Sei sulla pagina 1di 5

date/time : 2015-01-10, 21:31:27, 848ms

computer name : CARISTA


user name : user pc <admin>
registered owner : user pc
operating system : Windows NT New x64 build 9200
system language : Indonesian
system up time : 7 minutes 10 seconds
program up time : 141 milliseconds
processors : 2x Intel(R) Celeron(R) CPU N2830 @ 2.16GHz
physical memory : 745/1934 MB (free/total)
free disk space : (C:) 96,93 GB (D:) 90,87 GB
display mode : 1366x768, 32 bit
process id : $f4
allocated memory : 30,36 MB
executable : Adventure-Patcher.exe
exec. date/time : 2015-01-10 16:15
version : 2.6.1.66
compiled with : Delphi 2010
madExcept version : 3.0l
callstack crc : $929b4c78, $45747216, $b33b1ea7
exception number : 1
exception class : EPNGInvalidFileHeader
exception message : The file being readed is not a valid "Portable Network Graph
ics" image because it contains an invalid header. This file may be corruped, try
obtaining it again.
main thread ($c08):
005781c4 +02c Adventure-Patcher.exe pngimage TPngImage.RaiseError
00578e6e +06e Adventure-Patcher.exe pngimage TPngImage.LoadFromSt
ream
0060a0b1 +199 Adventure-Patcher.exe ThorProgressbar 202 +31 TThorProgressbar.Ren
der
0060a1ce +02a Adventure-Patcher.exe ThorProgressbar 220 +6 TThorProgressbar.Set
BackImage
006046c5 +11d Adventure-Patcher.exe GUIManager 88 +14 TGUIManager.MakeProg
ressBar
00604cb0 +068 Adventure-Patcher.exe GUIManager 152 +7 TGUIManager.Create
0060af0b +11b Adventure-Patcher.exe Main 150 +20 TMainFrm.FormCreate
00513929 +031 Adventure-Patcher.exe Forms TCustomForm.DoCreate
00513565 +011 Adventure-Patcher.exe Forms TCustomForm.AfterCon
struction
004059e1 +01d Adventure-Patcher.exe System 985 +0 @AfterConstruction
0051353b +18f Adventure-Patcher.exe Forms TCustomForm.Create
0051dd5e +076 Adventure-Patcher.exe Forms TApplication.CreateF
orm
00618cb3 +32f Adventure-Patcher.exe Thor 232 +68 initialization
775b8541 +00c KERNEL32.DLL BaseThreadInitThunk
thread $1090 (TEventThread):
774e11f2 +4d KERNELBASE.dll SleepEx
774e1197 +0a KERNELBASE.dll Sleep
00566951 +4d Adventure-Patcher.exe EventThread 44 +15 TEventThread.Run
005564d8 +f0 Adventure-Patcher.exe IdThread 351 +38 TIdThread.Execute
0046474f +2b Adventure-Patcher.exe madExcept HookedTThreadExecute
0049d0e6 +42 Adventure-Patcher.exe Classes ThreadProc
00406770 +28 Adventure-Patcher.exe System 985 +0 ThreadWrapper
00464631 +0d Adventure-Patcher.exe madExcept CallThreadProcSafe
0046469b +37 Adventure-Patcher.exe madExcept ThreadExceptFrame
775b8541 +0c KERNEL32.DLL BaseThreadInitThunk
>> created by main thread ($c08) at:
005566da +52 Adventure-Patcher.exe IdThread 418 +20 TIdThread.Create
thread $12e4 (TMainWorker): <suspended>
00603ffa +32 Adventure-Patcher.exe MainWorker 167 +4 TMainWorker.Create
modules:
00400000 Adventure-Patcher.exe 2.6.1.66 D:\Ragnarok\adventure
736b0000 olepro32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
736d0000 wsock32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
736e0000 msimg32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
73d50000 dwmapi.dll 6.2.9200.16384 C:\Windows\SYSTEM32
73d70000 uxtheme.dll 6.2.9200.16384 C:\Windows\system32
73ed0000 comctl32.dll 6.10.9200.16384 C:\Windows\WinSxS\x86_microsoft.w
indows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985
74ad0000 apphelp.dll 6.2.9200.16384 C:\Windows\system32
75110000 SHCORE.DLL 6.2.9200.16384 C:\Windows\SYSTEM32
752a0000 version.dll 6.2.9200.16384 C:\Windows\SYSTEM32
752b0000 winspool.drv 6.2.9200.16384 C:\Windows\SYSTEM32
753d0000 bcryptPrimitives.dll 6.2.9200.16384 C:\Windows\SYSTEM32
75430000 CRYPTBASE.dll 6.2.9200.16384 C:\Windows\SYSTEM32
75440000 SspiCli.dll 6.2.9200.16384 C:\Windows\SYSTEM32
75460000 MSCTF.dll 6.2.9200.16384 C:\Windows\SYSTEM32
758f0000 IMM32.DLL 6.2.9200.16384 C:\Windows\system32
75a80000 gdi32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
75b80000 user32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
75ca0000 NSI.dll 6.2.9200.16384 C:\Windows\SYSTEM32
75cc0000 advapi32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
75d70000 RPCRT4.dll 6.2.9200.16384 C:\Windows\SYSTEM32
75e20000 shell32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
76ef0000 msvcrt.dll 7.0.9200.16384 C:\Windows\SYSTEM32
771f0000 WS2_32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
77240000 ole32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
77360000 combase.dll 6.2.9200.16384 C:\Windows\SYSTEM32
774a0000 SHLWAPI.dll 6.2.9200.16384 C:\Windows\SYSTEM32
774e0000 KERNELBASE.dll 6.2.9200.16384 C:\Windows\SYSTEM32
77590000 KERNEL32.DLL 6.2.9200.16384 C:\Windows\SYSTEM32
776c0000 sechost.dll 6.2.9200.16384 C:\Windows\SYSTEM32
779a0000 oleaut32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
77bf0000 comdlg32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
77da0000 ntdll.dll 6.2.9200.16384 C:\Windows\SYSTEM32
processes:
0000 Idle 0 0 0
0004 System 0 0 0
0134 smss.exe 0 0 0
01b0 csrss.exe 0 0 0
01ec wininit.exe 0 0 0
01fc csrss.exe 1 0 0
0228 winlogon.exe 1 0 0
0254 services.exe 0 0 0
025c lsass.exe 0 0 0
02b8 svchost.exe 0 0 0
02e0 PCFasterSvc.exe 0 0 0
0354 svchost.exe 0 0 0
03d8 svchost.exe 0 0 0
01ac svchost.exe 0 0 0
01c4 dwm.exe 1 0 0
018c svchost.exe 0 0 0
037c igfxCUIService.exe 0 0 0
0378 svchost.exe 0 0 0
0484 svchost.exe 0 0 0
04ec bassvc.exe 0 0 0
0584 spoolsv.exe 0 0 0
05a0 svchost.exe 0 0 0
0630 dasHost.exe 0 0 0
0660 ekrn.exe 0 0 0
0680 taskhostex.exe 1 13 18 normal
0710 sqlservr.exe 0 0 0
0728 explorer.exe 1 857 538 normal
0690 StartManSvc.exe 0 0 0
0650 PSIService.exe 0 0 0
0820 sparkservice.exe 0 0 0
0870 sqlwriter.exe 0 0 0
08a8 svchost.exe 0 0 0
0918 TeamViewer_Service.exe 0 0 0
0950 tvnserver.exe 0 0 0
0b04 WmiPrvSE.exe 0 0 0
0698 SearchIndexer.exe 0 0 0
0844 bastray.exe 1 27 22 normal C:\Program Files (x86)\Bai
du Security\MoboMarket\1.3.2.4623
0880 svchost.exe 0 0 0
06c8 PresentationFontCache.exe 0 0 0
0d3c egui.exe 1 166 48 normal
0d9c tvnserver.exe 1 15 8 normal
0e84 issch.exe 1 4 2 normal C:\Program Files (x86)\Com
mon Files\InstallShield\UpdateService
0ec4 PCFTray.exe 1 24 27 normal C:\Program Files (x86)\Bai
du Security\PC Faster
0f0c SSDMonitor.exe 1 16 9 normal C:\Program Files (x86)\Com
mon Files\PC Tools\sMonitor
0f3c svchost.exe 0 0 0
0fa4 igfxEM.exe 1 13 19 normal
0fac igfxHK.exe 1 13 12 normal
0fbc igfxTray.exe 1 12 6 normal
0fe4 jusched.exe 1 9 2 normal C:\Program Files (x86)\Com
mon Files\Java\Java Update
0e7c audiodg.exe 0 0 0
0e34 CCleaner64.exe 1 77 31 below normal
08b0 unsecapp.exe 1 9 4 normal
0e20 chrome.exe 1 145 45 normal C:\Users\user pc\AppData\L
ocal\Google\Chrome\Application
0c14 chrome.exe 1 11 4 normal C:\Users\user pc\AppData\L
ocal\Google\Chrome\Application
116c chrome.exe 1 403 1 normal C:\Users\user pc\AppData\L
ocal\Google\Chrome\Application
0aa4 chrome.exe 1 251 1 below normal C:\Users\user pc\AppData\L
ocal\Google\Chrome\Application
0770 chrome.exe 1 31 1 below normal C:\Users\user pc\AppData\L
ocal\Google\Chrome\Application
0914 svchost.exe 0 0 0
0e1c dllhost.exe 1 0 0
0e3c dllhost.exe 0 0 0
00f4 Adventure-Patcher.exe 1 54 36 normal D:\Ragnarok\adventure
hardware:
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
- Fax
- Microsoft XPS Document Writer
- PrimoPDF
- Root Print Queue
- Send To OneNote 2013
+ {36fc9e60-c465-11cf-8056-444553540000}
- Generic USB Hub
- Intel(R) USB 3.0 eXtensible Host Controller - 0100 (Microsoft)
.
- USB Composite Device
- USB Root Hub (xHCI)
+ {4d36e965-e325-11ce-bfc1-08002be10318}
- MATSHITA DVD-RAM UJ8FBS
+ {4d36e966-e325-11ce-bfc1-08002be10318}
- ACPI x64-based PC
+ {4d36e967-e325-11ce-bfc1-08002be10318}
- TOSHIBA MQ01ABF050
+ {4d36e968-e325-11ce-bfc1-08002be10318}
- Intel(R) HD Graphics (driver 10.18.10.3496)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
- Standard SATA AHCI Controller
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
- Standard PS/2 Keyboard
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
- CyberLink WebCam Virtual Driver (driver 6.0.5600.0)
- High Definition Audio Device
- Intel(R) Display Audio (driver 6.16.0.3135)
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
- Generic PnP Monitor
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
- HID-compliant mouse
- PS/2 Compatible Mouse
+ {4d36e972-e325-11ce-bfc1-08002be10318}
- Bluetooth Device (Personal Area Network) #2
- Qualcomm Atheros AR956x Wireless Network Adapter (driver 10.0.0.225)
- Realtek PCIe GBE Family Controller #2 (driver 8.18.621.2013)
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
- Microsoft Storage Spaces Controller
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Power Button
- ACPI Thermal Zone
- Composite Bus Enumerator
- High Definition Audio Controller
- High precision event timer
- Intel(R) 82802 Firmware Hub Device
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft Basic Display Driver
- Microsoft Basic Render Driver
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator
- Motherboard resources
- Motherboard resources
- PCI Express Root Complex
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- Plug and Play Software Device Enumerator
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- Standard Power Management Controller
- System CMOS/real time clock
- System timer
- UMBus Root Bus Enumerator
- Volume Manager
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
- Intel(R) Celeron(R) CPU N2830 @ 2.16GHz
- Intel(R) Celeron(R) CPU N2830 @ 2.16GHz
+ {533c5b84-ec70-11d2-9505-00c04f79deaf}
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
+ {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
- Microsoft Device Association Root Enumerator
+ {6bdd1fc6-810f-11d0-bec7-08002be2092f}
- Lenovo EasyCamera
+ {72631e54-78a4-11d0-bcf7-00aa00b7b32a}
- Microsoft AC Adapter
- Microsoft ACPI-Compliant Control Method Battery
+ {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
- USB Input Device
+ {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
- Microphone (4- High Definition Audio Device)
- Speakers (4- High Definition Audio Device)
+ {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
- Microsoft Bluetooth Enumerator
- Microsoft Bluetooth LE Enumerator
- Qualcomm Atheros AR3012 Bluetooth 4.0 + HS (driver 8.0.0.230)
disassembling:
[...]
0060a091 mov edx, $60a198
0060a096 call -$2021ab ($407ef0) ; System.@UStrEqual
0060a09b jnz loc_60a107
0060a09d 201 mov dl, 1
0060a09f mov eax, [$570cf0]
0060a0a4 call -$92141 ($577f68) ; pngimage.TPngImage.Create
0060a0a9 mov ebx, eax
0060a0ab 202 mov edx, esi
0060a0ad mov eax, ebx
0060a0af mov ecx, [eax]
0060a0b1 > call dword ptr [ecx+$5c]
0060a0b4 203 mov eax, ebx
0060a0b6 mov edx, [eax]
0060a0b8 call dword ptr [edx+$24]
0060a0bb mov edx, eax
0060a0bd mov eax, [ebp-8]
0060a0c0 call -$11c791 ($4ed934) ; Controls.TControl.SetHeight
0060a0c5 204 mov eax, ebx
0060a0c7 mov edx, [eax]
0060a0c9 call dword ptr [edx+$30]
0060a0cc mov edx, eax
[...]

Potrebbero piacerti anche