Bugreport
Bugreport
Bugreport
modules:
00400000 GLCDFontCreator.exe 1.1.0.0 C:\Users\Public\Documents\
Mikroelektronika\GLCD Font Creator
73a60000 profapi.dll 6.1.7600.16385 C:\Windows\system32
73a70000 USERENV.dll 6.1.7600.16385 C:\Windows\system32
73a90000 version.dll 6.1.7600.16385 C:\Windows\system32
748d0000 propsys.dll 7.0.7600.16385 C:\Windows\system32
74a20000 mscms.dll 6.1.7600.16385 C:\Windows\system32
74aa0000 ntmarta.dll 6.1.7600.16385 C:\Windows\system32
74ad0000 dwmapi.dll 6.1.7600.16385 C:\Windows\system32
74af0000 uxtheme.dll 6.1.7600.16385 C:\Windows\system32
74b70000 winmm.dll 6.1.7600.16385 C:\Windows\system32
74bb0000 winspool.drv 6.1.7600.16385 C:\Windows\system32
74c10000 comctl32.dll 6.10.7600.16385 C:\Windows\WinSxS\
x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc
74db0000 wsock32.dll 6.1.7600.16385 C:\Windows\system32
74dc0000 msimg32.dll 6.1.7600.16385 C:\Windows\system32
75470000 CRYPTBASE.dll 6.1.7600.16385 C:\Windows\syswow64
75480000 SspiCli.dll 6.1.7600.16385 C:\Windows\syswow64
754e0000 MSCTF.dll 6.1.7600.16385 C:\Windows\syswow64
755b0000 WS2_32.dll 6.1.7600.16385 C:\Windows\syswow64
755f0000 ADVAPI32.dll 6.1.7600.16385 C:\Windows\syswow64
75690000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\syswow64
75720000 shell32.dll 6.1.7600.16385 C:\Windows\syswow64
76370000 comdlg32.dll 6.1.7600.16385 C:\Windows\syswow64
763f0000 WINTRUST.dll 6.1.7600.16385 C:\Windows\syswow64
76420000 NSI.dll 6.1.7600.16385 C:\Windows\syswow64
76430000 SETUPAPI.dll 6.1.7600.16385 C:\Windows\syswow64
765d0000 msvcrt.dll 7.0.7600.16385 C:\Windows\syswow64
76680000 MSASN1.dll 6.1.7600.16385 C:\Windows\syswow64
76690000 USP10.dll 1.626.7600.16385 C:\Windows\syswow64
76730000 oleaut32.dll 6.1.7600.16385 C:\Windows\syswow64
76820000 kernel32.dll 6.1.7600.16385 C:\Windows\syswow64
76a20000 WLDAP32.dll 6.1.7600.16385 C:\Windows\syswow64
76a70000 CFGMGR32.dll 6.1.7600.16385 C:\Windows\syswow64
76aa0000 CRYPT32.dll 6.1.7600.16385 C:\Windows\syswow64
76bc0000 imm32.dll 6.1.7600.16385 C:\Windows\syswow64
76c20000 DEVOBJ.dll 6.1.7600.16385 C:\Windows\syswow64
76d00000 USER32.dll 6.1.7600.16385 C:\Windows\syswow64
77000000 ole32.dll 6.1.7600.16385 C:\Windows\syswow64
77160000 sechost.dll 6.1.7600.16385 C:\Windows\SysWOW64
77180000 SHLWAPI.dll 6.1.7600.16385 C:\Windows\syswow64
771e0000 RPCRT4.dll 6.1.7600.16385 C:\Windows\syswow64
772d0000 GDI32.dll 6.1.7600.16385 C:\Windows\syswow64
77360000 KERNELBASE.dll 6.1.7600.16385 C:\Windows\syswow64
774f0000 psapi.dll 6.1.7600.16385 C:\Windows\syswow64
778e0000 LPK.dll 6.1.7600.16385 C:\Windows\syswow64
77910000 ntdll.dll 6.1.7600.16385 C:\Windows\SysWOW64
processes:
000 Idle 0
004 System 0
128 smss.exe 0
190 csrss.exe 0
1c0 wininit.exe 0
1d8 csrss.exe 1
1fc services.exe 0
214 lsass.exe 0
21c lsm.exe 0
280 svchost.exe 0
2c8 svchost.exe 0
304 svchost.exe 0
334 winlogon.exe 1
348 svchost.exe 0
36c svchost.exe 0
3b0 stacsv64.exe 0
18c svchost.exe 0
458 WUDFHost.exe 0
4a8 svchost.exe 0
504 wlanext.exe 0
50c conhost.exe 0
594 spoolsv.exe 0
5b8 svchost.exe 0
5d8 svchost.exe 0
634 taskhost.exe 1 normal
680 dwm.exe 1 high
694 AESTSr64.exe 0
6f4 svchost.exe 0
71c explorer.exe 1 normal
440 GoogleCrashHandler.exe 0
78c GoogleCrashHandler64.exe 0
8f0 alg.exe 0
988 hkcmd.exe 1 normal
998 igfxpers.exe 1 normal
9b8 sttray64.exe 1 normal
a04 FavoritesMicrosoft-ver4.4.2.0.exe 1 normal C:\ProgramData\FavoritesMicrosoft-
ver4.4.2.0
b14 SearchIndexer.exe 0
57c GLCDFontCreator.exe 1 normal C:\Users\Public\Documents\
Mikroelektronika\GLCD Font Creator
3d0 svchost.exe 0
7cc wmpnetwk.exe 0
b88 WmiPrvSE.exe 0
8a4 SearchProtocolHost.exe 0
bc4 SearchFilterHost.exe 0
204 audiodg.exe 0
hardware:
+ Batteries
- Microsoft AC Adapter
- Microsoft ACPI-Compliant Control Method Battery
- Microsoft ACPI-Compliant Control Method Battery
- Microsoft Composite Battery
+ Computer
- ACPI x64-based PC
+ Disk drives
- TOSHIBA MK3261GSYN SCSI Disk Device
+ Display adapters
- Intel(R) HD Graphics (driver 8.15.10.2993)
+ DVD/CD-ROM drives
- TSSTcorp DVD+-RW TS-U633F SCSI CdRom Device
+ IDE ATA/ATAPI controllers
- Ricoh PCIe SD Bus Host Adapter (driver 6.13.3.4)
+ IEEE 1394 Bus host controllers
- Ricoh 1394 OHCI Compliant Host Controller
+ Imaging devices
- Integrated Webcam
+ Keyboards
- Standard PS/2 Keyboard
+ Mice and other pointing devices
- PS/2 Compatible Mouse
+ Monitors
- Generic PnP Monitor
+ Network adapters
- DW1520 Wireless-N WLAN Half-Mini Card (driver 6.30.223.215)
- Intel(R) 82577LM Gigabit Network Connection (driver 12.10.13.0)
- Microsoft Virtual WiFi Miniport Adapter
+ Ports (COM & LPT)
- ECP Printer Port (LPT1)
+ Processors
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
+ Smart Card Filter
- Smart card filter driver
+ Smart card readers
- Broadcom Usbccid Smartcard Reader (WUDF) (driver 22.19.17.974)
+ Sound, video and game controllers
- IDT High Definition Audio CODEC (driver 6.10.0.6292)
- Intel(R) Display Audio (driver 6.16.0.3208)
+ Storage controllers
- Intel(R) Chipset SATA/PCIe RST Premium Controller (driver 15.9.8.1050)
+ Storage volume shadow copies
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
+ System devices
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Power Button
- ACPI Sleep Button
- Composite Bus Enumerator
- Direct memory access controller
- File as Volume Driver
- Generic Bus
- High Definition Audio Controller
- High precision event timer
- Intel Device (driver 10.0.24.0)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 1 - 3B42
(driver 9.1.9.1005)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 2 - 3B44
(driver 9.1.9.1005)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 3 - 3B46
(driver 9.1.9.1005)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 4 - 3B48
(driver 9.1.9.1005)
- Intel(R) 82801 PCI Bridge - 2448
- Intel(R) 82802 Firmware Hub Device
- Intel(R) processor DRAM Controller - 0044 (driver 9.1.9.1005)
- Intel(R) QM57 Express Chipset LPC Interface Controller - 3B07 (driver
9.1.9.1005)
- Intel(R) Turbo Boost Technology Driver (driver 1.2.0.1002)
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator Driver
- Microsoft Windows Management Interface for ACPI
- Motherboard resources
- Motherboard resources
- Numeric data processor
- PCI bus
- PCI bus
- Plug and Play Software Device Enumerator
- Printer Port Logical Interface
- Programmable interrupt controller
- QPI Link 0 - 2D10 (driver 9.1.9.1005)
- QPI Physical 0 - 2D11 (driver 9.1.9.1005)
- QuickPath Architecture Generic Non-core Registers - 2C62 (driver 9.1.9.1005)
- QuickPath Architecture System Address Decoder - 2D01 (driver 9.1.9.1005)
- Remote Desktop Device Redirector Bus
- Reserved - 2D12 (driver 9.1.9.1005)
- Reserved - 2D13 (driver 9.1.9.1005)
- STMicroelectronics 3-Axis Digital Accelerometer (driver 2.2.3.11)
- System CMOS/real time clock
- System timer
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- UMBus Enumerator
- UMBus Root Bus Enumerator
- Volume Manager
+ Universal Serial Bus controllers
- Generic USB Hub
- Generic USB Hub
- Intel(R) 5 Series/3400 Series Chipset Family USB Enhanced Host Controller -
3B34 (driver 9.1.9.1006)
- Intel(R) 5 Series/3400 Series Chipset Family USB Enhanced Host Controller -
3B3C (driver 9.1.9.1006)
- USB Composite Device
- USB Composite Device
- USB Root Hub
- USB Root Hub
+ {09e9a11d-ccb2-45ae-9be8-65c263e60490}
- Dell ControlVault w/o Fingerprint Sensor (driver 6.1.7600.20222)
cpu registers:
eax = 020a1ff0
ebx = 02006290
ecx = 00000000
edx = 00471167
esi = 005ca144
edi = 01ff4fc0
eip = 00471167
esp = 0018f2bc
ebp = 0018f304
stack dump:
0018f2bc 67 11 47 00 de fa ed 0e - 01 00 00 00 07 00 00 00 g.G.............
0018f2cc d0 f2 18 00 67 11 47 00 - f0 1f 0a 02 90 62 00 02 ....g.G......b..
0018f2dc 44 a1 5c 00 c0 4f ff 01 - 04 f3 18 00 ec f2 18 00 D.\..O..........
0018f2ec 00 00 00 00 c0 4f ff 01 - 90 62 00 02 44 a1 5c 00 .....O...b..D.\.
0018f2fc 0b 62 00 02 00 00 00 00 - 1c f3 18 00 33 bf 4b 00 .b..........3.K.
0018f30c 44 a1 5c 00 24 53 5c 00 - 44 a1 5c 00 c0 4f ff 01 D.\.$S\.D.\..O..
0018f31c 60 f3 18 00 51 12 47 00 - 44 a1 5c 00 00 00 00 00 `...Q.G.D.\.....
0018f32c 2b 43 4a 00 c0 4f ff 01 - 90 62 00 02 01 14 06 02 +CJ..O...b......
0018f33c 6a 41 4a 00 84 f3 18 00 - 24 4b 40 00 60 f3 18 00 jAJ.....$K@.`...
0018f34c f0 ce 01 02 01 00 00 00 - 90 14 06 02 00 00 00 00 ................
0018f35c 44 a1 5c 00 7c f3 18 00 - 2c 9f 5c 00 f0 ce 01 02 D.\.|...,.\.....
0018f36c 30 64 4b 00 90 14 06 02 - c0 4f ff 01 90 62 00 02 0dK......O...b..
0018f37c 94 f3 18 00 c0 87 5c 00 - dc f3 18 00 24 4b 40 00 ......\.....$K@.
0018f38c 94 f3 18 00 90 62 00 02 - f8 f3 18 00 a6 16 47 00 .....b........G.
0018f39c 90 14 06 02 96 60 4b 00 - 00 f4 18 00 08 6d 4b 00 .....`K......mK.
0018f3ac 90 14 06 02 5d 6d 4b 00 - 58 d1 b1 04 74 15 47 00 ....]mK.X...t.G.
0018f3bc 58 d1 b1 04 f0 d5 fa 01 - 00 67 4e 00 48 87 07 02 X........gN.H...
0018f3cc f0 d5 fa 01 de 48 52 00 - ff ff ff ff 05 66 4e 00 .....HR......fN.
0018f3dc a4 f4 18 00 f4 48 40 00 - f8 f3 18 00 00 00 00 00 .....H@.........
0018f3ec bb 0f 26 00 00 00 00 00 - f0 d5 fa 01 10 f4 18 00 ..&.............
disassembling:
[...]
005c9f1a mov ecx, [eax]
005c9f1c call dword ptr [ecx+$6c]
005c9f1f 1458 mov edx, $5ca144
005c9f24 mov eax, [ebp-8]
005c9f27 mov ecx, [eax]
005c9f29 > call dword ptr [ecx+$18]
005c9f2c 1459 xor eax, eax
005c9f2e push ebp
005c9f2f push $5ca128 ; System.@HandleFinally
005c9f34 push dword ptr fs:[eax]
005c9f37 mov fs:[eax], esp
[...]
modules:
00400000 GLCDFontCreator.exe 1.1.0.0 C:\Users\Public\Documents\
Mikroelektronika\GLCD Font Creator
73a60000 profapi.dll 6.1.7600.16385 C:\Windows\system32
73a70000 USERENV.dll 6.1.7600.16385 C:\Windows\system32
73a90000 version.dll 6.1.7600.16385 C:\Windows\system32
748d0000 propsys.dll 7.0.7600.16385 C:\Windows\system32
74a20000 mscms.dll 6.1.7600.16385 C:\Windows\system32
74aa0000 ntmarta.dll 6.1.7600.16385 C:\Windows\system32
74ad0000 dwmapi.dll 6.1.7600.16385 C:\Windows\system32
74af0000 uxtheme.dll 6.1.7600.16385 C:\Windows\system32
74b70000 winmm.dll 6.1.7600.16385 C:\Windows\system32
74bb0000 winspool.drv 6.1.7600.16385 C:\Windows\system32
74c10000 comctl32.dll 6.10.7600.16385 C:\Windows\WinSxS\
x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc
74db0000 wsock32.dll 6.1.7600.16385 C:\Windows\system32
74dc0000 msimg32.dll 6.1.7600.16385 C:\Windows\system32
75470000 CRYPTBASE.dll 6.1.7600.16385 C:\Windows\syswow64
75480000 SspiCli.dll 6.1.7600.16385 C:\Windows\syswow64
754e0000 MSCTF.dll 6.1.7600.16385 C:\Windows\syswow64
755b0000 WS2_32.dll 6.1.7600.16385 C:\Windows\syswow64
755f0000 ADVAPI32.dll 6.1.7600.16385 C:\Windows\syswow64
75690000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\syswow64
75720000 shell32.dll 6.1.7600.16385 C:\Windows\syswow64
76370000 comdlg32.dll 6.1.7600.16385 C:\Windows\syswow64
763f0000 WINTRUST.dll 6.1.7600.16385 C:\Windows\syswow64
76420000 NSI.dll 6.1.7600.16385 C:\Windows\syswow64
76430000 SETUPAPI.dll 6.1.7600.16385 C:\Windows\syswow64
765d0000 msvcrt.dll 7.0.7600.16385 C:\Windows\syswow64
76680000 MSASN1.dll 6.1.7600.16385 C:\Windows\syswow64
76690000 USP10.dll 1.626.7600.16385 C:\Windows\syswow64
76730000 oleaut32.dll 6.1.7600.16385 C:\Windows\syswow64
76820000 kernel32.dll 6.1.7600.16385 C:\Windows\syswow64
76a20000 WLDAP32.dll 6.1.7600.16385 C:\Windows\syswow64
76a70000 CFGMGR32.dll 6.1.7600.16385 C:\Windows\syswow64
76aa0000 CRYPT32.dll 6.1.7600.16385 C:\Windows\syswow64
76bc0000 imm32.dll 6.1.7600.16385 C:\Windows\syswow64
76c20000 DEVOBJ.dll 6.1.7600.16385 C:\Windows\syswow64
76d00000 USER32.dll 6.1.7600.16385 C:\Windows\syswow64
77000000 ole32.dll 6.1.7600.16385 C:\Windows\syswow64
77160000 sechost.dll 6.1.7600.16385 C:\Windows\SysWOW64
77180000 SHLWAPI.dll 6.1.7600.16385 C:\Windows\syswow64
771e0000 RPCRT4.dll 6.1.7600.16385 C:\Windows\syswow64
772d0000 GDI32.dll 6.1.7600.16385 C:\Windows\syswow64
77360000 KERNELBASE.dll 6.1.7600.16385 C:\Windows\syswow64
774f0000 psapi.dll 6.1.7600.16385 C:\Windows\syswow64
778e0000 LPK.dll 6.1.7600.16385 C:\Windows\syswow64
77910000 ntdll.dll 6.1.7600.16385 C:\Windows\SysWOW64
processes:
000 Idle 0
004 System 0
128 smss.exe 0
190 csrss.exe 0
1c0 wininit.exe 0
1d8 csrss.exe 1
1fc services.exe 0
214 lsass.exe 0
21c lsm.exe 0
280 svchost.exe 0
2c8 svchost.exe 0
304 svchost.exe 0
334 winlogon.exe 1
348 svchost.exe 0
36c svchost.exe 0
3b0 stacsv64.exe 0
18c svchost.exe 0
458 WUDFHost.exe 0
4a8 svchost.exe 0
504 wlanext.exe 0
50c conhost.exe 0
594 spoolsv.exe 0
5b8 svchost.exe 0
5d8 svchost.exe 0
634 taskhost.exe 1 normal
680 dwm.exe 1 high
694 AESTSr64.exe 0
6f4 svchost.exe 0
71c explorer.exe 1 normal
440 GoogleCrashHandler.exe 0
78c GoogleCrashHandler64.exe 0
8f0 alg.exe 0
988 hkcmd.exe 1 normal
998 igfxpers.exe 1 normal
9b8 sttray64.exe 1 normal
a04 FavoritesMicrosoft-ver4.4.2.0.exe 1 normal C:\ProgramData\FavoritesMicrosoft-
ver4.4.2.0
b14 SearchIndexer.exe 0
57c GLCDFontCreator.exe 1 normal C:\Users\Public\Documents\
Mikroelektronika\GLCD Font Creator
3d0 svchost.exe 0
7cc wmpnetwk.exe 0
ac8 SearchProtocolHost.exe 0
080 SearchFilterHost.exe 0
hardware:
+ Batteries
- Microsoft AC Adapter
- Microsoft ACPI-Compliant Control Method Battery
- Microsoft ACPI-Compliant Control Method Battery
- Microsoft Composite Battery
+ Computer
- ACPI x64-based PC
+ Disk drives
- TOSHIBA MK3261GSYN SCSI Disk Device
+ Display adapters
- Intel(R) HD Graphics (driver 8.15.10.2993)
+ DVD/CD-ROM drives
- TSSTcorp DVD+-RW TS-U633F SCSI CdRom Device
+ IDE ATA/ATAPI controllers
- Ricoh PCIe SD Bus Host Adapter (driver 6.13.3.4)
+ IEEE 1394 Bus host controllers
- Ricoh 1394 OHCI Compliant Host Controller
+ Imaging devices
- Integrated Webcam
+ Keyboards
- Standard PS/2 Keyboard
+ Mice and other pointing devices
- PS/2 Compatible Mouse
+ Monitors
- Generic PnP Monitor
+ Network adapters
- DW1520 Wireless-N WLAN Half-Mini Card (driver 6.30.223.215)
- Intel(R) 82577LM Gigabit Network Connection (driver 12.10.13.0)
- Microsoft Virtual WiFi Miniport Adapter
+ Ports (COM & LPT)
- ECP Printer Port (LPT1)
+ Processors
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
+ Smart Card Filter
- Smart card filter driver
+ Smart card readers
- Broadcom Usbccid Smartcard Reader (WUDF) (driver 22.19.17.974)
+ Sound, video and game controllers
- IDT High Definition Audio CODEC (driver 6.10.0.6292)
- Intel(R) Display Audio (driver 6.16.0.3208)
+ Storage controllers
- Intel(R) Chipset SATA/PCIe RST Premium Controller (driver 15.9.8.1050)
+ Storage volume shadow copies
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
+ System devices
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Power Button
- ACPI Sleep Button
- Composite Bus Enumerator
- Direct memory access controller
- File as Volume Driver
- Generic Bus
- High Definition Audio Controller
- High precision event timer
- Intel Device (driver 10.0.24.0)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 1 - 3B42
(driver 9.1.9.1005)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 2 - 3B44
(driver 9.1.9.1005)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 3 - 3B46
(driver 9.1.9.1005)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 4 - 3B48
(driver 9.1.9.1005)
- Intel(R) 82801 PCI Bridge - 2448
- Intel(R) 82802 Firmware Hub Device
- Intel(R) processor DRAM Controller - 0044 (driver 9.1.9.1005)
- Intel(R) QM57 Express Chipset LPC Interface Controller - 3B07 (driver
9.1.9.1005)
- Intel(R) Turbo Boost Technology Driver (driver 1.2.0.1002)
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator Driver
- Microsoft Windows Management Interface for ACPI
- Motherboard resources
- Motherboard resources
- Numeric data processor
- PCI bus
- PCI bus
- Plug and Play Software Device Enumerator
- Printer Port Logical Interface
- Programmable interrupt controller
- QPI Link 0 - 2D10 (driver 9.1.9.1005)
- QPI Physical 0 - 2D11 (driver 9.1.9.1005)
- QuickPath Architecture Generic Non-core Registers - 2C62 (driver 9.1.9.1005)
- QuickPath Architecture System Address Decoder - 2D01 (driver 9.1.9.1005)
- Remote Desktop Device Redirector Bus
- Reserved - 2D12 (driver 9.1.9.1005)
- Reserved - 2D13 (driver 9.1.9.1005)
- STMicroelectronics 3-Axis Digital Accelerometer (driver 2.2.3.11)
- System CMOS/real time clock
- System timer
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- UMBus Enumerator
- UMBus Root Bus Enumerator
- Volume Manager
+ Universal Serial Bus controllers
- Generic USB Hub
- Generic USB Hub
- Intel(R) 5 Series/3400 Series Chipset Family USB Enhanced Host Controller -
3B34 (driver 9.1.9.1006)
- Intel(R) 5 Series/3400 Series Chipset Family USB Enhanced Host Controller -
3B3C (driver 9.1.9.1006)
- USB Composite Device
- USB Composite Device
- USB Root Hub
- USB Root Hub
+ {09e9a11d-ccb2-45ae-9be8-65c263e60490}
- Dell ControlVault w/o Fingerprint Sensor (driver 6.1.7600.20222)
cpu registers:
eax = 020a2250
ebx = 02006290
ecx = 00000000
edx = 00471167
esi = 005cae38
edi = 01ff4ba0
eip = 00471167
esp = 0018fa88
ebp = 0018fad0
stack dump:
0018fa88 67 11 47 00 de fa ed 0e - 01 00 00 00 07 00 00 00 g.G.............
0018fa98 9c fa 18 00 67 11 47 00 - 50 22 0a 02 90 62 00 02 ....g.G.P"...b..
0018faa8 38 ae 5c 00 a0 4b ff 01 - d0 fa 18 00 b8 fa 18 00 8.\..K..........
0018fab8 00 00 00 00 a0 4b ff 01 - 90 62 00 02 38 ae 5c 00 .....K...b..8.\.
0018fac8 0b 62 00 02 00 00 00 00 - e8 fa 18 00 33 bf 4b 00 .b..........3.K.
0018fad8 38 ae 5c 00 24 53 5c 00 - 38 ae 5c 00 a0 4b ff 01 8.\.$S\.8.\..K..
0018fae8 2c fb 18 00 51 12 47 00 - 38 ae 5c 00 00 00 00 00 ,...Q.G.8.\.....
0018faf8 2b 43 4a 00 a0 4b ff 01 - 90 62 00 02 01 11 06 02 +CJ..K...b......
0018fb08 6a 41 4a 00 50 fb 18 00 - 24 4b 40 00 2c fb 18 00 jAJ.P...$K@.,...
0018fb18 f0 ce 01 02 01 00 00 00 - d0 11 06 02 00 00 00 00 ................
0018fb28 38 ae 5c 00 48 fb 18 00 - 20 ac 5c 00 f0 ce 01 02 8.\.H.....\.....
0018fb38 30 64 4b 00 d0 11 06 02 - a0 4b ff 01 90 62 00 02 0dK......K...b..
0018fb48 60 fb 18 00 1c 84 5c 00 - a8 fb 18 00 24 4b 40 00 `.....\.....$K@.
0018fb58 60 fb 18 00 90 62 00 02 - c4 fb 18 00 a6 16 47 00 `....b........G.
0018fb68 d0 11 06 02 96 60 4b 00 - cc fb 18 00 08 6d 4b 00 .....`K......mK.
0018fb78 d0 11 06 02 5d 6d 4b 00 - a8 25 05 02 74 15 47 00 ....]mK..%..t.G.
0018fb88 a8 25 05 02 90 d2 fa 01 - 00 67 4e 00 48 87 07 02 .%.......gN.H...
0018fb98 90 d2 fa 01 de 48 52 00 - ff ff ff ff 05 66 4e 00 .....HR......fN.
0018fba8 70 fc 18 00 f4 48 40 00 - c4 fb 18 00 00 00 00 00 p....H@.........
0018fbb8 bb 0f 26 00 00 00 00 00 - 90 d2 fa 01 dc fb 18 00 ..&.............
disassembling:
[...]
005cac0e mov ecx, [eax]
005cac10 call dword ptr [ecx+$6c]
005cac13 1638 mov edx, $5cae38
005cac18 mov eax, [ebp-8]
005cac1b mov ecx, [eax]
005cac1d > call dword ptr [ecx+$18]
005cac20 1639 xor eax, eax
005cac22 push ebp
005cac23 push $5cae1c ; System.@HandleFinally
005cac28 push dword ptr fs:[eax]
005cac2b mov fs:[eax], esp
[...]
modules:
00400000 GLCDFontCreator.exe 1.1.0.0 C:\Users\Public\Documents\
Mikroelektronika\GLCD Font Creator
73e50000 profapi.dll 6.1.7600.16385 C:\Windows\system32
73e60000 USERENV.dll 6.1.7600.16385 C:\Windows\system32
73e80000 version.dll 6.1.7600.16385 C:\Windows\system32
74c20000 mscms.dll 6.1.7600.16385 C:\Windows\system32
74ca0000 ntmarta.dll 6.1.7600.16385 C:\Windows\system32
74cd0000 propsys.dll 7.0.7600.16385 C:\Windows\system32
74dd0000 msimg32.dll 6.1.7600.16385 C:\Windows\system32
74de0000 dwmapi.dll 6.1.7600.16385 C:\Windows\system32
74e00000 uxtheme.dll 6.1.7600.16385 C:\Windows\system32
74e80000 winmm.dll 6.1.7600.16385 C:\Windows\system32
74ec0000 winspool.drv 6.1.7600.16385 C:\Windows\system32
74f20000 comctl32.dll 6.10.7600.16385 C:\Windows\WinSxS\
x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc
750c0000 wsock32.dll 6.1.7600.16385 C:\Windows\system32
756b0000 CRYPTBASE.dll 6.1.7600.16385 C:\Windows\syswow64
756c0000 SspiCli.dll 6.1.7600.16385 C:\Windows\syswow64
75720000 WLDAP32.dll 6.1.7600.16385 C:\Windows\syswow64
757a0000 CFGMGR32.dll 6.1.7600.16385 C:\Windows\syswow64
757e0000 CRYPT32.dll 6.1.7600.16385 C:\Windows\syswow64
75900000 psapi.dll 6.1.7600.16385 C:\Windows\syswow64
759a0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\syswow64
75b70000 USP10.dll 1.626.7600.16385 C:\Windows\syswow64
75c10000 imm32.dll 6.1.7600.16385 C:\Windows\syswow64
75c70000 ole32.dll 6.1.7600.16385 C:\Windows\syswow64
75dd0000 RPCRT4.dll 6.1.7600.16385 C:\Windows\syswow64
75ec0000 WS2_32.dll 6.1.7600.16385 C:\Windows\syswow64
75f00000 WINTRUST.dll 6.1.7600.16385 C:\Windows\syswow64
75f30000 NSI.dll 6.1.7600.16385 C:\Windows\syswow64
75f40000 SETUPAPI.dll 6.1.7600.16385 C:\Windows\syswow64
760e0000 MSASN1.dll 6.1.7600.16385 C:\Windows\syswow64
76150000 GDI32.dll 6.1.7600.16385 C:\Windows\syswow64
761e0000 KERNELBASE.dll 6.1.7600.16385 C:\Windows\syswow64
76230000 SHLWAPI.dll 6.1.7600.16385 C:\Windows\syswow64
76290000 oleaut32.dll 6.1.7600.16385 C:\Windows\syswow64
76320000 ADVAPI32.dll 6.1.7600.16385 C:\Windows\syswow64
763c0000 sechost.dll 6.1.7600.16385 C:\Windows\SysWOW64
763e0000 kernel32.dll 6.1.7600.16385 C:\Windows\syswow64
764e0000 USER32.dll 6.1.7600.16385 C:\Windows\syswow64
765e0000 comdlg32.dll 6.1.7600.16385 C:\Windows\syswow64
76760000 msvcrt.dll 7.0.7600.16385 C:\Windows\syswow64
76810000 DEVOBJ.dll 6.1.7600.16385 C:\Windows\syswow64
76830000 shell32.dll 6.1.7600.16385 C:\Windows\syswow64
77680000 MSCTF.dll 6.1.7600.16385 C:\Windows\syswow64
77b20000 LPK.dll 6.1.7600.16385 C:\Windows\syswow64
77b50000 ntdll.dll 6.1.7600.16385 C:\Windows\SysWOW64
processes:
000 Idle 0
004 System 0
128 smss.exe 0
190 csrss.exe 0
1c0 wininit.exe 0
1d8 csrss.exe 1
1fc services.exe 0
214 lsass.exe 0
21c lsm.exe 0
284 svchost.exe 0
2cc svchost.exe 0
308 svchost.exe 0
328 svchost.exe 0
354 svchost.exe 0
374 stacsv64.exe 0
3a4 winlogon.exe 1
294 svchost.exe 0
420 WUDFHost.exe 0
47c svchost.exe 0
4f8 wlanext.exe 0
500 conhost.exe 0
588 taskhost.exe 1 normal
5d4 dwm.exe 1 high
5dc spoolsv.exe 0
608 svchost.exe 0
628 svchost.exe 0
64c explorer.exe 1 normal
694 AESTSr64.exe 0
6e4 svchost.exe 0
830 alg.exe 0
8c4 GoogleCrashHandler.exe 0
8e8 GoogleCrashHandler64.exe 0
9a8 hkcmd.exe 1 normal
9bc igfxpers.exe 1 normal
9c4 sttray64.exe 1 normal
9cc FavoritesMicrosoft-ver4.4.2.0.exe 1 normal C:\ProgramData\FavoritesMicrosoft-
ver4.4.2.0
ad4 SearchIndexer.exe 0
bc0 GLCDFontCreator.exe 1 normal C:\Users\Public\Documents\
Mikroelektronika\GLCD Font Creator
878 svchost.exe 0
7b0 wmpnetwk.exe 0
858 javaw.exe 1 normal C:\Program Files (x86)\Arduino\java\
bin
ac8 audiodg.exe 0
b2c SearchProtocolHost.exe 0
720 SearchFilterHost.exe 0
hardware:
+ Batteries
- Microsoft AC Adapter
- Microsoft ACPI-Compliant Control Method Battery
- Microsoft ACPI-Compliant Control Method Battery
- Microsoft Composite Battery
+ Computer
- ACPI x64-based PC
+ Disk drives
- TOSHIBA MK3261GSYN SCSI Disk Device
+ Display adapters
- Intel(R) HD Graphics (driver 8.15.10.2993)
+ DVD/CD-ROM drives
- TSSTcorp DVD+-RW TS-U633F SCSI CdRom Device
+ IDE ATA/ATAPI controllers
- Ricoh PCIe SD Bus Host Adapter (driver 6.13.3.4)
+ IEEE 1394 Bus host controllers
- Ricoh 1394 OHCI Compliant Host Controller
+ Imaging devices
- Integrated Webcam
+ Keyboards
- Standard PS/2 Keyboard
+ Mice and other pointing devices
- PS/2 Compatible Mouse
+ Monitors
- Generic PnP Monitor
+ Network adapters
- DW1520 Wireless-N WLAN Half-Mini Card (driver 6.30.223.215)
- Intel(R) 82577LM Gigabit Network Connection (driver 12.10.13.0)
- Microsoft Virtual WiFi Miniport Adapter
+ Ports (COM & LPT)
- ECP Printer Port (LPT1)
+ Processors
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
+ Smart Card Filter
- Smart card filter driver
+ Smart card readers
- Broadcom Usbccid Smartcard Reader (WUDF) (driver 22.19.17.974)
+ Sound, video and game controllers
- IDT High Definition Audio CODEC (driver 6.10.0.6292)
- Intel(R) Display Audio (driver 6.16.0.3208)
+ Storage controllers
- Intel(R) Chipset SATA/PCIe RST Premium Controller (driver 15.9.8.1050)
+ Storage volume shadow copies
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
+ System devices
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Power Button
- ACPI Sleep Button
- Composite Bus Enumerator
- Direct memory access controller
- File as Volume Driver
- Generic Bus
- High Definition Audio Controller
- High precision event timer
- Intel Device (driver 10.0.24.0)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 1 - 3B42
(driver 9.1.9.1005)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 2 - 3B44
(driver 9.1.9.1005)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 3 - 3B46
(driver 9.1.9.1005)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 4 - 3B48
(driver 9.1.9.1005)
- Intel(R) 82801 PCI Bridge - 2448
- Intel(R) 82802 Firmware Hub Device
- Intel(R) processor DRAM Controller - 0044 (driver 9.1.9.1005)
- Intel(R) QM57 Express Chipset LPC Interface Controller - 3B07 (driver
9.1.9.1005)
- Intel(R) Turbo Boost Technology Driver (driver 1.2.0.1002)
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator Driver
- Microsoft Windows Management Interface for ACPI
- Motherboard resources
- Motherboard resources
- Numeric data processor
- PCI bus
- PCI bus
- Plug and Play Software Device Enumerator
- Printer Port Logical Interface
- Programmable interrupt controller
- QPI Link 0 - 2D10 (driver 9.1.9.1005)
- QPI Physical 0 - 2D11 (driver 9.1.9.1005)
- QuickPath Architecture Generic Non-core Registers - 2C62 (driver 9.1.9.1005)
- QuickPath Architecture System Address Decoder - 2D01 (driver 9.1.9.1005)
- Remote Desktop Device Redirector Bus
- Reserved - 2D12 (driver 9.1.9.1005)
- Reserved - 2D13 (driver 9.1.9.1005)
- STMicroelectronics 3-Axis Digital Accelerometer (driver 2.2.3.11)
- System CMOS/real time clock
- System timer
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- UMBus Enumerator
- UMBus Root Bus Enumerator
- Volume Manager
+ Universal Serial Bus controllers
- Generic USB Hub
- Generic USB Hub
- Intel(R) 5 Series/3400 Series Chipset Family USB Enhanced Host Controller -
3B34 (driver 9.1.9.1006)
- Intel(R) 5 Series/3400 Series Chipset Family USB Enhanced Host Controller -
3B3C (driver 9.1.9.1006)
- USB Composite Device
- USB Composite Device
- USB Root Hub
- USB Root Hub
+ {09e9a11d-ccb2-45ae-9be8-65c263e60490}
- Dell ControlVault w/o Fingerprint Sensor (driver 6.1.7600.20222)
cpu registers:
eax = 020130a0
ebx = 00000083
ecx = 020130a0
edx = 005446ae
esi = 00000000
edi = 00000000
eip = 005446ae
esp = 0018fb44
ebp = 0018fb9c
stack dump:
0018fb44 ae 46 54 00 de fa ed 0e - 01 00 00 00 07 00 00 00 .FT.............
0018fb54 58 fb 18 00 ae 46 54 00 - a0 30 01 02 83 00 00 00 X....FT..0......
0018fb64 00 00 00 00 00 00 00 00 - 9c fb 18 00 74 fb 18 00 ............t...
0018fb74 b4 fb 18 00 24 4b 40 00 - 9c fb 18 00 83 00 00 00 ....$K@.........
0018fb84 70 45 f6 01 83 00 00 00 - 00 d7 f6 01 00 00 00 00 pE..............
0018fb94 00 00 00 00 00 00 00 00 - 9c fc 18 00 24 51 54 00 ............$QT.
0018fba4 00 00 00 00 00 00 00 00 - 00 00 00 00 07 67 5b 00 .............g[.
0018fbb4 c0 fb 18 00 24 4b 40 00 - 9c fc 18 00 a4 fc 18 00 ....$K@.........
0018fbc4 24 4b 40 00 9c fc 18 00 - d0 30 9c 04 10 fd 18 00 [email protected]......
0018fbd4 00 63 65 02 00 00 00 00 - 00 00 00 00 00 00 00 00 .ce.............
0018fbe4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018fbf4 00 00 00 00 00 00 00 00 - 00 00 00 00 08 5d 65 02 .............]e.
0018fc04 0b 00 00 00 07 0e 00 00 - 00 00 00 00 00 00 00 00 ................
0018fc14 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018fc24 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018fc34 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018fc44 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018fc54 00 00 00 00 01 00 00 00 - 01 00 00 00 1a 00 00 00 ................
0018fc64 70 45 f6 01 41 00 00 00 - 01 00 00 00 83 00 00 00 pE..A...........
0018fc74 b8 fc 18 00 00 63 65 02 - 00 00 00 00 00 00 00 00 .....ce.........
disassembling:
[...]
00544695 call -$ed5ca ($4570d0) ; SysUtils.Format
0054469a mov ecx, [ebp-4]
0054469d mov dl, 1
0054469f mov eax, [$454648]
005446a4 call -$ea201 ($45a4a8) ; SysUtils.Exception.Create
005446a9 > call -$13fa66 ($404c48) ; System.@RaiseExcept
005446ae jmp loc_5446b9
005446b0 304 mov eax, [eax+$1c4]
005446b6 mov ebx, [eax+edx*4]
005446b9 306 xor eax, eax
005446bb pop edx
[...]
modules:
00400000 GLCDFontCreator.exe 1.1.0.0 C:\Users\Public\Documents\
Mikroelektronika\GLCD Font Creator
73b60000 propsys.dll 7.0.7600.16385 C:\Windows\system32
73da0000 profapi.dll 6.1.7600.16385 C:\Windows\system32
73db0000 USERENV.dll 6.1.7600.16385 C:\Windows\system32
73dd0000 version.dll 6.1.7600.16385 C:\Windows\system32
73e10000 mscms.dll 6.1.7600.16385 C:\Windows\system32
73e90000 ntmarta.dll 6.1.7600.16385 C:\Windows\system32
73ec0000 winspool.drv 6.1.7600.16385 C:\Windows\system32
74b80000 comctl32.dll 6.10.7600.16385 C:\Windows\WinSxS\
x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc
74d40000 dwmapi.dll 6.1.7600.16385 C:\Windows\system32
75000000 msimg32.dll 6.1.7600.16385 C:\Windows\system32
750a0000 uxtheme.dll 6.1.7600.16385 C:\Windows\system32
75150000 winmm.dll 6.1.7600.16385 C:\Windows\system32
75190000 wsock32.dll 6.1.7600.16385 C:\Windows\system32
75600000 CRYPTBASE.dll 6.1.7600.16385 C:\Windows\syswow64
75610000 SspiCli.dll 6.1.7600.16385 C:\Windows\syswow64
75670000 USER32.dll 6.1.7600.16385 C:\Windows\syswow64
758d0000 DEVOBJ.dll 6.1.7600.16385 C:\Windows\syswow64
758f0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\syswow64
75980000 MSASN1.dll 6.1.7600.16385 C:\Windows\syswow64
75990000 comdlg32.dll 6.1.7600.16385 C:\Windows\syswow64
75a10000 sechost.dll 6.1.7600.16385 C:\Windows\SysWOW64
75a30000 ole32.dll 6.1.7600.16385 C:\Windows\syswow64
75b90000 SHLWAPI.dll 6.1.7600.16385 C:\Windows\syswow64
75bf0000 psapi.dll 6.1.7600.16385 C:\Windows\syswow64
75c00000 KERNELBASE.dll 6.1.7600.16385 C:\Windows\syswow64
75c50000 CRYPT32.dll 6.1.7600.16385 C:\Windows\syswow64
75d70000 kernel32.dll 6.1.7600.16385 C:\Windows\syswow64
75ea0000 WINTRUST.dll 6.1.7600.16385 C:\Windows\syswow64
75ed0000 MSCTF.dll 6.1.7600.16385 C:\Windows\syswow64
75fa0000 ADVAPI32.dll 6.1.7600.16385 C:\Windows\syswow64
76040000 RPCRT4.dll 6.1.7600.16385 C:\Windows\syswow64
76130000 USP10.dll 1.626.7600.16385 C:\Windows\syswow64
761d0000 GDI32.dll 6.1.7600.16385 C:\Windows\syswow64
76460000 imm32.dll 6.1.7600.16385 C:\Windows\syswow64
764c0000 LPK.dll 6.1.7600.16385 C:\Windows\syswow64
76610000 CFGMGR32.dll 6.1.7600.16385 C:\Windows\syswow64
76640000 NSI.dll 6.1.7600.16385 C:\Windows\syswow64
76650000 WLDAP32.dll 6.1.7600.16385 C:\Windows\syswow64
766a0000 oleaut32.dll 6.1.7600.16385 C:\Windows\syswow64
76730000 SETUPAPI.dll 6.1.7600.16385 C:\Windows\syswow64
768d0000 msvcrt.dll 7.0.7600.16385 C:\Windows\syswow64
76980000 shell32.dll 6.1.7600.16385 C:\Windows\syswow64
775d0000 WS2_32.dll 6.1.7600.16385 C:\Windows\syswow64
77aa0000 ntdll.dll 6.1.7600.16385 C:\Windows\SysWOW64
processes:
0000 Idle 0
0004 System 0
0128 smss.exe 0
0190 csrss.exe 0
01d0 wininit.exe 0
01e8 csrss.exe 1
020c services.exe 0
0224 lsass.exe 0
022c lsm.exe 0
029c svchost.exe 0
02e4 svchost.exe 0
0320 svchost.exe 0
0340 svchost.exe 0
035c svchost.exe 0
0390 winlogon.exe 1
03d0 stacsv64.exe 0
01e0 svchost.exe 0
0440 WUDFHost.exe 0
047c svchost.exe 0
0504 wlanext.exe 0
050c conhost.exe 0
0570 spoolsv.exe 0
058c svchost.exe 0
05ac svchost.exe 0
05f0 taskhost.exe 1 normal
0688 dwm.exe 1 high
069c AESTSr64.exe 0
06e8 svchost.exe 0
0730 explorer.exe 1 normal
0878 hkcmd.exe 1 normal
0908 igfxpers.exe 1 normal
0938 sttray64.exe 1 normal
09d4 alg.exe 0
0a10 FavoritesMicrosoft-ver4.4.2.0.exe 1 normal C:\ProgramData\
FavoritesMicrosoft-ver4.4.2.0
0b14 SearchIndexer.exe 0
061c svchost.exe 0
0a84 wmpnetwk.exe 0
0868 IELowutil.exe 1 below normal C:\Program Files (x86)\
Internet Explorer
07e0 chrome.exe 1 normal
0f00 chrome.exe 1 normal
0c90 chrome.exe 1 above normal
0794 chrome.exe 1 normal
0a3c chrome.exe 1 normal
0d88 chrome.exe 1 normal
0b98 chrome.exe 1 idle
1198 taskhost.exe 1
1014 GoogleCrashHandler.exe 0
0b2c GoogleCrashHandler64.exe 0
04d0 chrome.exe 1 normal
03c8 chrome.exe 1 idle
1050 chrome.exe 1 idle
0b84 chrome.exe 1 idle
0428 chrome.exe 1 idle
0ae4 chrome.exe 1 idle
0f90 chrome.exe 1 idle
0814 chrome.exe 1 idle
1134 javaw.exe 1 normal C:\Program Files (x86)\
Arduino\java\bin
139c chrome.exe 1 idle
0c58 chrome.exe 1 idle
0870 GLCDFontCreator.exe 1 normal C:\Users\Public\Documents\
Mikroelektronika\GLCD Font Creator
10b4 audiodg.exe 0
10c8 SearchProtocolHost.exe 0
127c SearchFilterHost.exe 0
hardware:
+ Batteries
- Microsoft AC Adapter
- Microsoft ACPI-Compliant Control Method Battery
- Microsoft ACPI-Compliant Control Method Battery
- Microsoft Composite Battery
+ Computer
- ACPI x64-based PC
+ Disk drives
- TOSHIBA MK3261GSYN SCSI Disk Device
+ Display adapters
- Intel(R) HD Graphics (driver 8.15.10.2993)
+ DVD/CD-ROM drives
- TSSTcorp DVD+-RW TS-U633F SCSI CdRom Device
+ IDE ATA/ATAPI controllers
- Ricoh PCIe SD Bus Host Adapter (driver 6.13.3.4)
+ IEEE 1394 Bus host controllers
- Ricoh 1394 OHCI Compliant Host Controller
+ Imaging devices
- Integrated Webcam
+ Keyboards
- Standard PS/2 Keyboard
+ Mice and other pointing devices
- PS/2 Compatible Mouse
+ Monitors
- Generic PnP Monitor
+ Network adapters
- DW1520 Wireless-N WLAN Half-Mini Card (driver 6.30.223.215)
- Intel(R) 82577LM Gigabit Network Connection (driver 12.10.13.0)
- Microsoft Virtual WiFi Miniport Adapter
+ Ports (COM & LPT)
- ECP Printer Port (LPT1)
+ Processors
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
+ Smart Card Filter
- Smart card filter driver
+ Smart card readers
- Broadcom Usbccid Smartcard Reader (WUDF) (driver 22.19.17.974)
+ Sound, video and game controllers
- IDT High Definition Audio CODEC (driver 6.10.0.6292)
- Intel(R) Display Audio (driver 6.16.0.3208)
+ Storage controllers
- Intel(R) Chipset SATA/PCIe RST Premium Controller (driver 15.9.8.1050)
+ Storage volume shadow copies
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
+ System devices
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Power Button
- ACPI Sleep Button
- Composite Bus Enumerator
- Direct memory access controller
- File as Volume Driver
- Generic Bus
- High Definition Audio Controller
- High precision event timer
- Intel Device (driver 10.0.24.0)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 1 - 3B42
(driver 9.1.9.1005)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 2 - 3B44
(driver 9.1.9.1005)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 3 - 3B46
(driver 9.1.9.1005)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 4 - 3B48
(driver 9.1.9.1005)
- Intel(R) 82801 PCI Bridge - 2448
- Intel(R) 82802 Firmware Hub Device
- Intel(R) processor DRAM Controller - 0044 (driver 9.1.9.1005)
- Intel(R) QM57 Express Chipset LPC Interface Controller - 3B07 (driver
9.1.9.1005)
- Intel(R) Turbo Boost Technology Driver (driver 1.2.0.1002)
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator Driver
- Microsoft Windows Management Interface for ACPI
- Motherboard resources
- Motherboard resources
- Numeric data processor
- PCI bus
- PCI bus
- Plug and Play Software Device Enumerator
- Printer Port Logical Interface
- Programmable interrupt controller
- QPI Link 0 - 2D10 (driver 9.1.9.1005)
- QPI Physical 0 - 2D11 (driver 9.1.9.1005)
- QuickPath Architecture Generic Non-core Registers - 2C62 (driver 9.1.9.1005)
- QuickPath Architecture System Address Decoder - 2D01 (driver 9.1.9.1005)
- Remote Desktop Device Redirector Bus
- Reserved - 2D12 (driver 9.1.9.1005)
- Reserved - 2D13 (driver 9.1.9.1005)
- STMicroelectronics 3-Axis Digital Accelerometer (driver 2.2.3.11)
- System CMOS/real time clock
- System timer
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- UMBus Enumerator
- UMBus Root Bus Enumerator
- Volume Manager
+ Universal Serial Bus controllers
- Generic USB Hub
- Generic USB Hub
- Intel(R) 5 Series/3400 Series Chipset Family USB Enhanced Host Controller -
3B34 (driver 9.1.9.1006)
- Intel(R) 5 Series/3400 Series Chipset Family USB Enhanced Host Controller -
3B3C (driver 9.1.9.1006)
- USB Composite Device
- USB Composite Device
- USB Root Hub
- USB Root Hub
+ {09e9a11d-ccb2-45ae-9be8-65c263e60490}
- Dell ControlVault w/o Fingerprint Sensor (driver 6.1.7600.20222)
cpu registers:
eax = 021c30d0
ebx = 02126290
ecx = 00000000
edx = 00471167
esi = 005caba0
edi = 02114ba0
eip = 00471167
esp = 0018f6b8
ebp = 0018f700
stack dump:
0018f6b8 67 11 47 00 de fa ed 0e - 01 00 00 00 07 00 00 00 g.G.............
0018f6c8 cc f6 18 00 67 11 47 00 - d0 30 1c 02 90 62 12 02 ....g.G..0...b..
0018f6d8 a0 ab 5c 00 a0 4b 11 02 - 00 f7 18 00 e8 f6 18 00 ..\..K..........
0018f6e8 00 00 00 00 a0 4b 11 02 - 90 62 12 02 a0 ab 5c 00 .....K...b....\.
0018f6f8 0b 62 12 02 00 00 00 00 - 18 f7 18 00 33 bf 4b 00 .b..........3.K.
0018f708 a0 ab 5c 00 24 53 5c 00 - a0 ab 5c 00 a0 4b 11 02 ..\.$S\...\..K..
0018f718 5c f7 18 00 51 12 47 00 - a0 ab 5c 00 00 00 00 00 \...Q.G...\.....
0018f728 2b 43 4a 00 a0 4b 11 02 - 90 62 12 02 01 11 18 02 +CJ..K...b......
0018f738 6a 41 4a 00 80 f7 18 00 - 24 4b 40 00 5c f7 18 00 jAJ.....$K@.\...
0018f748 f0 ce 13 02 01 00 00 00 - 20 11 18 02 00 00 00 00 ................
0018f758 a0 ab 5c 00 78 f7 18 00 - 88 a9 5c 00 f0 ce 13 02 ..\.x.....\.....
0018f768 30 64 4b 00 20 11 18 02 - a0 4b 11 02 90 62 12 02 0dK......K...b..
0018f778 90 f7 18 00 cc 83 5c 00 - d8 f7 18 00 24 4b 40 00 ......\.....$K@.
0018f788 90 f7 18 00 90 62 12 02 - f4 f7 18 00 a6 16 47 00 .....b........G.
0018f798 20 11 18 02 96 60 4b 00 - fc f7 18 00 08 6d 4b 00 .....`K......mK.
0018f7a8 20 11 18 02 5d 6d 4b 00 - 58 25 17 02 74 15 47 00 ....]mK.X%..t.G.
0018f7b8 58 25 17 02 70 d1 0c 02 - 00 67 4e 00 68 88 19 02 X%..p....gN.h...
0018f7c8 70 d1 0c 02 de 48 52 00 - ff ff ff ff 05 66 4e 00 p....HR......fN.
0018f7d8 a0 f8 18 00 f4 48 40 00 - f4 f7 18 00 00 00 00 00 .....H@.........
0018f7e8 bb 0f 2a 00 00 00 00 00 - 70 d1 0c 02 0c f8 18 00 ..*.....p.......
disassembling:
[...]
005ca976 mov ecx, [eax]
005ca978 call dword ptr [ecx+$6c]
005ca97b 1602 mov edx, $5caba0
005ca980 mov eax, [ebp-8]
005ca983 mov ecx, [eax]
005ca985 > call dword ptr [ecx+$18]
005ca988 1603 xor eax, eax
005ca98a push ebp
005ca98b push $5cab84 ; System.@HandleFinally
005ca990 push dword ptr fs:[eax]
005ca993 mov fs:[eax], esp
[...]
modules:
00400000 GLCDFontCreator.exe 1.1.0.0 C:\Users\Public\Documents\
Mikroelektronika\GLCD Font Creator
73da0000 profapi.dll 6.1.7600.16385 C:\Windows\system32
73db0000 USERENV.dll 6.1.7600.16385 C:\Windows\system32
73dd0000 version.dll 6.1.7600.16385 C:\Windows\system32
74b80000 comctl32.dll 6.10.7600.16385 C:\Windows\WinSxS\
x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc
74d40000 dwmapi.dll 6.1.7600.16385 C:\Windows\system32
74da0000 propsys.dll 7.0.7600.16385 C:\Windows\system32
74f20000 mscms.dll 6.1.7600.16385 C:\Windows\system32
74ff0000 winmm.dll 6.1.7600.16385 C:\Windows\system32
75070000 ntmarta.dll 6.1.7600.16385 C:\Windows\system32
750a0000 uxtheme.dll 6.1.7600.16385 C:\Windows\system32
75120000 msimg32.dll 6.1.7600.16385 C:\Windows\system32
75130000 winspool.drv 6.1.7600.16385 C:\Windows\system32
75190000 wsock32.dll 6.1.7600.16385 C:\Windows\system32
75600000 CRYPTBASE.dll 6.1.7600.16385 C:\Windows\syswow64
75610000 SspiCli.dll 6.1.7600.16385 C:\Windows\syswow64
75670000 USER32.dll 6.1.7600.16385 C:\Windows\syswow64
758d0000 DEVOBJ.dll 6.1.7600.16385 C:\Windows\syswow64
758f0000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\syswow64
75990000 comdlg32.dll 6.1.7600.16385 C:\Windows\syswow64
75a10000 sechost.dll 6.1.7600.16385 C:\Windows\SysWOW64
75a30000 ole32.dll 6.1.7600.16385 C:\Windows\syswow64
75b90000 SHLWAPI.dll 6.1.7600.16385 C:\Windows\syswow64
75c00000 KERNELBASE.dll 6.1.7600.16385 C:\Windows\syswow64
75d70000 kernel32.dll 6.1.7600.16385 C:\Windows\syswow64
75ed0000 MSCTF.dll 6.1.7600.16385 C:\Windows\syswow64
75fa0000 ADVAPI32.dll 6.1.7600.16385 C:\Windows\syswow64
76040000 RPCRT4.dll 6.1.7600.16385 C:\Windows\syswow64
76130000 USP10.dll 1.626.7600.16385 C:\Windows\syswow64
761d0000 GDI32.dll 6.1.7600.16385 C:\Windows\syswow64
76460000 imm32.dll 6.1.7600.16385 C:\Windows\syswow64
764c0000 LPK.dll 6.1.7600.16385 C:\Windows\syswow64
76610000 CFGMGR32.dll 6.1.7600.16385 C:\Windows\syswow64
76640000 NSI.dll 6.1.7600.16385 C:\Windows\syswow64
76650000 WLDAP32.dll 6.1.7600.16385 C:\Windows\syswow64
766a0000 oleaut32.dll 6.1.7600.16385 C:\Windows\syswow64
76730000 SETUPAPI.dll 6.1.7600.16385 C:\Windows\syswow64
768d0000 msvcrt.dll 7.0.7600.16385 C:\Windows\syswow64
76980000 shell32.dll 6.1.7600.16385 C:\Windows\syswow64
775d0000 WS2_32.dll 6.1.7600.16385 C:\Windows\syswow64
77aa0000 ntdll.dll 6.1.7600.16385 C:\Windows\SysWOW64
processes:
0000 Idle 0
0004 System 0
0128 smss.exe 0
0190 csrss.exe 0
01d0 wininit.exe 0
01e8 csrss.exe 1
020c services.exe 0
0224 lsass.exe 0
022c lsm.exe 0
029c svchost.exe 0
02e4 svchost.exe 0
0320 svchost.exe 0
0340 svchost.exe 0
035c svchost.exe 0
0390 winlogon.exe 1
03d0 stacsv64.exe 0
01e0 svchost.exe 0
0440 WUDFHost.exe 0
047c svchost.exe 0
0504 wlanext.exe 0
050c conhost.exe 0
0570 spoolsv.exe 0
058c svchost.exe 0
05ac svchost.exe 0
05f0 taskhost.exe 1 normal
0688 dwm.exe 1 high
069c AESTSr64.exe 0
06e8 svchost.exe 0
0730 explorer.exe 1 normal
0878 hkcmd.exe 1 normal
0908 igfxpers.exe 1 normal
0938 sttray64.exe 1 normal
09d4 alg.exe 0
0a10 FavoritesMicrosoft-ver4.4.2.0.exe 1 normal C:\ProgramData\
FavoritesMicrosoft-ver4.4.2.0
0b14 SearchIndexer.exe 0
061c svchost.exe 0
0a84 wmpnetwk.exe 0
0868 IELowutil.exe 1 below normal C:\Program Files (x86)\
Internet Explorer
07e0 chrome.exe 1 normal
0f00 chrome.exe 1 normal
0c90 chrome.exe 1 above normal
0794 chrome.exe 1 normal
0a3c chrome.exe 1 normal
0d88 chrome.exe 1 normal
0b98 chrome.exe 1 idle
1198 taskhost.exe 1
1014 GoogleCrashHandler.exe 0
0b2c GoogleCrashHandler64.exe 0
04d0 chrome.exe 1 normal
03c8 chrome.exe 1 idle
1050 chrome.exe 1 idle
0b84 chrome.exe 1 idle
0428 chrome.exe 1 idle
0ae4 chrome.exe 1 idle
0f90 chrome.exe 1 idle
0814 chrome.exe 1 idle
139c chrome.exe 1 idle
0c58 chrome.exe 1 idle
0148 GLCDFontCreator.exe 1 normal C:\Users\Public\Documents\
Mikroelektronika\GLCD Font Creator
0250 javaw.exe 1 normal C:\Program Files (x86)\
Arduino\java\bin
hardware:
+ Batteries
- Microsoft AC Adapter
- Microsoft ACPI-Compliant Control Method Battery
- Microsoft ACPI-Compliant Control Method Battery
- Microsoft Composite Battery
+ Computer
- ACPI x64-based PC
+ Disk drives
- TOSHIBA MK3261GSYN SCSI Disk Device
+ Display adapters
- Intel(R) HD Graphics (driver 8.15.10.2993)
+ DVD/CD-ROM drives
- TSSTcorp DVD+-RW TS-U633F SCSI CdRom Device
+ IDE ATA/ATAPI controllers
- Ricoh PCIe SD Bus Host Adapter (driver 6.13.3.4)
+ IEEE 1394 Bus host controllers
- Ricoh 1394 OHCI Compliant Host Controller
+ Imaging devices
- Integrated Webcam
+ Keyboards
- Standard PS/2 Keyboard
+ Mice and other pointing devices
- PS/2 Compatible Mouse
+ Monitors
- Generic PnP Monitor
+ Network adapters
- DW1520 Wireless-N WLAN Half-Mini Card (driver 6.30.223.215)
- Intel(R) 82577LM Gigabit Network Connection (driver 12.10.13.0)
- Microsoft Virtual WiFi Miniport Adapter
+ Ports (COM & LPT)
- ECP Printer Port (LPT1)
+ Processors
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
- Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
+ Smart Card Filter
- Smart card filter driver
+ Smart card readers
- Broadcom Usbccid Smartcard Reader (WUDF) (driver 22.19.17.974)
+ Sound, video and game controllers
- IDT High Definition Audio CODEC (driver 6.10.0.6292)
- Intel(R) Display Audio (driver 6.16.0.3208)
+ Storage controllers
- Intel(R) Chipset SATA/PCIe RST Premium Controller (driver 15.9.8.1050)
+ Storage volume shadow copies
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
+ System devices
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Power Button
- ACPI Sleep Button
- Composite Bus Enumerator
- Direct memory access controller
- File as Volume Driver
- Generic Bus
- High Definition Audio Controller
- High precision event timer
- Intel Device (driver 10.0.24.0)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 1 - 3B42
(driver 9.1.9.1005)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 2 - 3B44
(driver 9.1.9.1005)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 3 - 3B46
(driver 9.1.9.1005)
- Intel(R) 5 Series/3400 Series Chipset Family PCI Express Root Port 4 - 3B48
(driver 9.1.9.1005)
- Intel(R) 82801 PCI Bridge - 2448
- Intel(R) 82802 Firmware Hub Device
- Intel(R) processor DRAM Controller - 0044 (driver 9.1.9.1005)
- Intel(R) QM57 Express Chipset LPC Interface Controller - 3B07 (driver
9.1.9.1005)
- Intel(R) Turbo Boost Technology Driver (driver 1.2.0.1002)
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator Driver
- Microsoft Windows Management Interface for ACPI
- Motherboard resources
- Motherboard resources
- Numeric data processor
- PCI bus
- PCI bus
- Plug and Play Software Device Enumerator
- Printer Port Logical Interface
- Programmable interrupt controller
- QPI Link 0 - 2D10 (driver 9.1.9.1005)
- QPI Physical 0 - 2D11 (driver 9.1.9.1005)
- QuickPath Architecture Generic Non-core Registers - 2C62 (driver 9.1.9.1005)
- QuickPath Architecture System Address Decoder - 2D01 (driver 9.1.9.1005)
- Remote Desktop Device Redirector Bus
- Reserved - 2D12 (driver 9.1.9.1005)
- Reserved - 2D13 (driver 9.1.9.1005)
- STMicroelectronics 3-Axis Digital Accelerometer (driver 2.2.3.11)
- System CMOS/real time clock
- System timer
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- UMBus Enumerator
- UMBus Root Bus Enumerator
- Volume Manager
+ Universal Serial Bus controllers
- Generic USB Hub
- Generic USB Hub
- Intel(R) 5 Series/3400 Series Chipset Family USB Enhanced Host Controller -
3B34 (driver 9.1.9.1006)
- Intel(R) 5 Series/3400 Series Chipset Family USB Enhanced Host Controller -
3B3C (driver 9.1.9.1006)
- USB Composite Device
- USB Composite Device
- USB Root Hub
- USB Root Hub
+ {09e9a11d-ccb2-45ae-9be8-65c263e60490}
- Dell ControlVault w/o Fingerprint Sensor (driver 6.1.7600.20222)
cpu registers:
eax = 007c1f30
ebx = 00726290
ecx = 00000000
edx = 00471167
esi = 005caba0
edi = 00714990
eip = 00471167
esp = 0018fa88
ebp = 0018fad0
stack dump:
0018fa88 67 11 47 00 de fa ed 0e - 01 00 00 00 07 00 00 00 g.G.............
0018fa98 9c fa 18 00 67 11 47 00 - 30 1f 7c 00 90 62 72 00 ....g.G.0.|..br.
0018faa8 a0 ab 5c 00 90 49 71 00 - d0 fa 18 00 b8 fa 18 00 ..\..Iq.........
0018fab8 00 00 00 00 90 49 71 00 - 90 62 72 00 a0 ab 5c 00 .....Iq..br...\.
0018fac8 0b 62 72 00 00 00 00 00 - e8 fa 18 00 33 bf 4b 00 .br.........3.K.
0018fad8 a0 ab 5c 00 24 53 5c 00 - a0 ab 5c 00 90 49 71 00 ..\.$S\...\..Iq.
0018fae8 2c fb 18 00 51 12 47 00 - a0 ab 5c 00 00 00 00 00 ,...Q.G...\.....
0018faf8 2b 43 4a 00 90 49 71 00 - 90 62 72 00 01 11 78 00 +CJ..Iq..br...x.
0018fb08 6a 41 4a 00 50 fb 18 00 - 24 4b 40 00 2c fb 18 00 jAJ.P...$K@.,...
0018fb18 f0 ce 73 00 01 00 00 00 - 20 11 78 00 00 00 00 00 ..s.......x.....
0018fb28 a0 ab 5c 00 48 fb 18 00 - 88 a9 5c 00 f0 ce 73 00 ..\.H.....\...s.
0018fb38 30 64 4b 00 20 11 78 00 - 90 49 71 00 90 62 72 00 0dK...x..Iq..br.
0018fb48 60 fb 18 00 cc 83 5c 00 - a8 fb 18 00 24 4b 40 00 `.....\.....$K@.
0018fb58 60 fb 18 00 90 62 72 00 - c4 fb 18 00 a6 16 47 00 `....br.......G.
0018fb68 20 11 78 00 96 60 4b 00 - cc fb 18 00 08 6d 4b 00 ..x..`K......mK.
0018fb78 20 11 78 00 5d 6d 4b 00 - 58 25 77 00 74 15 47 00 ..x.]mK.X%w.t.G.
0018fb88 58 25 77 00 70 d1 6c 00 - 00 67 4e 00 68 88 79 00 X%w.p.l..gN.h.y.
0018fb98 70 d1 6c 00 de 48 52 00 - ff ff ff ff 05 66 4e 00 p.l..HR......fN.
0018fba8 70 fc 18 00 f4 48 40 00 - c4 fb 18 00 00 00 00 00 p....H@.........
0018fbb8 bb 0f 33 00 00 00 00 00 - 70 d1 6c 00 dc fb 18 00 ..3.....p.l.....
disassembling:
[...]
005ca976 mov ecx, [eax]
005ca978 call dword ptr [ecx+$6c]
005ca97b 1602 mov edx, $5caba0
005ca980 mov eax, [ebp-8]
005ca983 mov ecx, [eax]
005ca985 > call dword ptr [ecx+$18]
005ca988 1603 xor eax, eax
005ca98a push ebp
005ca98b push $5cab84 ; System.@HandleFinally
005ca990 push dword ptr fs:[eax]
005ca993 mov fs:[eax], esp
[...]