Vous êtes sur la page 1sur 7

date/time

computer name
user name
registered owner
operating system
system language
system up time
program up time
processors
physical memory
free disk space
display mode
process id
allocated memory
executable
current module
module date/time
version
compiled with
madExcept version
callstack crc
exception number
exception class
exception message

:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:

2011-11-10, 11:34:29, 941ms


JORDANDESKTOP
Jordan Desktop <admin>
Microsoft / Microsoft
Windows 7 x64 Service Pack 1 build 7601
English
5 days 1 hour
12 minutes 41 seconds
8x Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz
1965/4087 MB (free/total)
(C:) 1647.89 GB
1600x900, 32 bit
$aa3c
145.32 MB
Phoenix.exe
Main.dll
2011-09-04 09:33
1.0.4.27
Delphi 2010
3.0m
$abf02dac, $a40950c1, $07ab523c
1
Exception
Unknown.

main thread ($9bf0):


028b0dfe +04e Main.dll
028b188a +766 Main.dll
744f7945 +016 USER32.dll
74b0611d +25d USP10.dll
744f7945 +016 USER32.dll
02899b69 +389 Main.dll
775b0117 +02b ntdll.dll
744f7945 +016 USER32.dll
02899ee3 +1bf Main.dll
775b0117 +02b ntdll.dll
744e96c0 +047 USER32.dll
744e7885 +00a USER32.dll
7450c81a +119 USER32.dll
74505144 +057 USER32.dll
775b0117 +02b ntdll.dll
7450ce85 +031 USER32.dll
7452cb53 +047 USER32.dll
743d33c8 +010 kernel32.dll

MzL_Main 9198 +1 CopyFiles_Folders


MzL_Main 9380 +142 @@ParseInstallScript
CallWindowProcA
ScriptTextOut
CallWindowProcA
MzL_Main 2431 +105 @@ChildDlgProc
KiUserCallbackDispatcher
CallWindowProcA
MzL_Main 2483 +46 @@CommonRectDlgProc
KiUserCallbackDispatcher
SendMessageW
DispatchMessageW
IsDialogMessageW
IsDialogMessage
KiUserCallbackDispatcher
DialogBoxIndirectParamAorW
DialogBoxParamA
BaseThreadInitThunk

thread $9db4:
775c0146 +0e ntdll.dll
NtWaitForMultipleObjects
743d33c8 +10 kernel32.dll BaseThreadInitThunk
thread $cad4:
775c0146 +0e ntdll.dll
7536096e +fa KERNELBASE.dll
743d1a27 +89 kernel32.dll
744f0864 +00 USER32.dll
744f0b64 +1a USER32.dll
743d33c8 +10 kernel32.dll

NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjectsEx
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjects
BaseThreadInitThunk

thread $a928:
775bf8ba +0e ntdll.dll
NtWaitForSingleObject
75360822 +92 KERNELBASE.dll WaitForSingleObjectEx

743d118f +3e kernel32.dll


743d33c8 +10 kernel32.dll

WaitForSingleObjectEx
BaseThreadInitThunk

thread $6dbc:
744e7908 +26 USER32.dll
GetMessageW
743d33c8 +10 kernel32.dll BaseThreadInitThunk
thread $5de4:
744e7908 +26 USER32.dll
GetMessageW
743d33c8 +10 kernel32.dll BaseThreadInitThunk
thread $b634:
775c1f2f +0b ntdll.dll
NtWaitForWorkViaWorkerFactory
743d33c8 +10 kernel32.dll BaseThreadInitThunk
thread $baa8:
7450f5b7 +0e USER32.dll
WaitMessage
7450ce85 +31 USER32.dll
DialogBoxIndirectParamAorW
7450d004 +3a USER32.dll
DialogBoxParamW
0271e985 +0d Main.dll
Windows
@@DialogBox
028b4f13 +37 Main.dll
Banner 381 +3 @@BannerThread
743d33c8 +10 kernel32.dll
BaseThreadInitThunk
thread $bc2c:
775c1f2f +0b ntdll.dll
NtWaitForWorkViaWorkerFactory
743d33c8 +10 kernel32.dll BaseThreadInitThunk
modules:
00400000 Phoenix.exe
p
01f70000 lua.dll
p\Phx_data\Res\SharedDLLs
01fa0000 RainCWrapper.dll
p\Phx_data\Res\SharedDLLs
02710000 Main.dll
p\Phx_data\Res\SharedDLLs
02f30000 SimDecrypt.dll
p\Phx_data\Res\SharedDLLs
03210000 InstallOptions.dll
l\Temp\nsq5C2D.tmp
03220000 name2ip.dll
l\Temp\nsq5C2D.tmp
04a50000 NSISArray.dll
l\Temp\nsq5C2D.tmp
04a70000 HLLib.dll
p\Phx_Data\Res\SharedDLLs
04ab0000 Phx_Default.dll
p\Phx_Data\Plugins
059b0000 ButtonEvent.dll
l\Temp\nsq5C2D.tmp
059c0000 nsDialogs.dll
l\Temp\nsq5C2D.tmp
10000000 System.dll
l\Temp\nsq5C2D.tmp
19600000 tv_w32.dll
wer\Version6
5f270000 netshell.dll
5f790000 rain.dll
p\Phx_data\Res\SharedDLLs
5fed0000 ieproxy.dll

1.0.4.28

C:\Users\Jordan Desktop\Deskto
C:\Users\Jordan Desktop\Deskto
C:\Users\Jordan Desktop\Deskto

1.0.4.27

C:\Users\Jordan Desktop\Deskto
C:\Users\Jordan Desktop\Deskto
C:\Users\JORDAN~1\AppData\Loca
C:\Users\JORDAN~1\AppData\Loca
C:\Users\JORDAN~1\AppData\Loca

2.4.0.0

C:\Users\Jordan Desktop\Deskto

1.0.5.8

C:\Users\Jordan Desktop\Deskto
C:\Users\JORDAN~1\AppData\Loca
C:\Users\JORDAN~1\AppData\Loca
C:\Users\JORDAN~1\AppData\Loca

6.0.11656.0

C:\Program Files (x86)\TeamVie

6.1.7601.17514

C:\Windows\System32
C:\Users\Jordan Desktop\Deskto

9.0.8112.16421

C:\Program Files (x86)\Interne

t Explorer
601a0000 PortableDeviceApi.dll 6.1.7601.17514
C:\Windows\system32
60230000 SAMLIB.dll
6.1.7600.16385
C:\Windows\system32
602f0000 SearchFolder.dll
6.1.7601.17514
C:\Windows\system32
65590000 explorerframe.dll
6.1.7601.21624
C:\Windows\system32
65760000 StructuredQuery.dll 7.0.7601.17514
C:\Windows\System32
657c0000 EhStorAPI.dll
6.1.7601.17514
C:\Windows\system32
65830000 MSVCR80.dll
8.0.50727.4940
C:\Windows\WinSxS\x86_microsof
t.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc
658d0000 thumbcache.dll
6.1.7601.17514
C:\Windows\SysWOW64
65990000 tiptsf.dll
6.1.7600.16385
C:\Program Files (x86)\Common
Files\microsoft shared\ink
65b70000 actxprxy.dll
6.1.7601.21624
C:\Windows\SysWOW64
65d30000 shdocvw.dll
6.1.7601.17514
C:\Windows\System32
663c0000 DUI70.dll
6.1.7600.16385
C:\Windows\system32
66480000 ntshrui.dll
6.1.7601.17514
C:\Windows\system32
66940000 msls31.dll
3.10.349.0
C:\Windows\system32
67ac0000 RichEd20.DLL
5.31.23.1230
C:\Windows\system32
67c50000 ieframe.DLL
9.0.8112.16421
C:\Windows\system32
686e0000 DUser.dll
6.1.7600.16385
C:\Windows\system32
687f0000 EhStorShell.dll
6.1.7600.16385
C:\Windows\system32
6c240000 CRTDLL.dll
4.0.1183.1
C:\Windows\system32
6e2b0000 rasadhlp.dll
6.1.7600.16385
C:\Windows\system32
6e300000 WINNSI.DLL
6.1.7600.16385
C:\Windows\system32
6e310000 IPHLPAPI.DLL
6.1.7601.17514
C:\Windows\system32
6e340000 DNSAPI.dll
6.1.7601.21689
C:\Windows\system32
6e3c0000 nlaapi.dll
6.1.7601.17514
C:\Windows\System32
6e3d0000 wshtcpip.dll
6.1.7600.16385
C:\Windows\System32
6e480000 mswsock.dll
6.1.7601.17514
C:\Windows\system32
6e4c0000 rsaenh.dll
6.1.7600.16385
C:\Windows\system32
6e500000 CRYPTSP.dll
6.1.7600.16385
C:\Windows\system32
6e7b0000 MPR.dll
6.1.7600.16385
C:\Windows\system32
6e7d0000 dwmapi.dll
6.1.7600.16385
C:\Windows\system32
6e820000 winmm.dll
6.1.7601.17514
C:\Windows\system32
6e860000 uxtheme.dll
6.1.7600.16385
C:\Windows\system32
6e8e0000 VDFParse.dll
C:\Users\Jordan Desktop\Deskto
p\Phx_data\Res\SharedDLLs
6e900000 msvfw32.dll
6.1.7601.17514
C:\Windows\system32
6ea60000 samcli.dll
6.1.7601.17514
C:\Windows\system32
6eb90000 COMCTL32.dll
6.10.7601.17514
C:\Windows\WinSxS\x86_microsof
t.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2
6ed30000 apphelp.dll
6.1.7601.17514
C:\Windows\system32
6fdd0000 OLEACC.dll
7.0.0.0
C:\Windows\system32
6feb0000 NetworkExplorer.dll 6.1.7601.17514
C:\Windows\system32
702f0000 DAVHLPR.dll
6.1.7600.16385
C:\Windows\System32
70300000 davclnt.dll
6.1.7601.21687
C:\Windows\System32
70320000 ntlanman.dll
6.1.7601.17514
C:\Windows\System32
70340000 drprov.dll
6.1.7600.16385
C:\Windows\System32
70350000 LINKINFO.dll
6.1.7600.16385
C:\Windows\system32
70360000 XmlLite.dll
1.3.1000.0
C:\Windows\system32
704c0000 sensapi.dll
6.1.7600.16385
C:\Windows\system32
704d0000 rtutils.dll
6.1.7601.17514
C:\Windows\system32
704e0000 rasman.dll
6.1.7600.16385
C:\Windows\system32
70500000 RASAPI32.dll
6.1.7601.21626
C:\Windows\system32
70570000 slc.dll
6.1.7600.16385
C:\Windows\system32
70680000 msimg32.dll
6.1.7600.16385
C:\Windows\system32
70690000 WindowsCodecs.dll
6.1.7601.21624
C:\Windows\system32
708f0000 npmproxy.dll
6.1.7600.16385
C:\Windows\System32
70a50000 propsys.dll
7.0.7601.17514
C:\Windows\system32
70b50000 gdiplus.dll
6.1.7601.21640
C:\Windows\WinSxS\x86_microsof

t.windows.gdiplus_6595b64144ccf1df_1.1.7601.21640_none_5c073f81a00db207
71a20000 SHFOLDER.DLL
6.1.7600.16385
C:\Windows\system32
73370000 srvcli.dll
6.1.7601.17514
C:\Windows\system32
73390000 netutils.dll
6.1.7601.17514
C:\Windows\system32
733a0000 NETAPI32.dll
6.1.7601.17514
C:\Windows\system32
733c0000 WINSTA.dll
6.1.7601.17514
C:\Windows\System32
73410000 Secur32.dll
6.1.7601.21685
C:\Windows\system32
73810000 RpcRtRemote.dll
6.1.7601.17514
C:\Windows\system32
73ad0000 cscapi.dll
6.1.7601.17514
C:\Windows\system32
73ae0000 wkscli.dll
6.1.7601.17514
C:\Windows\system32
73c40000 profapi.dll
6.1.7600.16385
C:\Windows\system32
73c80000 wsock32.dll
6.1.7600.16385
C:\Windows\system32
73f70000 ntmarta.dll
6.1.7600.16385
C:\Windows\system32
73fb0000 winspool.drv
6.1.7601.21685
C:\Windows\system32
74010000 VERSION.dll
6.1.7600.16385
C:\Windows\system32
74020000 snxhk.dll
6.0.1289.0
C:\Program Files\AVAST Softwar
e\Avast
74160000 CRYPTBASE.dll
6.1.7600.16385
C:\Windows\syswow64
74170000 SspiCli.dll
6.1.7601.21685
C:\Windows\syswow64
741d0000 msvcrt.dll
7.0.7600.16385
C:\Windows\syswow64
74280000 MSASN1.dll
6.1.7601.21624
C:\Windows\syswow64
74290000 NSI.dll
6.1.7600.16385
C:\Windows\syswow64
742a0000 urlmon.dll
9.0.8112.16421
C:\Windows\syswow64
743c0000 kernel32.dll
6.1.7601.21651
C:\Windows\syswow64
744d0000 USER32.dll
6.1.7601.17514
C:\Windows\syswow64
745d0000 CRYPT32.dll
6.1.7601.21667
C:\Windows\syswow64
746f0000 IMM32.DLL
6.1.7601.17514
C:\Windows\system32
74750000 Normaliz.dll
6.1.7600.16385
C:\Windows\syswow64
74760000 OLEAUT32.dll
6.1.7601.17514
C:\Windows\syswow64
747f0000 ADVAPI32.dll
6.1.7601.21687
C:\Windows\syswow64
74920000 GDI32.dll
6.1.7601.17514
C:\Windows\syswow64
749b0000 WLDAP32.dll
6.1.7601.17514
C:\Windows\syswow64
74a00000 DEVOBJ.dll
6.1.7600.16385
C:\Windows\syswow64
74a20000 MSCTF.dll
6.1.7600.16385
C:\Windows\syswow64
74af0000 PSAPI.DLL
6.1.7600.16385
C:\Windows\syswow64
74b00000 USP10.dll
1.626.7601.17561 C:\Windows\syswow64
74ba0000 iertutil.dll
9.0.8112.16421
C:\Windows\syswow64
74d60000 sechost.dll
6.1.7600.16385
C:\Windows\SysWOW64
74d80000 ole32.dll
6.1.7601.21624
C:\Windows\syswow64
74ee0000 CLBCatQ.DLL
2001.12.8530.16385 C:\Windows\syswow64
74f70000 wininet.dll
9.0.8112.16421
C:\Windows\syswow64
75090000 SETUPAPI.dll
6.1.7601.17514
C:\Windows\syswow64
75230000 WINTRUST.dll
6.1.7601.17514
C:\Windows\syswow64
75290000 comdlg32.dll
6.1.7601.17514
C:\Windows\syswow64
75310000 WS2_32.dll
6.1.7601.17514
C:\Windows\syswow64
75350000 KERNELBASE.dll
6.1.7601.17576
C:\Windows\syswow64
753a0000 SHELL32.dll
6.1.7601.21687
C:\Windows\syswow64
76b00000 SHLWAPI.dll
6.1.7601.17514
C:\Windows\syswow64
76bc0000 RPCRT4.dll
6.1.7601.21682
C:\Windows\syswow64
76cb0000 CFGMGR32.dll
6.1.7601.17514
C:\Windows\syswow64
77570000 LPK.dll
6.1.7600.16385
C:\Windows\syswow64
775a0000 ntdll.dll
6.1.7601.17514
C:\Windows\SysWOW64
processes:
0000 Idle
0004 System
01d0 smss.exe
023c csrss.exe
0288 wininit.exe
029c csrss.exe

0
0
0
0
0
1

0
0
0
0
0
0

0
0
0
0
0
0

02d0 services.exe
0 0
0
02e8 winlogon.exe
1 0
0
0310 lsass.exe
0 0
0
0318 lsm.exe
0 0
0
0384 svchost.exe
0 0
0
03d4 nvvsvc.exe
0 0
0
03ec nvSCPAPISvr.exe
0 0
0
0110 svchost.exe
0 0
0
02a0 svchost.exe
0 0
0
01e0 svchost.exe
0 0
0
0430 svchost.exe
0 0
0
04a4 svchost.exe
0 0
0
04f4 WUDFHost.exe
0 0
0
0530 WUDFHost.exe
0 0
0
057c svchost.exe
0 0
0
05f0 svchost.exe
0 0
0
0618 AvastSvc.exe
0 0
0
0718 nvxdsync.exe
1 0
0
0724 nvvsvc.exe
1 0
0
070c spoolsv.exe
0 0
0
0818 armsvc.exe
0 0
0
0844 BCUService.exe
0 0
0
0864 svchost.exe
0 0
0
0ab4 taskhost.exe
1 23 29 normal
0b28 sppsvc.exe
0 0
0
0b7c svchost.exe
0 0
0
0524 nvtray.exe
1 82 4 normal
0914 WMPSideShowGadget.exe 1 74 30 normal
0a54 wmplayer.exe
1 357 65 normal C:\Program
ia Player
0c70 dwm.exe
1 32 4 high
0c88 explorer.exe
1 731 236 normal
0d1c LCore.exe
1 77 59 normal
0d40 sidebar.exe
1 116 39 normal
0db8 MegaManager.exe
1 751 597 normal C:\Program
Mega Manager
0e5c nusb3mon.exe
1 21 9 normal C:\Program
ctronics\USB 3.0 Host Controller Driver\Application
0e70 BCU.exe
1 9
4 normal C:\Program
owser Configuration Utility
0ea4 QFanHelp.exe
1 40 20 normal C:\Program
0eac AiChargerAP.exe
1 22 16 normal C:\Program
i Charger
0ec8 AvastUI.exe
1 135 39 normal C:\Program
ast
0fa4 CurseClient.exe
1 32 39 high
0d34 taskhost.exe
0 0
0
0d0c svchost.exe
0 0
0
1360 LCDClock.exe
1 65 32 normal
13e0 LCDMedia.exe
1 158 38 normal C:\Program
oftware\plugins\LCDAppletsMono-8.01.067\Applets\x86
13fc WmiPrvSE.exe
0 0
0
1034 LCDPop3.exe
1 116 25 normal
13a4 Skype.exe
1 471 266 normal C:\Program
11bc firefox.exe
1 147 93 normal C:\Program
efox
169c plugin-container.exe 1 60 42 normal C:\Program
efox
1438 daemonu.exe
0 0
0 normal
0b38 svchost.exe
0 0
0

Files (x86)\Windows Med

Files (x86)\Megaupload\
Files (x86)\Renesas Ele
Files (x86)\DeviceVM\Br
Files\ASUS\Fan Xpert
Files (x86)\ASUS\ASUS A
Files\AVAST Software\Av

Files\Logitech Gaming S

Files (x86)\Skype\Phone
Files (x86)\Mozilla Fir
Files (x86)\Mozilla Fir

14a0 Steam.exe
0fe0 taskhost.exe
3a2c plugin-container.exe
efox
49b4 audiodg.exe
4588 plugin-container.exe
efox
754c pbsetup.exe
mp\Rar$EX66.336
97bc PnkBstrB.exe
94d8 PnkBstrA.exe
ce00 explorer.exe
ce74 realsched.exe
ayer\update
60cc explorer.exe
7f58 TeamViewer.exe
Version6
4038 TeamViewer_Desktop.exe
c900 tv_w32.exe
a630 tv_x64.exe
aa3c Phoenix.exe
88dc msiexec.exe

1 1175 123 normal C:\Program Files (x86)\Steam


1 12 4 normal
1 35 38 normal C:\Program Files (x86)\Mozilla Fir
0 0
1 9

0
12 normal C:\Program Files (x86)\Mozilla Fir

1 41

18 normal C:\Users\JORDAN~1\AppData\Local\Te

0
0
1
1

0
0
125 normal
10 normal C:\Program Files (x86)\Real\RealPl

0
0
203
9

1 211 125 normal


1 634 144 normal C:\Program Files (x86)\TeamViewer\
1
1
1
1
0

0
0
0
151
0

0
0
0
118 normal C:\Users\Jordan Desktop\Desktop
0

disassembling:
[...]
028b0dd1
add
edi, -$10
028b0dd4
xor
eax, eax
028b0dd6
push
ebp
028b0dd7
push
$28b105c
;
028b0ddc
push
dword ptr fs:[eax]
028b0ddf
mov
fs:[eax], esp
028b0de2 9198 lea
eax, [ebp-$10]
028b0de5
call
-$199912 ($27174d8)
;
028b0de5
028b0dea
mov
edx, 1
028b0def
dec
edx
028b0df0
test
eax, eax
028b0df2
jz
loc_28b0df9
028b0df2
028b0df4
cmp
edx, [eax-4]
028b0df7
jb
loc_28b0dfe
028b0df7
028b0df9
loc_28b0df9:
028b0df9
call
-$19b6ee ($2715710)
;
028b0df9
028b0dfe
loc_28b0dfe:
028b0dfe
> inc
edx
028b0dff
lea
eax, [eax+edx-1]
028b0e03
push
eax
028b0e04
push
ebx
028b0e05
call
-$da96a ($27d64a0)
;
028b0e05
028b0e0a
add
esp, 8
028b0e05
028b0e0d
loc_28b0e0d:
028b0e0d 9201 cmp
byte ptr [ebp-$11], 0
028b0e11
jz
loc_28b0e22
028b0e11
028b0e13 9202 lea
eax, [ebp-4]
028b0e16
mov
edx, $28b1078
;

@.HandleFinally

@.UniqueStringA

@.BoundErr

VDFParse.@@KV_GetName

'file'

028b0e1b
028b0e1b
028b0e20
028b0e20
028b0e20
028b0e20
[...]

call

-$19a134 ($2716cec)

jmp

loc_28b0e2f

; @.LStrLAsg

; ---------------------------------------------------------

Vous aimerez peut-être aussi