150000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
761b0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
761e0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76270000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76280000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76320000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76330000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76350000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76590000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76630000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76760000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
768b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76960000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76a60000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76a70000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76b20000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76bc0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76c00000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77850000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77dc0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77df0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02cc svchost.exe 0 0 0
03f0 svchost.exe 0 0 0
0410 svchost.exe 0 0 0
0470 audiodg.exe 0 0 0
04a4 svchost.exe 0 0 0
0514 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0654 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07e8 OSPPSVC.EXE 0 0 0
0684 svchost.exe 0 0 0
0430 scpbradserv.exe 0 0 0
0748 svchost.exe 0 0 0
081c core.exe 0 0 0
08fc RapportInjService_x64.exe 0 0 0
0a1c fbserver.exe 0 0 0
0b88 WUDFHost.exe 0 0 0
0ac4 NisSrv.exe 0 0 0
0e74 TrustedInstaller.exe 0 0 0
0f2c WmiPrvSE.exe 0 0 0
0e58 taskhost.exe 1 26 24 normal
0e8c core.exe 1 9 22 normal
0f80 PresentationFontCache.exe 0 0 0
0ed0 dwm.exe 1 16 4 high
0fe8 explorer.exe 1 387 225 normal
07dc scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c54 igfxEM.exe 1 14 13 normal
0af8 igfxHK.exe 1 14 13 normal
0a0c RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0788 svchost.exe 0 0 0
0c04 msseces.exe 1 143 61 normal
0ea8 RapportInjService_x64.exe 1 4 3 normal
0f14 PrnStatusMX.exe 1 23 18 normal
0e98 GoogleCrashHandler.exe 0 0 0
0204 GoogleCrashHandler64.exe 0 0 0
1014 SearchIndexer.exe 0 0 0
1064 sppsvc.exe 0 0 0
1244 Store.exe 1 271 269 normal C:\Program Files (x86)\Store
1208 wuauclt.exe 1 12 7 normal
0cec WmiPrvSE.exe 0 0 0
11b0 chrome.exe 1 25 63 normal
11a8 chrome.exe 1 9 4 normal
1350 chrome.exe 1 7 4 above normal
112c chrome.exe 1 4 1 normal
0148 chrome.exe 1 4 1 normal
1150 chrome.exe 1 4 1 idle
1568 chrome.exe 1 4 1 idle
15f0 chrome.exe 1 4 3 normal
1074 WmiPrvSE.exe 0 0 0
165c VSSVC.exe 0 0 0
1508 svchost.exe 0 0 0
0e48 MpCmdRun.exe 0 0 0
133c MpCmdRun.exe 0 0 0
0e30 conhost.exe 0 0 0
0718 splwow64.exe 1 9 3 normal
05f4 rundll32.exe 1 116 48 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 0047002e
ebx = 04313b40
ecx = 8b000001
edx = 00000000
esi = 042952b0
edi = 00000000
eip = 00487029
esp = 00188c4c
ebp = 00188c54
stack dump:
00188c4c 00 00 00 00 00 00 00 00 - ac cc 18 00 ca 00 6d 00 ..............m.
00188c5c 00 00 00 00 00 00 00 00 - b0 cc 18 00 0c 89 40 00 ..............@.
00188c6c ac cc 18 00 b0 52 29 04 - 40 3b 31 04 cc 22 fd 07 .....R).@;1.."..
00188c7c 01 00 fc 07 f0 68 a1 06 - 76 ad 18 00 c4 8c 18 00 .....h..v.......
00188c8c a8 8c 18 00 f7 5b de 4b - 40 3b 31 04 01 00 00 00 .....[.K@;1.....
00188c9c 2e 00 47 00 76 ad 18 00 - c4 8c 18 00 01 00 00 00 ..G.v...........
00188cac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188cbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188ccc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188cdc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188cec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188cfc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d2c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d3c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d4c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d5c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00188d7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
006d00a3 push ebp
006d00a4 push $6d0414 ; System.@HandleFinally
006d00a9 push dword ptr fs:[eax]
006d00ac mov fs:[eax], esp
006d00af 339 call -$277ea8 ($45820c) ; System.SysUtils.Now
006d00b4 fstp qword ptr [$15c4828]
006d00ba wait
006d00bb 340 push 0
006d00bd push 0
006d00bf mov eax, [ebp-$4010]
006d00c5 > call -$2490ae ($48701c) ; System.Classes.TStream.SetPosition
006d00ca 341 xor eax, eax
006d00cc mov [ebp-$400c], eax
006d00d2 342 xor eax, eax
006d00d4 mov [ebp-$4014], eax
006d00da 343 push ebp
006d00db call -$21c ($6cfec4) ; LZW.InitTable
006d00e0 pop ecx
006d00e1 344 push ebp
006d00e2 call -$1bb ($6cff2c) ; LZW.ReadCode
006d00e7 pop ecx
[...]
thread $1258:
77e0f8da +0e ntdll.dll NtWaitForSingleObject
758d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7604118f +3e kernel32.dll WaitForSingleObjectEx
76041143 +0d kernel32.dll WaitForSingleObject
76043368 +10 kernel32.dll BaseThreadInitThunk
thread $125c:
77e10166 +0e ntdll.dll NtWaitForMultipleObjects
76043368 +10 kernel32.dll BaseThreadInitThunk
thread $1260:
77e11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76043368 +10 kernel32.dll BaseThreadInitThunk
thread $1268:
77e10166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76043368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1248) at:
73f22713 +24f netbios.dll Netbios
thread $1664:
77e0f8da +0e ntdll.dll NtWaitForSingleObject
758d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7604118f +3e kernel32.dll WaitForSingleObjectEx
76041143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76043368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1248) at:
740c4c95 +00 winspool.drv
thread $1768:
77e11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76043368 +10 kernel32.dll BaseThreadInitThunk
thread $1748:
77e11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76043368 +10 kernel32.dll BaseThreadInitThunk
modules:
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02620000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02650000 BCLW32.dll C:\Program
Files (x86)\Store
06260000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06370000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
706c0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70a20000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70c20000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70d30000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
71310000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
71410000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
71420000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
71430000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
71450000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71490000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71690000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
716d0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
716f0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71a80000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71f00000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71f50000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71fb0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72010000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
72c20000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72c40000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72ce0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72d20000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72ed0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72ef0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72f00000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73ef0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73f20000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73f30000 security.dll 6.1.7600.16385 C:\Windows\
system32
73f40000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73f50000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73fb0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
740b0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
747c0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74810000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74840000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74870000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
748b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
748d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
748e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
748f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74950000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
749c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74b60000 version.dll 6.1.7600.16385 C:\Windows\
system32
74b70000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75680000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75690000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75750000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75760000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75830000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75850000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
758b0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
758c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75940000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75950000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75960000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
759b0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75a30000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75a50000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75b40000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75df0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75e00000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75f60000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75ff0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76000000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76030000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76140000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76150000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
761b0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
761e0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76270000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76280000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76320000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76330000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76350000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76590000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76630000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76760000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
768b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76960000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76a60000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76a70000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76b20000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76bc0000 WS2_32.dll 6.1.7601.23451 C:\Windows\
syswow64
76c00000 shell32.dll 6.1.7601.23893 C:\Windows\
syswow64
77850000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
77dc0000 api-ms-win-downlevel-version-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
77df0000 ntdll.dll 6.1.7601.23915 C:\Windows\
SysWOW64
7c340000 MSVCR71.dll 7.10.3052.4 C:\Program
Files (x86)\Store
processes:
0000 Idle 0 0 0
0004 System 0 0 0
013c smss.exe 0 0 0
01f8 csrss.exe 0 0 0
0254 csrss.exe 1 0 0
025c wininit.exe 0 0 0
0284 winlogon.exe 1 0 0
02c0 services.exe 0 0 0
02c8 lsass.exe 0 0 0
02d0 lsm.exe 0 0 0
0330 svchost.exe 0 0 0
037c svchost.exe 0 0 0
03d4 MsMpEng.exe 0 0 0
015c RapportMgmtService.exe 0 0 0
0250 svchost.exe 0 0 0
02cc svchost.exe 0 0 0
03f0 svchost.exe 0 0 0
0410 svchost.exe 0 0 0
0470 audiodg.exe 0 0 0
04a4 svchost.exe 0 0 0
0514 igfxCUIService.exe 0 0 0
0560 svchost.exe 0 0 0
0620 spoolsv.exe 0 0 0
0628 taskeng.exe 0 0 0
0654 svchost.exe 0 0 0
06dc armsvc.exe 0 0 0
06f4 atkexComSvc.exe 0 0 0
0734 svchost.exe 0 0 0
0758 fbguard.exe 0 0 0
0780 svchost.exe 0 0 0
0794 NetExpressUpdater.exe 0 0 0
07e8 OSPPSVC.EXE 0 0 0
0684 svchost.exe 0 0 0
0430 scpbradserv.exe 0 0 0
0748 svchost.exe 0 0 0
081c core.exe 0 0 0
08fc RapportInjService_x64.exe 0 0 0
0a1c fbserver.exe 0 0 0
0b88 WUDFHost.exe 0 0 0
0ac4 NisSrv.exe 0 0 0
0e74 TrustedInstaller.exe 0 0 0
0f2c WmiPrvSE.exe 0 0 0
0e58 taskhost.exe 1 26 24 normal
0e8c core.exe 1 9 22 normal
0f80 PresentationFontCache.exe 0 0 0
0ed0 dwm.exe 1 16 4 high
0fe8 explorer.exe 1 387 226 normal
07dc scpbradguard.exe 1 31 11 normal C:\Program Files (x86)\
scpbrad
0c54 igfxEM.exe 1 14 13 normal
0af8 igfxHK.exe 1 14 13 normal
0a0c RapportService.exe 1 14 18 normal C:\Program Files (x86)\
Trusteer\Rapport\bin
0788 svchost.exe 0 0 0
0c04 msseces.exe 1 143 61 normal
0ea8 RapportInjService_x64.exe 1 4 3 normal
0f14 PrnStatusMX.exe 1 23 18 normal
0e98 GoogleCrashHandler.exe 0 0 0
0204 GoogleCrashHandler64.exe 0 0 0
1014 SearchIndexer.exe 0 0 0
1064 sppsvc.exe 0 0 0
1244 Store.exe 1 254 261 normal C:\Program Files (x86)\Store
1208 wuauclt.exe 1 12 7 normal
0cec WmiPrvSE.exe 0 0 0
11b0 chrome.exe 1 25 63 normal
11a8 chrome.exe 1 9 4 normal
1350 chrome.exe 1 7 4 above normal
112c chrome.exe 1 4 1 normal
0148 chrome.exe 1 4 1 normal
1150 chrome.exe 1 4 1 normal
1568 chrome.exe 1 4 1 idle
15f0 chrome.exe 1 4 3 normal
1074 WmiPrvSE.exe 0 0 0
165c VSSVC.exe 0 0 0
1508 svchost.exe 0 0 0
0e48 MpCmdRun.exe 0 0 0
133c MpCmdRun.exe 0 0 0
0e30 conhost.exe 0 0 0
0718 splwow64.exe 1 9 3 normal
05f4 rundll32.exe 1 116 48 normal
hardware:
+ Computer
- ACPI x64-based PC
+ Disk drives
- PH5-CE120 ATA Device
- WDC WD10EZEX-00BN5A0 ATA Device
+ Display adapters
- Intel(R) HD Graphics 4400 (driver 10.18.14.4264)
+ Human Interface Devices
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- Dispositivo de Entrada USB
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- Dispositivo de teclado HID
+ Mice and other pointing devices
- Mouse compatível com HID
- Mouse compatível com HID
+ Monitors
- Monitor Genérico PnP
+ Network adapters
- Adaptador do Microsoft ISATAP
- Miniporta de rede remota (IP)
- Miniporta de Rede Remota (IPv6)
- Miniporta de rede remota (L2TP)
- Miniporta de rede remota (Monitor de rede)
- Miniporta de rede remota (PPTP)
- Miniporta WAN (PPPOE)
- Miniporta WAN (SSTP)
- Realtek PCIe GBE Family Controller (driver 7.92.115.2015)
- Teredo Tunneling Pseudo-Interface
- WAN Miniport (IKEv2)
+ Processors
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
- Intel(R) Core(TM) i3-4170 CPU @ 3.70GHz
+ Provedor de Impressão WSD
- Dispositivo de Impressão WSD
+ Sound, video and game controllers
- Dispositivo de High Definition Audio
- Realtek High Definition Audio (driver 6.0.1.7982)
+ Storage volume shadow copies
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
- Cópia de sombra de volume genérica
+ System devices
- AMDA00 Interface (driver 1.0.1.0)
- Arquivo como Driver de Volume
- Botão de recurso fixo ACPI
- Botão ligar/desligar ACPI
- CMOS do sistema/relógio em tempo real
- Controlador de acesso direto à memória
- Controlador de High Definition Audio
- Controlador de High Definition Audio
- Controlador de interrupção programável
- Driver de BIOS de Gerenciamento de Sistema Microsoft
- Driver de enumerador da unidade virtual Microsoft
- Enumerador de Barramento de Composição
- Enumerador de Barramento de Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Gerenciador de volumes
- Intel(R) 82802 Firmware Hub Device
- Intel(R) Management Engine Interface (driver 9.0.0.1287)
- IPBusEnum Root Enumerator
- Microsoft ACPI-Compliant System
- Microsoft Windows Management Interface for ACPI
- NPI3B9347 (HP LaserJet P3010 Series)
- PCI bus
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Placa de sistema
- Processador de dados numéricos
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Recursos da placa-mãe
- Remote Desktop Device Redirector Bus
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- Timer de eventos de alta precisão
- Timer do sistema
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Ventilador ACPI
- Zona termal ACPI
- Zona termal ACPI
+ Universal Serial Bus controllers
- Controlador host eXtensível Intel(R) USB 3.0 (driver 3.0.1.41)
- Generic USB Hub
- Generic USB Hub
- Hub de raiz Intel(R) USB 3.0 (driver 3.0.1.41)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
cpu registers:
eax = 753bfffe
ebx = 00180100
ecx = 000204f0
edx = 04304601
esi = 042952b0
edi = 0018e36c
eip = 0034005f
esp = 0018e0bc
ebp = 0018e130
stack dump:
0018e0bc f7 75 40 00 f5 1d 6f 00 - b0 52 29 04 01 01 18 00 [email protected]).....
0018e0cc 53 55 6f 00 40 73 a7 06 - 40 73 a7 06 f7 75 40 00 SUo.@[email protected]@.
0018e0dc 87 fa e9 00 38 e1 18 00 - 0c 89 40 00 30 e1 18 00 [email protected]...
0018e0ec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e0fc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e10c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e11c 00 00 00 00 00 00 00 00 - 00 00 00 00 20 e8 a5 06 ............ ...
0018e12c 50 04 29 04 b4 e1 18 00 - 09 92 e9 00 1c e5 18 00 P.).............
0018e13c 0c 89 40 00 b4 e1 18 00 - 00 00 00 00 00 00 00 00 ..@.............
0018e14c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e15c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e16c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e17c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018e18c 00 00 00 00 40 73 a7 06 - f0 0b 34 04 90 0e 34 04 [email protected].
0018e19c 30 11 34 04 30 26 34 04 - 50 f4 33 04 90 f9 33 04 0.4.0&4.P.3...3.
0018e1ac f0 f6 33 04 50 04 29 04 - 04 e3 18 00 ed 04 53 00 ..3.P.).......S.
0018e1bc 40 73 a7 06 33 35 55 00 - 6c e3 18 00 62 44 62 00 @s..35U.l...bDb.
0018e1cc b8 43 62 00 6c e3 18 00 - 61 40 55 00 40 73 a7 06 .Cb.l...a@U.@s..
0018e1dc 94 ff 52 00 6c e3 18 00 - 4c e5 18 00 40 73 a7 06 ..R.l...L...@s..
0018e1ec f3 00 00 00 05 8b 99 76 - 68 74 97 76 0f 09 01 05 .......vht.v....
disassembling:
004075ec public System.TObject.Free: ; function entry point
004075ec 35 test eax, eax
004075ee jz loc_4075f7
004075f0 mov dl, 1
004075f2 mov ecx, [eax]
004075f4 > call dword ptr [ecx-4]
004075f7 ret
thread $1258:
77e0f8da +0e ntdll.dll NtWaitForSingleObject
758d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7604118f +3e kernel32.dll WaitForSingleObjectEx
76041143 +0d kernel32.dll WaitForSingleObject
76043368 +10 kernel32.dll BaseThreadInitThunk
thread $125c:
77e10166 +0e ntdll.dll NtWaitForMultipleObjects
76043368 +10 kernel32.dll BaseThreadInitThunk
thread $1268:
77e10166 +00e ntdll.dll NtWaitForMultipleObjects
004d797d +00d Store.exe madExcept CallThreadProcSafe
004d79e7 +037 Store.exe madExcept ThreadExceptFrame
76043368 +010 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1248) at:
73f22713 +24f netbios.dll Netbios
thread $1664:
77e0f8da +0e ntdll.dll NtWaitForSingleObject
758d15c8 +92 KERNELBASE.dll WaitForSingleObjectEx
7604118f +3e kernel32.dll WaitForSingleObjectEx
76041143 +0d kernel32.dll WaitForSingleObject
004d797d +0d Store.exe madExcept CallThreadProcSafe
004d79e7 +37 Store.exe madExcept ThreadExceptFrame
76043368 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($1248) at:
740c4c95 +00 winspool.drv
thread $13fc:
77e11f4f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
76043368 +10 kernel32.dll BaseThreadInitThunk
modules:
003b0000 WINPPLA.DLL C:\Program
Files (x86)\Store
00400000 Store.exe 1.0.0.0 C:\Program
Files (x86)\Store
02540000 iconv.dll 1.9.0.0 C:\Program
Files (x86)\Store
02620000 WinPort.dll 1.0.0.1 C:\Program
Files (x86)\Store
02650000 BCLW32.dll C:\Program
Files (x86)\Store
06260000 libeay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
06370000 ssleay32.dll 0.9.8.14 C:\Program
Files (x86)\Store
10000000 libxml2.dll C:\Program
Files (x86)\Store
4bde0000 IDAPI32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4c9e0000 IDR20009.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4d3e0000 SQLMSS32.DLL 5.2.0.2 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
4e8e0000 BANTAM.DLL 1.0.0.8 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
62e80000 zlib1.dll 1.2.8.0 C:\Program
Files (x86)\Store
706c0000 dwmapi.dll 6.1.7601.18917 C:\Windows\
system32
70a20000 srvcli.dll 6.1.7601.17514 C:\Windows\
system32
70c20000 schannel.dll 6.1.7601.23915 C:\Windows\
SysWOW64
70d30000 uxtheme.dll 6.1.7600.16385 C:\Windows\
system32
71310000 propsys.dll 7.0.7601.17514 C:\Windows\
system32
71410000 wkscli.dll 6.1.7601.17514 C:\Windows\
system32
71420000 netutils.dll 6.1.7601.17514 C:\Windows\
system32
71430000 NETAPI32.dll 6.1.7601.17887 C:\Windows\
system32
71450000 credssp.dll 6.1.7601.23915 C:\Windows\
system32
71490000 Fwpuclnt.dll 6.1.7601.18283 C:\Windows\
system32
71690000 bcryptprimitives.dll 6.1.7601.23451 C:\Windows\
SysWOW64
716d0000 bcrypt.dll 6.1.7601.23915 C:\Windows\
system32
716f0000 wshtcpip.dll 6.1.7600.16385 C:\Windows\
System32
71a80000 ncrypt.dll 6.1.7601.23915 C:\Windows\
system32
71f00000 webio.dll 6.1.7601.23375 C:\Windows\
system32
71f50000 winhttp.dll 6.1.7601.23451 C:\Windows\
system32
71fb0000 mswsock.dll 6.1.7601.23451 C:\Windows\
system32
72010000 rooksbas.DLL 3.7.0.1 C:\Program
Files (x86)\Trusteer\Rapport\bin
72c20000 mpr.dll 6.1.7600.16385 C:\Windows\
system32
72c40000 comctl32.dll 5.82.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
72ce0000 odbcint.dll 6.1.7600.16385 C:\Windows\
system32
72d20000 odbc32.DLL 6.1.7601.17514 C:\Windows\
system32
72ed0000 olepro32.dll 6.1.7601.23452 C:\Windows\
system32
72ef0000 msimg32.dll 6.1.7600.16385 C:\Windows\
system32
72f00000 comctl32.DLL 6.10.7601.18837 C:\Windows\
WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
73320000 NTWDBLIB.DLL 2000.80.2039.0 C:\Program
Files (x86)\Common Files\Borland Shared\BDE
73420000 mscms.dll 6.1.7601.23677 C:\Windows\
system32
734a0000 prnfldr.dll 6.1.7601.17514 C:\Windows\
system32
73ef0000 DBNETLIB.DLL 6.1.7600.16385 C:\Windows\
system32
73f20000 netbios.dll 6.1.7600.16385 C:\Windows\
system32
73f30000 security.dll 6.1.7600.16385 C:\Windows\
system32
73f40000 softpub.dll 6.1.7600.16385 C:\Windows\
system32
73f50000 FaultRep.dll 6.1.7601.17514 C:\Windows\
system32
73fb0000 cryptui.dll 6.1.7601.23471 C:\Windows\
system32
740b0000 winspool.drv 6.1.7601.17514 C:\Windows\
system32
74200000 slc.dll 6.1.7600.16385 C:\Windows\
system32
747c0000 apphelp.dll 6.1.7601.19050 C:\Windows\
system32
74810000 WINSTA.dll 6.1.7601.18540 C:\Windows\
system32
74840000 ntmarta.dll 6.1.7600.16385 C:\Windows\
system32
74870000 rsaenh.dll 6.1.7600.16385 C:\Windows\
system32
748b0000 CRYPTSP.dll 6.1.7601.23471 C:\Windows\
system32
748d0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.788 C:\Windows\
system32
748e0000 wsock32.dll 6.1.7600.16385 C:\Windows\
system32
748f0000 SECUR32.DLL 6.1.7601.23915 C:\Windows\
system32
74950000 winmm.dll 6.1.7601.17514 C:\Windows\
system32
749c0000 gdiplus.dll 6.1.7601.23894 C:\Windows\
WinSxS\
x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
74b60000 version.dll 6.1.7600.16385 C:\Windows\
system32
74b70000 wtsapi32.dll 6.1.7601.17514 C:\Windows\
system32
75680000 CRYPTBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75690000 SspiCli.dll 6.1.7601.23915 C:\Windows\
syswow64
75750000 profapi.dll 6.1.7600.16385 C:\Windows\
syswow64
75760000 MSCTF.dll 6.1.7601.23915 C:\Windows\
syswow64
75830000 DEVOBJ.dll 6.1.7601.17621 C:\Windows\
syswow64
75850000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\
syswow64
758b0000 LPK.dll 6.1.7601.23807 C:\Windows\
syswow64
758c0000 KERNELBASE.dll 6.1.7601.23915 C:\Windows\
syswow64
75940000 MSASN1.dll 6.1.7601.17514 C:\Windows\
syswow64
75950000 api-ms-win-downlevel-advapi32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75960000 WLDAP32.dll 6.1.7601.23889 C:\Windows\
syswow64
759b0000 comdlg32.dll 6.1.7601.17514 C:\Windows\
syswow64
75a30000 sechost.dll 6.1.7601.18869 C:\Windows\
SysWOW64
75a50000 RPCRT4.dll 6.1.7601.23915 C:\Windows\
syswow64
75b40000 wininet.dll 11.0.9600.18817 C:\Windows\
syswow64
75df0000 api-ms-win-downlevel-ole32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
75e00000 ole32.dll 6.1.7601.23889 C:\Windows\
syswow64
75f60000 GDI32.dll 6.1.7601.23914 C:\Windows\
syswow64
75ff0000 psapi.dll 6.1.7600.16385 C:\Windows\
syswow64
76000000 WINTRUST.dll 6.1.7601.23769 C:\Windows\
syswow64
76030000 kernel32.dll 6.1.7601.23915 C:\Windows\
syswow64
76140000 api-ms-win-downlevel-user32-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76150000 IMM32.DLL 6.1.7601.17514 C:\Windows\
system32
761b0000 CFGMGR32.dll 6.1.7601.17621 C:\Windows\
syswow64
761e0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\
syswow64
76270000 NSI.dll 6.1.7601.23889 C:\Windows\
syswow64
76280000 USP10.dll 1.626.7601.23894 C:\Windows\
syswow64
76320000 api-ms-win-downlevel-shlwapi-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76330000 USERENV.dll 6.1.7601.17514 C:\Windows\
syswow64
76350000 iertutil.dll 11.0.9600.18817 C:\Windows\
syswow64
76590000 oleaut32.dll 6.1.7601.23775 C:\Windows\
syswow64
76630000 CRYPT32.dll 6.1.7601.23769 C:\Windows\
syswow64
76760000 URLMON.DLL 11.0.9600.18817 C:\Windows\
syswow64
768b0000 msvcrt.dll 7.0.7601.17744 C:\Windows\
syswow64
76960000 USER32.dll 6.1.7601.23594 C:\Windows\
syswow64
76a60000 api-ms-win-downlevel-normaliz-l1-1-0.dll 6.2.9200.16492 C:\Windows\
syswow64
76a70000 ADVAPI32.dll 6.1.7601.23915 C:\Windows\
syswow64
76b20000 normaliz.DLL 6.1.7600.16385 C:\Windows\
syswow64
76bc0000 WS2_32.dll