date/time : 2011-09-09, 11:24:58, 250ms
computer name : INTER1
user name : Administrator <admin>
registered owner : Zlatan Ibrahimovic / Internazionale
operating system : Windows XP Service Pack 2 build 2600
system language : Indonesian
system up time : 2 hours 16 minutes
program up time : 4 seconds
processors : 2x Intel(R) Pentium(R) D CPU 2.66GHz
physical memory : 513/958 MB (free/total)
free disk space : (C:) 60,31 GB
display mode : 1024x768, 32 bit
process id : $8d8
allocated memory : 8,95 MB
command line : "C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha\lib\ExtMan.exe" run
executable : ExtMan.exe
exec. date/time : 2011-09-06 09:10
compiled with : Delphi 2006/07
madExcept version : 3.0m beta 1
contact name : Indra
contact email : indra.ramadhan094@gmail.com
callstack crc : $8d7f6f94, $02e9af5b, $02e9af5b
exception number : 1
exception class : EAccessViolation
exception message : Access violation at address 03C1C290. Read of address 03C1C290.
thread $240:
>> stack not accessible, exception location:
03c1c290 +0 ???
thread $cb4:
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
00450379 +0d ExtMan.exe madExcept CallThreadProcSafe
004503e3 +37 ExtMan.exe madExcept ThreadExceptFrame
>> created by thread $240 at:
77dfa17c +00 advapi32.dll
thread $ba8:
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094ec +00 kernel32.dll WaitForMultipleObjectsEx
7c809c81 +13 kernel32.dll WaitForMultipleObjects
00450379 +0d ExtMan.exe madExcept CallThreadProcSafe
004503e3 +37 ExtMan.exe madExcept ThreadExceptFrame
>> created by thread $240 at:
032215be +00 IDMShellExt.dll
modules:
00400000 ExtMan.exe C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha\lib
02fd0000 Normaliz.dll 6.0.5441.0 C:\WINDOWS\system32
03220000 IDMShellExt.dll 6.0.6.4 C:\Program Files\Internet Download Manager
0ffd0000 rsaenh.dll 5.1.2600.2161 C:\WINDOWS\system32
10000000 guard32.dll 5.5.64714.1382 C:\WINDOWS\system32
4ffe0000 fltlib.dll 5.1.2600.2180 C:\WINDOWS\system32
5ad70000 uxtheme.dll 6.0.2900.2180 C:\WINDOWS\system32
5b0a0000 umdmxfrm.dll 5.1.2600.0 C:\WINDOWS\system32
5cd70000 serwvdrv.dll 5.1.2600.0 C:\WINDOWS\system32
5dca0000 iertutil.dll 7.0.5730.13 C:\WINDOWS\system32
661c0000 GRA8E1~1.DLL 12.0.4518.1014 C:\PROGRA~1\MICROS~2\Office12
68ef0000 GrooveUtil.DLL 12.0.4518.1014 C:\PROGRA~1\MICROS~2\Office12
68ff0000 GrooveNew.DLL 12.0.4518.1014 C:\PROGRA~1\MICROS~2\Office12
71aa0000 WS2HELP.dll 5.1.2600.2180 C:\WINDOWS\system32
71ab0000 WS2_32.dll 5.1.2600.2180 C:\WINDOWS\system32
71ad0000 wsock32.dll 5.1.2600.2180 C:\WINDOWS\system32
71b20000 mpr.dll 5.1.2600.2180 C:\WINDOWS\system32
73000000 winspool.drv 5.1.2600.2180 C:\WINDOWS\system32
74720000 MSCTF.dll 5.1.2600.2180 C:\WINDOWS\system32
74c80000 oleacc.dll 4.2.5406.0 C:\WINDOWS\system32
755c0000 msctfime.ime 5.1.2600.2180 C:\WINDOWS\system32
76080000 MSVCP60.dll 6.2.3104.0 C:\WINDOWS\system32
76380000 msimg32.dll 5.1.2600.2180 C:\WINDOWS\system32
76390000 IMM32.DLL 5.1.2600.2180 C:\WINDOWS\system32
763b0000 comdlg32.dll 6.0.2900.2180 C:\WINDOWS\system32
76b40000 winmm.dll 5.1.2600.2180 C:\WINDOWS\system32
76bf0000 PSAPI.dll 5.1.2600.2180 C:\WINDOWS\system32
76d60000 iphlpapi.dll 5.1.2600.2180 C:\WINDOWS\system32
76fd0000 CLBCATQ.DLL 2001.12.4414.258 C:\WINDOWS\system32
77050000 COMRes.dll 2001.12.4414.258 C:\WINDOWS\system32
77120000 oleaut32.dll 5.1.2600.2180 C:\WINDOWS\system32
771b0000 WININET.dll 7.0.5730.13 C:\WINDOWS\system32
773d0000 comctl32.dll 6.0.2900.2180 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9
774e0000 ole32.dll 5.1.2600.2180 C:\WINDOWS\system32
77920000 SETUPAPI.dll 5.1.2600.2180 C:\WINDOWS\system32
77a80000 CRYPT32.dll 5.131.2600.2180 C:\WINDOWS\system32
77b20000 MSASN1.dll 5.1.2600.2180 C:\WINDOWS\system32
77b40000 appHelp.dll 5.1.2600.2180 C:\WINDOWS\system32
77c00000 version.dll 5.1.2600.2180 C:\WINDOWS\system32
77c10000 msvcrt.dll 7.0.2600.2180 C:\WINDOWS\system32
77d40000 USER32.dll 5.1.2600.2180 C:\WINDOWS\system32
77dd0000 advapi32.dll 5.1.2600.2180 C:\WINDOWS\system32
77e70000 RPCRT4.dll 5.1.2600.2180 C:\WINDOWS\system32
77f10000 GDI32.dll 5.1.2600.2180 C:\WINDOWS\system32
77f60000 SHLWAPI.dll 6.0.2900.2995 C:\WINDOWS\system32
77fe0000 Secur32.dll 5.1.2600.2180 C:\WINDOWS\system32
78130000 MSVCR80.dll 8.0.50727.6195 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86
7c630000 ATL80.DLL 8.0.50727.6195 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_a4c618fa
7c800000 kernel32.dll 5.1.2600.2180 C:\WINDOWS\system32
7c900000 ntdll.dll 5.1.2600.2180 C:\WINDOWS\system32
7c9c0000 SHELL32.dll 6.0.2900.2180 C:\WINDOWS\system32
processes:
000 Idle 0 0
004 System 0 0 normal
37c smss.exe 0 0 normal C:\WINDOWS\system32
3bc csrss.exe 62 63 normal C:\WINDOWS\system32
3d8 winlogon.exe 44 14 high C:\WINDOWS\system32
404 services.exe 4 2 normal C:\WINDOWS\system32
410 lsass.exe 4 3 normal C:\WINDOWS\system32
4c4 svchost.exe 4 1 normal C:\WINDOWS\system32
518 svchost.exe 4 1 normal C:\WINDOWS\system32
58c svchost.exe 11 35 normal C:\WINDOWS\system32
5c4 AIPS.exe 4 3 normal C:\Program Files\netcut\services
5f4 svchost.exe 4 1 normal C:\WINDOWS\system32
674 svchost.exe 4 1 normal C:\WINDOWS\system32
6e4 spoolsv.exe 4 4 normal C:\WINDOWS\system32
0bc Explorer.EXE 296 144 normal C:\WINDOWS
130 SOUNDMAN.EXE 18 8 normal C:\WINDOWS
138 VTTimer.exe 12 5 normal C:\WINDOWS\system32
144 VTtrayp.exe 12 5 normal C:\WINDOWS\system32
150 egui.exe 203 63 normal C:\Program Files\ESET\ESET Smart Security
1b8 ekrn.exe 8 13 normal C:\Program Files\ESET\ESET Smart Security
1c4 ctfmon.exe 18 12 normal C:\WINDOWS\system32
1e8 YahooMessenger.exe 789 346 normal C:\PROGRA~1\Yahoo!\MESSEN~1
1f4 msnmsgr.exe 65 76 normal C:\Program Files\Windows Live\Messenger
2a8 SeaPort.exe 5 6 normal C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort
384 GoogleUpdate.exe 5 3 normal C:\Program Files\Google\Update
494 slmdmsr.exe 4 1 normal C:\WINDOWS\system32
084 wdfmgr.exe 4 1 normal C:\WINDOWS\system32
75c SearchIndexer.exe 5 7 normal C:\WINDOWS\system32
828 wscntfy.exe 20 9 normal C:\WINDOWS\system32
aa0 wmiprvse.exe 8 7 normal C:\WINDOWS\system32\wbem
bf0 alg.exe 5 2 normal C:\WINDOWS\System32
e1c YahooMessenger.exe 9 9 normal C:\PROGRA~1\Yahoo!\MESSEN~1
4a4 taskmgr.exe 110 130 high C:\WINDOWS\system32
c5c PCMAV.exe 227 155 normal C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha
754 chrome.exe 74 52 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
aac chrome.exe 30 1 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
a6c chrome.exe 10 1 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
920 SearchProtocolHost.exe 5 14 below normal C:\WINDOWS\system32
4e8 SearchFilterHost.exe 5 10 below normal C:\WINDOWS\system32
2bc svchost.exe 5 4 normal C:\WINDOWS\system32
8d8 ExtMan.exe 161 90 normal C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha\lib
cpu registers:
eax = 7ffdf000
ebx = 00000000
ecx = 03e40fda
edx = 00000002
esi = 03e40fd5
edi = 0012fe68
eip = 03c1c290
esp = 0012fe04
ebp = 0012fe2c
stack dump:
0012fe04 17 58 40 00 28 a0 af 00 - 28 a0 af 00 ea 2e 40 00 .X@.(...(.....@.
0012fe14 18 a0 af 00 28 50 4d 00 - 06 2f 40 00 66 00 40 00 .Q@.(..../@.fQ@.
0012fe24 50 00 40 00 54 fe 12 00 - 06 2f 40 00 1a fe 08 00 KT@.T..../@..Q@.
0012fe34 c0 00 00 00 b8 fe 12 00 - 27 2f 40 00 1f 01 00 00 ........'/@.+...
0012fe44 27 ff 12 00 27 2f 40 00 - 54 fe 12 00 17 58 40 00 ,...'/@.T....X@.
0012fe54 f8 f1 a3 00 f8 f1 a3 00 - 27 01 00 00 d0 54 40 00 ....,...'/@.h...
0012fe64 2c de aa 00 2c ff 12 00 - fe 00 00 00 00 00 13 00 .X@...........D.
0012fe74 10 fe 12 00 03 00 00 00 - 00 bc 44 00 b4 fe 12 00 ,....S@.....t...
0012fe84 b8 fe 12 00 e8 de aa 00 - 98 fe 12 00 5d bd 44 00 ....(.D.....].D.
0012fe94 e8 fe 12 00 f8 fe 12 00 - aa bd 44 00 e8 fe 12 00 ..........D.....
0012fea4 24 fb c4 00 00 00 00 00 - 02 00 00 00 08 a0 af 00 $...............
0012feb4 28 a0 af 00 38 a0 af 00 - 08 4e b2 00 90 4d b2 00 (...8....N...M..
0012fec4 00 f0 12 00 00 00 03 00 - 04 00 00 00 00 10 00 00 ................
0012fed4 00 10 00 00 04 00 00 00 - 00 00 02 00 07 00 00 00 ................
0012fee4 2c ff 12 00 6c ff 12 00 - a0 c1 44 00 6c ff 12 00 ,...l.....D.l...
0012fef4 6c ff 12 00 04 ff 12 00 - 9e c4 44 00 6c ff 12 00 l.........D.l...
0012ff04 8c ff 12 00 29 c5 44 00 - 6c ff 12 00 24 fb c4 00 ....).D.l...$...
0012ff14 c0 f0 a1 00 78 ff 12 00 - 00 00 00 00 00 00 00 00 ....x...........
0012ff24 00 00 00 00 00 00 00 00 - 08 46 08 01 b8 cd a3 00 .........F......
0012ff34 b8 bf 08 01 00 00 00 00 - 60 83 44 85 18 54 5f 85 ........`.D..T_.
disassembling:
7c90e99f public NtWaitForMultipleObjects: ; function entry point
7c90e99f mov eax, $10e
7c90e9a4 mov edx, $7ffe0300
7c90e9a9 > call dword ptr [edx] ; KiFastSystemCall (ntdll.dll)
7c90e9ab ret $14
date/time : 2011-09-08, 10:10:50, 859ms
computer name : INTER1
user name : Administrator <admin>
registered owner : Zlatan Ibrahimovic / Internazionale
operating system : Windows XP Service Pack 2 build 2600
system language : Indonesian
system up time : 32 minutes 39 seconds
program up time : 14 minutes 43 seconds
processors : 2x Intel(R) Pentium(R) D CPU 2.66GHz
physical memory : 709/958 MB (free/total)
free disk space : (C:) 61,13 GB
display mode : 1024x768, 32 bit
process id : $25c
allocated memory : 48,15 MB
executable : PCMAV.exe
exec. date/time : 2011-09-06 11:01
version : 6.0.0.0
compiled with : Delphi 2006/07
madExcept version : 3.0m beta 1
PCMAV.exe.mad : $00026e0c, $202e3f26, $1c644614
contact name : Indra
contact email : indra.ramadhan094@gmail.com
callstack crc : $989739ed, $d339bcf6, $d339bcf6
exception number : 1
exception class : EAccessViolation
exception message : Access violation at address 0060B160 in module 'PCMAV.exe'. Read of address 00000004.
main thread ($5a4):
0060b160 +000 PCMAV.exe segment%276 public%12303
0068402e +006 PCMAV.exe segment%291 public%13036
005a4bb9 +015 PCMAV.exe segment%206 public%10420
005a4c64 +018 PCMAV.exe segment%206 public%10424
005a5109 +021 PCMAV.exe segment%206 public%10429
00475ecc +014 PCMAV.exe segment%31 public%3532
77d4bcc7 +00a USER32.dll DispatchMessageA
004c47f4 +0fc PCMAV.exe segment%58 public%6000
004c4816 +00a PCMAV.exe segment%58 public%6001
00683755 +16d PCMAV.exe segment%291 public%13032
004a704c +064 PCMAV.exe segment%54 public%4998
0048c55e +01e PCMAV.exe segment%43 public%4236
0048c65c +00c PCMAV.exe segment%43 public%4242
004a6b47 +2bb PCMAV.exe segment%54 public%4991
004aab3e +4fa PCMAV.exe segment%54 public%5138
0048c408 +06c PCMAV.exe segment%43 public%4230
004a67d4 +024 PCMAV.exe segment%54 public%4987
004aac8f +023 PCMAV.exe segment%54 public%5140
004ab65b +00b PCMAV.exe segment%54 public%5147
004a6b47 +2bb PCMAV.exe segment%54 public%4991
004aab3e +4fa PCMAV.exe segment%54 public%5138
004a9529 +02d PCMAV.exe segment%54 public%5107
004aa268 +02c PCMAV.exe segment%54 public%5133
00475ecc +014 PCMAV.exe segment%31 public%3532
77d4b7a6 +044 USER32.dll SendMessageW
77d4e361 +016 USER32.dll CallWindowProcA
004aac3b +0d7 PCMAV.exe segment%54 public%5139
004a746c +010 PCMAV.exe segment%54 public%5015
004a6b47 +2bb PCMAV.exe segment%54 public%4991
004aab3e +4fa PCMAV.exe segment%54 public%5138
0048c408 +06c PCMAV.exe segment%43 public%4230
004aa268 +02c PCMAV.exe segment%54 public%5133
00475ecc +014 PCMAV.exe segment%31 public%3532
77d4bcc7 +00a USER32.dll DispatchMessageA
004c47f4 +0fc PCMAV.exe segment%58 public%6000
004c482e +00a PCMAV.exe segment%58 public%6002
004c4b3f +0b3 PCMAV.exe segment%58 public%6007
0069027d +1c9 PCMAV.exe segment%423 public%13231
thread $6d0 (TWndProc): <suspended>
0066790f +1f PCMAV.exe segment%282 public%12790
thread $218:
7c90e286 +00a ntdll.dll NtReadFile
7c80186f +061 kernel32.dll ReadFile
005b674d +1e5 PCMAV.exe segment%208 public%10609
00452b5d +00d PCMAV.exe segment%23 public%2340
00452bc7 +037 PCMAV.exe segment%23 public%2341
>> created by thread $794 at:
005b69bc +22c PCMAV.exe segment%208 public%10610
thread $688 (TRegMonitorThread):
7c90e9be +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
00678f4e +12 PCMAV.exe segment%288 public%12949
00452c7b +2b PCMAV.exe segment%23 public%2342
00474758 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by main thread ($5a4) at:
00678e38 +18 PCMAV.exe segment%288 public%12946
thread $708 (TRegMonitorThread):
7c90e9be +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
00678f4e +12 PCMAV.exe segment%288 public%12949
00452c7b +2b PCMAV.exe segment%23 public%2342
00474758 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by main thread ($5a4) at:
00678e38 +18 PCMAV.exe segment%288 public%12946
thread $5dc:
7c90d85a +a ntdll.dll NtDelayExecution
thread $35c:
7c90e9a9 +a ntdll.dll NtWaitForMultipleObjects
thread $5b8:
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094ec +00 kernel32.dll WaitForMultipleObjectsEx
7c809c81 +13 kernel32.dll WaitForMultipleObjects
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by main thread ($5a4) at:
769c8951 +00 userenv.dll
thread $724:
7c90e286 +00a ntdll.dll NtReadFile
7c80186f +061 kernel32.dll ReadFile
005b674d +1e5 PCMAV.exe segment%208 public%10609
00452b5d +00d PCMAV.exe segment%23 public%2340
00452bc7 +037 PCMAV.exe segment%23 public%2341
>> created by thread $608 at:
005b69bc +22c PCMAV.exe segment%208 public%10610
thread $b8:
7c90d85a +0a ntdll.dll NtDelayExecution
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by main thread ($5a4) at:
77e8760d +00 RPCRT4.dll
thread $7e8:
7c90e319 +a ntdll.dll NtRemoveIoCompletion
thread $448:
7c90e319 +0a ntdll.dll NtRemoveIoCompletion
7c80cbd3 +23 kernel32.dll GetQueuedCompletionStatus
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by thread $b8 at:
77e8760d +00 RPCRT4.dll
thread $2e8 (TgtTimerThread):
7c90e9be +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
004d1e74 +10 PCMAV.exe segment%64 public%6319
00452c7b +2b PCMAV.exe segment%23 public%2342
00474758 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by main thread ($5a4) at:
004d1dfb +1b PCMAV.exe segment%64 public%6316
thread $4dc (TgtTimerThread):
7c90e9be +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
004d1e74 +10 PCMAV.exe segment%64 public%6319
00452c7b +2b PCMAV.exe segment%23 public%2342
00474758 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by main thread ($5a4) at:
004d1dfb +1b PCMAV.exe segment%64 public%6316
thread $38c (TgtTimerThread):
7c90e9be +0a ntdll.dll NtWaitForSingleObject
7c8025d5 +85 kernel32.dll WaitForSingleObjectEx
7c80253d +0d kernel32.dll WaitForSingleObject
004d1e74 +10 PCMAV.exe segment%64 public%6319
00452c7b +2b PCMAV.exe segment%23 public%2342
00474758 +34 PCMAV.exe segment%31 public%3425
004056f4 +28 PCMAV.exe segment%0 public%250
00452b5d +0d PCMAV.exe segment%23 public%2340
00452bc7 +37 PCMAV.exe segment%23 public%2341
>> created by main thread ($5a4) at:
004d1dfb +1b PCMAV.exe segment%64 public%6316
processes:
000 Idle 0 0
004 System 0 0 normal
09c smss.exe 0 0 normal C:\WINDOWS\system32
0d0 csrss.exe 43 48 normal C:\WINDOWS\system32
0e8 winlogon.exe 35 13 high C:\WINDOWS\system32
114 services.exe 4 1 normal C:\WINDOWS\system32
120 lsass.exe 4 2 normal C:\WINDOWS\system32
1bc svchost.exe 4 1 normal C:\WINDOWS\system32
1e8 svchost.exe 4 1 normal C:\WINDOWS\system32
220 svchost.exe 4 1 normal C:\WINDOWS\system32
2f8 Explorer.EXE 251 109 normal C:\WINDOWS
374 taskmgr.exe 111 127 high C:\WINDOWS\system32
25c PCMAV.exe 240 161 normal C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha
cpu registers:
eax = 00000000
ebx = 02856080
ecx = 04878460
edx = 02856080
esi = 0012f46c
edi = 00000401
eip = 0060b160
esp = 0012f444
ebp = 0012f47c
stack dump:
0012f444 33 40 68 00 bc 4b 5a 00 - 80 60 85 02 67 4c 5a 00 3@h..KZ..`..gLZ.
0012f454 80 60 85 02 0e 51 5a 00 - e4 f4 12 00 01 0e 58 01 .`...QZ.......X.
0012f464 00 00 00 00 ce 5e 47 00 - 01 04 00 00 00 00 00 00 .....^G.........
0012f474 00 00 00 00 00 00 00 00 - a8 f4 12 00 09 87 d4 77 ...............w
0012f484 ac 00 06 00 01 04 00 00 - 00 00 00 00 00 00 00 00 ................
0012f494 01 0e 58 01 cd ab ba dc - 00 00 00 00 e4 f4 12 00 ..X.............
0012f4a4 01 0e 58 01 10 f5 12 00 - eb 87 d4 77 01 0e 58 01 ..X........w..X.
0012f4b4 ac 00 06 00 01 04 00 00 - 00 00 00 00 00 00 00 00 ................
0012f4c4 ac f5 12 00 a4 f5 12 00 - a8 9f aa 00 14 00 00 00 ................
0012f4d4 01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00 ................
0012f4e4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012f4f4 00 00 00 00 c4 f4 12 00 - 68 f0 12 00 60 f5 12 00 ........h...`...
0012f504 94 04 d7 77 08 88 d4 77 - ff ff ff ff 70 f5 12 00 ...w...w....p...
0012f514 a5 89 d4 77 00 00 00 00 - 01 0e 58 01 ac 00 06 00 ...w......X.....
0012f524 01 04 00 00 00 00 00 00 - 00 00 00 00 bc 9f aa 00 ................
0012f534 01 00 00 00 a4 f5 12 00 - d0 99 27 01 01 00 00 00 ..........'.....
0012f544 a4 f5 12 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012f554 00 00 00 00 38 f5 12 00 - 68 f0 12 00 1c f9 12 00 ....8...h.......
0012f564 94 04 d7 77 c8 89 d4 77 - ff ff ff ff 80 f5 12 00 ...w...w........
0012f574 cc bc d4 77 a4 f5 12 00 - 01 00 00 00 ac 00 06 00 ...w............
disassembling:
0060b160 public segment%276.public%12303 (PCMAV.exe): ; function entry point
0060b160 > mov eax, [eax+4]
0060b163 call +$118 ($60b280) ; segment%276.public%12305 (PCMAV.exe)
0060b163
0060b168 ret
date/time : 2011-09-09, 11:24:58, 250ms
computer name : INTER1
user name : Administrator <admin>
registered owner : Zlatan Ibrahimovic / Internazionale
operating system : Windows XP Service Pack 2 build 2600
system language : Indonesian
system up time : 2 hours 16 minutes
program up time : 4 seconds
processors : 2x Intel(R) Pentium(R) D CPU 2.66GHz
physical memory : 513/958 MB (free/total)
free disk space : (C:) 60,31 GB
display mode : 1024x768, 32 bit
process id : $8d8
allocated memory : 8,95 MB
command line : "C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha\lib\ExtMan.exe" run
executable : ExtMan.exe
exec. date/time : 2011-09-06 09:10
compiled with : Delphi 2006/07
madExcept version : 3.0m beta 1
contact name : Indra
contact email : indra.ramadhan094@gmail.com
callstack crc : $8d7f6f94, $02e9af5b, $02e9af5b
exception number : 1
exception class : EAccessViolation
exception message : Access violation at address 03C1C290. Read of address 03C1C290.
thread $240:
>> stack not accessible, exception location:
03c1c290 +0 ???
thread $cb4:
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
00450379 +0d ExtMan.exe madExcept CallThreadProcSafe
004503e3 +37 ExtMan.exe madExcept ThreadExceptFrame
>> created by thread $240 at:
77dfa17c +00 advapi32.dll
thread $ba8:
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094ec +00 kernel32.dll WaitForMultipleObjectsEx
7c809c81 +13 kernel32.dll WaitForMultipleObjects
00450379 +0d ExtMan.exe madExcept CallThreadProcSafe
004503e3 +37 ExtMan.exe madExcept ThreadExceptFrame
>> created by thread $240 at:
032215be +00 IDMShellExt.dll
modules:
00400000 ExtMan.exe C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha\lib
02fd0000 Normaliz.dll 6.0.5441.0 C:\WINDOWS\system32
03220000 IDMShellExt.dll 6.0.6.4 C:\Program Files\Internet Download Manager
0ffd0000 rsaenh.dll 5.1.2600.2161 C:\WINDOWS\system32
10000000 guard32.dll 5.5.64714.1382 C:\WINDOWS\system32
4ffe0000 fltlib.dll 5.1.2600.2180 C:\WINDOWS\system32
5ad70000 uxtheme.dll 6.0.2900.2180 C:\WINDOWS\system32
5b0a0000 umdmxfrm.dll 5.1.2600.0 C:\WINDOWS\system32
5cd70000 serwvdrv.dll 5.1.2600.0 C:\WINDOWS\system32
5dca0000 iertutil.dll 7.0.5730.13 C:\WINDOWS\system32
661c0000 GRA8E1~1.DLL 12.0.4518.1014 C:\PROGRA~1\MICROS~2\Office12
68ef0000 GrooveUtil.DLL 12.0.4518.1014 C:\PROGRA~1\MICROS~2\Office12
68ff0000 GrooveNew.DLL 12.0.4518.1014 C:\PROGRA~1\MICROS~2\Office12
71aa0000 WS2HELP.dll 5.1.2600.2180 C:\WINDOWS\system32
71ab0000 WS2_32.dll 5.1.2600.2180 C:\WINDOWS\system32
71ad0000 wsock32.dll 5.1.2600.2180 C:\WINDOWS\system32
71b20000 mpr.dll 5.1.2600.2180 C:\WINDOWS\system32
73000000 winspool.drv 5.1.2600.2180 C:\WINDOWS\system32
74720000 MSCTF.dll 5.1.2600.2180 C:\WINDOWS\system32
74c80000 oleacc.dll 4.2.5406.0 C:\WINDOWS\system32
755c0000 msctfime.ime 5.1.2600.2180 C:\WINDOWS\system32
76080000 MSVCP60.dll 6.2.3104.0 C:\WINDOWS\system32
76380000 msimg32.dll 5.1.2600.2180 C:\WINDOWS\system32
76390000 IMM32.DLL 5.1.2600.2180 C:\WINDOWS\system32
763b0000 comdlg32.dll 6.0.2900.2180 C:\WINDOWS\system32
76b40000 winmm.dll 5.1.2600.2180 C:\WINDOWS\system32
76bf0000 PSAPI.dll 5.1.2600.2180 C:\WINDOWS\system32
76d60000 iphlpapi.dll 5.1.2600.2180 C:\WINDOWS\system32
76fd0000 CLBCATQ.DLL 2001.12.4414.258 C:\WINDOWS\system32
77050000 COMRes.dll 2001.12.4414.258 C:\WINDOWS\system32
77120000 oleaut32.dll 5.1.2600.2180 C:\WINDOWS\system32
771b0000 WININET.dll 7.0.5730.13 C:\WINDOWS\system32
773d0000 comctl32.dll 6.0.2900.2180 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9
774e0000 ole32.dll 5.1.2600.2180 C:\WINDOWS\system32
77920000 SETUPAPI.dll 5.1.2600.2180 C:\WINDOWS\system32
77a80000 CRYPT32.dll 5.131.2600.2180 C:\WINDOWS\system32
77b20000 MSASN1.dll 5.1.2600.2180 C:\WINDOWS\system32
77b40000 appHelp.dll 5.1.2600.2180 C:\WINDOWS\system32
77c00000 version.dll 5.1.2600.2180 C:\WINDOWS\system32
77c10000 msvcrt.dll 7.0.2600.2180 C:\WINDOWS\system32
77d40000 USER32.dll 5.1.2600.2180 C:\WINDOWS\system32
77dd0000 advapi32.dll 5.1.2600.2180 C:\WINDOWS\system32
77e70000 RPCRT4.dll 5.1.2600.2180 C:\WINDOWS\system32
77f10000 GDI32.dll 5.1.2600.2180 C:\WINDOWS\system32
77f60000 SHLWAPI.dll 6.0.2900.2995 C:\WINDOWS\system32
77fe0000 Secur32.dll 5.1.2600.2180 C:\WINDOWS\system32
78130000 MSVCR80.dll 8.0.50727.6195 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86
7c630000 ATL80.DLL 8.0.50727.6195 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_a4c618fa
7c800000 kernel32.dll 5.1.2600.2180 C:\WINDOWS\system32
7c900000 ntdll.dll 5.1.2600.2180 C:\WINDOWS\system32
7c9c0000 SHELL32.dll 6.0.2900.2180 C:\WINDOWS\system32
processes:
000 Idle 0 0
004 System 0 0 normal
37c smss.exe 0 0 normal C:\WINDOWS\system32
3bc csrss.exe 62 63 normal C:\WINDOWS\system32
3d8 winlogon.exe 44 14 high C:\WINDOWS\system32
404 services.exe 4 2 normal C:\WINDOWS\system32
410 lsass.exe 4 3 normal C:\WINDOWS\system32
4c4 svchost.exe 4 1 normal C:\WINDOWS\system32
518 svchost.exe 4 1 normal C:\WINDOWS\system32
58c svchost.exe 11 35 normal C:\WINDOWS\system32
5c4 AIPS.exe 4 3 normal C:\Program Files\netcut\services
5f4 svchost.exe 4 1 normal C:\WINDOWS\system32
674 svchost.exe 4 1 normal C:\WINDOWS\system32
6e4 spoolsv.exe 4 4 normal C:\WINDOWS\system32
0bc Explorer.EXE 296 144 normal C:\WINDOWS
130 SOUNDMAN.EXE 18 8 normal C:\WINDOWS
138 VTTimer.exe 12 5 normal C:\WINDOWS\system32
144 VTtrayp.exe 12 5 normal C:\WINDOWS\system32
150 egui.exe 203 63 normal C:\Program Files\ESET\ESET Smart Security
1b8 ekrn.exe 8 13 normal C:\Program Files\ESET\ESET Smart Security
1c4 ctfmon.exe 18 12 normal C:\WINDOWS\system32
1e8 YahooMessenger.exe 789 346 normal C:\PROGRA~1\Yahoo!\MESSEN~1
1f4 msnmsgr.exe 65 76 normal C:\Program Files\Windows Live\Messenger
2a8 SeaPort.exe 5 6 normal C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort
384 GoogleUpdate.exe 5 3 normal C:\Program Files\Google\Update
494 slmdmsr.exe 4 1 normal C:\WINDOWS\system32
084 wdfmgr.exe 4 1 normal C:\WINDOWS\system32
75c SearchIndexer.exe 5 7 normal C:\WINDOWS\system32
828 wscntfy.exe 20 9 normal C:\WINDOWS\system32
aa0 wmiprvse.exe 8 7 normal C:\WINDOWS\system32\wbem
bf0 alg.exe 5 2 normal C:\WINDOWS\System32
e1c YahooMessenger.exe 9 9 normal C:\PROGRA~1\Yahoo!\MESSEN~1
4a4 taskmgr.exe 110 130 high C:\WINDOWS\system32
c5c PCMAV.exe 227 155 normal C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha
754 chrome.exe 74 52 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
aac chrome.exe 30 1 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
a6c chrome.exe 10 1 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
920 SearchProtocolHost.exe 5 14 below normal C:\WINDOWS\system32
4e8 SearchFilterHost.exe 5 10 below normal C:\WINDOWS\system32
2bc svchost.exe 5 4 normal C:\WINDOWS\system32
8d8 ExtMan.exe 161 90 normal C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha\lib
cpu registers:
eax = 7ffdf000
ebx = 00000000
ecx = 03e40fda
edx = 00000002
esi = 03e40fd5
edi = 0012fe68
eip = 03c1c290
esp = 0012fe04
ebp = 0012fe2c
stack dump:
0012fe04 17 58 40 00 28 a0 af 00 - 28 a0 af 00 ea 2e 40 00 .X@.(...(.....@.
0012fe14 18 a0 af 00 28 50 4d 00 - 06 2f 40 00 66 00 40 00 .Q@.(..../@.fQ@.
0012fe24 50 00 40 00 54 fe 12 00 - 06 2f 40 00 1a fe 08 00 KT@.T..../@..Q@.
0012fe34 c0 00 00 00 b8 fe 12 00 - 27 2f 40 00 1f 01 00 00 ........'/@.+...
0012fe44 27 ff 12 00 27 2f 40 00 - 54 fe 12 00 17 58 40 00 ,...'/@.T....X@.
0012fe54 f8 f1 a3 00 f8 f1 a3 00 - 27 01 00 00 d0 54 40 00 ....,...'/@.h...
0012fe64 2c de aa 00 2c ff 12 00 - fe 00 00 00 00 00 13 00 .X@...........D.
0012fe74 10 fe 12 00 03 00 00 00 - 00 bc 44 00 b4 fe 12 00 ,....S@.....t...
0012fe84 b8 fe 12 00 e8 de aa 00 - 98 fe 12 00 5d bd 44 00 ....(.D.....].D.
0012fe94 e8 fe 12 00 f8 fe 12 00 - aa bd 44 00 e8 fe 12 00 ..........D.....
0012fea4 24 fb c4 00 00 00 00 00 - 02 00 00 00 08 a0 af 00 $...............
0012feb4 28 a0 af 00 38 a0 af 00 - 08 4e b2 00 90 4d b2 00 (...8....N...M..
0012fec4 00 f0 12 00 00 00 03 00 - 04 00 00 00 00 10 00 00 ................
0012fed4 00 10 00 00 04 00 00 00 - 00 00 02 00 07 00 00 00 ................
0012fee4 2c ff 12 00 6c ff 12 00 - a0 c1 44 00 6c ff 12 00 ,...l.....D.l...
0012fef4 6c ff 12 00 04 ff 12 00 - 9e c4 44 00 6c ff 12 00 l.........D.l...
0012ff04 8c ff 12 00 29 c5 44 00 - 6c ff 12 00 24 fb c4 00 ....).D.l...$...
0012ff14 c0 f0 a1 00 78 ff 12 00 - 00 00 00 00 00 00 00 00 ....x...........
0012ff24 00 00 00 00 00 00 00 00 - 08 46 08 01 b8 cd a3 00 .........F......
0012ff34 b8 bf 08 01 00 00 00 00 - 60 83 44 85 18 54 5f 85 ........`.D..T_.
disassembling:
7c90e99f public NtWaitForMultipleObjects: ; function entry point
7c90e99f mov eax, $10e
7c90e9a4 mov edx, $7ffe0300
7c90e9a9 > call dword ptr [edx] ; KiFastSystemCall (ntdll.dll)
7c90e9ab ret $14
date/time : 2011-09-09, 11:27:25, 31ms
computer name : INTER1
user name : Administrator <admin>
registered owner : Zlatan Ibrahimovic / Internazionale
operating system : Windows XP Service Pack 2 build 2600
system language : Indonesian
system up time : 2 hours 18 minutes
program up time : 4 seconds
processors : 2x Intel(R) Pentium(R) D CPU 2.66GHz
physical memory : 505/958 MB (free/total)
free disk space : (C:) 60,31 GB
display mode : 1024x768, 32 bit
process id : $a3c
allocated memory : 9,17 MB
command line : "C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha\lib\ExtMan.exe" run
executable : ExtMan.exe
exec. date/time : 2011-09-06 09:10
compiled with : Delphi 2006/07
madExcept version : 3.0m beta 1
contact name : Indra
contact email : indra.ramadhan094@gmail.com
callstack crc : $0366cecc, $4fc2ed9b, $4fc2ed9b
exception number : 1
exception class : EAccessViolation
exception message : Access violation at address 0366CECC. Read of address 0366CECC.
thread $f40:
0366cecc +00 ???
7c90eae0 +10 ntdll.dll KiUserCallbackDispatcher
77d4e670 +0a USER32.dll DestroyWindow
00493528 +28 ExtMan.exe Controls TWinControl.DestroyWindowHandle
004a7a47 +33 ExtMan.exe Forms TCustomForm.DestroyWindowHandle
004a453b +73 ExtMan.exe Forms TCustomForm.Destroy
0046e64f +47 ExtMan.exe Classes TComponent.DestroyComponents
004a2786 +32 ExtMan.exe Forms DoneApplication
00454dea +26 ExtMan.exe SysUtils DoExitProc
00404f65 +21 ExtMan.exe System 49 +0 @Halt0
thread $b24:
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
00450379 +0d ExtMan.exe madExcept CallThreadProcSafe
004503e3 +37 ExtMan.exe madExcept ThreadExceptFrame
>> created by thread $f40 at:
77dfa17c +00 advapi32.dll
thread $ac8:
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094ec +00 kernel32.dll WaitForMultipleObjectsEx
7c809c81 +13 kernel32.dll WaitForMultipleObjects
00450379 +0d ExtMan.exe madExcept CallThreadProcSafe
004503e3 +37 ExtMan.exe madExcept ThreadExceptFrame
>> created by thread $f40 at:
032215be +00 IDMShellExt.dll
modules:
00400000 ExtMan.exe C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha\lib
02fd0000 Normaliz.dll 6.0.5441.0 C:\WINDOWS\system32
03220000 IDMShellExt.dll 6.0.6.4 C:\Program Files\Internet Download Manager
0ffd0000 rsaenh.dll 5.1.2600.2161 C:\WINDOWS\system32
10000000 guard32.dll 5.5.64714.1382 C:\WINDOWS\system32
4ffe0000 fltlib.dll 5.1.2600.2180 C:\WINDOWS\system32
5ad70000 uxtheme.dll 6.0.2900.2180 C:\WINDOWS\system32
5b0a0000 umdmxfrm.dll 5.1.2600.0 C:\WINDOWS\system32
5cd70000 serwvdrv.dll 5.1.2600.0 C:\WINDOWS\system32
5dca0000 iertutil.dll 7.0.5730.13 C:\WINDOWS\system32
661c0000 GRA8E1~1.DLL 12.0.4518.1014 C:\PROGRA~1\MICROS~2\Office12
68ef0000 GrooveUtil.DLL 12.0.4518.1014 C:\PROGRA~1\MICROS~2\Office12
68ff0000 GrooveNew.DLL 12.0.4518.1014 C:\PROGRA~1\MICROS~2\Office12
71aa0000 WS2HELP.dll 5.1.2600.2180 C:\WINDOWS\system32
71ab0000 WS2_32.dll 5.1.2600.2180 C:\WINDOWS\system32
71ad0000 wsock32.dll 5.1.2600.2180 C:\WINDOWS\system32
71b20000 mpr.dll 5.1.2600.2180 C:\WINDOWS\system32
73000000 winspool.drv 5.1.2600.2180 C:\WINDOWS\system32
74720000 MSCTF.dll 5.1.2600.2180 C:\WINDOWS\system32
74c80000 oleacc.dll 4.2.5406.0 C:\WINDOWS\system32
755c0000 msctfime.ime 5.1.2600.2180 C:\WINDOWS\system32
76080000 MSVCP60.dll 6.2.3104.0 C:\WINDOWS\system32
76380000 msimg32.dll 5.1.2600.2180 C:\WINDOWS\system32
76390000 IMM32.DLL 5.1.2600.2180 C:\WINDOWS\system32
763b0000 comdlg32.dll 6.0.2900.2180 C:\WINDOWS\system32
76b40000 winmm.dll 5.1.2600.2180 C:\WINDOWS\system32
76bf0000 PSAPI.dll 5.1.2600.2180 C:\WINDOWS\system32
76d60000 iphlpapi.dll 5.1.2600.2180 C:\WINDOWS\system32
76fd0000 CLBCATQ.DLL 2001.12.4414.258 C:\WINDOWS\system32
77050000 COMRes.dll 2001.12.4414.258 C:\WINDOWS\system32
77120000 oleaut32.dll 5.1.2600.2180 C:\WINDOWS\system32
771b0000 WININET.dll 7.0.5730.13 C:\WINDOWS\system32
773d0000 comctl32.dll 6.0.2900.2180 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9
774e0000 ole32.dll 5.1.2600.2180 C:\WINDOWS\system32
77920000 SETUPAPI.dll 5.1.2600.2180 C:\WINDOWS\system32
77a80000 CRYPT32.dll 5.131.2600.2180 C:\WINDOWS\system32
77b20000 MSASN1.dll 5.1.2600.2180 C:\WINDOWS\system32
77b40000 appHelp.dll 5.1.2600.2180 C:\WINDOWS\system32
77c00000 version.dll 5.1.2600.2180 C:\WINDOWS\system32
77c10000 msvcrt.dll 7.0.2600.2180 C:\WINDOWS\system32
77d40000 USER32.dll 5.1.2600.2180 C:\WINDOWS\system32
77dd0000 advapi32.dll 5.1.2600.2180 C:\WINDOWS\system32
77e70000 RPCRT4.dll 5.1.2600.2180 C:\WINDOWS\system32
77f10000 GDI32.dll 5.1.2600.2180 C:\WINDOWS\system32
77f60000 SHLWAPI.dll 6.0.2900.2995 C:\WINDOWS\system32
77fe0000 Secur32.dll 5.1.2600.2180 C:\WINDOWS\system32
78130000 MSVCR80.dll 8.0.50727.6195 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86
7c630000 ATL80.DLL 8.0.50727.6195 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_a4c618fa
7c800000 kernel32.dll 5.1.2600.2180 C:\WINDOWS\system32
7c900000 ntdll.dll 5.1.2600.2180 C:\WINDOWS\system32
7c9c0000 SHELL32.dll 6.0.2900.2180 C:\WINDOWS\system32
processes:
000 Idle 0 0
004 System 0 0 normal
37c smss.exe 0 0 normal C:\WINDOWS\system32
3bc csrss.exe 62 63 normal C:\WINDOWS\system32
3d8 winlogon.exe 44 14 high C:\WINDOWS\system32
404 services.exe 4 2 normal C:\WINDOWS\system32
410 lsass.exe 6 5 normal C:\WINDOWS\system32
4c4 svchost.exe 4 1 normal C:\WINDOWS\system32
518 svchost.exe 4 1 normal C:\WINDOWS\system32
58c svchost.exe 11 34 normal C:\WINDOWS\system32
5c4 AIPS.exe 4 3 normal C:\Program Files\netcut\services
5f4 svchost.exe 4 1 normal C:\WINDOWS\system32
674 svchost.exe 4 1 normal C:\WINDOWS\system32
6e4 spoolsv.exe 4 4 normal C:\WINDOWS\system32
0bc Explorer.EXE 300 146 normal C:\WINDOWS
130 SOUNDMAN.EXE 18 8 normal C:\WINDOWS
138 VTTimer.exe 12 5 normal C:\WINDOWS\system32
144 VTtrayp.exe 12 5 normal C:\WINDOWS\system32
150 egui.exe 202 63 normal C:\Program Files\ESET\ESET Smart Security
1b8 ekrn.exe 8 15 normal C:\Program Files\ESET\ESET Smart Security
1c4 ctfmon.exe 18 12 normal C:\WINDOWS\system32
1e8 YahooMessenger.exe 779 333 normal C:\PROGRA~1\Yahoo!\MESSEN~1
1f4 msnmsgr.exe 65 76 normal C:\Program Files\Windows Live\Messenger
2a8 SeaPort.exe 5 6 normal C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort
384 GoogleUpdate.exe 5 3 normal C:\Program Files\Google\Update
494 slmdmsr.exe 4 1 normal C:\WINDOWS\system32
084 wdfmgr.exe 4 1 normal C:\WINDOWS\system32
75c SearchIndexer.exe 5 10 normal C:\WINDOWS\system32
828 wscntfy.exe 20 9 normal C:\WINDOWS\system32
aa0 wmiprvse.exe 8 7 normal C:\WINDOWS\system32\wbem
bf0 alg.exe 5 2 normal C:\WINDOWS\System32
e1c YahooMessenger.exe 9 9 normal C:\PROGRA~1\Yahoo!\MESSEN~1
4a4 taskmgr.exe 110 130 high C:\WINDOWS\system32
c5c PCMAV.exe 227 154 normal C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha
754 chrome.exe 74 52 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
aac chrome.exe 30 1 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
a6c chrome.exe 10 1 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
920 SearchProtocolHost.exe 5 14 below normal C:\WINDOWS\system32
2bc svchost.exe 5 4 normal C:\WINDOWS\system32
c38 SearchFilterHost.exe 9 9 below normal C:\WINDOWS\system32
a3c ExtMan.exe 155 88 normal C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha\lib
cpu registers:
eax = 7ffde000
ebx = 00000000
ecx = 03360fda
edx = 00000002
esi = 03360fd5
edi = 0012fe68
eip = 0366cecc
esp = 0012fe04
ebp = 0012fe2c
stack dump:
0012fe04 17 58 40 00 48 a0 af 00 - 48 a0 af 00 ea 2e 40 00 .X@.H...H.....@.
0012fe14 b8 a0 af 00 48 50 4d 00 - 06 2f 40 00 66 00 40 00 .Q@.H..../@.fQ@.
0012fe24 50 00 40 00 54 fe 12 00 - 06 2f 40 00 1a fe a6 00 KT@.T..../@..Q@.
0012fe34 c0 00 00 00 b8 fe 12 00 - 27 2f 40 00 1f 01 00 00 ........'/@.+...
0012fe44 27 ff 12 00 27 2f 40 00 - 54 fe 12 00 17 58 40 00 ,...'/@.T....X@.
0012fe54 f8 f1 a3 00 f8 f1 a3 00 - 27 01 00 00 d0 54 40 00 ....,...'/@.h...
0012fe64 2c de aa 00 2c ff 12 00 - fe 00 00 00 00 00 13 00 .X@...........D.
0012fe74 10 fe 12 00 03 00 00 00 - 00 bc 44 00 b4 fe 12 00 ,....S@.....t...
0012fe84 b8 fe 12 00 e8 de aa 00 - 98 fe 12 00 5d bd 44 00 ....(.D.....].D.
0012fe94 e8 fe 12 00 f8 fe 12 00 - aa bd 44 00 e8 fe 12 00 ..........D.....
0012fea4 24 fb c4 00 00 00 00 00 - 02 00 00 00 28 a0 af 00 $...........x...
0012feb4 08 a0 af 00 38 a0 af 00 - b0 4e b2 00 38 4e b2 00 ....8....N..8N..
0012fec4 00 f0 12 00 00 00 03 00 - 04 00 00 00 00 10 00 00 ................
0012fed4 00 10 00 00 04 00 00 00 - 00 00 02 00 07 00 00 00 ................
0012fee4 2c ff 12 00 6c ff 12 00 - a0 c1 44 00 6c ff 12 00 ,...l.....D.l...
0012fef4 6c ff 12 00 04 ff 12 00 - 9e c4 44 00 6c ff 12 00 l.........D.l...
0012ff04 8c ff 12 00 29 c5 44 00 - 6c ff 12 00 24 fb c4 00 ....).D.l...$...
0012ff14 c0 f0 a1 00 78 ff 12 00 - 00 00 00 00 00 00 00 00 ....x...........
0012ff24 00 00 00 00 00 00 00 00 - 78 a0 a6 00 b8 cd a3 00 ........x.......
0012ff34 d8 a0 a9 00 00 00 00 00 - 68 83 44 85 20 30 5f 85 ........h.D..0_.
disassembling:
00404f44 public System.@Halt0: ; function entry point
00404f44 49 push ebx
00404f45 push esi
00404f46 push edi
00404f47 push ebp
00404f48 mov ebx, $4dd7c4
00404f4d mov edi, $4db044
00404f52 cmp byte ptr [ebx+$28], 0
00404f56 jnz loc_404f6c
00404f58 cmp dword ptr [edi], 0
00404f5b jz loc_404f6c
00404f5d mov eax, [edi]
00404f5f mov esi, eax
00404f61 xor eax, eax
00404f63 mov [edi], eax
00404f65 > call esi
00404f67 cmp dword ptr [edi], 0
00404f6a jnz loc_404f5d
00404f6c cmp dword ptr [$4d5004], 0
00404f73 jz loc_404f86
00404f75 call -$156 ($404e24) ; System.MakeErrorMessage
00404f7a call +$4a88d ($44f80c) ; madExcept.InterceptWriteErrorMessage
00404f7f xor eax, eax
00404f81 mov [$4d5004], eax
00404f86 cmp byte ptr [ebx+$28], 2
00404f8a jnz loc_404f9a
00404f8c cmp dword ptr [$4d5000], 0
00404f93 jnz loc_404f9a
00404f95 xor eax, eax
00404f97 mov [ebx+$c], eax
00404f9a call +$4a9b1 ($44f950) ; madExcept.InterceptFinalizeUnits
00404f9f cmp byte ptr [ebx+$28], 1
00404fa3 jbe loc_404fae
00404fa5 cmp dword ptr [$4d5000], 0
00404fac jz loc_404fd1
00404fae mov edi, [ebx+$10]
00404fb1 test edi, edi
00404fb3 jz loc_404fd1
00404fb5 mov eax, edi
00404fb7 call +$1d84 ($406d40) ; System.UnregisterModule
00404fbc mov ebp, [ebx+$10]
00404fbf mov esi, [ebp+$10]
00404fc2 cmp esi, [ebp+4]
00404fc5 jz loc_404fd1
00404fc7 test esi, esi
00404fc9 jz loc_404fd1
00404fcb push esi
00404fcc call -$3d0d ($4012c4) ; System.FreeLibrary
00404fd1 call -$332 ($404ca4) ; System.UnsetExceptionHandler
00404fd6 cmp byte ptr [ebx+$28], 1
00404fda jnz loc_404fdf
00404fdc call dword ptr [ebx+$24]
00404fdf cmp byte ptr [ebx+$28], 0
00404fe3 jz loc_404fea
00404fe5 call -$162 ($404e88) ; System.ExitDll
00404fea cmp dword ptr [ebx], 0
00404fed jnz loc_405009
00404fef cmp dword ptr [$4db024], 0
00404ff6 jz loc_404ffe
00404ff8 call dword ptr [$4db024]
00404ffe mov eax, [$4d5000]
00405003 push eax
00405004 call -$3d65 ($4012a4) ; System.ExitProcess
00405009 mov eax, [ebx]
0040500b mov esi, eax
0040500d mov edi, ebx
0040500f mov ecx, $b
00405014 rep movsd
00405016 jmp loc_404f86
date/time : 2011-09-09, 11:28:13, 343ms
computer name : INTER1
user name : Administrator <admin>
registered owner : Zlatan Ibrahimovic / Internazionale
operating system : Windows XP Service Pack 2 build 2600
system language : Indonesian
system up time : 2 hours 19 minutes
program up time : 4 seconds
processors : 2x Intel(R) Pentium(R) D CPU 2.66GHz
physical memory : 514/958 MB (free/total)
free disk space : (C:) 60,31 GB
display mode : 1024x768, 32 bit
process id : $718
allocated memory : 9,12 MB
command line : "C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha\lib\ExtMan.exe" run
executable : ExtMan.exe
exec. date/time : 2011-09-06 09:10
compiled with : Delphi 2006/07
madExcept version : 3.0m beta 1
contact name : Indra
contact email : indra.ramadhan094@gmail.com
callstack crc : $8d7f6f94, $02e9af5b, $02e9af5b
exception number : 1
exception class : EAccessViolation
exception message : Access violation at address 033EB974. Read of address 033EB974.
thread $cec:
>> stack not accessible, exception location:
033eb974 +0 ???
thread $478:
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
00450379 +0d ExtMan.exe madExcept CallThreadProcSafe
004503e3 +37 ExtMan.exe madExcept ThreadExceptFrame
>> created by thread $cec at:
77dfa17c +00 advapi32.dll
thread $330:
7c90e9a9 +0a ntdll.dll NtWaitForMultipleObjects
7c8094ec +00 kernel32.dll WaitForMultipleObjectsEx
7c809c81 +13 kernel32.dll WaitForMultipleObjects
00450379 +0d ExtMan.exe madExcept CallThreadProcSafe
004503e3 +37 ExtMan.exe madExcept ThreadExceptFrame
>> created by thread $cec at:
032215be +00 IDMShellExt.dll
modules:
00400000 ExtMan.exe C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha\lib
02fd0000 Normaliz.dll 6.0.5441.0 C:\WINDOWS\system32
03220000 IDMShellExt.dll 6.0.6.4 C:\Program Files\Internet Download Manager
0ffd0000 rsaenh.dll 5.1.2600.2161 C:\WINDOWS\system32
10000000 guard32.dll 5.5.64714.1382 C:\WINDOWS\system32
4ffe0000 fltlib.dll 5.1.2600.2180 C:\WINDOWS\system32
5ad70000 uxtheme.dll 6.0.2900.2180 C:\WINDOWS\system32
5b0a0000 umdmxfrm.dll 5.1.2600.0 C:\WINDOWS\system32
5cd70000 serwvdrv.dll 5.1.2600.0 C:\WINDOWS\system32
5dca0000 iertutil.dll 7.0.5730.13 C:\WINDOWS\system32
661c0000 GRA8E1~1.DLL 12.0.4518.1014 C:\PROGRA~1\MICROS~2\Office12
68ef0000 GrooveUtil.DLL 12.0.4518.1014 C:\PROGRA~1\MICROS~2\Office12
68ff0000 GrooveNew.DLL 12.0.4518.1014 C:\PROGRA~1\MICROS~2\Office12
71aa0000 WS2HELP.dll 5.1.2600.2180 C:\WINDOWS\system32
71ab0000 WS2_32.dll 5.1.2600.2180 C:\WINDOWS\system32
71ad0000 wsock32.dll 5.1.2600.2180 C:\WINDOWS\system32
71b20000 mpr.dll 5.1.2600.2180 C:\WINDOWS\system32
73000000 winspool.drv 5.1.2600.2180 C:\WINDOWS\system32
74720000 MSCTF.dll 5.1.2600.2180 C:\WINDOWS\system32
74c80000 oleacc.dll 4.2.5406.0 C:\WINDOWS\system32
755c0000 msctfime.ime 5.1.2600.2180 C:\WINDOWS\system32
76080000 MSVCP60.dll 6.2.3104.0 C:\WINDOWS\system32
76380000 msimg32.dll 5.1.2600.2180 C:\WINDOWS\system32
76390000 IMM32.DLL 5.1.2600.2180 C:\WINDOWS\system32
763b0000 comdlg32.dll 6.0.2900.2180 C:\WINDOWS\system32
76b40000 winmm.dll 5.1.2600.2180 C:\WINDOWS\system32
76bf0000 PSAPI.dll 5.1.2600.2180 C:\WINDOWS\system32
76d60000 iphlpapi.dll 5.1.2600.2180 C:\WINDOWS\system32
76fd0000 CLBCATQ.DLL 2001.12.4414.258 C:\WINDOWS\system32
77050000 COMRes.dll 2001.12.4414.258 C:\WINDOWS\system32
77120000 oleaut32.dll 5.1.2600.2180 C:\WINDOWS\system32
771b0000 WININET.dll 7.0.5730.13 C:\WINDOWS\system32
773d0000 comctl32.dll 6.0.2900.2180 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9
774e0000 ole32.dll 5.1.2600.2180 C:\WINDOWS\system32
77920000 SETUPAPI.dll 5.1.2600.2180 C:\WINDOWS\system32
77a80000 CRYPT32.dll 5.131.2600.2180 C:\WINDOWS\system32
77b20000 MSASN1.dll 5.1.2600.2180 C:\WINDOWS\system32
77b40000 appHelp.dll 5.1.2600.2180 C:\WINDOWS\system32
77c00000 version.dll 5.1.2600.2180 C:\WINDOWS\system32
77c10000 msvcrt.dll 7.0.2600.2180 C:\WINDOWS\system32
77d40000 USER32.dll 5.1.2600.2180 C:\WINDOWS\system32
77dd0000 advapi32.dll 5.1.2600.2180 C:\WINDOWS\system32
77e70000 RPCRT4.dll 5.1.2600.2180 C:\WINDOWS\system32
77f10000 GDI32.dll 5.1.2600.2180 C:\WINDOWS\system32
77f60000 SHLWAPI.dll 6.0.2900.2995 C:\WINDOWS\system32
77fe0000 Secur32.dll 5.1.2600.2180 C:\WINDOWS\system32
78130000 MSVCR80.dll 8.0.50727.6195 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86
7c630000 ATL80.DLL 8.0.50727.6195 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_a4c618fa
7c800000 kernel32.dll 5.1.2600.2180 C:\WINDOWS\system32
7c900000 ntdll.dll 5.1.2600.2180 C:\WINDOWS\system32
7c9c0000 SHELL32.dll 6.0.2900.2180 C:\WINDOWS\system32
processes:
000 Idle 0 0
004 System 0 0 normal
37c smss.exe 0 0 normal C:\WINDOWS\system32
3bc csrss.exe 62 63 normal C:\WINDOWS\system32
3d8 winlogon.exe 44 14 high C:\WINDOWS\system32
404 services.exe 4 2 normal C:\WINDOWS\system32
410 lsass.exe 6 4 normal C:\WINDOWS\system32
4c4 svchost.exe 4 1 normal C:\WINDOWS\system32
518 svchost.exe 4 1 normal C:\WINDOWS\system32
58c svchost.exe 11 36 normal C:\WINDOWS\system32
5c4 AIPS.exe 4 3 normal C:\Program Files\netcut\services
5f4 svchost.exe 4 1 normal C:\WINDOWS\system32
674 svchost.exe 4 1 normal C:\WINDOWS\system32
6e4 spoolsv.exe 4 4 normal C:\WINDOWS\system32
0bc Explorer.EXE 307 147 normal C:\WINDOWS
130 SOUNDMAN.EXE 18 8 normal C:\WINDOWS
138 VTTimer.exe 12 5 normal C:\WINDOWS\system32
144 VTtrayp.exe 12 5 normal C:\WINDOWS\system32
150 egui.exe 202 63 normal C:\Program Files\ESET\ESET Smart Security
1b8 ekrn.exe 8 14 normal C:\Program Files\ESET\ESET Smart Security
1c4 ctfmon.exe 18 12 normal C:\WINDOWS\system32
1e8 YahooMessenger.exe 776 332 normal C:\PROGRA~1\Yahoo!\MESSEN~1
1f4 msnmsgr.exe 65 76 normal C:\Program Files\Windows Live\Messenger
2a8 SeaPort.exe 5 6 normal C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort
384 GoogleUpdate.exe 5 3 normal C:\Program Files\Google\Update
494 slmdmsr.exe 4 1 normal C:\WINDOWS\system32
084 wdfmgr.exe 4 1 normal C:\WINDOWS\system32
75c SearchIndexer.exe 5 7 normal C:\WINDOWS\system32
828 wscntfy.exe 20 9 normal C:\WINDOWS\system32
aa0 wmiprvse.exe 8 7 normal C:\WINDOWS\system32\wbem
bf0 alg.exe 5 2 normal C:\WINDOWS\System32
e1c YahooMessenger.exe 9 9 normal C:\PROGRA~1\Yahoo!\MESSEN~1
4a4 taskmgr.exe 110 130 high C:\WINDOWS\system32
c5c PCMAV.exe 227 154 normal C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha
754 chrome.exe 74 52 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
aac chrome.exe 30 1 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
a6c chrome.exe 10 1 normal C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application
920 SearchProtocolHost.exe 5 14 below normal C:\WINDOWS\system32
2bc svchost.exe 5 4 normal C:\WINDOWS\system32
c38 SearchFilterHost.exe 9 9 below normal C:\WINDOWS\system32
718 ExtMan.exe 75 9 normal C:\Documents and Settings\Administrator\My Documents\Downloads\Asgard Alpha\lib
cpu registers:
eax = 7ffde000
ebx = 00000000
ecx = 03380fda
edx = 00000002
esi = 03380fd5
edi = 0012fe68
eip = 033eb974
esp = 0012fe04
ebp = 0012fe2c
stack dump:
0012fe04 17 58 40 00 18 a0 af 00 - 18 a0 af 00 ea 2e 40 00 .X@...........@.
0012fe14 08 51 40 00 18 50 4d 00 - 06 2f 40 00 66 00 40 00 .Q@....../@.fQ@.
0012fe24 50 00 40 00 54 fe 12 00 - 06 2f 40 00 1a fe 09 00 KT@.T..../@..Q@.
0012fe34 c0 00 00 00 b8 fe 12 00 - 27 2f 40 00 1f 01 00 00 ........'/@.+...
0012fe44 27 ff 12 00 27 2f 40 00 - 54 fe 12 00 17 58 40 00 ,...'/@.T....X@.
0012fe54 f8 f1 a3 00 f8 f1 a3 00 - 27 01 00 00 d0 54 40 00 ....,...'/@.h...
0012fe64 2c de aa 00 2c ff 12 00 - fe 00 00 00 00 00 13 00 .X@...........D.
0012fe74 10 fe 12 00 03 00 00 00 - 00 bc 44 00 b4 fe 12 00 ,....S@.....t...
0012fe84 b8 fe 12 00 e8 de aa 00 - 98 fe 12 00 5d bd 44 00 ....(.D.....].D.
0012fe94 e8 fe 12 00 f8 fe 12 00 - aa bd 44 00 e8 fe 12 00 ..........D.....
0012fea4 24 fb c4 00 00 00 00 00 - 02 00 00 00 58 a0 af 00 $...............
0012feb4 18 a0 af 00 28 a0 af 00 - c0 4d b2 00 a8 4d b2 00 ....(....M...M..
0012fec4 00 f0 12 00 00 00 03 00 - 04 00 00 00 00 10 00 00 ................
0012fed4 00 10 00 00 04 00 00 00 - 00 00 02 00 07 00 00 00 ................
0012fee4 2c ff 12 00 6c ff 12 00 - a0 c1 44 00 6c ff 12 00 ,...l.....D.l...
0012fef4 6c ff 12 00 04 ff 12 00 - 9e c4 44 00 6c ff 12 00 l.........D.l...
0012ff04 8c ff 12 00 29 c5 44 00 - 6c ff 12 00 24 fb c4 00 ....).D.l...$...
0012ff14 c0 f0 a1 00 78 ff 12 00 - 00 00 00 00 00 00 00 00 ....x...........
0012ff24 00 00 00 00 00 00 00 00 - 68 b6 09 01 b8 cd a3 00 ........h.......
0012ff34 18 30 0a 01 00 00 00 00 - e8 57 e2 85 20 10 7b 85 .0.......W....{.
disassembling:
7c90e99f public NtWaitForMultipleObjects: ; function entry point
7c90e99f mov eax, $10e
7c90e9a4 mov edx, $7ffe0300
7c90e9a9 > call dword ptr [edx] ; KiFastSystemCall (ntdll.dll)
7c90e9ab ret $14