EurekaLog 6.1.04 Application: ----------------------------------------------------------------------------------------------------------------------------------------------------------------- 1.1 Start Date : Tue, 15 Jul 2014 15:09:26 +1100 1.2 Name/Description: gsmeta.exe 1.3 Version Number : 6.0.5.8704 1.4 Parameters : "C:\Users\дпк23\Documents\СМЕТЫ\2014\80-кв. жилой дом в г. Бикин\Бикин ( по РД )\02-01-11 - электромонтажные работы теплового пункта.gsf" 1.5 Compilation Date: Fri, 17 Jan 2014 20:59:40 +1100 1.6 Up Time : 0 second Exception: ------------------------------------------------------------------------------------------------------------ 2.1 Date : Tue, 15 Jul 2014 15:09:27 +1100 2.2 Address : 77028DC9 2.3 Module Name : ntdll.dll - (Системная библиотека NT) 2.4 Module Version: 6.1.7601.17725 2.5 Type : EAccessViolation 2.6 Message : Access violation at address 77028DC9 in module 'ntdll.dll'. Write of address 00000014. 2.7 ID : C646 2.8 Count : 1 2.9 Status : New 2.10 Note : User: ------------------------------------------------------- 3.1 ID : дпк23 3.2 Name : 3.3 Email : 3.4 Company : 3.5 Privileges: SeIncreaseQuotaPrivilege - OFF SeSecurityPrivilege - OFF SeTakeOwnershipPrivilege - OFF SeLoadDriverPrivilege - OFF SeSystemProfilePrivilege - OFF SeSystemtimePrivilege - OFF SeProfileSingleProcessPrivilege - OFF SeIncreaseBasePriorityPrivilege - OFF SeCreatePagefilePrivilege - OFF SeBackupPrivilege - OFF SeRestorePrivilege - OFF SeShutdownPrivilege - OFF SeDebugPrivilege - OFF SeSystemEnvironmentPrivilege - OFF SeChangeNotifyPrivilege - ON SeRemoteShutdownPrivilege - OFF SeUndockPrivilege - OFF SeManageVolumePrivilege - OFF SeImpersonatePrivilege - ON SeCreateGlobalPrivilege - ON SeIncreaseWorkingSetPrivilege - OFF SeTimeZonePrivilege - OFF SeCreateSymbolicLinkPrivilege - OFF Active Controls: ----------------------------------- 4.1 Form Class : #32770 4.2 Form Text : Error occurred 4.3 Control Class: 4.4 Control Text : Computer: ----------------------------------------------------------------------------------- 5.1 Name : P23 5.2 Total Memory : 8076 Mb 5.3 Free Memory : 5289 Mb 5.4 Total Disk : 199,95 Gb 5.5 Free Disk : 177,71 Gb 5.6 System Up Time: 40 minutes, 42 seconds 5.7 Processor : Intel(R) Core(TM) i5-4440 CPU @ 3.10GHz 5.8 Display Mode : 1920 x 1080, 32 bit 5.9 Display DPI : 96 5.10 Video Card : Intel(R) HD Graphics 4600 (driver 9.18.10.3186 - RAM 2112 MB) 5.11 Printer : Canon iR1133 UFRII LT (driver 21.10) Operating System: -------------------------------------------- 6.1 Type : Microsoft Windows 7 (64 bit) 6.2 Build # : 7601 6.3 Update : Service Pack 1 6.4 Language: Russian 6.5 Charset : 204 Network: --------------------------------- 7.1 IP Address: 192.168.008.023 7.2 Submask : 255.255.255.000 7.3 Gateway : 192.168.008.001 7.4 DNS 1 : 212.019.002.001 7.5 DNS 2 : 212.019.003.001 7.6 DHCP : OFF Call Stack Information: ---------------------------------------------------------------------------------------------------- |Address |Module |Unit |Class |Procedure/Method |Line | ---------------------------------------------------------------------------------------------------- |*Exception Thread: ID=3752; Priority=0; Class=; [Main] | |--------------------------------------------------------------------------------------------------| |77028DC9|ntdll.dll | | | | | |770122A0|ntdll.dll | | |RtlEnterCriticalSection | | |009320C2|gsmeta.exe|Common.Logger.pas |TGSLoggerAbstractAppender|Flush |348[1] | |009320AC|gsmeta.exe|Common.Logger.pas |TGSLoggerAbstractAppender|Flush |347[0] | |00931FC8|gsmeta.exe|Common.Logger.pas |TGSLoggerAbstractAppender|Destroy |328[1] | |00931FB4|gsmeta.exe|Common.Logger.pas |TGSLoggerAbstractAppender|Destroy |327[0] | |0093223E|gsmeta.exe|Common.Logger.pas |TGSLoggerFileAppender |Destroy |382[1] | |77012260|ntdll.dll | | |RtlLeaveCriticalSection | | |7700012E|ntdll.dll | | |KiUserExceptionDispatcher| | |770122DF|ntdll.dll | | |RtlRestoreLastWin32Error | | |77012320|ntdll.dll | | |memcpy | | |00409DB0|gsmeta.exe|System.pas | |_RaiseExcept | | |0047A88D|gsmeta.exe|System.Classes.pas|TFileStream |Create | | |0047A768|gsmeta.exe|System.Classes.pas|TFileStream |Create | | |0047A744|gsmeta.exe|System.Classes.pas|TFileStream |Create | | |0047A724|gsmeta.exe|System.Classes.pas|TFileStream |Create | | |00932183|gsmeta.exe|Common.Logger.pas |TGSLoggerFileAppender |Create |369[3] | |00932134|gsmeta.exe|Common.Logger.pas |TGSLoggerFileAppender |Create |366[0] | |00940580|gsmeta.exe|Common.Bootlog.pas|TBootLogger |SetEnabled |125[14]| |00940444|gsmeta.exe|Common.Bootlog.pas|TBootLogger |SetEnabled |111[0] | |0144C29F|gsmeta.exe|Gs_StartUtils.pas |TInitializator |Create |254[2] | |0144C268|gsmeta.exe|Gs_StartUtils.pas |TInitializator |Create |252[0] | |0144B833|gsmeta.exe|Gs_StartUtils.pas |TInitializator |Init |138[2] | |0040A0EE|gsmeta.exe|System.pas | |InitUnits | | |0040A0AC|gsmeta.exe|System.pas | |InitUnits | | |0040A157|gsmeta.exe|System.pas | |_StartExe | | |0040A118|gsmeta.exe|System.pas | |_StartExe | | |0041026E|gsmeta.exe|SysInit.pas | |_InitExe | | ---------------------------------------------------------------------------------------------------- Modules Information: ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Handle |Name |Description |Version |Size |Modified |Path | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |00400000|gsmeta.exe | |6.0.5.8704 |28513568|2014-01-17 12:59:54|C:\program files (x86)\grand\grandsmeta 6\client | |04440000|SysInfo.dll | |6.1.1.8425 |3386656 |2014-01-17 12:58:38|C:\program files (x86)\grand\grandsmeta 6\client | |69D10000|olepro32.dll | |6.1.7601.17514 |90112 |2010-11-21 14:24:04|C:\Windows\system32 | |69D50000|oleacc.dll |Active Accessibility Core Component |7.0.0.0 |233472 |2011-08-27 15:26:28|C:\Windows\system32 | |6BB40000|gdiplus.dll |Microsoft GDI+ |6.1.7601.18120 |1625088 |2013-04-03 15:50:22|C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36 | |6C140000|WINSTA.dll |Winstation Library |6.1.7601.17514 |156672 |2010-11-21 14:23:56|C:\Windows\system32 | |6C170000|wtsapi32.dll |Windows Remote Desktop Session Host Server SDK APIs |6.1.7601.17514 |40448 |2010-11-21 14:23:56|C:\Windows\system32 | |6C190000|msimg32.dll |GDIEXT Client DLL |6.1.7600.16385 |4608 |2009-07-14 12:15:46|C:\Windows\system32 | |6C740000|dwmapi.dll |Интерфейс API диспетчера окон рабочего стола (Майкрософт) |6.1.7600.16385 |67072 |2009-07-14 12:15:14|C:\Windows\system32 | |6C900000|winspool.drv |Драйвер диспетчера очереди Windows |6.1.7601.17514 |320000 |2010-11-21 14:24:10|C:\Windows\system32 | |72960000|uxtheme.dll |Библиотека тем UxTheme (Microsoft) |6.1.7600.16385 |245760 |2009-07-14 12:11:26|C:\Windows\system32 | |72A80000|WINNSI.DLL |Network Store Information RPC interface |6.1.7600.16385 |16896 |2009-07-14 12:16:20|C:\Windows\system32 | |72A90000|iphlpapi.dll |IP Helper API |6.1.7601.17514 |103936 |2010-11-21 14:24:34|C:\Windows\system32 | |72BE0000|winmm.dll |MCI API DLL |6.1.7601.17514 |194048 |2010-11-21 14:24:18|C:\Windows\system32 | |72C20000|wsock32.dll |Windows Socket 32-Bit DLL |6.1.7600.16385 |15360 |2009-07-14 12:16:22|C:\Windows\system32 | |733A0000|Secur32.dll |Security Support Provider Interface |6.1.7601.18270 |22016 |2013-09-25 12:57:28|C:\Windows\system32 | |733B0000|rsaenh.dll |Microsoft Enhanced Cryptographic Provider |6.1.7600.16385 |242936 |2009-07-14 12:17:56|C:\Windows\system32 | |733F0000|CRYPTSP.dll |Cryptographic Service Provider API |6.1.7600.16385 |78848 |2009-07-14 12:15:08|C:\Windows\system32 | |73410000|mswsock.dll |Расширение поставщика службы API Microsoft Windows Sockets 2.0|6.1.7601.17514 |232448 |2010-11-21 14:24:10|C:\Windows\system32 | |73450000|comctl32.dll |Библиотека элементов управления взаимодействия с пользователем|6.10.7601.17514 |1680896 |2010-11-21 14:23:56|C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2| |74A40000|version.dll |Version Checking and File Installation Libraries |6.1.7600.16385 |21504 |2009-07-14 12:16:18|C:\Windows\system32 | |74A50000|profapi.dll |User Profile Basic API |6.1.7600.16385 |31744 |2009-07-14 12:16:14|C:\Windows\system32 | |74B40000|CRYPTBASE.dll |Base cryptographic API DLL |6.1.7600.16385 |36864 |2009-07-14 12:15:08|C:\Windows\syswow64 | |74B50000|SspiCli.dll |Security Support Provider Interface |6.1.7601.18270 |96768 |2013-09-25 12:58:18|C:\Windows\syswow64 | |74BB0000|kernel32.dll |Библиотека клиента Windows NT BASE API |6.1.7601.18409 |1114112 |2014-03-04 20:16:18|C:\Windows\syswow64 | |74CC0000|msvcrt.dll |Windows NT CRT DLL |7.0.7601.17744 |690688 |2011-12-16 18:53:00|C:\Windows\syswow64 | |74DC0000|shell32.dll |Общая библиотека оболочки Windows |6.1.7601.18222 |12872704|2013-07-26 12:56:00|C:\Windows\syswow64 | |75A10000|ADVAPI32.dll |Расширенная библиотека API Windows 32 |6.1.7601.17514 |640512 |2010-11-21 14:24:30|C:\Windows\syswow64 | |75AB0000|cfgmgr32.dll |Configuration Manager DLL |6.1.7601.17621 |145920 |2011-05-24 21:39:40|C:\Windows\syswow64 | |75AE0000|MSASN1.dll |ASN.1 Runtime APIs |6.1.7601.17514 |34304 |2010-11-21 14:23:50|C:\Windows\syswow64 | |75B50000|Imagehlp.dll |Windows NT Image Helper |6.1.7601.18288 |159232 |2013-10-19 12:37:00|C:\Windows\syswow64 | |75B90000|comdlg32.dll |Библиотека общих диалоговых окон |6.1.7601.17514 |485888 |2010-11-21 14:23:50|C:\Windows\syswow64 | |75C10000|urlmon.dll |Расширения OLE32 для Win32 |8.0.7601.18404 |1232896 |2014-02-24 13:05:16|C:\Windows\syswow64 | |75D50000|KERNELBASE.dll|Библиотека клиента Windows NT BASE API |6.1.7601.18229 |274944 |2013-08-02 12:50:44|C:\Windows\syswow64 | |75DA0000|ole32.dll |Microsoft OLE для Windows |6.1.7601.17514 |1414144 |2010-11-21 14:24:02|C:\Windows\syswow64 | |75F00000|MSCTF.dll |Серверная библиотека MSCTF |6.1.7600.16385 |828928 |2009-07-14 12:15:44|C:\Windows\syswow64 | |75FD0000|wininet.dll |Расширения Интернета для Win32 |8.0.7601.18404 |981504 |2014-02-24 13:05:26|C:\Windows\syswow64 | |76270000|GDI32.dll |GDI Client DLL |6.1.7601.18275 |311808 |2013-10-03 13:00:46|C:\Windows\syswow64 | |76300000|IMM32.DLL |Multi-User Windows IMM32 API Client DLL |6.1.7601.17514 |119808 |2010-11-21 14:24:26|C:\Windows\system32 | |76480000|user32.dll |Многопользовательская библиотека клиента USER API Windows |6.1.7601.17514 |833024 |2010-11-21 14:24:22|C:\Windows\syswow64 | |76580000|SHLWAPI.dll |Библиотека небольших программ оболочки |6.1.7601.17514 |350208 |2010-11-21 14:23:50|C:\Windows\syswow64 | |765E0000|wintrust.dll |Microsoft Trust Verification APIs |6.1.7601.18205 |175104 |2013-07-09 15:52:12|C:\Windows\syswow64 | |76610000|sechost.dll |Host for SCM/SDDL/LSA Lookup APIs |6.1.7600.16385 |92160 |2009-07-14 12:16:14|C:\Windows\SysWOW64 | |76630000|NSI.dll |NSI User-mode interface DLL |6.1.7600.16385 |8704 |2009-07-14 12:16:12|C:\Windows\syswow64 | |76640000|LPK.dll |Language Pack |6.1.7601.18177 |25600 |2013-06-06 15:57:02|C:\Windows\syswow64 | |76650000|CRYPT32.dll |API32 криптографии |6.1.7601.18277 |1168384 |2013-10-06 06:57:26|C:\Windows\syswow64 | |76770000|USP10.dll |Uniscribe Unicode script processor |1.626.7601.17514|626176 |2010-11-21 14:24:18|C:\Windows\syswow64 | |76830000|WS2_32.dll |32-разрядная библиотека Windows Socket 2.0 |6.1.7601.17514 |206848 |2010-11-21 14:23:56|C:\Windows\syswow64 | |76870000|RPCRT4.dll |Библиотека удаленного вызова процедур |6.1.7601.18205 |663552 |2013-07-09 15:52:34|C:\Windows\syswow64 | |76960000|iertutil.dll |Run time utility for Internet Explorer |8.0.7601.18404 |2078208 |2014-02-24 13:05:02|C:\Windows\syswow64 | |76B60000|oleaut32.dll | |6.1.7601.17676 |571904 |2011-08-27 15:26:28|C:\Windows\syswow64 | |76FC0000|PSAPI.DLL |Process Status Helper |6.1.7600.16385 |6144 |2009-07-14 12:16:14|C:\Windows\syswow64 | |76FF0000|ntdll.dll |Системная библиотека NT |6.1.7601.17725 |1292080 |2011-11-17 16:38:40|C:\Windows\SysWOW64 | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Processes Information: ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |ID |Name |Description |Version |Memory|Priority |Threads|Path | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |0 |[System Process] | | |0 | |4 | | |4 |System | | |0 |Normal |150 | | |160 |svchost.exe |Хост-процесс для служб Windows |6.1.7600.16385|0 |Normal |35 | | |204 |audiodg.exe | | |0 |Normal |8 | | |364 |smss.exe | | |0 |Above-Normal|2 | | |484 |chrome.exe |Google Chrome |35.0.1916.153 |0 |Below-Normal|10 |C:\Program Files (x86)\Google\Chrome\Application | |488 |csrss.exe | | |0 |High |9 | | |552 |wininit.exe |Автозагрузка приложений Windows |6.1.7600.16385|0 |High |3 | | |576 |csrss.exe | | |0 |High |13 | | |620 |services.exe | | |0 |Normal |11 | | |652 |lsass.exe | | |0 |Normal |10 | | |660 |winlogon.exe | | |0 |High |3 | | |668 |lsm.exe | | |0 |Normal |10 | | |768 |GSmeta.exe | |6.0.5.8704 |0 |Normal |4 | | |792 |svchost.exe |Хост-процесс для служб Windows |6.1.7600.16385|0 |Normal |11 | | |804 |SearchFilterHost.exe |Microsoft Windows Search Filter Host |7.0.7600.16385|0 |Low |5 | | |808 |svchost.exe |Хост-процесс для служб Windows |6.1.7600.16385|0 |Normal |28 | | |868 |svchost.exe |Хост-процесс для служб Windows |6.1.7600.16385|0 |Normal |9 | | |912 |chrome.exe |Google Chrome |35.0.1916.153 |0 |Below-Normal|11 |C:\Program Files (x86)\Google\Chrome\Application | |944 |svchost.exe |Хост-процесс для служб Windows |6.1.7600.16385|0 |Normal |21 | | |996 |svchost.exe |Хост-процесс для служб Windows |6.1.7600.16385|0 |Normal |27 | | |1212|svchost.exe |Хост-процесс для служб Windows |6.1.7600.16385|0 |Normal |16 | | |1332|spoolsv.exe | | |0 |Normal |20 | | |1360|svchost.exe |Хост-процесс для служб Windows |6.1.7600.16385|0 |Normal |20 | | |1456|agent.exe | | |0 |Normal |6 | | |1536|schedul2.exe | | |0 |Normal |9 | | |1544|LMS.exe | | |0 |Normal |6 | | |1568|armsvc.exe | | |0 |Normal |4 | | |1608|arsm.exe | | |0 |Normal |21 | | |1644|ekrn.exe | | |0 |Normal |20 | | |1716|HeciServer.exe |Intel(R) Capability Licensing Service Interface |1.27.798.1 |0 |Normal |4 | | |1760|mms.exe | | |0 |Normal |51 | | |1768|rserver3.exe | | |0 |Normal |9 | | |1816|svchost.exe |Хост-процесс для служб Windows |6.1.7600.16385|0 |Normal |9 | | |2136|taskhost.exe | | |0 |Normal |11 | | |2236|dwm.exe | | |0 |High |5 | | |2264|explorer.exe |Проводник |6.1.7601.17514|0 |Normal |44 | | |2312|IAStorDataMgrSvc.exe | | |0 |Normal |8 | | |2588|schedhlp.exe |Acronis Scheduler Helper |8.0.0.8200 |0 |Normal |2 |C:\Program Files (x86)\Common Files\Acronis\Schedule2 | |2596|TrayMonitor.exe |Acronis Backup & Recovery 11 Tray Monitor |11.5.0.32308 |0 |Normal |7 |C:\Program Files (x86)\Acronis\TrayMonitor | |2604|igfxtray.exe | | |0 |Normal |3 | | |2612|hkcmd.exe | | |0 |Normal |3 | | |2652|igfxpers.exe | | |0 |Normal |4 | | |2676|igfxsrvc.exe | | |0 |Normal |4 | | |2684|egui.exe | | |0 |Normal |6 | | |2740|CNMFSUT6.EXE | | |0 |Normal |6 | | |2756|GrandUM.exe | |1.0.21.8463 |0 |Normal |4 |C:\Program Files (x86)\Grand\UpdateManager | |2792|chrome.exe |Google Chrome |35.0.1916.153 |0 |Normal |33 |C:\Program Files (x86)\Google\Chrome\Application | |2840|iusb3mon.exe |iusb3mon |2.5.0.19 |0 |Normal |4 |C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application| |2860|TibMounterMonitor.exe |Acronis TIB Monitor |4.2.0.1077 |0 |Normal |5 |C:\Program Files (x86)\Common Files\Acronis\TibMounter | |2988|chrome.exe |Google Chrome |35.0.1916.153 |0 |Normal |11 |C:\Program Files (x86)\Google\Chrome\Application | |3060|chrome.exe |Google Chrome |35.0.1916.153 |0 |Normal |6 |C:\Program Files (x86)\Google\Chrome\Application | |3100|FamItrfc.Exe | | |0 |High |2 | | |3168|chrome.exe |Google Chrome |35.0.1916.153 |0 |Below-Normal|11 |C:\Program Files (x86)\Google\Chrome\Application | |3228|chrome.exe |Google Chrome |35.0.1916.153 |0 |Below-Normal|11 |C:\Program Files (x86)\Google\Chrome\Application | |3240|FamItrfc.Exe |Radmin component |3.4.0.1016 |0 |High |5 |C:\Windows\SysWOW64\rserver30 | |3344|GSmeta.exe | |6.0.5.8704 |0 |Normal |3 | | |3408|chrome.exe |Google Chrome |35.0.1916.153 |0 |Below-Normal|11 |C:\Program Files (x86)\Google\Chrome\Application | |3520|chrome.exe |Google Chrome |35.0.1916.153 |0 |Below-Normal|11 |C:\Program Files (x86)\Google\Chrome\Application | |3568|WmiPrvSE.exe |WMI Provider Host |6.1.7601.17514|0 |Normal |6 | | |3624|WmiPrvSE.exe |WMI Provider Host |6.1.7601.17514|0 |Normal |7 | | |3804|chrome.exe |Google Chrome |35.0.1916.153 |0 |Below-Normal|14 |C:\Program Files (x86)\Google\Chrome\Application | |3832|chrome.exe |Google Chrome |35.0.1916.153 |0 |Below-Normal|11 |C:\Program Files (x86)\Google\Chrome\Application | |3988|Jhi_service.exe |Intel(R) Dynamic Application Loader Host Interface|9.0.0.1323 |0 |Normal |4 | | |3996|svchost.exe |Хост-процесс для служб Windows |6.1.7600.16385|0 |Normal |14 | | |4068|SearchIndexer.exe |Индексатор службы Microsoft Windows Search |7.0.7600.16385|0 |Normal |14 | | |4412|chrome.exe |Google Chrome |35.0.1916.153 |0 |Below-Normal|11 |C:\Program Files (x86)\Google\Chrome\Application | |4512|GSmeta.exe | |6.0.5.8704 |0 |Normal |4 | | |4588|svchost.exe |Хост-процесс для служб Windows |6.1.7600.16385|0 |Normal |5 | | |4600|SearchProtocolHost.exe|Microsoft Windows Search Protocol Host |7.0.7600.16385|0 |Low |8 | | |4660|GSmeta.exe | |6.0.5.8704 |0 |Normal |4 | | |4668|WUDFHost.exe | | |0 |Normal |8 | | |4752|gsmeta.exe | |6.0.5.8704 |0 |Normal |4 |C:\program files (x86)\grand\grandsmeta 6\client | |4756|svchost.exe |Хост-процесс для служб Windows |6.1.7600.16385|0 |Normal |20 | | |4908|wmpnetwk.exe | | |0 |Normal |9 | | |4932|GSmeta.exe | |6.0.5.8704 |0 |Normal |3 | | |4976|IAStorIcon.exe |IAStorIcon |12.6.0.1033 |0 |Normal |7 |C:\Program Files\Intel\Intel(R) Rapid Storage Technology | |5028|chrome.exe |Google Chrome |35.0.1916.153 |0 |Normal |17 |C:\Program Files (x86)\Google\Chrome\Application | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Assembler Information: ------------------------------------------------------------ 77028DAC mov eax, ecx 77028DAE lock 77028DAF cmpxchg [edi], ebx 77028DB2 cmp eax, ecx 77028DB4 jnz -$000001A8 77028DBA xor eax, eax 77028DBC mov [ebp+$0C], eax 77028DBF mov [ebp+$08], eax 77028DC2 mov eax, [esi] 77028DC4 cmp eax, -$01 77028DC7 jz +$03 77028DC9 inc dword ptr [eax+$14] ; <-- EXCEPTION 77028DCC mov ebx, [ebp-$0C] 77028DCF mov edi, [ebp-$10] 77028DD2 cmp byte ptr [$7FFE0382], $00 77028DD9 jnz +$000499DA 77028DDF mov eax, [ebp-$04] 77028DE2 push edi 77028DE3 push $00 77028DE5 cmp eax, -$01 77028DE8 jz +$00049A23 77028DEE push eax Registers: ----------------------------- EAX: 00000000 EDI: 04DDC618 EBX: FFFFFFFC ESI: 04DDC614 ECX: 00000000 ESP: 0018F6A8 EDX: 00000004 EIP: 77028DC9 Stack: Memory Dump: ------------------ --------------------------------------------------------------------------- 0018F6A8: 04DDC614 05B501D0: FF 40 14 8B 5D F4 8B 7D F0 80 3D 82 03 FE 7F 00 .@..]..}..=..... 0018F6AC: 04DDC618 05B501E0: 0F 85 DA 99 04 00 8B 45 FC 57 6A 00 83 F8 FF 0F .......E.Wj..... 0018F6B0: 00408FD6 05B501F0: 84 23 9A 04 00 50 E8 A8 6A FE FF 3D 02 01 00 00 .#...P..j..=.... 0018F6B4: 00000000 05B50200: 0F 84 24 9A 04 00 85 C0 0F 8C B8 9A 04 00 83 7D ..$............} 0018F6B8: 00000000 05B50210: EC 00 0F 85 CC 00 00 00 5F 5E B8 02 00 00 00 5B ........_^.....[ 0018F6BC: 00000000 05B50220: 8B E5 5D C2 08 00 8B C1 33 45 FC 8B DE 8B D0 8B ..].....3E...... 0018F6C0: 00000000 05B50230: C1 F0 0F B1 13 3B C1 0F 85 F6 FD FF FF F7 45 F8 .....;........E. 0018F6C4: 00000000 05B50240: 00 00 00 02 0F 84 E2 FE FF FF 8B 47 14 8B D0 81 ...........G.... 0018F6C8: 00000000 05B50250: E2 FF FF FF 00 81 FA D0 07 00 00 0F 83 CB FE FF ................ 0018F6CC: 00000000 05B50260: FF 40 89 47 14 E9 C2 FE FF FF 8D 1B EB B8 F6 C3 .@.G............ 0018F6D0: 00000000 05B50270: 01 0F 84 56 9A 04 00 F6 C3 02 0F 84 17 94 FE FF ...V............ 0018F6D4: 00000000 05B50280: 8D 43 02 8B C8 8B C3 F0 0F B1 0F 3B C3 0F 85 04 .C.........;.... 0018F6D8: 00000000 05B50290: 94 FE FF 56 E8 0A 00 00 00 E9 F9 93 FE FF 90 90 ...V............ 0018F6DC: 00000000 05B502A0: 90 90 90 8B FF 55 8B EC 56 8B 75 08 8B 46 10 85 .....U..V.u..F.. 0018F6E0: 00000000 05B502B0: C0 0F 84 E1 98 04 00 6A 00 83 F8 FF 0F 84 E4 98 .......j........ 0018F6E4: 00000000 05B502C0: 04 00 50 E8 E3 6A FE FF 5E 85 C0 0F 8C E8 98 04 ..P..j..^.......