Вы находитесь на странице: 1из 11

date/time : 2018-06-19, 09:39:54, 74ms

computer name : W7-HUGO


user name : Hugo <admin>
operating system : Windows NT New x64 build 9200
system language : Spanish
system up time : 11 hours 46 minutes
program up time : 14 seconds
processors : 4x Intel(R) Core(TM) i5-4670K CPU @ 3.40GHz
physical memory : 10508/16323 MB (free/total)
free disk space : (C:) 124,86 GB
display mode : 2194x1234, 32 bit
process id : $994
allocated memory : 74,69 MB
executable : iobituninstaller-pro.exe
exec. date/time : 2016-12-24 18:00
version : 5.1.0.107
compiled with : Delphi 2009
madExcept version : 3.0i
callstack crc : $37209b13, $653b796a, $653b796a
exception number : 1
exception class : EAccessViolation
exception message : Access violation at address 004EBA18 in module
'iobituninstaller-pro.exe'. Write of address 00000005.

main thread ($3214):


004eba18 +0cc iobituninstaller-pro.exe Unit_GetLicenseType 605 +36
GetASCInstallType
004f6775 +24d iobituninstaller-pro.exe Main 852 +63
TfrmIUSetup.InitSaveIUInnoSetup
004f6f0b +10f iobituninstaller-pro.exe Main 1050 +24
TfrmIUSetup.RdImageButton_InstallClick
004b21f3 +06f iobituninstaller-pro.exe Controls TControl.Click
004dd29f +02f iobituninstaller-pro.exe RdImageButton 1708 +10
TRdImageButton.Click
004b2666 +066 iobituninstaller-pro.exe Controls
TControl.WMLButtonUp
004b1c8a +2d2 iobituninstaller-pro.exe Controls
TControl.WndProc
004b618f +513 iobituninstaller-pro.exe Controls
TWinControl.WndProc
76add608 +048 oleaut32.dll SysFreeString
004b18c4 +024 iobituninstaller-pro.exe Controls
TControl.Perform
004b5b1f +097 iobituninstaller-pro.exe Controls
TWinControl.IsControlMouseMsg
004b603a +3be iobituninstaller-pro.exe Controls
TWinControl.WndProc
0049f750 +594 iobituninstaller-pro.exe Forms
TCustomForm.WndProc
004b58a8 +02c iobituninstaller-pro.exe Controls
TWinControl.MainWndProc
00478ec8 +014 iobituninstaller-pro.exe Classes StdWndProc
75ed79cb +00b user32.dll
DispatchMessageW
004a7c67 +0f3 iobituninstaller-pro.exe Forms
TApplication.ProcessMessage
004a7caa +00a iobituninstaller-pro.exe Forms
TApplication.HandleMessage
004a7fd5 +0c9 iobituninstaller-pro.exe Forms
TApplication.Run
004f8eb4 +078 iobituninstaller-pro.exe IObitSetup 35 +8 initialization
75998482 +022 KERNEL32.DLL
BaseThreadInitThunk

thread $11d0:
75998482 +22 KERNEL32.DLL BaseThreadInitThunk

thread $1e38:
75998482 +22 KERNEL32.DLL BaseThreadInitThunk

thread $5ec:
75998482 +22 KERNEL32.DLL BaseThreadInitThunk

thread $1fe8:
75998482 +22 KERNEL32.DLL BaseThreadInitThunk

thread $3058:
75998482 +22 KERNEL32.DLL BaseThreadInitThunk

thread $264c:
75b61c9d +12d KERNELBASE.dll WaitForMultipleObjectsEx
00454c09 +00d iobituninstaller-pro.exe madExcept CallThreadProcSafe
00454c73 +037 iobituninstaller-pro.exe madExcept ThreadExceptFrame
75998482 +022 KERNEL32.DLL BaseThreadInitThunk
>> created by main thread ($3214) at:
74f95cca +000 combase.dll

modules:
00400000 iobituninstaller-pro.exe 5.1.0.107 C:\Users\Hugo\Downloads
5cf60000 wbemdisp.dll 6.2.17134.1 C:\Windows\system32\wbem
62cd0000 fastprox.dll 6.2.17134.1 C:\Windows\system32\wbem
62da0000 wbemcomn.dll 6.2.17134.1 C:\Windows\SYSTEM32
632c0000 wmiutils.dll 6.2.17134.1 C:\Windows\system32\wbem
684c0000 wbemsvc.dll 6.2.17134.1 C:\Windows\system32\wbem
68660000 wbemprox.dll 6.2.17134.1 C:\Windows\system32\wbem
69ef0000 CoreMessaging.dll 6.2.17134.112 C:\Windows\System32
69f80000 CoreUIComponents.dll 6.2.17134.112 C:\Windows\System32
6a1e0000 TextInputFramework.dll 6.2.17134.1 C:\Windows\System32
6aba0000 wintypes.dll 6.2.17134.112 C:\Windows\SYSTEM32
6d600000 apphelp.dll 6.2.17134.1 C:\Windows\SYSTEM32
70270000 sxs.dll 6.2.17134.1 C:\Windows\SYSTEM32
70fe0000 wininet.dll 11.0.17134.112 C:\Windows\SYSTEM32
71e30000 uxtheme.dll 6.2.17134.1 C:\Windows\system32
71f10000 dwmapi.dll 6.2.17134.1 C:\Windows\system32
72360000 comctl32.dll 6.10.17134.112
C:\Windows\WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.17134.112_none_42ecccf244e44518
72600000 ntmarta.dll 6.2.17134.1 C:\Windows\SYSTEM32
72660000 bcrypt.dll 6.2.17134.112 C:\Windows\SYSTEM32
72fd0000 version.dll 6.2.17134.1 C:\Windows\SYSTEM32
73160000 wsock32.dll 6.2.17134.1 C:\Windows\SYSTEM32
73730000 msimg32.dll 6.2.17134.1 C:\Windows\SYSTEM32
73740000 CRYPTBASE.dll 6.2.17134.1 C:\Windows\System32
73750000 SspiCli.dll 6.2.17134.1 C:\Windows\System32
73770000 shlwapi.dll 6.2.17134.1 C:\Windows\System32
737c0000 comdlg32.dll 6.2.17134.1 C:\Windows\System32
738a0000 shell32.dll 6.2.17134.81 C:\Windows\System32
74bf0000 clbcatq.dll 2001.12.10941.16384 C:\Windows\System32
74c80000 MSCTF.dll 6.2.17134.1 C:\Windows\System32
74dd0000 msvcp_win.dll 6.2.17134.1 C:\Windows\System32
74e50000 RPCRT4.dll 6.2.17134.112 C:\Windows\System32
74f10000 combase.dll 6.2.17134.112 C:\Windows\System32
751d0000 windows.storage.dll 6.2.17134.81 C:\Windows\System32
75980000 KERNEL32.DLL 6.2.17134.1 C:\Windows\System32
75a60000 KERNELBASE.dll 6.2.17134.112 C:\Windows\System32
75c50000 shcore.dll 6.2.17134.112 C:\Windows\System32
75ce0000 advapi32.dll 6.2.17134.1 C:\Windows\System32
75e60000 cfgmgr32.dll 6.2.17134.1 C:\Windows\System32
75ea0000 user32.dll 6.2.17134.1 C:\Windows\System32
76080000 profapi.dll 6.2.17134.1 C:\Windows\System32
760b0000 ole32.dll 6.2.17134.1 C:\Windows\System32
765e0000 FLTLIB.DLL 6.2.17134.1 C:\Windows\System32
765f0000 sechost.dll 6.2.17134.1 C:\Windows\System32
76640000 kernel.appcore.dll 6.2.17134.112 C:\Windows\System32
76650000 powrprof.dll 6.2.17134.1 C:\Windows\System32
766a0000 IMM32.DLL 6.2.17134.1 C:\Windows\System32
766d0000 ucrtbase.dll 6.2.17134.1 C:\Windows\System32
76800000 gdi32full.dll 6.2.17134.112 C:\Windows\System32
76970000 msvcrt.dll 7.0.17134.1 C:\Windows\System32
76a30000 WS2_32.dll 6.2.17134.1 C:\Windows\System32
76aa0000 win32u.dll 6.2.17134.1 C:\Windows\System32
76ac0000 oleaut32.dll 6.2.17134.48 C:\Windows\System32
76b60000 bcryptPrimitives.dll 6.2.17134.112 C:\Windows\System32
76d60000 psapi.dll 6.2.17134.1 C:\Windows\System32
76d70000 GDI32.dll 6.2.17134.1 C:\Windows\System32
76e90000 ntdll.dll 6.2.17134.112 C:\Windows\SYSTEM32

processes:
0000 Idle 0 0 0
0004 System 0 0 0
0060 Registry 0 0 0
0230 smss.exe 0 0 0
0300 csrss.exe 0 0 0
036c wininit.exe 0 0 0
0374 csrss.exe 1 0 0
03b8 services.exe 0 0 0
03c4 lsass.exe 0 0 0
0044 winlogon.exe 1 0 0
0410 svchost.exe 0 0 0
042c svchost.exe 0 0 0
0448 fontdrvhost.exe 0 0 0
044c fontdrvhost.exe 1 0 0
04a0 svchost.exe 0 0 0
04d4 svchost.exe 0 0 0
0514 dwm.exe 1 0 0
0550 WUDFHost.exe 0 0 0
05e0 svchost.exe 0 0 0
05f4 svchost.exe 0 0 0
0648 svchost.exe 0 0 0
0664 svchost.exe 0 0 0
06b8 svchost.exe 0 0 0
0700 TeraCopyService.exe 0 0 0
0720 svchost.exe 0 0 0
0740 svchost.exe 0 0 0
0770 svchost.exe 0 0 0
079c svchost.exe 0 0 0
07d8 svchost.exe 0 0 0
07fc svchost.exe 0 0 0
06f4 NVDisplay.Container.exe 0 0 0
081c svchost.exe 0 0 0
0890 svchost.exe 0 0 0
0898 svchost.exe 0 0 0
08a0 svchost.exe 0 0 0
091c svchost.exe 0 0 0
0934 Memory Compression 0 0 0
095c svchost.exe 0 0 0
0964 svchost.exe 0 0 0
09d4 NVDisplay.Container.exe 1 0 0
0a38 svchost.exe 0 0 0
0a74 svchost.exe 0 0 0
0b80 sihost.exe 1 0 14 normal C:\Windows\System32
04ec svchost.exe 1 0 2 normal C:\Windows\System32
0c3c svchost.exe 1 0 11 normal C:\Windows\System32
0cac taskhostw.exe 1 8 6 normal C:\Windows\System32
0cd8 EzUpdt.exe 1 94 40 below normal C:\Program Files
(x86)\ASUS\AI Suite III\EZ Update
0cec DipAwayMode.exe 1 101 64 below normal C:\Program Files
(x86)\ASUS\AI Suite III\DIP4\DIPAwayMode
0cf4 AISuite3.exe 1 635 157 below normal C:\Program Files
(x86)\ASUS\AI Suite III
0d78 svchost.exe 0 0 0
0da0 ctfmon.exe 1 2 22 high C:\Windows\System32
0e4c explorer.exe 1 312 309 normal C:\Windows
0e84 svchost.exe 0 0 0
0f60 svchost.exe 0 0 0
0fc4 svchost.exe 0 0 0
1038 ShellExperienceHost.exe 1 7 65 normal
C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy
1110 SearchUI.exe 1 14 50 normal
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy
11b4 RuntimeBroker.exe 1 40 19 normal C:\Windows\System32
11e4 svchost.exe 0 0 0
121c RuntimeBroker.exe 1 36 17 normal C:\Windows\System32
122c svchost.exe 0 0 0
13f4 SettingSyncHost.exe 1 1 5 below normal C:\Windows\System32
14b0 svchost.exe 0 0 0
14b8 svchost.exe 0 0 0
14e0 svchost.exe 0 0 0
1564 svchost.exe 0 0 0
15fc spoolsv.exe 0 0 0
1670 svchost.exe 0 0 0
17b0 svchost.exe 0 0 0
17d4 svchost.exe 0 0 0
17dc svchost.exe 0 0 0
077c dasHost.exe 0 0 0
052c atkexComSvc.exe 0 0 0
0624 AdobeUpdateService.exe 0 0 0
0b84 mDNSResponder.exe 0 0 0
0bcc avp.exe 0 0 0
0bd8 aaHMSvc.exe 0 0 0
0bdc AsusFanControlService.exe 0 0 0
0bf0 SkypeC2CAutoUpdateSvc.exe 0 0 0
0bf4 svchost.exe 0 0 0
0520 svchost.exe 0 0 0
0aa8 svchost.exe 0 0 0
051c SkypeC2CPNRSvc.exe 0 0 0
16c0 DUMeterSvc.exe 0 0 0
1734 EPCP.exe 0 0 0
1818 svchost.exe 0 0 0
18f4 escsvc64.exe 0 0 0
191c svchost.exe 0 0 0
1964 NvTelemetryContainer.exe 0 0 0
1980 nvcontainer.exe 0 0 0
1988 ForwardDaemon.exe 0 0 0
19d8 PSIService.exe 0 0 0
19e0 FoxitConnectedPDFService.exe 0 0 0
19ec svchost.exe 0 0 0
19e8 svchost.exe 0 0 0
19f8 svchost.exe 0 0 0
1a0c svchost.exe 0 0 0
1a44 SecurityHealthService.exe 0 0 0
1a54 ss_conn_service.exe 0 0 0
1a5c GLCRIconSvc.exe 0 0 0
1aac svchost.exe 0 0 0
1bd8 svchost.exe 0 0 0
1c4c svchost.exe 0 0 0
1c5c dllhost.exe 1 0 7 normal C:\Windows\System32
1c68 svchost.exe 0 0 0
1d20 svchost.exe 0 0 0
1d8c NMMediaServerService.exe 0 0 0 normal
1934 nvcontainer.exe 1 3 9 normal C:\Program Files
(x86)\NVIDIA Corporation\NvContainer
1b00 nvcontainer.exe 1 0 14 normal C:\Program Files
(x86)\NVIDIA Corporation\NvContainer
27d4 GoogleCrashHandler.exe 0 0 0
24f0 NVIDIA Web Helper.exe 1 2 13 below normal C:\Program Files
(x86)\NVIDIA Corporation\NvNode
17a0 conhost.exe 1 10 3 below normal C:\Windows\System32
1678 GoogleCrashHandler64.exe 0 0 0
26a8 svchost.exe 0 0 0
22a8 SearchIndexer.exe 0 0 0
28bc RuntimeBroker.exe 1 40 9 normal C:\Windows\System32
28c8 U3BoostSvr64.exe 1 12 17 below normal C:\Program Files
(x86)\ASUS\AI Suite III\USB 3.0 Boost
297c svchost.exe 0 0 0
2988 avpui.exe 1 120 80 normal C:\Program Files
(x86)\Kaspersky Lab\Kaspersky Internet Security 18.0.0
2a10 MSASCuiL.exe 1 7 6 normal C:\Program Files\Windows
Defender
2bd0 RtkNGUI64.exe 1 18 28 normal C:\Program
Files\Realtek\Audio\HDA
2794 SetPoint.exe 1 32 19 normal C:\Program
Files\Logitech\SetPointP
2c08 KHALMNPR.exe 1 0 16 normal C:\Program Files\Common
Files\Logishrd\KHAL3
2ecc nvsphelper64.exe 1 3 5 normal C:\Program Files\NVIDIA
Corporation\ShadowPlay
2ed8 NVIDIA Share.exe 1 18 29 normal C:\Program Files
(x86)\NVIDIA Corporation\NVIDIA GeForce Experience
2fe4 NVIDIA Share.exe 1 0 1 normal C:\Program Files
(x86)\NVIDIA Corporation\NVIDIA GeForce Experience
2e64 AsusMiniBar.exe 1 137 56 below normal C:\Program Files
(x86)\ASUS\AI Suite III
2fdc E_YATIPCE.EXE 1 15 9 normal
C:\Windows\System32\spool\drivers\x64\3
2cb0 TWCU.exe 1 1699 1431 normal C:\Program Files
(x86)\TP-LINK\TP-LINK Wireless Configuration Utility
2d04 jusched.exe 1 0 2 normal C:\Program Files
(x86)\Common Files\Java\Java Update
2d78 SamsungMagician.exe 1 64 70 normal C:\Program Files
(x86)\Samsung\Samsung Magician
205c PWRISOVM.EXE 1 13 8 normal C:\Program Files
(x86)\PowerISO
2e60 AiChargerAP.exe 1 15 22 normal C:\Program Files
(x86)\ASUS\ASUS Ai Charger
1d18 EEventManager.exe 1 10 15 normal C:\Program Files
(x86)\Epson Software\Event Manager
2ea0 TrayTipAgentE.exe 1 0 1 normal C:\Program Files
(x86)\EaseUS\EaseUS Partition Master 12.5\bin\TrayPopupE
1388 DUMeter.exe 1 73 52 normal C:\Program Files
(x86)\DU Meter
0de8 svchost.exe 0 0 0
3188 Xplorer2UltPortable.exe 1 15 6 normal
C:\Utilitarios\Xplorer2Portable
31fc xplorer2_64.exe 1 403 207 normal
C:\Utilitarios\Xplorer2Portable\App\Xplorer2Ult
2f90 svchost.exe 1 0 1 normal C:\Windows\System32
0394 svchost.exe 0 0 0
05bc svchost.exe 0 0 0
32fc ksde.exe 0 0 0
1950 svchost.exe 0 0 0
1974 SgrmBroker.exe 0 0 0
1b48 svchost.exe 0 0 0
33c8 svchost.exe 0 0 0
11c8 NASvc.exe 0 0 0
329c ksdeui.exe 1 49 30 normal C:\Program Files
(x86)\Kaspersky Lab\Kaspersky Secure Connection 2.0
26bc procexp.exe 1 0 2 normal
C:\Utilitarios\ProcessExplorer 16.02
2c88 PROCEXP64.exe 1 1341 485 high
C:\Users\Hugo\AppData\Local\Temp
246c svchost.exe 0 0 0
0ccc svchost.exe 0 0 0
12a8 WmiPrvSE.exe 0 0 0
0710 WmiPrvSE.exe 0 0 0
32bc ApplicationFrameHost.exe 1 66 46 normal C:\Windows\System32
0428 WinStore.App.exe 1 0 15 normal C:\Program
Files\WindowsApps\Microsoft.WindowsStore_11804.1001.10.0_x64__8wekyb3d8bbwe
1710 RuntimeBroker.exe 1 36 5 normal C:\Windows\System32
1ac4 svchost.exe 0 0 0
20a4 svchost.exe 0 0 0
3124 SystemSettings.exe 1 14 44 normal
C:\Windows\ImmersiveControlPanel
2288 svchost.exe 0 0 0
2938 svchost.exe 0 0 0
1698 Microsoft.Photos.exe 1 11 23 normal C:\Program
Files\WindowsApps\Microsoft.Windows.Photos_2018.18041.15530.0_x64__8wekyb3d8bbwe
160c RuntimeBroker.exe 1 1 21 normal C:\Windows\System32
29b4 svchost.exe 0 0 0
08b8 svchost.exe 0 0 0
2854 firefox.exe 1 68 250 normal C:\Program Files\Mozilla
Firefox
06f8 firefox.exe 1 5 43 normal C:\Program Files\Mozilla
Firefox
37c8 firefox.exe 1 2 143 normal C:\Program Files\Mozilla
Firefox
36e8 firefox.exe 1 2 98 normal C:\Program Files\Mozilla
Firefox
1044 firefox.exe 1 2 98 normal C:\Program Files\Mozilla
Firefox
08d8 firefox.exe 1 2 146 normal C:\Program Files\Mozilla
Firefox
2c6c WmiPrvSE.exe 0 0 0
1354 svchost.exe 0 0 0
35f8 svchost.exe 0 0 0
1128 dllhost.exe 1 0 4 normal C:\Windows\System32
1f24 SearchProtocolHost.exe 0 0 0
2c60 smartscreen.exe 1 0 8 normal C:\Windows\System32
12d0 DriverBooster.exe 1 300 164 normal C:\Program Files
(x86)\IObit\Driver Booster\5.2.0
04b8 PubMonitor.exe 1 34 30 normal C:\Program Files
(x86)\IObit\Driver Booster\5.2.0\Pub
1f40 svchost.exe 0 0 0
3180 WmiPrvSE.exe 0 0 0
34dc firefox.exe 1 2 119 normal C:\Program Files\Mozilla
Firefox
2f8c SmartDefrag.exe 1 372 189 normal C:\Program Files
(x86)\IObit\Smart Defrag
3360 audiodg.exe 0 0 0
15c8 avp.exe 0 0 0
1afc SearchFilterHost.exe 0 0 0 idle C:\Windows\System32
1970 ASCService.exe 0 0 0
1060 VSSVC.exe 0 0 0
1868 svchost.exe 0 0 0
38c8 ASC.exe 1 477 126 normal C:\Program Files
(x86)\IObit\Advanced SystemCare
38dc Monitor.exe 1 199 84 normal C:\Program Files
(x86)\IObit\Advanced SystemCare
3964 ASCTray.exe 1 164 114 normal C:\Program Files
(x86)\IObit\Advanced SystemCare
05cc AutoCare.exe 1 121 57 normal C:\Program Files
(x86)\IObit\Advanced SystemCare
0994 iobituninstaller-pro.exe 1 70 59 normal C:\Users\Hugo\Downloads
3a34 Install_PintoStartMenu.exe 1 60 26 normal C:\Program Files
(x86)\IObit\IObit Uninstaller
3a74 LiveUpdate.exe 0 0 0
3b54 PPUninstaller.exe 1 51 20 normal C:\Program Files
(x86)\IObit\IObit Uninstaller
3578 UninstallMonitor.exe 1 31 25 normal C:\Program Files
(x86)\IObit\IObit Uninstaller
2e70 IObitUninstaler.exe 1 166 38 normal C:\Program Files
(x86)\IObit\IObit Uninstaller
1374 AUpdate.exe 1 0 4 normal C:\Program Files
(x86)\IObit\IObit Uninstaller

hardware:
+ {14b62f50-3f15-11dd-ae16-0800200c9a66}
- [TV] Samsung 6 Series (50)
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
- Enviar a OneNote 2010
- Fax
- Foxit Reader PDF Printer
- Microsoft Print to PDF
- Microsoft XPS Document Writer
- Root Print Queue
- XP-230 Series(Red)
- XP-230 Series(Red) (Copiar 1)
+ {36fc9e60-c465-11cf-8056-444553540000}
- Generic USB Hub
- Generic USB Hub
- Generic USB Hub
- Genesys Logic USB2.0 Card Reader (driver 4.5.3.1)
- Intel(R) 8 Series/C220 Series USB EHCI #1 - 8C26 (driver 9.4.0.1025)
- Intel(R) 8 Series/C220 Series USB EHCI #2 - 8C2D (driver 9.4.0.1025)
- Intel(R) USB 3.0 eXtensible Host Controller - 1.0 (Microsoft)
- USB Composite Device
- USB Root Hub
- USB Root Hub
- USB Root Hub (USB 3.0)
+ {4d36e965-e325-11ce-bfc1-08002be10318}
- HL-DT-ST BD-RE WH16NS40 ATA Device
+ {4d36e966-e325-11ce-bfc1-08002be10318}
- ACPI x64-based PC
+ {4d36e967-e325-11ce-bfc1-08002be10318}
- Samsung SSD 860 EVO 500GB ATA Device
+ {4d36e968-e325-11ce-bfc1-08002be10318}
- NVIDIA GeForce GTX 970 (driver 24.21.13.9811)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
- ATA Channel 0
- ATA Channel 1
- Intel(R) 8 Series/C220 Series 4 port Serial ATA Storage Controller - 8C00
(driver 9.4.0.1023)
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
- HID Keyboard Device
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
- AnvSoft Virtual Sound Device (driver 1.2.0.0)
- NVIDIA High Definition Audio (driver 1.3.37.4)
- NVIDIA Virtual Audio Device (Wave Extensible) (WDM) (driver 4.4.0.0)
- Realtek High Definition Audio (driver 6.0.1.8372)
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
- Generic PnP Monitor
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
- HID-compliant mouse
+ {4d36e972-e325-11ce-bfc1-08002be10318}
- Qualcomm Atheros AR9287 Wireless Network Adapter (driver 10.0.3.456)
- Realtek PCIe GbE Family Controller #2 (driver 10.26.328.2018)
+ {4d36e978-e325-11ce-bfc1-08002be10318}
- Communications Port (COM1)
- Printer Port (LPT1)
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
- Microsoft Storage Spaces Controller
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
- ACPI Fan
- ACPI Fan
- ACPI Fan
- ACPI Fan
- ACPI Fan
- ACPI Fixed Feature Button
- ACPI Power Button
- ACPI Thermal Zone
- ACPI Thermal Zone
- AMDA00 Interface (driver 1.0.0.0)
- Composite Bus Enumerator
- Direct memory access controller
- High Definition Audio Controller
- High Definition Audio Controller
- High precision event timer
- Intel(R) 8 Series/C220 Series PCI Express Root Port #1 - 8C10 (driver
10.1.1.40)
- Intel(R) 8 Series/C220 Series PCI Express Root Port #2 - 8C12 (driver
10.1.1.40)
- Intel(R) 8 Series/C220 Series PCI Express Root Port #3 - 8C14 (driver
10.1.1.40)
- Intel(R) 8 Series/C220 Series SMBus Controller - 8C22 (driver 10.1.1.40)
- Intel(R) B85 LPC Controller - 8C50 (driver 10.1.1.40)
- Intel(R) Management Engine Interface (driver 11.7.0.1057)
- Intel(R) Xeon(R) processor E3 - 1200 v3/4th Gen Core processor DRAM Controller
- 0C00 (driver 10.1.1.40)
- Intel(R) Xeon(R) processor E3 - 1200 v3/4th Gen Core processor PCI Express x16
Controller - 0C01 (driver 10.1.1.40)
- Kaspersky Lab power events provider (driver 16.0.65.62)
- Legacy device
- Microsoft ACPI-Compliant System
- Microsoft Basic Display Driver
- Microsoft Basic Render Driver
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator
- Microsoft Windows Management Interface for ACPI
- Motherboard resources
- Motherboard resources
- Motherboard resources
- Motherboard resources
- Motherboard resources
- NDIS Virtual Network Adapter Enumerator
- Numeric data processor
- NVVHCI Enumerator (driver 2.2.2151.6378)
- PCI Express Root Complex
- Plug and Play Software Device Enumerator
- Printer Port Logical Interface
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- System board
- System CMOS/real time clock
- System timer
- UMBus Root Bus Enumerator
- Volume Manager
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
- Intel(R) Core(TM) i5-4670K CPU @ 3.40GHz
- Intel(R) Core(TM) i5-4670K CPU @ 3.40GHz
- Intel(R) Core(TM) i5-4670K CPU @ 3.40GHz
- Intel(R) Core(TM) i5-4670K CPU @ 3.40GHz
+ {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
- [TV] Samsung 6 Series (50)
- Microsoft Device Association Root Enumerator
- Microsoft GS Wavetable Synth
- Microsoft Radio Device Enumeration Bus
- Microsoft RRAS Root Enumerator
- Wi-Fi
+ {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
- HID-compliant consumer control device
- HID-compliant system controller
- HID-compliant vendor-defined device
- HID-compliant vendor-defined device
- HID-compliant vendor-defined device
- HID-compliant vendor-defined device
- Logitech USB Input Device (driver 1.10.78.0)
- USB Input Device
- USB Input Device
+ {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
- Microphone (AnvSoft Virtual Sound Device)
- Realtek Digital Output (Realtek High Definition Audio)
- Speakers (AnvSoft Virtual Sound Device)
- Speakers (Realtek High Definition Audio)
- U28E590 (NVIDIA High Definition Audio)
+ {ff646f80-8def-11d2-9449-00105a075f6b}
- pcouffin device for Amd 64 bits systems (driver 1.37.0.0)

cpu registers:
eax = 00000000
ebx = 00000000
ecx = 00000000
edx = 02f4c004
esi = 00000005
edi = 0019fab0
eip = 004eba18
esp = 0019fa14
ebp = 0019fa64

stack dump:
0019fa14 6c fa 19 00 b4 4e 40 00 - 64 fa 19 00 70 d2 4d 00 l....N@.d...p.M.
0019fa24 90 d7 f3 02 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0019fa34 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0019fa44 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0019fa54 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0019fa64 cc fa 19 00 7a 67 4f 00 - d4 fa 19 00 b4 4e 40 00 ....zgO......N@.
0019fa74 cc fa 19 00 64 fc 19 00 - 70 d2 4d 00 90 d7 f3 02 ....d...p.M.....
0019fa84 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0019fa94 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0019faa4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0019fab4 80 4f f8 02 e0 4e f8 02 - 90 d7 f3 02 00 00 00 00 .O...N..........
0019fac4 00 00 00 00 00 00 00 00 - f0 fa 19 00 10 6f 4f 00 .............oO.
0019fad4 10 fd 19 00 b4 4e 40 00 - f0 fa 19 00 64 fc 19 00 .....N@.....d...
0019fae4 70 d2 4d 00 d0 80 f1 02 - 00 00 00 00 58 fc 19 00 p.M.........X...
0019faf4 f9 21 4b 00 d0 80 f1 02 - a4 d2 4d 00 d0 80 f1 02 .!K.......M.....
0019fb04 6b 26 4b 00 6a 00 1a 00 - 6a 00 00 00 1a 00 00 00 k&K.j...j.......
0019fb14 00 00 00 00 00 00 00 00 - d0 00 00 00 34 00 00 00 ............4...
0019fb24 00 00 1a 00 d0 80 f1 02 - 64 fc 19 00 8d 1c 4b 00 ........d.....K.
0019fb34 00 00 1a 00 40 fd 19 00 - d0 80 f1 02 20 ee cc 74 ....@..........t
0019fb44 02 00 00 00 47 f4 cc 74 - 00 00 00 00 00 00 00 00 ....G..t........

disassembling:
[...]
004eba05 603 cmp dword ptr [ebp-$10], 0
004eba09 jz loc_4eba21
004eba0b 605 mov edx, [ebp-$10]
004eba0e mov eax, 5
004eba13 call -$173c ($4ea2dc) ; Unit_GetLicenseType.GetLicenseType
004eba18 > mov [esi], eax
004eba1a 606 mov bl, 1
004eba1c 607 jmp loc_4ebb22
004eba21 610 cmp dword ptr [ebp-$14], 0
004eba25 jz loc_4eba3d
004eba27 612 mov edx, [ebp-$14]
[...]

Вам также может понравиться