EurekaLog 7.0.1.0 Application: ---------------------------------------------------------- 1.1 Start Date : Thu, 31 May 2012 15:58:46 +0400 1.2 Name/Description: richedit.exe - (RichEdit VCL Demo) 1.3 Version Number : 1.0.0.0 1.4 Parameters : 1.5 Compilation Date: Thu, 31 May 2012 15:58:44 +0400 1.6 Up Time : 14 second(s) Exception: -------------------------------------------------------------------------------------------------------------- 2.1 Date : Thu, 31 May 2012 15:59:00 +0400 2.2 Address : 005E9F14 2.3 Module Name : richedit.exe - (RichEdit VCL Demo) 2.4 Module Version: 1.0.0.0 2.5 Type : EAccessViolation 2.6 Message : Access violation at address 005E9F14 in module 'richedit.exe'. Write of address 00000000 2.7 ID : 0DA60000 2.8 Count : 1 2.9 Status : New 2.10 Note : 2.11 Sent : 0 User: ------------------------------------------------------- 3.1 ID : Alexander 3.2 Name : Alexander 3.3 Email : alex@eurekalog.com 3.4 Company : EurekaLab s.a.s. 3.5 Privileges: SeShutdownPrivilege - OFF SeChangeNotifyPrivilege - ON SeUndockPrivilege - OFF SeIncreaseWorkingSetPrivilege - OFF SeTimeZonePrivilege - OFF Active Controls: ---------------------------------------------------------- 4.1 Form Class : TMainForm 4.2 Form Text : overview.rtf - Rich Edit Control Demo 4.3 Control Class: TRichEdit 4.4 Control Text : Computer: ----------------------------------------------------------------------------------- 5.1 Name : ALEX-LAPTOP 5.2 Total Memory : 4294168576 5.3 Free Memory : 934420480 5.4 Total Disk : 750050463744 5.5 Free Disk : 144784560128 5.6 System Up Time: 7 day(s), 5 hour(s), 51 minute(s), 13 second(s) 5.7 Processor : Intel(R) Core(TM)2 Duo CPU T9400 @ 2.53GHz 5.8 Display Mode : 1680 x 1050, 32 bit 5.9 Display DPI : 120 5.10 Video Card : NVIDIA GeForce 9700M GT (driver 8.17.12.9573 - RAM 536870912) 5.11 Printer : PDFCreator (driver 6.1.7600.16385) Operating System: -------------------------------------------- 6.1 Type : Microsoft Windows 7 (64 bit) 6.2 Build # : 7601 6.3 Update : Service pack 1 6.4 Language: Russian 6.5 Charset : 204 Network: --------------------------------------------------------------------------------------------------------------------------- 7.1 IP Address: 000.000.000.000 - 000.000.000.000 - 000.000.000.000 - 192.168.001.178 - 192.168.001.100 - 169.254.154.088 7.2 Submask : 000.000.000.000 - 000.000.000.000 - 000.000.000.000 - 255.255.255.000 - 255.255.255.000 - 255.255.000.000 7.3 Gateway : 000.000.000.000 - 000.000.000.000 - 000.000.000.000 - 192.168.001.001 - 192.168.001.001 - 000.000.000.000 7.4 DNS 1 : 000.000.000.000 - 000.000.000.000 - 000.000.000.000 - 008.008.008.008 - 192.168.001.001 - 000.000.000.000 7.5 DNS 2 : 000.000.000.000 - 000.000.000.000 - 000.000.000.000 - 000.000.000.000 - 000.000.000.000 - 000.000.000.000 7.6 DHCP : ON - ON - ON - ON - ON - OFF Call Stack Information: ---------------------------------------------------------------------------------------------------------------------------- |Methods |Details|Stack |Address |Module |Offset |Unit |Class |Procedure/Method |Line | ---------------------------------------------------------------------------------------------------------------------------- |*Exception Thread: ID=5264; Parent=0; Priority=0 | |Class=; Name=MAIN | |DeadLock=0; Wait Chain= | |Comment= | |--------------------------------------------------------------------------------------------------------------------------| |7FFFFFFE|04 |00000000|005E9F14|richedit.exe|001E9F14|remain | |Enumer |216[2] | |00000006|03 |0018FB20|74D4946A|USER32.dll |0001946A|USER32 | |InternalEnumWindows | | |00000006|03 |0018FB40|74D4D1E0|USER32.dll |0001D1E0|USER32 | |EnumWindows | | |00000006|04 |0018FB50|005E9F4E|richedit.exe|001E9F4E|remain |TMainForm |UpdateStatus |225[1] | |00000006|04 |0018FB88|005E9FDD|richedit.exe|001E9FDD|remain |TMainForm |SetFileName |234[4] | |00000006|04 |0018FB98|005EA440|richedit.exe|001EA440|remain |TMainForm |PerformFileOpen |325[3] | |00000006|04 |0018FBB4|005EA4AF|richedit.exe|001EA4AF|remain |TMainForm |FileOpen |361[4] | |00000006|04 |0018FD30|00464F47|richedit.exe|00064F47|Classes |TBasicAction |Execute |12988[3] | |00000004|04 |0018FBBC|00559A51|richedit.exe|00159A51|ActnList |TContainedAction|Execute |448[8] | |00000004|04 |0018FBCC|0055A80C|richedit.exe|0015A80C|ActnList |TCustomAction |Execute |1094[7] | |00000004|04 |0018FBD4|00464E0B|richedit.exe|00064E0B|Classes |TBasicActionLink|Execute |12917[2] | |00000004|04 |0018FBE0|0058A054|richedit.exe|0018A054|Menus |TMenuItem |Click |2525[17] | |00000004|04 |0018FBEC|0058B567|richedit.exe|0018B567|Menus |TMenu |DispatchCommand |3390[5] | |00000004|04 |0018FBF4|005CF8F3|richedit.exe|001CF8F3|Forms |TCustomForm |WMCommand |5715[2] | |00000004|04 |0018FC00|0056AEB8|richedit.exe|0016AEB8|Controls |TControl |WndProc |7074[91] | |00000004|04 |0018FC18|0056F77C|richedit.exe|0016F77C|Controls |TWinControl |WndProc |9831[144] | |00000006|04 |0018FDF0|004655EC|richedit.exe|000655EC|Classes | |StdWndProc |13491[8] | |00000006|03 |0018FE1C|74D462FA|USER32.dll |000162FA|USER32 | |InternalCallWinProc | | |00000006|03 |0018FE94|74D46D35|USER32.dll |00016D35|USER32 | |UserCallWinProcCheckWow | | |00000004|03 |0018FE68|7760010A|ntdll.dll |0001010A|ntdll | |KiUserCallbackDispatcher| | |00000006|03 |0018FEF4|74D477BF|USER32.dll |000177BF|USER32 | |DispatchMessageWorker | | |00000006|03 |0018FF04|74D47885|USER32.dll |00017885|USER32 | |DispatchMessageW | | |00000004|04 |0018FF20|005D577A|richedit.exe|001D577A|Forms |TApplication |HandleMessage |9790[1] | |00000004|04 |0018FF44|005D5AA5|richedit.exe|001D5AA5|Forms |TApplication |Run |9927[26] | |00000004|04 |0018FF74|005F373C|richedit.exe|001F373C|richeditdemo| |Initialization |27[4] | |00000004|03 |0018FF8C|74F63398|kernel32.dll|00013398|kernel32 | |BaseThreadInitThunk | | ---------------------------------------------------------------------------------------------------------------------------- Modules Information: -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Handle |Name |Description |Version |Size |Modified |Path | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |6E750000|ntshrui.dll |Shell extensions for sharing |6.1.7601.17755 |442880 |2012-01-04 12:58:41|C:\Windows\System32\ | |00400000|richedit.exe |RichEdit VCL Demo |1.0.0.0 |2531840 |2012-05-31 15:58:45|C:\Users\Alexander\Documents\RAD Studio\Projects\RichEdit\ | |73D10000|davhlpr.dll |DAV Helper DLL |6.1.7600.16385 |19456 |2009-07-14 05:15:08|C:\Windows\System32\ | |775F0000|ntdll.dll |NT Layer DLL |6.1.7601.17725 |1292080 |2011-11-17 09:38:39|C:\Windows\SysWOW64\ | |698F0000|ieframe.dll |Internet Browser |9.0.8112.16443 |9705984 |2012-02-28 05:27:13|C:\Windows\System32\ | |74F50000|kernel32.dll |Windows NT BASE API Client DLL |6.1.7601.17651 |1114112 |2011-07-16 08:24:22|C:\Windows\SysWOW64\ | |7C340000|msvcr71.dll |Microsoft® C Runtime Library |7.10.3052.4 |348160 |2006-01-11 19:23:34|C:\Windows\System32\ | |763C0000|KERNELBASE.dll |Windows NT BASE API Client DLL |6.1.7601.17651 |272384 |2011-07-16 08:24:22|C:\Windows\SysWOW64\ | |72D00000|RpcRtRemote.dll |Remote RPC Extension |6.1.7601.17514 |46080 |2010-11-20 05:21:04|C:\Windows\System32\ | |76BE0000|oleaut32.dll | |6.1.7601.17676 |571904 |2011-08-27 08:26:27|C:\Windows\SysWOW64\ | |72D50000|netutils.dll |Net Win32 API Helpers DLL |6.1.7601.17514 |22528 |2010-11-20 05:20:30|C:\Windows\System32\ | |766F0000|ole32.dll |Microsoft OLE for Windows |6.1.7601.17514 |1414144 |2010-11-20 05:20:50|C:\Windows\SysWOW64\ | |753F0000|msasn1.dll |ASN.1 Runtime APIs |6.1.7601.17514 |34304 |2010-11-20 05:19:46|C:\Windows\SysWOW64\ | |74E90000|msvcrt.dll |Windows NT CRT DLL |7.0.7601.17744 |690688 |2011-12-16 11:52:58|C:\Windows\SysWOW64\ | |71980000|msvcp90.dll |Microsoft® C++ Runtime Library |9.0.30729.6161 |569680 |2011-06-15 01:34:51|C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\ | |75060000|gdi32.dll |GDI Client DLL |6.1.7601.17514 |311296 |2010-11-20 05:08:52|C:\Windows\SysWOW64\ | |70DF0000|msls31.dll |Microsoft Line Services library file |3.10.349.0 |161792 |2011-04-17 20:21:54|C:\Windows\System32\ | |74D30000|user32.dll |Multi-User Windows USER API Client DLL |6.1.7601.17514 |833024 |2010-11-20 05:08:58|C:\Windows\SysWOW64\ | |65C80000|ieproxy.dll |IE ActiveX Interface Marshaling Library |9.0.8112.16421 |193536 |2011-04-17 20:21:54|C:\Program Files (x86)\Internet Explorer\ | |761E0000|advapi32.dll |Advanced Windows 32 Base API |6.1.7601.17514 |640512 |2010-11-20 05:18:04|C:\Windows\SysWOW64\ | |623B0000|fundisc.dll |Function Discovery Dll |6.1.7600.16385 |167424 |2009-07-14 05:15:21|C:\Windows\SysWOW64\ | |75560000|sechost.dll |Host for SCM/SDDL/LSA Lookup APIs |6.1.7600.16385 |92160 |2009-07-14 05:16:13|C:\Windows\SysWOW64\ | |73D20000|drprov.dll |Microsoft Remote Desktop Session Host Server Network Provider|6.1.7600.16385 |18944 |2009-07-14 05:15:13|C:\Windows\System32\ | |76530000|rpcrt4.dll |Remote Procedure Call Runtime |6.1.7601.17514 |663040 |2010-11-20 05:08:58|C:\Windows\SysWOW64\ | |61890000|zipfldr.dll |Compressed (zipped) Folders |6.1.7601.17514 |327680 |2010-11-20 05:21:42|C:\Windows\System32\ | |74CD0000|sspicli.dll |Security Support Provider Interface |6.1.7601.17725 |96768 |2011-11-17 09:28:48|C:\Windows\SysWOW64\ | |65250000|EhStorAPI.dll |Windows Enhanced Storage API |6.1.7601.17514 |128512 |2010-11-20 05:18:40|C:\Windows\System32\ | |74CC0000|CRYPTBASE.dll |Base cryptographic API DLL |6.1.7600.16385 |36864 |2009-07-14 05:15:07|C:\Windows\SysWOW64\ | |731D0000|GROOVEEX.DLL |Microsoft SharePoint Workspace Extensions |14.0.6106.5000 |4221328 |2011-06-12 11:15:00|C:\Program Files (x86)\Microsoft Office\Office14\ | |74F40000|lpk.dll |Language Pack |6.1.7600.16385 |25600 |2009-07-14 05:11:23|C:\Windows\SysWOW64\ | |6F0A0000|OFFICE.ODF | |14.0.6024.1000 |4297568 |2011-03-17 00:11:16|C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\ | |76850000|usp10.dll |Uniscribe Unicode script processor |1.626.7601.17514 |626176 |2010-11-20 05:21:34|C:\Windows\SysWOW64\ | |71F30000|cscapi.dll |Offline Files Win32 API |6.1.7601.17514 |34816 |2010-11-20 05:18:26|C:\Windows\System32\ | |73E70000|msimg32.dll |GDIEXT Client DLL |6.1.7600.16385 |4608 |2009-07-14 05:15:44|C:\Windows\System32\ | |72A60000|cryptsp.dll |Cryptographic Service Provider API |6.1.7600.16385 |78848 |2009-07-14 05:15:07|C:\Windows\System32\ | |74BA0000|version.dll |Version Checking and File Installation Libraries |6.1.7600.16385 |21504 |2009-07-14 05:16:17|C:\Windows\System32\ | |72DE0000|secur32.dll |Security Support Provider Interface |6.1.7601.17725 |22016 |2011-11-17 09:34:52|C:\Windows\System32\ | |75580000|shell32.dll |Windows Shell Common Dll |6.1.7601.17755 |12872704|2012-01-04 12:59:38|C:\Windows\SysWOW64\ | |618F0000|SearchFolder.dll |SearchFolder |6.1.7601.17514 |646144 |2010-11-20 05:21:08|C:\Windows\System32\ | |754D0000|shlwapi.dll |Shell Light-weight Utility Library |6.1.7601.17514 |350208 |2010-11-20 05:21:20|C:\Windows\SysWOW64\ | |768F0000|iertutil.dll |Run time utility for Internet Explorer |9.0.8112.16443 |1792000 |2012-02-28 05:04:32|C:\Windows\SysWOW64\ | |71F80000|comctl32.dll |User Experience Controls Library |6.10.7601.17514 |1680896 |2010-11-20 04:55:10|C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\| |68CB0000|fdProxy.dll |Function Discovery Proxy Dll |6.1.7600.16385 |27136 |2009-07-14 05:15:20|C:\Windows\SysWOW64\ | |74B40000|winspool.drv |Windows Spooler Driver |6.1.7601.17514 |320000 |2010-11-20 05:16:52|C:\Windows\System32\ | |72920000|winmm.dll |MCI API DLL |6.1.7601.17514 |194048 |2010-11-20 05:21:38|C:\Windows\System32\ | |76670000|comdlg32.dll |Common Dialogs DLL |6.1.7601.17514 |485888 |2010-11-20 05:18:24|C:\Windows\SysWOW64\ | |72C40000|ntlanman.dll |Microsoft® Lan Manager |6.1.7601.17514 |69120 |2010-11-20 05:20:48|C:\Windows\System32\ | |72960000|apphelp.dll |Application Compatibility Client Library |6.1.7601.17514 |295936 |2010-11-20 05:18:04|C:\Windows\System32\ | |5C450000|wpdshext.dll |Portable Devices Shell Extension |6.1.7601.17514 |2311168 |2010-11-20 05:21:40|C:\Windows\System32\ | |706C0000|AcLayers.dll |Windows Compatibility DLL |6.1.7601.17514 |562176 |2010-11-20 05:18:02|C:\Windows\AppPatch\ | |750F0000|wintrust.dll |Microsoft Trust Verification APIs |6.1.7601.17787 |172544 |2012-03-01 09:37:41|C:\Windows\SysWOW64\ | |74A30000|userenv.dll |Userenv |6.1.7601.17514 |81920 |2010-11-20 05:21:34|C:\Windows\System32\ | |5E340000|WMVCORE.DLL |Windows Media Playback/Authoring DLL |12.0.7601.17514 |2504192 |2010-11-20 05:20:58|C:\Windows\System32\ | |74A20000|profapi.dll |User Profile Basic API |6.1.7600.16385 |31744 |2009-07-14 05:16:12|C:\Windows\System32\ | |7C3A0000|msvcp71.dll |Microsoft® C++ Runtime Library |7.10.3077.0 |499712 |2010-12-16 22:38:04|C:\Windows\System32\ | |73DB0000|mpr.dll |Multiple Provider Router DLL |6.1.7600.16385 |64000 |2009-07-14 05:15:41|C:\Windows\System32\ | |70160000|EhStorShell.dll |Windows Enhanced Storage Shell Extension DLL |6.1.7600.16385 |189952 |2009-07-14 05:15:14|C:\Windows\System32\ | |76AB0000|imm32.dll |Multi-User Windows IMM32 API Client DLL |6.1.7601.17514 |119808 |2010-11-20 05:08:52|C:\Windows\System32\ | |72420000|msvcr90.dll |Microsoft® C Runtime Library |9.0.30729.6161 |653136 |2011-06-15 01:34:51|C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\ | |75400000|msctf.dll |MSCTF Server DLL |6.1.7600.16385 |828928 |2009-07-14 05:15:43|C:\Windows\SysWOW64\ | |73E30000|ATL90.dll |ATL Module for Windows (Unicode) |9.0.30729.6161 |159048 |2011-06-15 01:34:37|C:\Windows\winsxs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.6161_none_51cd0a7abbe4e19b\ | |72790000|uxtheme.dll |Microsoft UxTheme Library |6.1.7600.16385 |245760 |2009-07-14 05:11:24|C:\Windows\System32\ | |6E830000|GrooveIntlResource.dll| |14.0.6009.1000 |8801120 |2010-10-20 15:45:26|C:\Program Files (x86)\Microsoft Office\Office14\1033\ | |72400000|dwmapi.dll |Microsoft Desktop Window Manager API |6.1.7600.16385 |67072 |2009-07-14 05:15:13|C:\Windows\System32\ | |72D30000|srvcli.dll |Server Service Client DLL |6.1.7601.17514 |90112 |2010-11-20 05:21:28|C:\Windows\System32\ | |61BB0000|dbghelp.dll |Windows Image Helper |6.12.2.633 |1213200 |2011-02-21 10:39:28|C:\Program Files (x86)\EurekaLab\EurekaLog 7\Bin\ | |70230000|slc.dll |Software Licensing Client Dll |6.1.7600.16385 |27136 |2009-07-14 05:16:15|C:\Windows\System32\ | |65E60000|symsrv.dll |Symbol Server |6.12.2.633 |131856 |2011-02-21 10:39:28|C:\Program Files (x86)\EurekaLab\EurekaLog 7\Bin\ | |70200000|xmllite.dll |Microsoft XmlLite Library |1.3.1001.0 |180224 |2011-06-16 08:33:18|C:\Windows\System32\ | |72AA0000|IPHLPAPI.DLL |IP Helper API |6.1.7601.17514 |103936 |2010-11-20 05:19:24|C:\Windows\System32\ | |72A20000|rsaenh.dll |Microsoft Enhanced Cryptographic Provider |6.1.7600.16385 |242936 |2009-07-14 05:17:54|C:\Windows\System32\ | |75120000|nsi.dll |NSI User-mode interface DLL |6.1.7600.16385 |8704 |2009-07-14 05:16:11|C:\Windows\SysWOW64\ | |65020000|StructuredQuery.dll |Structured Query |7.0.7601.17514 |363520 |2010-11-20 05:21:28|C:\Windows\System32\ | |72A90000|winnsi.dll |Network Store Information RPC interface |6.1.7600.16385 |16896 |2009-07-14 05:16:19|C:\Windows\System32\ | |70760000|actxprxy.dll |ActiveX Interface Marshaling Library |6.1.7601.17514 |309760 |2010-11-20 05:18:02|C:\Windows\SysWOW64\ | |72DA0000|dhcpcsvc.dll |DHCP Client Service |6.1.7600.16385 |61952 |2009-07-14 05:15:11|C:\Windows\System32\ | |65850000|thumbcache.dll |Microsoft Thumbnail Cache |6.1.7601.17514 |82944 |2010-11-20 05:21:32|C:\Windows\SysWOW64\ | |76BA0000|ws2_32.dll |Windows Socket 2.0 32-Bit DLL |6.1.7601.17514 |206848 |2010-11-20 05:21:40|C:\Windows\SysWOW64\ | |72F30000|shdocvw.dll |Shell Doc Object and Control Library |6.1.7601.17514 |179712 |2010-11-20 05:21:16|C:\Windows\System32\ | |735E0000|dnsapi.dll |DNS Client API DLL |6.1.7601.17570 |270336 |2011-03-03 09:38:01|C:\Windows\System32\ | |73D70000|oleacc.dll |Active Accessibility Core Component |7.0.0.0 |233472 |2011-08-27 08:26:27|C:\Windows\System32\ | |73B30000|dhcpcsvc6.DLL |DHCPv6 Client |6.1.7600.16385 |43008 |2009-07-14 05:15:11|C:\Windows\System32\ | |738F0000|IconCodecService.dll |Converts a PNG part of the icon to a legacy bmp icon |6.1.7600.16385 |9728 |2009-07-14 05:15:27|C:\Windows\System32\ | |761D0000|psapi.dll |Process Status Helper |6.1.7600.16385 |6144 |2009-07-14 05:16:12|C:\Windows\SysWOW64\ | |6E7D0000|atl.dll |ATL Module for Windows XP (Unicode) |3.5.2284.0 |70144 |2009-07-14 05:14:57|C:\Windows\SysWOW64\ | |736C0000|riched20.dll |Rich Text Edit Control, v3.1 |5.31.23.1230 |473600 |2010-11-20 05:21:04|C:\Windows\System32\ | |62450000|provsvc.dll |Windows HomeGroup |6.1.7601.17514 |165376 |2010-11-20 05:20:58|C:\Windows\System32\ | |76B10000|clbcatq.dll |COM+ Configuration Catalog |2001.12.8530.16385|522240 |2009-07-14 05:15:03|C:\Windows\SysWOW64\ | |73EB0000|linkinfo.dll |Windows Volume Tracking |6.1.7600.16385 |22016 |2009-07-14 05:15:36|C:\Windows\System32\ | |75130000|setupapi.dll |Windows Setup API |6.1.7601.17514 |1667584 |2010-11-20 05:21:16|C:\Windows\SysWOW64\ | |5E5B0000|NetworkExplorer.dll |Network Explorer |6.1.7601.17514 |1661440 |2010-11-20 05:20:30|C:\Windows\System32\ | |75530000|cfgmgr32.dll |Configuration Manager DLL |6.1.7601.17621 |145920 |2011-05-24 14:39:38|C:\Windows\SysWOW64\ | |744E0000|winsta.dll |Winstation Library |6.1.7601.17514 |156672 |2010-11-20 05:21:38|C:\Windows\System32\ | |76280000|devobj.dll |Device Information Set DLL |6.1.7601.17621 |64512 |2011-05-24 14:40:05|C:\Windows\SysWOW64\ | |72AE0000|davclnt.dll |Web DAV Client DLL |6.1.7601.17514 |80384 |2010-11-20 05:18:28|C:\Windows\System32\ | |72120000|propsys.dll |Microsoft Property System |7.0.7601.17514 |988160 |2010-11-20 05:20:58|C:\Windows\System32\ | |72D20000|wkscli.dll |Workstation Service Client DLL |6.1.7601.17514 |47104 |2010-11-20 05:21:38|C:\Windows\System32\ | |74B10000|ntmarta.dll |Windows NT MARTA provider |6.1.7600.16385 |121856 |2009-07-14 05:16:11|C:\Windows\System32\ | |73740000|GdiPlus.dll |Microsoft GDI+ |6.1.7601.17825 |1625088 |2012-04-21 08:21:01|C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\ | |76620000|Wldap32.dll |Win32 LDAP API DLL |6.1.7601.17514 |269824 |2010-11-20 05:21:38|C:\Windows\SysWOW64\ | |650B0000|PortableDeviceApi.dll |Windows Portable Device API Components |6.1.7601.17514 |547840 |2010-11-20 05:20:56|C:\Windows\System32\ | |6FB10000|explorerframe.dll |ExplorerFrame |6.1.7601.17514 |1493504 |2010-11-20 05:19:02|C:\Windows\System32\ | |76410000|crypt32.dll |Crypto API32 |6.1.7601.17514 |1154048 |2010-11-20 05:18:26|C:\Windows\SysWOW64\ | |6F520000|duser.dll |Windows DirectUser Engine |6.1.7600.16385 |181248 |2009-07-14 05:15:13|C:\Windows\System32\ | |619A0000|audiodev.dll |Portable Media Devices Shell Extension |6.1.7601.17514 |243712 |2010-11-20 05:18:06|C:\Windows\System32\ | |6E580000|dui70.dll |Windows DirectUI Engine |6.1.7600.16385 |717824 |2009-07-14 05:15:13|C:\Windows\System32\ | |61750000|WMASF.DLL |Windows Media ASF DLL |12.0.7600.16385 |237568 |2009-07-14 05:16:19|C:\Windows\System32\ | |724D0000|WindowsCodecs.dll |Microsoft Windows Codecs Library |6.1.7601.17514 |1010688 |2010-11-20 05:21:38|C:\Windows\System32\ | |10000000|DropboxExt.14.dll |Dropbox Shell Extension |1.0.0.14 |94208 |2011-02-18 09:12:20|C:\Users\Alexander\AppData\Roaming\Dropbox\bin\ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Processes Information: ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |ID |Name |Description |Version |Memory |Priority |Threads|Path | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |0 |[System Process] | | |0 | |2 | | |4 |System | | |0 |Normal |163 | | |372 |SeaPort.EXE | | |0 |Normal |8 | | |384 |svchost.exe | | |0 |Normal |9 | | |404 |smss.exe | | |0 |Above-Normal|3 | | |604 |csrss.exe | | |0 |High |10 | | |624 |MsMpEng.exe | | |0 |Normal |24 | | |656 |fbguard.exe | | |0 |Normal |5 | | |664 |csrss.exe | | |0 |High |14 | | |672 |psxss.exe | | |0 |High |18 | | |696 |wininit.exe | | |0 |High |3 | | |724 |winlogon.exe | | |0 |High |3 | | |744 |tv_x64.exe | | |0 |Normal |2 | | |780 |services.exe | | |0 |Normal |8 | | |788 |lsass.exe | | |0 |Normal |11 | | |796 |lsm.exe | | |0 |Normal |12 | | |816 |chrome.exe |Google Chrome |19.0.1084.52 |17272832 |Normal |7 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |836 |caller64.exe | |1.1.0.0 |1482752 |Normal |1 |C:\Windows\Samsung\PanelMgr\ | |856 |dpupdchk.exe |dpupdchk.exe |8.20.469.0 |2842624 |Normal |1 |C:\Program Files\Microsoft IntelliType Pro\ | |904 |svchost.exe | | |0 |Normal |11 | | |968 |nvvsvc.exe | | |0 |Normal |5 | | |992 |nvSCPAPISvr.exe | | |0 |Normal |6 | | |1040|msseces.exe |Microsoft Security Client User Interface |4.0.1526.0 |3866624 |Normal |5 |C:\Program Files\Microsoft Security Client\ | |1044|svchost.exe | | |0 |Normal |23 | | |1084|svchost.exe | | |0 |Normal |33 | | |1108|svchost.exe | | |0 |Normal |64 | | |1180|TSVNCache.exe |TortoiseSVN status cache |1.6.16.21511 |8249344 |Normal |12 |C:\Program Files\TortoiseSVN\bin\ | |1200|audiodg.exe | | |14843904 |Normal |6 |C:\Windows\System32\ | |1296|svchost.exe | | |0 |Normal |25 | | |1308|chrome.exe |Google Chrome |19.0.1084.52 |23748608 |Normal |8 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |1364|TeamViewer_Service.exe | | |0 |Normal |12 | | |1436|svchost.exe | | |0 |Normal |33 | | |1604|AsLdrSrv.exe | | |0 |Normal |4 | | |1612|nvxdsync.exe | | |0 |Normal |8 | | |1624|nvvsvc.exe | | |0 |Normal |5 | | |1664|GFNEXSrv.exe | | |0 |Normal |4 | | |1760|spoolsv.exe | | |0 |Normal |14 | | |1808|svchost.exe | | |0 |Normal |34 | | |1840|svchost.exe | | |0 |Normal |18 | | |1956|NetworkLicenseServer.exe| | |0 |Normal |13 | | |1972|PKIMonitor.exe |PKIMonitor Application |5.1.66.0 |16171008 |Normal |14 |C:\Program Files\Aladdin\eToken\PKIClient\x64\ | |1984|ipoint.exe |IPoint.exe |7.0.261.0 |10354688 |Normal |9 |C:\Program Files\Microsoft IntelliPoint\ | |2000|TeamViewer.exe |TeamViewer Remote Control Application |7.0.12313.0 |5414912 |Normal |8 |C:\Program Files (x86)\TeamViewer\Version7\ | |2028|itype.exe |IType.exe |8.20.469.0 |9019392 |Normal |9 |C:\Program Files\Microsoft IntelliType Pro\ | |2092|GoogleCrashHandler64.exe| | |0 |Low |3 | | |2112|armsvc.exe | | |0 |Normal |4 | | |2136|svchost.exe | | |0 |Normal |9 | | |2160|tv_w32.exe | | |0 |Normal |2 | | |2216|svchost.exe | | |0 |Normal |6 | | |2280|wmdc.exe |Windows Mobile Device Center |6.1.6965.0 |3137536 |Normal |5 |C:\Windows\WindowsMobile\ | |2320|IAStorIcon.exe |IAStorIcon |9.5.6.1002 |11468800 |Normal |14 |C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\| |2332|taskhost.exe | | |7270400 |Normal |9 |C:\Windows\System32\ | |2400|dwm.exe | | |64561152 |High |5 |C:\Windows\System32\ | |2416|taskeng.exe |Task Scheduler Engine |6.1.7601.17514 |21045248 |Normal |7 |C:\Windows\System32\ | |2472|Steam.exe |Steam |1.0.1065.11 |33140736 |Normal |48 |C:\Program Files (x86)\Steam\ | |2492|notepad++.exe |Notepad++ : a free (GNU) source code editor|5.9.0.0 |20131840 |Normal |3 |C:\Program Files (x86)\Notepad++\ | |2544|BatteryLife.exe |Power4Gear Hybrid |1.1.0.1 |540672 |Below-Normal|5 |C:\Program Files\P4G\ | |2552|ACMON.exe |ACMON |1.0.8.0 |3055616 |Below-Normal|5 |C:\Program Files (x86)\ASUS\Splendid\ | |2560|HControl.exe | | |0 |Normal |7 | | |2612|explorer.exe |Windows Explorer |6.1.7601.17567 |87769088 |Normal |41 |C:\Windows\ | |2648|DCHelper.exe |TODO: |1.0.0.1 |2338816 |Below-Normal|7 |C:\Program Files (x86)\ASUS\Direct Console\ | |2696|DMedia.exe |ATK Media |2.0.6.4 |1040384 |Normal |1 |C:\Program Files (x86)\ASUS\ATK Media\ | |2784|ATKOSD2.exe |ATKOSD2 |7.0.6.4 |1216512 |Normal |2 |C:\Program Files (x86)\ASUS\ATKOSD2\ | |2816|chrome.exe |Google Chrome |19.0.1084.52 |35930112 |Normal |8 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |2860|GoogleCrashHandler.exe | | |0 |Low |3 | | |2964|eTSrv.exe | | |0 |Normal |5 | | |2968|richedit.exe |RichEdit VCL Demo |1.0.0.0 |88051712 |Normal |16 |D:\RAD Studio\Projects\RichEdit\ | |3040|nvtray.exe |NVIDIA Settings |7.17.12.9573 |14438400 |Normal |4 |C:\Program Files\NVIDIA Corporation\Display\ | |3088|MSOSYNC.EXE |Microsoft Office Document Cache |14.0.6108.5000 |5955584 |Normal |12 |C:\Program Files\Microsoft Office\Office14\ | |3232|ibguard.exe | | |0 |Normal |6 | | |3244|GoogleCrashHandler.exe |Google Crash Handler |1.3.21.111 |872448 |Low |4 |C:\Users\Alexander\AppData\Local\Google\Update\1.3.21.111\ | |3260|WDBtnMgrUI.exe |WD Drive Manager |2.0.111.0 |5103616 |Normal |2 |C:\Program Files\Western Digital\WD Drive Manager\ | |3300|GoogleCrashHandler64.exe|Google Crash Handler |1.3.21.111 |462848 |Low |3 |C:\Users\Alexander\AppData\Local\Google\Update\1.3.21.111\ | |3320|mdm.exe | | |0 |Normal |5 | | |3332|Direct Console.exe |Direct Console 2.0 |2.0.0.9 |4575232 |Normal |7 |C:\Program Files (x86)\ASUS\Direct Console\ | |3344|WLIDSVCM.EXE | | |0 |Normal |3 | | |3364|Dropbox.exe |Dropbox |1.2.52.0 |11018240 |Normal |19 |C:\Users\Alexander\AppData\Roaming\Dropbox\bin\ | |3408|TeamViewer_Service.exe | | |0 |Normal |6 | | |3412|HControlUser.exe |HControlUser |1.0.50.1 |991232 |Normal |1 |C:\Program Files (x86)\ASUS\ATK Hotkey\ | |3436|SearchIndexer.exe | | |0 |Normal |14 | | |3448|PnkBstrA.exe | | |0 |Normal |6 | | |3496|ACEngSvr.exe |ACEngSvr Module |1.0.0.4 |1978368 |Normal |3 |C:\Windows\SysWOW64\ | |3564|PsiService_2.exe | | |0 |Normal |4 | | |3624|NetFaxServer64.exe | | |0 |Normal |6 | | |3632|EvernoteClipper.exe |Evernote Clipper |4.5.6.6884 |913408 |Normal |2 |C:\Program Files (x86)\Evernote\Evernote\ | |3668|bds.exe |Embarcadero RAD Studio for Windows |15.0.3953.35171|327593984|Normal |33 |C:\Program Files (x86)\Embarcadero\RAD Studio\8.0\bin\ | |3712|PDFCreator.exe |PDFCreator |1.2.0.0 |3866624 |Normal |3 |C:\Program Files (x86)\Common Files\PDFCreator\ | |3736|sqlwriter.exe | | |0 |Normal |4 | | |3892|ONENOTEM.EXE |Microsoft OneNote Quick Launcher |14.0.6015.1000 |1847296 |Normal |1 |C:\Program Files\Microsoft Office\Office14\ | |3908|svchost.exe | | |0 |Normal |6 | | |3964|SSMMgr.exe | |3.2.2.3 |2187264 |Normal |5 |C:\Windows\Samsung\PanelMgr\ | |4000|chrome.exe |Google Chrome |19.0.1084.52 |42598400 |Below-Normal|6 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |4012|StreamingCore.exe | | |0 |Normal |6 | | |4048|wmagent.exe | | |856064 |Normal |2 |C:\Program Files (x86)\WebMoney Agent\ | |4192|procexp.exe |Sysinternals Process Explorer |11.33.0.0 |483328 |Normal |1 |C:\Users\Alexander\AppData\Roaming\ | |4220|chrome.exe |Google Chrome |19.0.1084.52 |8052736 |Normal |4 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |4408|chrome.exe |Google Chrome |19.0.1084.52 |25006080 |Normal |7 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |4504|sidebar.exe |Windows Desktop Gadgets |6.1.7601.17514 |1585152 |Below-Normal|6 |C:\Program Files\Windows Sidebar\ | |4512|svchost.exe | | |0 |Normal |14 | | |4724|svchost.exe | | |0 |Normal |16 | | |4756|WDBtnMgrSvc.exe | | |0 |Normal |4 | | |4784|WLIDSVC.EXE | | |0 |Normal |12 | | |4960|chrome.exe |Google Chrome |19.0.1084.52 |108568576|Below-Normal|6 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |4996|WmiApSrv.exe | | |0 |Normal |4 | | |5020|chrome.exe |Google Chrome |19.0.1084.52 |82173952 |Below-Normal|6 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |5108|EvernoteTray.exe |Evernote Tray Application |4.5.6.6884 |843776 |Normal |2 |C:\Program Files (x86)\Evernote\Evernote\ | |5188|winamp.exe |Winamp |5.5.7.2792 |34705408 |Normal |16 |C:\Program Files (x86)\Winamp\ | |5192|chrome.exe |Google Chrome |19.0.1084.52 |30658560 |Normal |8 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |5228|WmiPrvSE.exe | | |0 |Normal |7 | | |5448|uTorrent.exe |µTorrent |3.1.3.27220 |49238016 |Normal |19 |C:\Program Files (x86)\uTorrent\ | |5472|chrome.exe |Google Chrome |19.0.1084.52 |38338560 |Normal |8 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |5536|Skype.exe |Skype |5.8.66.158 |109662208|Normal |41 |C:\Program Files (x86)\Skype\Phone\ | |5608|chrome.exe |Google Chrome |19.0.1084.52 |18460672 |Normal |7 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |5612|chrome.exe |Google Chrome |19.0.1084.52 |15806464 |Normal |7 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |5624|chrome.exe |Google Chrome |19.0.1084.52 |22073344 |Normal |7 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |5824|chrome.exe |Google Chrome |19.0.1084.52 |13959168 |Normal |5 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |5852|chrome.exe |Google Chrome |19.0.1084.52 |50319360 |Normal |6 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |5936|chrome.exe |Google Chrome |19.0.1084.52 |300457984|Normal |34 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |6064|taskhost.exe | | |3907584 |Normal |5 |C:\Windows\System32\ | |6272|mysqld-nt.exe | | |0 |Normal |15 | | |6296|chrome.exe |Google Chrome |19.0.1084.52 |27406336 |Normal |6 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |6420|spmgr.exe | | |0 |Normal |9 | | |6520|ibserver.exe | | |0 |Normal |7 | | |6596|fbserver.exe | | |0 |Normal |7 | | |6680|chrome.exe |Google Chrome |19.0.1084.52 |23121920 |Normal |7 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |6692|PROCEXP64.exe |Sysinternals Process Explorer |11.33.0.0 |39178240 |High |4 |C:\Users\Alexander\AppData\Roaming\ | |7040|svchost.exe | | |0 |Normal |5 | | |7100|dllhost.exe | | |0 |Normal |5 | | |7140|chrome.exe |Google Chrome |19.0.1084.52 |30244864 |Normal |7 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |7232|ielowutil.exe |Internet Low-Mic Utility Tool |9.0.8112.16421 |540672 |Below-Normal|3 |C:\Program Files (x86)\Internet Explorer\ | |7296|chrome.exe |Google Chrome |19.0.1084.52 |47017984 |Below-Normal|6 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |7336|SteamService.exe | | |0 |Normal |4 | | |7492|WmiPrvSE.exe | | |0 |Normal |5 | | |7520|svchost.exe | | |0 |Normal |10 | | |7592|WmiPrvSE.exe | | |0 |Normal |14 | | |7736|qip.exe |QIP 2012 |4.0.0.7221 |199561216|Normal |69 |C:\Program Files (x86)\QIP 2010\ | |7812|ATKOSD.exe | | |0 |Normal |1 | | |7948|wmpnetwk.exe | | |0 |Normal |14 | | |7972|svchost.exe | | |0 |Below-Normal|4 | | |8044|KBFiltr.exe | | |0 |Normal |2 | | |8068|WDC.exe | | |0 |Normal |1 | | |8156|chrome.exe |Google Chrome |19.0.1084.52 |52989952 |Normal |6 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |8176|TOTALCMD.EXE |Total Commander 32 bit |8.0.0.0 |23891968 |Normal |7 |C:\Program Files\Total Commander\ | |8232|rundll32.exe |Windows host process (Rundll32) |6.1.7600.16385 |7073792 |Normal |2 |C:\Windows\SysWOW64\ | |8284|Evernote.exe |Evernote |4.5.6.6884 |9834496 |Normal |16 |C:\Program Files (x86)\Evernote\Evernote\ | |8312|chrome.exe |Google Chrome |19.0.1084.52 |25440256 |Normal |7 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |8408|Origin.exe |Origin |8.6.0.357 |59555840 |Normal |27 |C:\Program Files (x86)\Origin\ | |8560|chrome.exe |Google Chrome |19.0.1084.52 |53370880 |Below-Normal|6 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |8660|PnkBstrB.exe | | |0 |Normal |4 | | |8856|chrome.exe |Google Chrome |19.0.1084.52 |46436352 |Below-Normal|6 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |9056|chrome.exe |Google Chrome |19.0.1084.52 |7974912 |Normal |5 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |9252|chrome.exe |Google Chrome |19.0.1084.52 |51585024 |Below-Normal|6 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |9392|chrome.exe |Google Chrome |19.0.1084.52 |68755456 |Below-Normal|6 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |9516|taskeng.exe | | |0 |Below-Normal|6 | | |9564|KeePass.exe |KeePass |2.1.7.0 |67198976 |Normal |9 |C:\Program Files (x86)\KeePass Password Safe 2\ | |9720|chrome.exe |Google Chrome |19.0.1084.52 |19288064 |Normal |8 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |9764|chrome.exe |Google Chrome |19.0.1084.52 |20615168 |Normal |7 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |9824|chrome.exe |Google Chrome |19.0.1084.52 |18714624 |Normal |8 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | |9920|chrome.exe |Google Chrome |19.0.1084.52 |28585984 |Normal |11 |C:\Users\Alexander\AppData\Local\Google\Chrome\Application\ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ Assembler Information: ----------------------------------------------------------------------------------------------------------------- ; remain.Enumer (Line=214 - Offset=3) ; ----------------------------------- 005E9EFF push ebx ; ; Line=214 - Offset=4 ; ------------------- 005E9F00 push esi ; ; Line=214 - Offset=5 ; ------------------- 005E9F01 push edi ; ; Line=215 - Offset=6 ; ------------------- 005E9F02 xor eax, eax ; ; Line=215 - Offset=8 ; ------------------- 005E9F04 push ebp ; ; Line=215 - Offset=9 ; ------------------- 005E9F05 push $005E9F20 ; ; Line=215 - Offset=14 ; -------------------- 005E9F0A push dword ptr fs:[eax] ; ; Line=215 - Offset=17 ; -------------------- 005E9F0D mov fs:[eax], esp ; ; Line=216 - Offset=20 ; -------------------- 005E9F10 xor eax, eax ; ; Line=216 - Offset=22 ; -------------------- 005E9F12 xor edx, edx ; ; Line=216 - Offset=24 ; -------------------- 005E9F14 mov [eax], edx ; <-- EXCEPTION ; ; Line=216 - Offset=26 ; -------------------- 005E9F16 xor eax, eax ; ; Line=216 - Offset=28 ; -------------------- 005E9F18 pop edx ; ; Line=216 - Offset=29 ; -------------------- 005E9F19 pop ecx ; ; Line=216 - Offset=30 ; -------------------- 005E9F1A pop ecx ; ; Line=216 - Offset=31 ; -------------------- 005E9F1B mov fs:[eax], edx ; ; Line=216 - Offset=34 ; -------------------- 005E9F1E jmp remain.Enumer (Line=220) ; ; Line=216 - Offset=36 ; -------------------- 005E9F20 jmp System._HandleAnyException ; ; Line=218 - Offset=41 ; -------------------- 005E9F25 mov eax, dword ptr [$5FF5A0] ; ; Line=218 - Offset=46 ; -------------------- 005E9F2A mov eax, [eax] ; ; Line=218 - Offset=48 ; -------------------- 005E9F2C xor edx, edx Registers: ----------------------------- EAX: 00000000 EDI: 00000577 EBX: 00000000 ESI: 07C55FE8 ECX: BFB00000 EBP: 0018FAFC EDX: 00000000 ESP: 0018FAE4 EIP: 005E9F14 FLG: 00010246 EXP: 005E9F14 STK: 0018F640 Stack: Memory Dump: ------------------ --------------------------------------------------------------------------- 0018FB20: 0018F7AC 005E9F14: 89 10 33 C0 5A 59 59 64 89 10 EB 18 E9 3B C3 E1 ..3.ZYYd.....;.. 0018FB1C: 0018F7FC 005E9F24: FF A1 A0 F5 5F 00 8B 00 33 D2 E8 61 BC FE FF E8 ...._...3..a.... 0018FB18: 00C2F9E8 005E9F34: 80 C7 E1 FF 33 C0 5F 5E 5B 5D C2 08 00 8D 40 00 ....3._^[]....@. 0018FB14: 00000000 005E9F44: 55 8B EC 6A 00 68 FC 9E 5E 00 E8 AD 33 E2 FF 5D U..j.h..^...3..] 0018FB10: 00000001 005E9F54: C3 8D 40 00 55 8B EC 83 C4 E4 53 56 33 C9 89 4D ..@.U.....SV3..M 0018FB0C: 005DDB52 005E9F64: FC 89 4D E8 89 4D E4 8B F2 8B D8 33 C0 55 68 05 ..M..M.....3.Uh. 0018FB08: 0018F684 005E9F74: A0 5E 00 64 FF 30 64 89 20 8D 83 9C 04 00 00 8B .^.d.0d. ....... 0018FB04: 0018F7FC 005E9F84: D6 E8 62 D3 E1 FF 8D 45 FC 50 8D 55 E8 8B C6 E8 ..b....E.P.U.... 0018FB00: 0018F7FC 005E9F94: F0 BD E4 FF 8B 45 E8 89 45 EC C6 45 F0 11 8D 55 .....E..E..E...U 0018FAFC: 0018F7AC 005E9FA4: E4 A1 A0 F5 5F 00 8B 00 E8 1B B2 FE FF 8B 45 E4 ...._.........E. 0018FAF8: 00000001 005E9FB4: 89 45 F4 C6 45 F8 11 8D 55 EC B9 01 00 00 00 B8 .E..E...U....... 0018FAF4: 021A57F8 005E9FC4: 20 A0 5E 00 E8 6B C6 E4 FF 8B 55 FC 8B C3 E8 01 .^..k....U..... 0018FAF0: 0018F7AC 005E9FD4: F6 F7 FF 85 F6 74 07 8B C3 E8 62 FF FF FF 33 C0 .....t....b...3. 0018FAEC: 00000001 005E9FE4: 5A 59 59 64 89 10 68 0C A0 5E 00 8D 45 E4 BA 02 ZYYd..h..^..E... 0018FAE8: 005DEB6A 005E9FF4: 00 00 00 E8 70 CF E1 FF 8D 45 FC E8 08 CF E1 FF ....p....E...... 0018FAE4: 0018F664 005EA004: C3 E9 0A C5 E1 FF EB E3 5E 5B 8B E5 5D C3 00 00 ........^[..]...