Sunteți pe pagina 1din 31

date/time : 2013-01-26, 11:11:23, 792ms

computer name : BRYAN-PC


user name : Bryan <admin>
registered owner : Windows User
operating system : Windows NT New build 9200
system language : English
system up time : 17 hours 44 minutes
program up time : 5 hours 10 minutes
processors : 2x Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
physical memory : 690/1916 MB (free/total)
free disk space : (C:) 22.20 GB (D:) 74.72 GB
display mode : 1366x768, 32 bit
process id : $948
allocated memory : 43.39 MB
command line : D:\Extract\JetClean\JetClean.exe /AutoCleanIdle
executable : JetClean.exe
current module : madExcept_.bpl
exec. date/time : 2011-11-18 10:13
version : 0.2.0.99
compiled with : Delphi 2009
madExcept version : 3.0i
callstack crc : $5013fd25, $d54ceb73, $d54ceb73
count : 5
exception number : 1
exception class : EOutOfResources
exception message : Unable to insert a line.
main thread ($1240):
5013fd25 +000 vcl120.bpl
0050820d +4d9 JetClean.exe uMain 3881 +99 TfrmImCleanMain.LoadConfig
005059d0 +27c JetClean.exe uMain 3155 +62 TfrmImCleanMain.initial
0050294a +14a JetClean.exe uMain 1920 +32 TfrmImCleanMain.AutoCleanIdle
0051ab7c +1fc JetClean.exe JetClean 164 +62 initialization
76d01864 +010 KERNEL32.dll BaseThreadInitThunk
thread $80c:
77994309 +05 ntdll.dll NtWaitForMultipleObjects
7530be86 +00 KERNELBASE.dll WaitForMultipleObjectsEx
77858bb3 +51 user32.dll MsgWaitForMultipleObjects
76d01864 +10 KERNEL32.dll BaseThreadInitThunk
modules:
00400000 JetClean.exe 0.2.0.99 D:\Extract\JetClean
0f040000 TaskSchedule.dll 1.1.0.227 D:\Extract\JetClean
50000000 rtl120.bpl 12.0.3170.16989 D:\Extract\JetClean
50120000 vcl120.bpl 12.0.3210.17555 D:\Extract\JetClean
50310000 vclx120.bpl 12.0.3210.17555 D:\Extract\JetClean
57000000 madBasic_.bpl D:\Extract\JetClean
57800000 madDisAsm_.bpl D:\Extract\JetClean
59800000 madExcept_.bpl D:\Extract\JetClean
60900000 sqlite3.dll D:\Extract\JetClean
68a90000 snxhk.dll 7.0.1474.765 C:\Program Files\AVAST Softwar
e\Avast
6c150000 oledlg.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
6e880000 WINMMBASE.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
6e8b0000 winmm.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
70670000 mpr.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
71020000 version.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
71030000 wsock32.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
726e0000 msimg32.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
72730000 winspool.drv 6.2.9200.16384 C:\WINDOWS\SYSTEM32
72850000 oleacc.dll 7.2.9200.16384 C:\WINDOWS\SYSTEM32
72b20000 comctl32.dll 6.10.9200.16384 C:\WINDOWS\WinSxS\x86_microsof
t.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985
730d0000 dwmapi.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
738c0000 WindowsCodecs.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
741b0000 uxtheme.dll 6.2.9200.16384 C:\WINDOWS\system32
74dd0000 SspiCli.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
74e00000 bcryptPrimitives.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
74e60000 CRYPTBASE.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
74fd0000 profapi.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
75300000 KERNELBASE.dll 6.2.9200.16384 C:\WINDOWS\system32
75410000 IMM32.DLL 6.2.9200.16384 C:\WINDOWS\system32
75440000 RPCRT4.dll 6.2.9200.16384 C:\WINDOWS\system32
75520000 gdiplus.dll 6.2.9200.16384 C:\WINDOWS\WinSxS\x86_microsof
t.windows.gdiplus_6595b64144ccf1df_1.0.9200.16384_none_cad2e541479289ac
75690000 NSI.dll 6.2.9200.16384 C:\WINDOWS\system32
756a0000 IMAGEHLP.DLL 6.2.9200.16384 C:\WINDOWS\system32
756c0000 SHCORE.DLL 6.2.9200.16384 C:\WINDOWS\system32
75740000 shell32.dll 6.2.9200.16384 C:\WINDOWS\system32
76810000 MSCTF.dll 6.2.9200.16384 C:\WINDOWS\system32
768f0000 comdlg32.dll 6.2.9200.16384 C:\WINDOWS\system32
76980000 ole32.dll 6.2.9200.16384 C:\WINDOWS\system32
76aa0000 combase.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
76c40000 msvcrt.dll 7.0.9200.16384 C:\WINDOWS\system32
76d00000 KERNEL32.dll 6.2.9200.16384 C:\WINDOWS\system32
76e00000 sechost.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
76e40000 wininet.dll 10.0.9200.16384 C:\WINDOWS\system32
77000000 WS2_32.dll 6.2.9200.16384 C:\WINDOWS\system32
77200000 iertutil.dll 10.0.9200.16384 C:\WINDOWS\system32
773a0000 advapi32.dll 6.2.9200.16384 C:\WINDOWS\system32
77570000 gdi32.dll 6.2.9200.16384 C:\WINDOWS\system32
77680000 clbcatq.dll 2001.12.10130.16384 C:\WINDOWS\SYSTEM32
77760000 shlwapi.dll 6.2.9200.16384 C:\WINDOWS\system32
777a0000 oleaut32.dll 6.2.9200.16384 C:\WINDOWS\system32
77830000 psapi.dll 6.2.9200.16384 C:\WINDOWS\system32
77850000 user32.dll 6.2.9200.16384 C:\WINDOWS\system32
77980000 ntdll.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
processes:
0000 Idle 0 0 0
0004 System 0 0 0
01bc smss.exe 0 0 0
0258 csrss.exe 0 0 0
0324 wininit.exe 0 0 0
033c csrss.exe 1 0 0
0380 winlogon.exe 1 0 0
03ac services.exe 0 0 0
03b4 lsass.exe 0 0 0
0410 svchost.exe 0 0 0
0454 svchost.exe 0 0 0
0490 svchost.exe 0 0 0
04b8 dwm.exe 1 0 0
04c8 svchost.exe 0 0 0
04e4 svchost.exe 0 0 0
0558 svchost.exe 0 0 0
05d4 svchost.exe 0 0 0
0644 AvastSvc.exe 0 0 0
06f4 Explorer.EXE 1 2154 1247 normal C:\WINDOWS
07ec spoolsv.exe 0 0 0
0114 svchost.exe 0 0 0
0264 taskhostex.exe 1 13 21 normal C:\WINDOWS\syst
em32
0340 taskhost.exe 1 9 6 normal C:\WINDOWS\syst
em32
06d4 spd.exe 0 0 0
0668 WinFLService.exe 0 0 0
0664 mepService.exe 0 0 0
081c mep.exe 1 93 103 normal C:\Program File
s\EPSON\MyEpson Portal
0830 NBService.exe 0 0 0
0864 NitroPDFDriverService8.exe 0 0 0
0898 IoctlSvc.exe 0 0 0
08c0 TosBtSrv.exe 0 0 0
0918 TuneUpUtilitiesService32.exe 0 0 0
0acc SearchIndexer.exe 0 0 0
0b44 svchost.exe 0 0 0
0bb0 TuneUpUtilitiesApp32.exe 1 508 205 normal C:\Program File
s\TuneUp Utilities 2013
0bdc OSPPSVC.EXE 0 0 0
0d2c sppsvc.exe 0 0 0
0e1c UnlockerAssistant.exe 1 12 7 normal C:\Program File
s\Unlocker
0e2c ISUSPM.exe 1 9 5 normal C:\ProgramData\
FLEXnet\Connect\11
0e70 AvastUI.exe 1 125 38 normal C:\Program File
s\AVAST Software\Avast
0f08 EVDOHelp.exe 1 9 3 normal C:\Program File
s\CDMA-1XDO
0f2c cfosspeed.exe 1 34 21 normal C:\Program File
s\cFosSpeed
0ffc RtHDVCpl.exe 1 54 11 normal C:\Program File
s\Realtek\Audio\HDA
06f0 SynTPEnh.exe 1 66 34 above normal C:\Program File
s\Synaptics\SynTP
0dc4 Screenpresso.exe 1 30 17 normal C:\Users\Bryan\
AppData\Local\Learnpulse\Screenpresso
0eac SynTPHelper.exe 1 9 3 above normal C:\Program File
s\Synaptics\SynTP
0fa4 IDMan.exe 1 89 68 normal C:\Program File
s\Internet Download Manager
0fc8 SppExtComObj.Exe 0 0 0
029c IEMonitor.exe 1 17 17 normal C:\Program File
s\Internet Download Manager
0994 mediaget.exe 1 64 51 normal C:\Users\Bryan\
AppData\Local\MediaGet2
0cbc WinFLTray.exe 1 19 14 normal C:\Windows\Syst
em32
0d9c TosBtMng.exe 1 40 29 normal C:\Program File
s\Toshiba\Bluetooth Toshiba Stack
0fcc WmiPrvSE.exe 0 0 0
07c0 TosA2dp.exe 1 19 32 normal C:\Program File
s\Toshiba\Bluetooth Toshiba Stack
0eec TosBtHid.exe 1 15 9 normal C:\Program File
s\Toshiba\Bluetooth Toshiba Stack
0eb0 TosBtHsp.exe 1 18 38 normal C:\Program File
s\Toshiba\Bluetooth Toshiba Stack
0f40 TosAVRC.exe 1 20 34 normal C:\Program File
s\Toshiba\Bluetooth Toshiba Stack
1010 unsecapp.exe 1 9 3 normal C:\WINDOWS\syst
em32\wbem
1520 Warcraft III.exe 1 4 1 normal C:\Program File
s\Warcraft III Reign of Chaos & The Frozen Throne
1050 rundll32.exe 1 15 6 below normal C:\WINDOWS\syst
em32
15e4 war3.exe 1 0 0
1484 audiodg.exe 0 0 0
113c firefox.exe 1 491 445 normal C:\Program File
s\Mozilla Firefox
13c4 plugin-container.exe 1 25 25 normal C:\Program File
s\Mozilla Firefox
09ac FlashPlayerPlugin_11_5_502_146.exe 1 9 9 normal C:\WINDOWS\syst
em32\Macromed\Flash
07a4 FlashPlayerPlugin_11_5_502_146.exe 1 31 84 normal C:\WINDOWS\syst
em32\Macromed\Flash
1118 prevhost.exe 1 72 49 normal C:\WINDOWS\syst
em32
0d94 WINWORD.EXE 1 420 191 normal C:\Program File
s\Microsoft Office\Office14
0b5c splwow64.exe 1 4 2 normal C:\WINDOWS
05f0 NitroPDF.exe 1 820 328 normal C:\PROGRA~1\Nit
ro\PRO8~1
0470 Nitro_PIPAssistant.exe 1 36 12 normal C:\PROGRA~1\Nit
ro\PRO8~1
05ac taskhost.exe 1 9 3 normal C:\WINDOWS\syst
em32
1178 WinRAR.exe 1 135 48 normal C:\Program File
s\WinRAR
1320 taskeng.exe 1 9 3 normal C:\WINDOWS\syst
em32
0948 JetClean.exe 1 384 153 below normal D:\Extract\JetC
lean
1690 taskeng.exe 0 0 0
0c68 tosOBEX.exe 1 29 34 normal C:\Program File
s\Toshiba\Bluetooth Toshiba Stack
0b94 TosBtProc.exe 1 15 8 normal C:\Program File
s\TOSHIBA\Bluetooth Toshiba Stack
hardware:
+ Bluetooth
- Bluetooth RFBNEP (driver 6.0.303.0)
- Bluetooth RFBUS (driver 6.3.2206.0)
- Bluetooth RFCOMM (driver 6.0.219.0)
- Bluetooth RFCOMM (driver 6.0.219.0)
- Bluetooth RFHID (driver 6.0.2705.0)
- Bluetooth USB Controller-7 from TOSHIBA (driver 6.0.1519.0)
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
- Fax
- Microsoft XPS Document Writer
- Nitro PDF Creator (Pro 8)
- Root Print Queue
- Send To OneNote 2010
+ {36fc9e60-c465-11cf-8056-444553540000}
- Intel(R) ICH9 Family USB Universal Host Controller - 2934
- Intel(R) ICH9 Family USB Universal Host Controller - 2935
- Intel(R) ICH9 Family USB Universal Host Controller - 2936
- Intel(R) ICH9 Family USB Universal Host Controller - 2937
- Intel(R) ICH9 Family USB Universal Host Controller - 2938
- Intel(R) ICH9 Family USB Universal Host Controller - 2939
- Intel(R) ICH9 Family USB2 Enhanced Host Controller - 293A
- Intel(R) ICH9 Family USB2 Enhanced Host Controller - 293C
- USB Composite Device
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
+ {4d36e965-e325-11ce-bfc1-08002be10318}
- TSSTcorp CDDVDW TS-L633A ATA Device
+ {4d36e966-e325-11ce-bfc1-08002be10318}
- ACPI x86-based PC
+ {4d36e967-e325-11ce-bfc1-08002be10318}
- TOSHIBA MK3263GSX ATA Device
+ {4d36e968-e325-11ce-bfc1-08002be10318}
- Mobile Intel(R) 4 Series Express Chipset Family (Microsoft Corporation - WDD
M 1.1) (driver 8.15.10.2702)
- Mobile Intel(R) 4 Series Express Chipset Family (Microsoft Corporation - WDD
M 1.1) (driver 8.15.10.2702)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
- ATA Channel 0
- ATA Channel 0
- ATA Channel 1
- ATA Channel 1
- Standard Dual Channel PCI IDE Controller
- Standard Dual Channel PCI IDE Controller
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
- Standard PS/2 Keyboard
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
- High Definition Audio Device
- Realtek High Definition Audio (driver 6.0.1.5809)
+ {4d36e96d-e325-11ce-bfc1-08002be10318}
- Standard 33600 bps Modem
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
- Generic PnP Monitor
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
- HID-compliant mouse
- Synaptics PS/2 Port TouchPad (driver 12.2.10.0)
+ {4d36e972-e325-11ce-bfc1-08002be10318}
- Bluetooth Personal Area Network (driver 6.0.312.0)
- Realtek PCIe FE Family Controller
- Realtek RTL8191SE Wireless LAN 802.11n PCI-E NIC
+ {4d36e978-e325-11ce-bfc1-08002be10318}
- BT Port (COM10) (driver 5.0.2725.0)
- BT Port (COM11) (driver 5.0.2725.0)
- BT Port (COM12) (driver 5.0.2725.0)
- BT Port (COM13) (driver 5.0.2725.0)
- BT Port (COM14) (driver 5.0.2725.0)
- BT Port (COM20) (driver 5.0.2725.0)
- BT Port (COM21) (driver 5.0.2725.0)
- BT Port (COM22) (driver 5.0.2725.0)
- BT Port (COM40) (driver 5.0.2725.0)
- BT Port (COM7) (driver 5.0.2725.0)
- BT Port (COM8) (driver 5.0.2725.0)
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
- Microsoft Storage Spaces Controller
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
- ACPI Fan
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Power Button
- ACPI Thermal Zone
- Bluetooth ACPI (driver 5.0.1023.0)
- Composite Bus Enumerator
- Direct Application Launch Button
- Direct memory access controller
- High Definition Audio Controller
- High precision event timer
- Intel(R) 82801 PCI Bridge - 2448
- Intel(R) ICH9 Family PCI Express Root Port 1 - 2940
- Intel(R) ICH9 Family PCI Express Root Port 2 - 2942
- Intel(R) ICH9 Family PCI Express Root Port 5 - 2948
- Intel(R) ICH9 Family SMBus Controller - 2930
- Intel(R) ICH9M LPC Interface Controller - 2919
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft Basic Display Driver
- Microsoft Basic Render Driver
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator
- Mobile Intel(R) 4 Series Chipset Processor to DRAM Controller - 2A40
- Motherboard resources
- Numeric data processor
- PCI Express Root Complex
- Plug and Play Software Device Enumerator
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- System CMOS/real time clock
- System timer
- TOSHIBA Firmware Linkage Driver (driver 1.0.0.3)
- TOSHIBA x86 ACPI-Compliant Value Added Logical and General Purpose Device (d
river 2.0.0.1)
- UMBus Root Bus Enumerator
- Volume Manager
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
- Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
- Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
+ {533c5b84-ec70-11d2-9505-00c04f79deaf}
- Generic volume shadow copy
+ {6bdd1fc6-810f-11d0-bec7-08002be2092f}
- USB2.0 UVC WebCam
+ {72631e54-78a4-11d0-bcf7-00aa00b7b32a}
- Microsoft AC Adapter
- Microsoft ACPI-Compliant Control Method Battery
+ {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
- USB Input Device
+ {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
- Microphone (Realtek High Definition Audio)
- Speakers (Realtek High Definition Audio)
cpu registers:
eax = 0013fdd8
ebx = ffffffff
ecx = 00000007
edx = 00000000
esi = 00508638
edi = 03cec91c
eip = 7531277c
esp = 0013fdd8
ebp = 0013fe30
stack dump:
0013fdd8 de fa ed 0e 01 00 00 00 - 00 00 00 00 7c 27 31 75 ............|'1u
0013fde8 07 00 00 00 25 fd 13 50 - 78 d5 48 04 ff ff ff ff ....%..Px.H.....
0013fdf8 38 86 50 00 1c c9 ce 03 - 7c fe 13 00 64 fe 13 00 8.P.....|...d...
0013fe08 01 00 00 00 00 00 00 00 - 25 fd 13 50 07 00 00 00 ........%..P....
0013fe18 7c fe 13 00 73 15 80 59 - 22 00 00 00 78 c6 83 59 |...s..Y"...x..Y
0013fe28 78 d5 48 04 34 57 df 2d - 7c fe 13 00 25 fd 13 50 x.H.4W.-|...%..P
0013fe38 de fa ed 0e 01 00 00 00 - 07 00 00 00 48 fe 13 00 ............H...
0013fe48 25 fd 13 50 78 d5 48 04 - ff ff ff ff 38 86 50 00 %..Px.H.....8.P.
0013fe58 1c c9 ce 03 7c fe 13 00 - 64 fe 13 00 84 fe 13 00 ....|...d.......
0013fe68 70 7c 00 50 7c fe 13 00 - f0 96 76 01 f0 96 76 01 p|.P|.....v...v.
0013fe78 00 00 00 00 c0 fe 13 00 - 10 82 50 00 c8 fe 13 00 ..........P.....
0013fe88 70 7c 00 50 c0 fe 13 00 - 70 07 4e 04 f0 96 76 01 p|.P....p.N...v.
0013fe98 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0013fea8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0013feb8 00 00 00 00 00 00 00 00 - 00 ff 13 00 d5 59 50 00 .............YP.
0013fec8 08 ff 13 00 70 7c 00 50 - 00 ff 13 00 00 00 00 00 ....p|.P........
0013fed8 f0 96 76 01 00 00 00 00 - 00 00 00 00 00 00 00 00 ..v.............
0013fee8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0013fef8 00 00 00 00 00 00 00 00 - 38 ff 13 00 4f 29 50 00 ........8...O)P.
0013ff08 40 ff 13 00 70 7c 00 50 - 38 ff 13 00 00 00 00 00 @...p|.P8.......
disassembling:
[...]
005081f8 jmp loc_508220
005081fa 03881 mov eax, [esi+$5a0]
00508200 mov eax, [eax+$29c]
00508206 mov edx, $508638
0050820b mov ecx, [eax]
0050820d > call dword ptr [ecx+$38]
00508210 03882 xor edx, edx
00508212 mov eax, [esi+$5a0]
00508218 mov ecx, [eax]
0050821a call dword ptr [ecx+$e0]
00508220 03885 mov eax, [esi+$abc]
[...]
date/time : 2013-02-19, 16:17:14, 947ms
computer name : BRYAN-PC
user name : Bryan <admin>
registered owner : Windows User
operating system : Windows NT New build 9200
system language : English
system up time : 1 day 8 hours
program up time : 1 hour 46 minutes
processors : 2x Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
physical memory : 610/1916 MB (free/total)
free disk space : (C:) 18.70 GB (D:) 71.55 GB
display mode : 1366x768, 32 bit
process id : $1f2c
allocated memory : 41.96 MB
command line : D:\Extract\JetClean\JetClean.exe /AutoCleanIdle
executable : JetClean.exe
current module : madExcept_.bpl
exec. date/time : 2011-11-18 10:13
version : 0.2.0.99
compiled with : Delphi 2009
madExcept version : 3.0i
callstack crc : $09387b50, $44f4bf96, $2bbf13a0
exception number : 1
exception class : EOutOfResources
exception message : Not enough timers available.
main thread ($1fb4):
50162d51 +069 vcl120.bpl Extctrls TTimer.UpdateTimer
50162d7c +008 vcl120.bpl Extctrls TTimer.SetEnabled
004aeb18 +024 JetClean.exe PAnimateImageNote 67 +8 TAnimateImageNote.SetAnima
te
00512065 +21d JetClean.exe uMain 6615 +49 TfrmImCleanMain.ScanRegist
ry
00510d7c +02c JetClean.exe uMain 6306 +7 TfrmImCleanMain.Scan
00500439 +131 JetClean.exe uMain 1230 +38 TfrmImCleanMain.btnScanCli
ck
0050db45 +031 JetClean.exe uMain 5416 +5 TfrmImCleanMain.nScanRepai
rClick
005029d2 +1d2 JetClean.exe uMain 1929 +41 TfrmImCleanMain.AutoCleanI
dle
0051ab7c +1fc JetClean.exe JetClean 164 +62 initialization
772b1864 +010 KERNEL32.dll BaseThreadInitThunk
thread $1e48:
775b4309 +05 ntdll.dll NtWaitForMultipleObjects
74d8be86 +00 KERNELBASE.dll WaitForMultipleObjectsEx
75a78bb3 +51 user32.dll MsgWaitForMultipleObjects
772b1864 +10 KERNEL32.dll BaseThreadInitThunk
thread $23dc:
775b5ac1 +05 ntdll.dll NtDelayExecution
74d8124c +b5 KERNELBASE.dll SleepEx
74d81189 +0a KERNELBASE.dll Sleep
004cd7a9 +31 JetClean.exe Unit_JunkfilesThread 281 +13 TJunkfilesThread.Execut
e
772b1864 +10 KERNEL32.dll BaseThreadInitThunk
thread $239c:
775b5ac1 +05 ntdll.dll NtDelayExecution
74d8124c +b5 KERNELBASE.dll SleepEx
74d81189 +0a KERNELBASE.dll Sleep
004baf93 +43 JetClean.exe Unit_PrivacyThread 426 +18 TPrivacyThread.Execute
772b1864 +10 KERNEL32.dll BaseThreadInitThunk
thread $236c:
775b42b9 +05 ntdll.dll NtWaitForWorkViaWorkerFactory
772b1864 +10 KERNEL32.dll BaseThreadInitThunk
thread $23fc:
>> stack not accessible
thread $2424:
775b42b9 +05 ntdll.dll NtWaitForWorkViaWorkerFactory
772b1864 +10 KERNEL32.dll BaseThreadInitThunk
thread $2414:
775b4309 +05 ntdll.dll NtWaitForMultipleObjects
74d8be86 +00 KERNELBASE.dll WaitForMultipleObjectsEx
772b1864 +10 KERNEL32.dll BaseThreadInitThunk
modules:
00400000 JetClean.exe 0.2.0.99 D:\Extract\JetClean
10000000 UnlockerHook.dll C:\Program Files\Unlocker
50000000 rtl120.bpl 12.0.3170.16989 D:\Extract\JetClean
50120000 vcl120.bpl 12.0.3210.17555 D:\Extract\JetClean
50310000 vclx120.bpl 12.0.3210.17555 D:\Extract\JetClean
57000000 madBasic_.bpl D:\Extract\JetClean
57800000 madDisAsm_.bpl D:\Extract\JetClean
59800000 madExcept_.bpl D:\Extract\JetClean
60900000 sqlite3.dll D:\Extract\JetClean
65520000 wbemdisp.dll 6.2.9200.16384 C:\WINDOWS\system32\wbem
67ad0000 wbemprox.dll 6.2.9200.16384 C:\WINDOWS\system32\wbem
67ae0000 wmiutils.dll 6.2.9200.16384 C:\WINDOWS\system32\wbem
68460000 wbemcomn.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
6c6d0000 snxhk.dll 7.0.1474.765 C:\Program Files\AVAST Softwar
e\Avast
6c8f0000 wbemsvc.dll 6.2.9200.16384 C:\WINDOWS\system32\wbem
6c900000 fastprox.dll 6.2.9200.16384 C:\WINDOWS\system32\wbem
6da90000 TaskSchedule.dll 1.1.0.227 D:\Extract\JetClean
6e020000 oledlg.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
6e0a0000 msimg32.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
6e720000 Secur32.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
6eb10000 winspool.drv 6.2.9200.16384 C:\WINDOWS\SYSTEM32
6ee80000 WINMMBASE.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
6eeb0000 winmm.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
70ab0000 version.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
70b20000 wsock32.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
71130000 mpr.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
719c0000 XmlLite.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
71df0000 taskschd.dll 6.2.9200.16384 C:\Windows\System32
72ba0000 oleacc.dll 7.2.9200.16384 C:\WINDOWS\SYSTEM32
732f0000 comctl32.dll 6.10.9200.16384 C:\WINDOWS\WinSxS\x86_microsof
t.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985
734f0000 dwmapi.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
73a30000 WindowsCodecs.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
73dc0000 uxtheme.dll 6.2.9200.16453 C:\WINDOWS\system32
742d0000 rsaenh.dll 6.2.9200.16384 C:\WINDOWS\system32
745b0000 CRYPTSP.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
749d0000 SspiCli.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
74a10000 bcryptPrimitives.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
74a70000 CRYPTBASE.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
74a80000 sxs.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
74be0000 profapi.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
74d80000 KERNELBASE.dll 6.2.9200.16384 C:\WINDOWS\system32
75020000 gdi32.dll 6.2.9200.16384 C:\WINDOWS\system32
75130000 iertutil.dll 10.0.9200.16453 C:\WINDOWS\system32
75330000 urlmon.dll 10.0.9200.16453 C:\WINDOWS\system32
75460000 sechost.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
754a0000 clbcatq.dll 2001.12.10130.16384 C:\WINDOWS\SYSTEM32
75520000 NSI.dll 6.2.9200.16384 C:\WINDOWS\system32
75530000 psapi.dll 6.2.9200.16384 C:\WINDOWS\system32
75540000 combase.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
75830000 ole32.dll 6.2.9200.16384 C:\WINDOWS\system32
75950000 IMAGEHLP.DLL 6.2.9200.16384 C:\WINDOWS\system32
75970000 IMM32.DLL 6.2.9200.16384 C:\WINDOWS\system32
759a0000 shlwapi.dll 6.2.9200.16384 C:\WINDOWS\system32
759e0000 oleaut32.dll 6.2.9200.16384 C:\WINDOWS\system32
75a70000 user32.dll 6.2.9200.16384 C:\WINDOWS\system32
75ba0000 shell32.dll 6.2.9200.16384 C:\WINDOWS\system32
76c70000 SHCORE.DLL 6.2.9200.16384 C:\WINDOWS\system32
76cf0000 wininet.dll 10.0.9200.16453 C:\WINDOWS\system32
76eb0000 MSCTF.dll 6.2.9200.16384 C:\WINDOWS\system32
76f90000 comdlg32.dll 6.2.9200.16384 C:\WINDOWS\system32
77020000 gdiplus.dll 6.2.9200.16384 C:\WINDOWS\WinSxS\x86_microsof
t.windows.gdiplus_6595b64144ccf1df_1.0.9200.16384_none_cad2e541479289ac
77190000 msvcrt.dll 7.0.9200.16384 C:\WINDOWS\system32
772b0000 KERNEL32.dll 6.2.9200.16384 C:\WINDOWS\system32
773c0000 WS2_32.dll 6.2.9200.16384 C:\WINDOWS\system32
77410000 RPCRT4.dll 6.2.9200.16384 C:\WINDOWS\system32
774f0000 advapi32.dll 6.2.9200.16384 C:\WINDOWS\system32
775a0000 ntdll.dll 6.2.9200.16384 C:\WINDOWS\SYSTEM32
processes:
0000 Idle 0 0 0
0004 System 0 0 0
01b8 smss.exe 0 0 0
0260 csrss.exe 0 0 0
0314 csrss.exe 1 0 0
031c wininit.exe 0 0 0
0354 winlogon.exe 1 0 0
0374 services.exe 0 0 0
037c lsass.exe 0 0 0
03d4 svchost.exe 0 0 0
0418 svchost.exe 0 0 0
0468 dwm.exe 1 0 0
0474 svchost.exe 0 0 0
04cc svchost.exe 0 0 0
0528 svchost.exe 0 0 0
0554 svchost.exe 0 0 0
062c svchost.exe 0 0 0
0664 Explorer.EXE 1 2157 1102 normal C:\WINDOWS
0694 AvastSvc.exe 0 0 0
070c spoolsv.exe 0 0 0
0730 svchost.exe 0 0 0
07d8 spd.exe 0 0 0
01d4 FBDefragSrv.exe 0 0 0
01f4 mepService.exe 0 0 0
03a8 NBService.exe 0 0 0
0448 mep.exe 1 93 103 normal C:\Program File
s\EPSON\MyEpson Portal
065c taskhostex.exe 1 13 16 normal C:\WINDOWS\syst
em32
0748 taskhost.exe 1 9 9 normal C:\WINDOWS\syst
em32
0a90 NitroPDFDriverService8.exe 0 0 0
0b10 IoctlSvc.exe 0 0 0
0b34 svchost.exe 0 0 0
0b74 TosBtSrv.exe 0 0 0
0bc8 TuneUpUtilitiesService32.exe 0 0 0
0c20 UnlockerAssistant.exe 1 12 7 normal C:\Program File
s\Unlocker
0c7c OSPPSVC.EXE 0 0 0
0c88 AvastUI.exe 1 125 38 normal C:\Program File
s\AVAST Software\Avast
0d7c SearchIndexer.exe 0 0 0
0dd4 svchost.exe 0 0 0
0df8 RtHDVCpl.exe 1 54 11 normal C:\Program File
s\Realtek\Audio\HDA
0e78 TuneUpUtilitiesApp32.exe 1 564 236 normal C:\Program File
s\TuneUp Utilities 2013
0ebc SynTPEnh.exe 1 66 35 above normal C:\Program File
s\Synaptics\SynTP
0f6c cfosspeed.exe 1 28 15 normal C:\Program File
s\cFosSpeed
0f84 BoxSyncHelper.exe 1 33 25 normal C:\Program File
s\Box Sync
0f8c IDMan.exe 1 1402 387 normal C:\Program File
s\Internet Download Manager
0814 IEMonitor.exe 1 17 17 normal C:\Program File
s\Internet Download Manager
05e0 ftalk.exe 1 73 42 normal C:\Users\Bryan\
AppData\Local\fTalk
04b8 TosBtMng.exe 1 40 29 normal C:\Program File
s\Toshiba\Bluetooth Toshiba Stack
04e8 sppsvc.exe 0 0 0
094c BoxSync.exe 1 48 86 normal C:\Program File
s\Box Sync
0508 SynTPHelper.exe 1 9 3 above normal C:\Program File
s\Synaptics\SynTP
1138 isuspm.exe 1 9 5 normal C:\ProgramData\
FLEXnet\Connect\11
124c TosA2dp.exe 1 19 32 normal C:\Program File
s\Toshiba\Bluetooth Toshiba Stack
128c TosBtHid.exe 1 15 9 normal C:\Program File
s\Toshiba\Bluetooth Toshiba Stack
12fc TosBtHsp.exe 1 18 37 normal C:\Program File
s\Toshiba\Bluetooth Toshiba Stack
1304 WmiPrvSE.exe 0 0 0
133c SppExtComObj.Exe 0 0 0
14bc TosAVRC.exe 1 20 35 normal C:\Program File
s\Toshiba\Bluetooth Toshiba Stack
1694 unsecapp.exe 1 9 4 normal C:\WINDOWS\syst
em32\wbem
0de0 explorer.exe 1 532 229 normal C:\WINDOWS
10a8 firefox.exe 1 711 1189 normal C:\Program File
s\Mozilla Firefox
16a8 plugin-container.exe 1 14 23 normal C:\Program File
s\Mozilla Firefox
0dc8 FlashPlayerPlugin_11_5_502_149.exe 1 9 10 normal C:\WINDOWS\syst
em32\Macromed\Flash
10d0 FlashPlayerPlugin_11_5_502_149.exe 1 25 34 normal C:\WINDOWS\syst
em32\Macromed\Flash
05cc Integrator.exe 1 460 138 normal C:\Program File
s\Glary Utilities
1dd8 prevhost.exe 1 73 555 normal C:\WINDOWS\syst
em32
174c NitroPDF.exe 1 1285 985 normal C:\PROGRA~1\Nit
ro\PRO8~1
1e7c Nitro_PIPAssistant.exe 1 36 12 normal C:\PROGRA~1\Nit
ro\PRO8~1
0760 DllHost.exe 1 9 4 normal C:\WINDOWS\syst
em32
1bbc explorer.exe 1 849 431 normal C:\WINDOWS
1c04 WinRAR.exe 1 127 46 normal C:\Program File
s\WinRAR
184c audiodg.exe 0 0 0
1f2c JetClean.exe 1 416 199 below normal D:\Extract\JetC
lean
24f4 tosOBEX.exe 1 29 34 normal C:\Program File
s\Toshiba\Bluetooth Toshiba Stack
25e8 TosBtProc.exe 1 15 8 normal C:\Program File
s\TOSHIBA\Bluetooth Toshiba Stack
21b8 SearchProtocolHost.exe 0 0 0
2300 SearchFilterHost.exe 0 0 0 idle C:\WINDOWS\syst
em32
2400 dllhost.exe 0 0 0
1ccc rasautou.exe 1 66 36 above normal C:\WINDOWS\syst
em32
hardware:
+ Bluetooth
- Bluetooth RFBNEP (driver 6.0.303.0)
- Bluetooth RFBUS (driver 6.3.2206.0)
- Bluetooth RFCOMM (driver 6.0.219.0)
- Bluetooth RFCOMM (driver 6.0.219.0)
- Bluetooth RFHID (driver 6.0.2705.0)
- Bluetooth USB Controller-7 from TOSHIBA (driver 6.0.1519.0)
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
- Fax
- Microsoft XPS Document Writer
- Nitro PDF Creator (Pro 8)
- Root Print Queue
- Send To OneNote 2010
+ {36fc9e60-c465-11cf-8056-444553540000}
- Intel(R) ICH9 Family USB Universal Host Controller - 2934
- Intel(R) ICH9 Family USB Universal Host Controller - 2935
- Intel(R) ICH9 Family USB Universal Host Controller - 2936
- Intel(R) ICH9 Family USB Universal Host Controller - 2937
- Intel(R) ICH9 Family USB Universal Host Controller - 2938
- Intel(R) ICH9 Family USB Universal Host Controller - 2939
- Intel(R) ICH9 Family USB2 Enhanced Host Controller - 293A
- Intel(R) ICH9 Family USB2 Enhanced Host Controller - 293C
- USB Composite Device
- USB Mass Storage Device
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
+ {4d36e965-e325-11ce-bfc1-08002be10318}
- CDROM StrongRising.CO USB Device
- TSSTcorp CDDVDW TS-L633A ATA Device
+ {4d36e966-e325-11ce-bfc1-08002be10318}
- ACPI x86-based PC
+ {4d36e967-e325-11ce-bfc1-08002be10318}
- TOSHIBA MK3263GSX ATA Device
+ {4d36e968-e325-11ce-bfc1-08002be10318}
- Mobile Intel(R) 4 Series Express Chipset Family (Microsoft Corporation - WDD
M 1.1) (driver 8.15.10.2702)
- Mobile Intel(R) 4 Series Express Chipset Family (Microsoft Corporation - WDD
M 1.1) (driver 8.15.10.2702)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
- ATA Channel 0
- ATA Channel 0
- ATA Channel 1
- ATA Channel 1
- Standard Dual Channel PCI IDE Controller
- Standard Dual Channel PCI IDE Controller
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
- Standard PS/2 Keyboard
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
- High Definition Audio Device
- Realtek High Definition Audio (driver 6.0.1.5809)
+ {4d36e96d-e325-11ce-bfc1-08002be10318}
- Standard 33600 bps Modem
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
- Generic PnP Monitor
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
- HID-compliant mouse
- Synaptics PS/2 Port TouchPad (driver 12.2.10.0)
+ {4d36e972-e325-11ce-bfc1-08002be10318}
- Bluetooth Personal Area Network (driver 6.0.312.0)
- Realtek PCIe FE Family Controller
- Realtek RTL8191SE Wireless LAN 802.11n PCI-E NIC
+ {4d36e978-e325-11ce-bfc1-08002be10318}
- BT Port (COM10) (driver 5.0.2725.0)
- BT Port (COM11) (driver 5.0.2725.0)
- BT Port (COM12) (driver 5.0.2725.0)
- BT Port (COM13) (driver 5.0.2725.0)
- BT Port (COM14) (driver 5.0.2725.0)
- BT Port (COM20) (driver 5.0.2725.0)
- BT Port (COM21) (driver 5.0.2725.0)
- BT Port (COM22) (driver 5.0.2725.0)
- BT Port (COM7) (driver 5.0.2725.0)
- BT Port (COM8) (driver 5.0.2725.0)
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
- Microsoft Storage Spaces Controller
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
- ACPI Fan
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Power Button
- ACPI Thermal Zone
- Bluetooth ACPI (driver 5.0.1023.0)
- Composite Bus Enumerator
- Direct Application Launch Button
- Direct memory access controller
- High Definition Audio Controller
- High precision event timer
- Intel(R) 82801 PCI Bridge - 2448
- Intel(R) ICH9 Family PCI Express Root Port 1 - 2940
- Intel(R) ICH9 Family PCI Express Root Port 2 - 2942
- Intel(R) ICH9 Family PCI Express Root Port 5 - 2948
- Intel(R) ICH9 Family SMBus Controller - 2930
- Intel(R) ICH9M LPC Interface Controller - 2919
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft Basic Display Driver
- Microsoft Basic Render Driver
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator
- Mobile Intel(R) 4 Series Chipset Processor to DRAM Controller - 2A40
- Motherboard resources
- Numeric data processor
- PCI Express Root Complex
- Plug and Play Software Device Enumerator
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- System CMOS/real time clock
- System timer
- TOSHIBA Firmware Linkage Driver (driver 1.0.0.3)
- TOSHIBA x86 ACPI-Compliant Value Added Logical and General Purpose Device (d
river 2.0.0.1)
- UMBus Root Bus Enumerator
- Volume Manager
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
- Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
- Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
+ {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
- Microsoft Device Association Root Enumerator
+ {6bdd1fc6-810f-11d0-bec7-08002be2092f}
- USB2.0 UVC WebCam
+ {72631e54-78a4-11d0-bcf7-00aa00b7b32a}
- Microsoft AC Adapter
- Microsoft ACPI-Compliant Control Method Battery
+ {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
- USB Input Device
+ {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
- Microphone (Realtek High Definition Audio)
- Speakers (Realtek High Definition Audio)
cpu registers:
eax = 0013fdd8
ebx = 01b7acc0
ecx = 00000007
edx = 00000000
esi = 0000003c
edi = ff000015
eip = 74d9277c
esp = 0013fdd8
ebp = 0013fe34
stack dump:
0013fdd8 de fa ed 0e 01 00 00 00 - 00 00 00 00 7c 27 d9 74 ............|'.t
0013fde8 07 00 00 00 51 2d 16 50 - 20 f5 11 05 c0 ac b7 01 ....Q-.P........
0013fdf8 3c 00 00 00 15 00 00 ff - 80 fe 13 00 68 fe 13 00 <...........h...
0013fe08 de fa ed 0e 01 00 00 00 - 00 00 00 00 51 2d 16 50 ............Q-.P
0013fe18 07 00 00 00 80 fe 13 00 - 73 15 80 59 22 00 00 00 ........s..Y"...
0013fe28 78 c6 83 59 d8 39 2f 88 - 98 0c 04 50 80 fe 13 00 x..Y.9/....P....
0013fe38 51 2d 16 50 de fa ed 0e - 01 00 00 00 07 00 00 00 Q-.P............
0013fe48 4c fe 13 00 51 2d 16 50 - 20 f5 11 05 c0 ac b7 01 L...Q-.P........
0013fe58 3c 00 00 00 15 00 00 ff - 80 fe 13 00 68 fe 13 00 <...........h...
0013fe68 94 fe 13 00 70 7c 00 50 - 80 fe 13 00 20 d4 61 04 ....p|.P......a.
0013fe78 50 d7 a9 01 00 00 00 00 - 8c fe 13 00 81 2d 16 50 P............-.P
0013fe88 1d eb 4a 00 c8 fe 13 00 - 6a 20 51 00 dc fe 13 00 ..J.....j.Q.....
0013fe98 70 7c 00 50 c8 fe 13 00 - 00 00 00 00 50 d7 a9 01 p|.P........P...
0013fea8 50 d7 a9 01 00 00 00 00 - 00 00 00 00 00 00 00 00 P...............
0013feb8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0013fec8 d4 fe 13 00 81 0d 51 00 - 50 d7 a9 01 f4 fe 13 00 ......Q.P.......
0013fed8 3e 04 50 00 08 ff 13 00 - 70 7c 00 50 f4 fe 13 00 >.P.....p|.P....
0013fee8 50 d7 a9 01 00 00 00 00 - 00 00 00 00 00 ff 13 00 P...............
0013fef8 4a db 50 00 00 00 00 00 - 38 ff 13 00 d7 29 50 00 J.P.....8....)P.
0013ff08 40 ff 13 00 70 7c 00 50 - 38 ff 13 00 00 00 00 00 @...p|.P8.......
disassembling:
[...]
004aeb05 mov eax, [eax+$1f8]
004aeb0b call -$ab50c ($403604) ; Extctrls.TTimer.SetEnabled (vcl12
0.bpl)
004aeb10 pop ebp
004aeb11 ret
004aeb12 67 mov eax, [eax+$1f8]
004aeb18 > call -$ab519 ($403604) ; Extctrls.TTimer.SetEnabled (vcl12
0.bpl)
004aeb1d 68 pop ebp
004aeb1e ret
date/time : 2014-01-25, 18:49:13, 554ms
computer name : BRYN
user name : zyrechs <admin>
registered owner : zyrechs
operating system : Windows NT New build 9200
system language : English
system up time : 4 minutes 21 seconds
program up time : 1 minute 55 seconds
processors : 2x Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
physical memory : 1547/1916 MB (free/total)
free disk space : (C:) 37.83 GB (D:) 38.52 GB
display mode : 1366x768, 32 bit
process id : $ec4
allocated memory : 73.44 MB
executable : JetClean.exe
current module : madExcept_.bpl
exec. date/time : 2011-11-17 19:13
version : 0.2.0.99
compiled with : Delphi 2009
madExcept version : 3.0i
callstack crc : $500e1158, $9f17b51c, $23c1f298
exception number : 1
exception class : EAccessViolation
exception message : Access violation at address 500E1158 in module 'rtl120.bpl'.
Write of address 50125573.
main thread ($ec8):
500e1158 +000 rtl120.bpl
0044b493 +013 JetClean.exe RdLiteNote 1751 +1 TRdLitePng.Draw
501283be +02a vcl120.bpl Graphics TCanvas.StretchDraw
00468f8c +104 JetClean.exe PImageRect 278 +25 TImageRect.Paint
501da55b +057 vcl120.bpl Controls TCustomControl.PaintWindow
501d5451 +055 vcl120.bpl Controls TWinControl.PaintHandler
501d966a +046 vcl120.bpl Controls TWinControl.WMPrintClient
501d0c0e +2d2 vcl120.bpl Controls TControl.WndProc
501d529b +513 vcl120.bpl Controls TWinControl.WndProc
501d0834 +024 vcl120.bpl Controls TControl.Perform
501d5caa +0ce vcl120.bpl Controls TWinControl.WMPaint
501da4f4 +010 vcl120.bpl Controls TCustomControl.WMPaint
501d0c0e +2d2 vcl120.bpl Controls TControl.WndProc
501d529b +513 vcl120.bpl Controls TWinControl.WndProc
77218d97 +093 user32.dll GetWindowLongW
501d49b4 +02c vcl120.bpl Controls TWinControl.MainWndProc
77df688b +02b ntdll.dll KiUserCallbackDispatcher
77220777 +04b user32.dll UpdateWindow
501d8041 +015 vcl120.bpl Controls TWinControl.Update
501d8059 +011 vcl120.bpl Controls TWinControl.Repaint
00472050 +2a8 JetClean.exe PImageProgress 79 +37 TImageProgress.SetPosition
004e1c37 +157 JetClean.exe RegistryScan 817 +25 TScanRegistry.DoActiveX
004ef232 +aea JetClean.exe RegistryScan 5433 +212 TScanRegistry.Scan_ImClean
005120a8 +260 JetClean.exe uMain 6618 +52 TfrmImCleanMain.ScanRegistry
00510d7c +02c JetClean.exe uMain 6306 +7 TfrmImCleanMain.Scan
00500439 +131 JetClean.exe uMain 1230 +38 TfrmImCleanMain.btnScanClick
0050db45 +031 JetClean.exe uMain 5416 +5 TfrmImCleanMain.nScanRepairC
lick
501c3cef +0a7 vcl120.bpl Menus TMenuItem.Click
501c5343 +013 vcl120.bpl Menus TMenu.DispatchCommand
501c659a +082 vcl120.bpl Menus TPopupList.WndProc
501d49b4 +02c vcl120.bpl Controls TWinControl.MainWndProc
501c64e9 +01d vcl120.bpl Menus TPopupList.MainWndProc
77217c54 +00b user32.dll DispatchMessageW
501f9ec7 +0f3 vcl120.bpl Forms TApplication.ProcessMessage
501f9f0a +00a vcl120.bpl Forms TApplication.HandleMessage
501fa235 +0c9 vcl120.bpl Forms TApplication.Run
0051acb2 +332 JetClean.exe JetClean 206 +104 initialization
77111864 +010 KERNEL32.DLL BaseThreadInitThunk
thread $edc:
77df4309 +05 ntdll.dll NtWaitForMultipleObjects
757bbe86 +00 KERNELBASE.dll WaitForMultipleObjectsEx
77218bb3 +51 user32.dll MsgWaitForMultipleObjects
77111864 +10 KERNEL32.DLL BaseThreadInitThunk
thread $efc:
77df5ac1 +05 ntdll.dll NtDelayExecution
757b124c +b5 KERNELBASE.dll SleepEx
757b1189 +0a KERNELBASE.dll Sleep
004cd7a9 +31 JetClean.exe Unit_JunkfilesThread 281 +13 TJunkfilesThread.Execut
e
77111864 +10 KERNEL32.DLL BaseThreadInitThunk
thread $f0c:
77df5ac1 +05 ntdll.dll NtDelayExecution
757b124c +b5 KERNELBASE.dll SleepEx
757b1189 +0a KERNELBASE.dll Sleep
004baf93 +43 JetClean.exe Unit_PrivacyThread 426 +18 TPrivacyThread.Execute
77111864 +10 KERNEL32.DLL BaseThreadInitThunk
thread $f18:
77df42b9 +05 ntdll.dll NtWaitForWorkViaWorkerFactory
77111864 +10 KERNEL32.DLL BaseThreadInitThunk
thread $f1c:
77df42b9 +05 ntdll.dll NtWaitForWorkViaWorkerFactory
77111864 +10 KERNEL32.DLL BaseThreadInitThunk
thread $f20:
77df4309 +05 ntdll.dll NtWaitForMultipleObjects
757bbe86 +00 KERNELBASE.dll WaitForMultipleObjectsEx
77111864 +10 KERNEL32.DLL BaseThreadInitThunk
thread $f7c:
77218b38 +25 user32.dll GetMessageW
77111864 +10 KERNEL32.DLL BaseThreadInitThunk
modules:
00400000 JetClean.exe 0.2.0.99 D:\Extract\JetClean
50000000 rtl120.bpl 12.0.3170.16989 D:\Extract\JetClean
50120000 vcl120.bpl 12.0.3210.17555 D:\Extract\JetClean
50310000 vclx120.bpl 12.0.3210.17555 D:\Extract\JetClean
57000000 madBasic_.bpl D:\Extract\JetClean
57800000 madDisAsm_.bpl D:\Extract\JetClean
59800000 madExcept_.bpl D:\Extract\JetClean
60900000 sqlite3.dll D:\Extract\JetClean
68cf0000 wbemdisp.dll 6.2.9200.16384 C:\Windows\system32\wbem
69b30000 oledlg.dll 6.2.9200.16384 C:\Windows\SYSTEM32
69b50000 TaskSchedule.dll 1.1.0.227 D:\Extract\JetClean
69c20000 MLANG.dll 6.2.9200.16384 C:\Windows\SYSTEM32
69c60000 ieproxy.dll 10.0.9200.16384 C:\Program Files\Internet Expl
orer
69cb0000 ieframe.dll 10.0.9200.16384 C:\Windows\System32
6c260000 winspool.drv 6.2.9200.16384 C:\Windows\SYSTEM32
6c690000 thumbcache.dll 6.2.9200.16384 C:\Windows\System32
6d290000 apphelp.dll 6.2.9200.16384 C:\Windows\system32
6da20000 WINMMBASE.dll 6.2.9200.16384 C:\Windows\SYSTEM32
6da50000 winmm.dll 6.2.9200.16384 C:\Windows\SYSTEM32
6db70000 mpr.dll 6.2.9200.16384 C:\Windows\SYSTEM32
6df00000 msimg32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
6e0f0000 wmiutils.dll 6.2.9200.16384 C:\Windows\system32\wbem
6e110000 wbemsvc.dll 6.2.9200.16384 C:\Windows\system32\wbem
6e120000 fastprox.dll 6.2.9200.16384 C:\Windows\system32\wbem
6f360000 wbemprox.dll 6.2.9200.16384 C:\Windows\system32\wbem
6f4b0000 Secur32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
70050000 wsock32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
70c20000 wbemcomn.dll 6.2.9200.16384 C:\Windows\SYSTEM32
70f10000 PROPSYS.dll 7.0.9200.16384 C:\Windows\SYSTEM32
710e0000 MrmCoreR.dll 6.2.9200.16384 C:\Windows\SYSTEM32
71470000 version.dll 6.2.9200.16384 C:\Windows\SYSTEM32
71780000 ntmarta.dll 6.2.9200.16384 C:\Windows\SYSTEM32
71e90000 mssprxy.dll 7.0.9200.16384 C:\Windows\system32
71f50000 oleacc.dll 7.2.9200.16384 C:\Windows\SYSTEM32
725b0000 LINKINFO.dll 6.2.9200.16384 C:\Windows\SYSTEM32
728b0000 Bcp47Langs.dll 6.2.9200.16384 C:\Windows\SYSTEM32
72ae0000 XmlLite.dll 6.2.9200.16384 C:\Windows\SYSTEM32
73810000 dwmapi.dll 6.2.9200.16384 C:\Windows\SYSTEM32
73830000 WindowsCodecs.dll 6.2.9200.16384 C:\Windows\SYSTEM32
74080000 uxtheme.dll 6.2.9200.16384 C:\Windows\system32
74620000 taskschd.dll 6.2.9200.16384 C:\Windows\System32
748f0000 rsaenh.dll 6.2.9200.16384 C:\Windows\system32
74a30000 comctl32.dll 6.10.9200.16384 C:\Windows\WinSxS\x86_microsof
t.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985
74e80000 CRYPTSP.dll 6.2.9200.16384 C:\Windows\SYSTEM32
752e0000 SspiCli.dll 6.2.9200.16384 C:\Windows\SYSTEM32
75310000 bcryptPrimitives.dll 6.2.9200.16384 C:\Windows\SYSTEM32
75370000 CRYPTBASE.dll 6.2.9200.16384 C:\Windows\SYSTEM32
75380000 sxs.dll 6.2.9200.16384 C:\Windows\SYSTEM32
75430000 profapi.dll 6.2.9200.16384 C:\Windows\SYSTEM32
75520000 CFGMGR32.dll 6.2.9200.16384 C:\Windows\system32
75570000 DEVOBJ.dll 6.2.9200.16384 C:\Windows\system32
757b0000 KERNELBASE.dll 6.2.9200.16384 C:\Windows\system32
75870000 ole32.dll 6.2.9200.16384 C:\Windows\system32
75990000 gdi32.dll 6.2.9200.16384 C:\Windows\system32
75aa0000 shlwapi.dll 6.2.9200.16384 C:\Windows\system32
75ae0000 combase.dll 6.2.9200.16384 C:\Windows\SYSTEM32
75c20000 shell32.dll 6.2.9200.16384 C:\Windows\system32
76cf0000 MSCTF.dll 6.2.9200.16384 C:\Windows\system32
76dd0000 psapi.dll 6.2.9200.16384 C:\Windows\system32
76e40000 RPCRT4.dll 6.2.9200.16384 C:\Windows\system32
76f20000 msvcrt.dll 7.0.9200.16384 C:\Windows\system32
76fe0000 NSI.dll 6.2.9200.16384 C:\Windows\system32
76ff0000 urlmon.dll 10.0.9200.16384 C:\Windows\system32
77110000 KERNEL32.DLL 6.2.9200.16384 C:\Windows\system32
77210000 user32.dll 6.2.9200.16384 C:\Windows\system32
77350000 gdiplus.dll 6.2.9200.16384 C:\Windows\WinSxS\x86_microsof
t.windows.gdiplus_6595b64144ccf1df_1.0.9200.16384_none_cad2e541479289ac
774c0000 sechost.dll 6.2.9200.16384 C:\Windows\SYSTEM32
77500000 SHCORE.DLL 6.2.9200.16384 C:\Windows\system32
77580000 clbcatq.dll 2001.12.10130.16384 C:\Windows\SYSTEM32
77600000 wininet.dll 10.0.9200.16384 C:\Windows\system32
777c0000 SETUPAPI.dll 6.2.9200.16384 C:\Windows\system32
77970000 IMM32.DLL 6.2.9200.16384 C:\Windows\system32
779a0000 comdlg32.dll 6.2.9200.16384 C:\Windows\system32
77a30000 WS2_32.dll 6.2.9200.16384 C:\Windows\system32
77ae0000 IMAGEHLP.DLL 6.2.9200.16384 C:\Windows\system32
77b00000 iertutil.dll 10.0.9200.16384 C:\Windows\system32
77ca0000 advapi32.dll 6.2.9200.16384 C:\Windows\system32
77d50000 oleaut32.dll 6.2.9200.16384 C:\Windows\system32
77de0000 ntdll.dll 6.2.9200.16384 C:\Windows\SYSTEM32
processes:
000 Idle 0 0 0
004 System 0 0 0
120 smss.exe 0 0 0
180 csrss.exe 0 0 0
1c4 wininit.exe 0 0 0
1e8 services.exe 0 0 0
1f8 lsass.exe 0 0 0
21c csrss.exe 1 0 0
24c winlogon.exe 1 0 0
2ac svchost.exe 0 0 0
2e0 svchost.exe 0 0 0
314 svchost.exe 0 0 0
33c dwm.exe 1 0 0
384 svchost.exe 0 0 0
3b4 svchost.exe 0 0 0
3f4 svchost.exe 0 0 0
46c svchost.exe 0 0 0
544 spoolsv.exe 0 0 0
560 svchost.exe 0 0 0
5e8 svchost.exe 0 0 0
5fc svchost.exe 0 0 0
618 MsMpEng.exe 0 0 0
7d0 WUDFHost.exe 0 0 0
420 taskhostex.exe 1 13 17 normal C:\Windows\system32
448 taskhost.exe 1 9 6 normal C:\Windows\system32
5c4 Explorer.EXE 1 374 357 normal C:\Windows
8c8 svchost.exe 0 0 0
9cc SearchIndexer.exe 0 0 0
a54 UnlockerAssistant.exe 1 12 7 normal C:\Program Files\Unlocker
bc8 CCleaner.exe 1 158 71 below normal C:\Program Files\CCleaner
e08 audiodg.exe 0 0 0
ec4 JetClean.exe 1 466 245 normal D:\Extract\JetClean
f88 SearchProtocolHost.exe 0 0 0
f9c SearchFilterHost.exe 0 0 0 idle C:\Windows\system32
fc0 SearchProtocolHost.exe 1 5 6 idle C:\Windows\system32
fe4 WMIADAP.exe 0 0 0
810 WmiPrvSE.exe 0 0 0
hardware:
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
- Fax
- Microsoft XPS Document Writer
- Root Print Queue
+ {36fc9e60-c465-11cf-8056-444553540000}
- Intel(R) ICH9 Family USB Universal Host Controller - 2934
- Intel(R) ICH9 Family USB Universal Host Controller - 2935
- Intel(R) ICH9 Family USB Universal Host Controller - 2936
- Intel(R) ICH9 Family USB Universal Host Controller - 2937
- Intel(R) ICH9 Family USB Universal Host Controller - 2938
- Intel(R) ICH9 Family USB Universal Host Controller - 2939
- Intel(R) ICH9 Family USB2 Enhanced Host Controller - 293A
- Intel(R) ICH9 Family USB2 Enhanced Host Controller - 293C
- USB Composite Device
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
+ {4d36e965-e325-11ce-bfc1-08002be10318}
- TSSTcorp CDDVDW TS-L633A
+ {4d36e966-e325-11ce-bfc1-08002be10318}
- ACPI x86-based PC
+ {4d36e967-e325-11ce-bfc1-08002be10318}
- TOSHIBA MK3263GSX
+ {4d36e968-e325-11ce-bfc1-08002be10318}
- Mobile Intel(R) 4 Series Express Chipset Family (Microsoft Corporation - WDD
M 1.1) (driver 8.15.10.2702)
- Mobile Intel(R) 4 Series Express Chipset Family (Microsoft Corporation - WDD
M 1.1) (driver 8.15.10.2702)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
- Standard SATA AHCI Controller
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
- Standard PS/2 Keyboard
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
- High Definition Audio Device
- High Definition Audio Device
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
- Generic PnP Monitor
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
- HID-compliant mouse
- PS/2 Compatible Mouse
+ {4d36e972-e325-11ce-bfc1-08002be10318}
- Bluetooth Device (Personal Area Network)
- Realtek PCIe FE Family Controller
- Realtek RTL8191SE Wireless LAN 802.11n PCI-E NIC
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
- Microsoft Storage Spaces Controller
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
- ACPI Fan
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Power Button
- ACPI Thermal Zone
- Composite Bus Enumerator
- Direct Application Launch Button
- Direct memory access controller
- High Definition Audio Controller
- High precision event timer
- Intel(R) 82801 PCI Bridge - 2448
- Intel(R) ICH9 Family PCI Express Root Port 1 - 2940
- Intel(R) ICH9 Family PCI Express Root Port 2 - 2942
- Intel(R) ICH9 Family PCI Express Root Port 5 - 2948
- Intel(R) ICH9 Family SMBus Controller - 2930
- Intel(R) ICH9M LPC Interface Controller - 2919
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft Basic Display Driver
- Microsoft Basic Render Driver
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator
- Mobile Intel(R) 4 Series Chipset Processor to DRAM Controller - 2A40
- Motherboard resources
- Numeric data processor
- PCI Express Root Complex
- Plug and Play Software Device Enumerator
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- System CMOS/real time clock
- System timer
- UMBus Root Bus Enumerator
- Volume Manager
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
- Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
- Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
+ {533c5b84-ec70-11d2-9505-00c04f79deaf}
- Generic volume shadow copy
+ {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
- Microsoft Device Association Root Enumerator
+ {6bdd1fc6-810f-11d0-bec7-08002be2092f}
- USB2.0 UVC WebCam
+ {72631e54-78a4-11d0-bcf7-00aa00b7b32a}
- Microsoft AC Adapter
- Microsoft ACPI-Compliant Control Method Battery
+ {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
- USB Input Device
+ {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
- Microphone (High Definition Audio Device)
- Microphone (High Definition Audio Device)
- Speakers (High Definition Audio Device)
+ {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
- Generic Bluetooth Adapter
- Microsoft Bluetooth Enumerator
+ {eec5ad98-8080-425f-922a-dabf3de3f69a}
- Z130
cpu registers:
eax = 50125520
ebx = 016212c0
ecx = 0000000c
edx = 00000001
esi = 0013f0fc
edHotkey Driver (driver 8.0.0.4)
- USB Input Device
+ {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
- Microphone (High Definition Audio Device)
- Microphone (High Definition Audio Device)
- Speakers (High Definition Audio Device)
+ {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
- Audio Source Service
- AV Remote Target Service
- Generic Bluetooth Adapter
- Handsfree Audio Gateway Service
- Headset Audio Gateway Service
- Microsoft Bluetooth Enumerator
- Object Push Service
- Personal Area Network NAP Service
- Phonebook Access Pse Service
- Z130
cpu registers:
eax = 000001ad
ebx = 0000020d
ecx = 04df84d0
edx = 04191480
esi = 00000200
edi = 00050000
eip = 63be9532
esp = 0013d9f8
ebp = 0013da0c
stack dump:
0013d9f8 55 81 ff ff 80 14 19 04 - 01 00 00 00 d0 20 00 00 U...............
0013da08 d0 84 df 04 58 da 13 00 - 0d 95 be 63 05 00 00 00 ....X......c....
0013da18 ad 01 00 00 0d 02 00 00 - 55 81 ff ff 00 00 05 00 ........U.......
0013da28 ab 02 00 00 00 00 00 00 - 0d 02 00 00 ad 01 00 00 ................
0013da38 f0 59 19 04 52 55 01 3f - 00 00 a0 40 5c 55 fd be .Y..RU.?...@\U..
0013da48 00 00 a0 40 d0 84 df 04 - 00 00 00 80 00 00 c0 42 ...@...........B
0013da58 84 da 13 00 e3 f8 ba 63 - 05 00 00 00 ad 01 00 00 .......c........
0013da68 0d 02 00 00 05 00 00 00 - 8c db 13 00 ad 01 00 00 ................
0013da78 ad 01 00 00 0d 02 00 00 - ad 01 00 00 4c e5 13 00 ............L...
0013da88 d8 3e bb 63 05 00 00 00 - ad 01 00 00 0d 02 00 00 .>.c............
0013da98 1d e6 13 00 e0 e9 13 00 - d0 84 df 04 00 00 00 80 ................
0013daa8 0c 00 00 00 ff ff ff 7f - 00 00 00 00 ff ff ff ff ................
0013dab8 0c 00 00 00 a0 db 13 00 - ff ff ff 7f 00 00 00 80 ................
0013dac8 00 00 00 00 9f ff ff ff - 00 00 00 00 c0 00 00 00 ................
0013dad8 00 00 00 00 c0 db 13 00 - 00 00 00 80 00 00 00 00 ................
0013dae8 0b 00 00 00 0c 00 00 00 - 0c 00 00 00 30 e3 13 00 ............0...
0013daf8 50 db 13 00 00 00 00 00 - 94 ea ba 63 31 4d 61 74 P..........c1Mat
0013db08 ff ff ff ff ff ff 7f 41 - 0c 00 00 00 50 e3 13 00 .......A....P...
0013db18 70 db 13 00 00 00 00 00 - 94 ea ba 63 31 4d 61 74 p..........c1Mat
0013db28 ff ff ff ff ff ff bf 44 - 00 00 00 80 00 00 00 80 .......D........
disassembling:
[...]
0043ee2e mov eax, esi
0043ee30 call -$6bed ($438248) ; GdiPlus.GdipHandle (JetClean.e
xe)
0043ee35 push eax
0043ee36 mov eax, [ebx+$c]
0043ee39 push eax
0043ee3a > call dword ptr [$51c498] ; GdipDrawImageRectRectI (gdiplu
s.dll)
0043ee40 mov ebx, eax
0043ee42 test ebx, ebx
0043ee44 jz loc_43ee59
0043ee46 mov ecx, ebx
0043ee48 mov dl, 1
[...]
date/time : 2014-04-30, 07:25:40, 755ms
computer name : SANDA-PC
user name : Sanda <admin>
registered owner : Sanda
operating system : Windows NT New build 9200
system language : English
system up time : 3 minutes 34 seconds
program up time : 10 seconds
processors : 2x Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
physical memory : 1279/1916 MB (free/total)
free disk space : (C:) 21,90 GB (D:) 143,91 GB
display mode : 1366x768, 32 bit
process id : $988
allocated memory : 40,73 MB
executable : JetClean.exe
current module : madExcept_.bpl
exec. date/time : 2011-11-18 10:13
version : 0.2.0.99
compiled with : Delphi 2009
madExcept version : 3.0i
callstack crc : $0402e950, $3aed67e6, $7df8c2ef
exception number : 1
exception class : EAccessViolation
exception message : Access violation at address 0402E950. Write of address 00000
000.
main thread ($8c4):
0402e950 +000 ???
6d04dcd7 +205 gdiplus.dll GdipDrawImageRectRect
6d04daba +0ab gdiplus.dll GdipDrawImageRectRectI
0043ee3a +04a JetClean.exe GdiPlus 16092 +1 TGPGraphics.DrawImage
0044b6f9 +25d JetClean.exe Numeric data processor
- PCI Express Root Complex
- Plug and Play Software Device Enumerator
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- System CMOS/real time clock
- System timer
- TOSHIBA x86 ACPI-Compliant Value Added Logical and General Purpose Device (d
river 3.0.0.0)
- UMBus Root Bus Enumerator
- Volume Manager
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
- Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
- Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
+ {533c5b84-ec70-11d2-9505-00c04f79deaf}
- Generic volume shadow copy
- Generic volume shadow copy
+ {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
- Microsoft Device Association Root Enumerator
+ {6bdd1fc6-810f-11d0-bec7-08002be2092f}
- USB2.0 UVC WebCam
+ {72631e54-78a4-11d0-bcf7-00aa00b7b32a}
- Microsoft AC Adapter
- Microsoft ACPI-Compliant Control Method Battery
+ {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
- HID-compliant consumer control device
- HID-compliant consumer control device
- HID-compliant device
- Toshiba Hotkey Driver (driver 8.0.0.4)
- USB Input Device
+ {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
- Microphone (High Definition Audio Device)
- Microphone (High Definition Audio Device)
- Speakers (High Definition Audio Device)
+ {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
- Audio Source Service
- AV Remote Target Service
- Generic Bluetooth Adapter
- Handsfree Audio Gateway Service
- Headset Audio Gateway Service
- Microsoft Bluetooth Enumerator
- Object Push Service
- Personal Area Network NAP Service
- Phonebook Access Pse Service
- Z130
cpu registers:
eax = 00000000
ebx = 0425d7bc
ecx = 0425ca34
edx = 00000000
esi = 74e4bda6
edi = 00000000
eip = 74e4bdb3
esp = 0013e430
ebp = 0013e468
stack dump:
0013e430 38 1b 29 69 34 ca 25 04 - 70 d6 25 04 00 00 00 00 8.)i4.%.p.%.....
0013e440 bc d7 25 04 00 00 00 00 - 00 00 00 00 34 ca 25 04 ..%.........4.%.
0013e450 03 00 00 00 00 00 00 00 - 01 00 00 00 00 00 00 00 ................
0013e460 00 00 00 00 58 e8 0b 04 - b0 e4 13 00 5e d8 29 69 ....X.......^.)i
0013e470 08 ca 25 04 bc d7 25 04 - 00 00 00 00 00 00 00 00 ..%...%.........
0013e480 a8 23 1a 04 f8 d6 25 04 - f0 d6 25 04 00 00 00 00 .#....%...%.....
0013e490 10 e1 25 04 28 31 24 04 - 00 00 00 00 bc d7 25 04 ..%.(1$.......%.
0013e4a0 50 d7 25 04 01 00 00 00 - 01 00 00 00 08 16 24 04 P.%...........$.
0013e4b0 80 e5 13 00 d5 1e 29 69 - 70 d6 25 04 01 00 00 00 ......)ip.%.....
0013e4c0 3c 92 19 04 00 00 00 00 - 00 00 00 00 98 85 f0 04 <...............
0013e4d0 30 17 0c 04 01 00 00 00 - 08 18 02 00 a8 23 1a 04 0............#..
0013e4e0 04 00 00 00 00 40 03 44 - 0c 00 00 00 00 80 d6 43 .....@.D.......C
0013e4f0 01 00 00 00 01 00 00 00 - 04 00 00 00 08 18 02 00 ................
0013e500 28 31 24 04 00 00 00 00 - 00 00 00 00 01 00 00 00 (1$.............
0013e510 01 00 00 00 02 00 00 00 - 00 00 00 00 00 00 00 00 ................
0013e520 01 00 00 00 0c 00 00 00 - 00 00 00 00 00 00 00 00 ................
0013e530 01 00 00 00 01 00 00 00 - aa 3c 6b b9 28 07 d3 11 .........<k.(...
0013e540 9d 7b 00 00 f8 1e f3 2e - 08 18 02 00 01 00 00 00 .{..............
0013e550 0c 00 00 00 01 00 00 00 - 01 00 00 00 00 00 00 00 ................
0013e560 00 00 00 00 00 00 58 40 - 00 00 00 00 00 00 58 40 ......X@......X@
disassembling:
[...]
0043ee2e mov eax, esi
0043ee30 call -$6bed ($438248) ; GdiPlus.GdipHandle (JetClean.e
xe)
0043ee35 push eax
0043ee36 mov eax, [ebx+$c]
0043ee39 push eax
0043ee3a > call dword ptr [$51c498] ; GdipDrawImageRectRectI (gdiplu
s.dll)
0043ee40 mov ebx, eax
0043ee42 test ebx, ebx
0043ee44 jz loc_43ee59
0043ee46 mov ecx, ebx
0043ee48 mov dl, 1
[...]
date/time : 2014-05-02, 20:18:03, 235ms
computer name : SANDA-PC
user name : Sanda <admin>
registered owner : Sanda
operating system : Windows NT New build 9200
system language : English
system up time : 10 minutes 41 seconds
program up time : 2 minutes 22 seconds
processors : 2x Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
physical memory : 1477/1916 MB (free/total)
free disk space : (C:) 21,98 GB (D:) 143,92 GB
display mode : 1366x768, 32 bit
process id : $954
allocated memory : 58,99 MB
executable : JetClean.exe
current module : madExcept_.bpl
exec. date/time : 2011-11-18 10:13
version : 0.2.0.99
compiled with : Delphi 2009
madExcept version : 3.0i
callstack crc : $596c2016, $4c4657bc, $14347cf1
count : 2
exception number : 3
exception class : EGdipError
exception message : (GDI+ Error) One of the arguments is already in use in anoth
er thread.
main thread ($95c):
0043bab8 +02c JetClean.exe GdiPlus 12592 +2 TGPImage.GetWidth
0044ba4a +012 JetClean.exe RdLiteNote 1895 +2 TRdLitePng.GetWidth
0044a669 +011 JetClean.exe RdLiteNote 1326 +3 TLitePicture.GetWidth
00468f1b +093 JetClean.exe PImageRect 267 +14 TImageRect.Paint
501da55b +057 vcl120.bpl Controls TCustomControl.PaintWindow
501d5451 +055 vcl120.bpl Controls TWinControl.PaintHandler
501d966a +046 vcl120.bpl Controls TWinControl.WMPrintClient
501d0c0e +2d2 vcl120.bpl Controls TControl.WndProc
501d529b +513 vcl120.bpl Controls TWinControl.WndProc
501d0834 +024 vcl120.bpl Controls TControl.Perform
501d5caa +0ce vcl120.bpl Controls TWinControl.WMPaint
501da4f4 +010 vcl120.bpl Controls TCustomControl.WMPaint
501d0c0e +2d2 vcl120.bpl Controls TControl.WndProc
501d529b +513 vcl120.bpl Controls TWinControl.WndProc
75048d97 +093 user32.dll GetWindowLongW
501d49b4 +02c vcl120.bpl Controls TWinControl.MainWndProc
776270ab +02b ntdll.dll KiUserCallbackDispatcher
75050777 +04b user32.dll UpdateWindow
501d8041 +015 vcl120.bpl Controls TWinControl.Update
501d8059 +011 vcl120.bpl Controls TWinControl.Repaint
00472050 +2a8 JetClean.exe PImageProgress 79 +37 TImageProgress.SetPosition
004e1c37 +157 JetClean.exe RegistryScan 817 +25 TScanRegistry.DoActiveX
004ef232 +aea JetClean.exe RegistryScan 5433 +212 TScanRegistry.Scan_ImClean
005120a8 +260 JetClean.exe uMain 6618 +52 TfrmImCleanMain.ScanRegistr
y
00510d7c +02c JetClean.exe uMain 6306 +7 TfrmImCleanMain.Scan
00500439 +131 JetClean.exe uMain 1230 +38 TfrmImCleanMain.btnScanClic
k
0050db45 +031 JetClean.exe uMain 5416 +5 TfrmImCleanMain.nScanRepair
Click
501c3cef +0a7 vcl120.bpl Menus TMenuItem.Click
501c5343 +013 vcl120.bpl Menus TMenu.DispatchCommand
501c659a +082 vcl120.bpl Menus TPopupList.WndProc
501d49b4 +02c vcl120.bpl Controls TWinControl.MainWndProc
501c64e9 +01d vcl120.bpl Menus TPopupList.MainWndProc
75047c54 +00b user32.dll DispatchMessageW
501f9ec7 +0f3 vcl120.bpl Forms TApplication.ProcessMessage
501f9f0a +00a vcl120.bpl Forms TApplication.HandleMessage
501fa235 +0c9 vcl120.bpl Forms TApplication.Run
0051acb2 +332 JetClean.exe JetClean 206 +104 initialization
75ab173c +010 KERNEL32.DLL BaseThreadInitThunk
thread $4a0:
77624b0d +05 ntdll.dll NtWaitForMultipleObjects
74e4bdef +00 KERNELBASE.dll WaitForMultipleObjectsEx
75048bb3 +51 user32.dll MsgWaitForMultipleObjects
75ab173c +10 KERNEL32.DLL BaseThreadInitThunk
thread $ce0:
776262c5 +05 ntdll.dll NtDelayExecution
74e4124c +b5 KERNELBASE.dll SleepEx
74e41189 +0a KERNELBASE.dll Sleep
004cd7a9 +31 JetClean.exe Unit_JunkfilesThread 281 +13 TJunkfilesThread.Execut
e
75ab173c +10 KERNEL32.DLL BaseThreadInitThunk
thread $cd0:
776262c5 +05 ntdll.dll NtDelayExecution
74e4124c +b5 KERNELBASE.dll SleepEx
74e41189 +0a KERNELBASE.dll Sleep
004baf93 +43 JetClean.exe Unit_PrivacyThread 426 +18 TPrivacyThread.Execute
75ab173c +10 KERNEL32.DLL BaseThreadInitThunk
thread $200:
77624abd +05 ntdll.dll NtWaitForWorkViaWorkerFactory
75ab173c +10 KERNEL32.DLL BaseThreadInitThunk
thread $cdc:
77624b0d +05 ntdll.dll NtWaitForMultipleObjects
74e4bdef +00 KERNELBASE.dll WaitForMultipleObjectsEx
75ab173c +10 KERNEL32.DLL BaseThreadInitThunk
thread $4e0:
77624b0d +05 ntdll.dll NtWaitForMultipleObjects
74e4bdef +00 KERNELBASE.dll WaitForMultipleObjectsEx
75ab1484 +13 KERNEL32.DLL WaitForMultipleObjects
75ab173c +10 KERNEL32.DLL BaseThreadInitThunk
thread $510:
77624abd +05 ntdll.dll NtWaitForWorkViaWorkerFactory
75ab173c +10 KERNEL32.DLL BaseThreadInitThunk
thread $9e4:
77624abd +05 ntdll.dll NtWaitForWorkViaWorkerFactory
75ab173c +10 KERNEL32.DLL BaseThreadInitThunk
thread $794:
75048b38 +25 user32.dll GetMessageW
75ab173c +10 KERNEL32.DLL BaseThreadInitThunk
modules:
00400000 JetClean.exe 0.2.0.99 D:\Extract\JetClean
50000000 rtl120.bpl 12.0.3170.16989 D:\Extract\JetClean
50120000 vcl120.bpl 12.0.3210.17555 D:\Extract\JetClean
50310000 vclx120.bpl 12.0.3210.17555 D:\Extract\JetClean
57000000 madBasic_.bpl D:\Extract\JetClean
57800000 madDisAsm_.bpl D:\Extract\JetClean
59800000 madExcept_.bpl D:\Extract\JetClean
5f740000 ieframe.dll 10.0.9200.16863 C:\Windows\System32
60900000 sqlite3.dll D:\Extract\JetClean
62d70000 oledlg.dll 6.2.9200.16384 C:\Windows\SYSTEM32
64c60000 LINKINFO.dll 6.2.9200.16384 C:\Windows\SYSTEM32
64c70000 ntshrui.dll 6.2.9200.16384 C:\Windows\system32
657f0000 msi.dll 5.0.9200.16384 C:\Windows\SYSTEM32
66570000 IDMShellExt.dll 6.19.4.12 C:\Program Files\Internet Do
wnload Manager
675f0000 thumbcache.dll 6.2.9200.16384 C:\Windows\System32
68630000 actxprxy.dll 6.2.9200.16519 C:\Windows\System32
68c00000 wmiutils.dll 6.2.9200.16384 C:\Windows\system32\wbem
69240000 wbemdisp.dll 6.2.9200.16384 C:\Windows\system32\wbem
69280000 gdiplus.dll 6.2.9200.16518 C:\Windows\WinSxS\x86_micros
oft.windows.gdiplus_6595b64144ccf1df_1.0.9200.16518_none_cacb87d347993f71
693f0000 TaskSchedule.dll 1.1.0.227 D:\Extract\JetClean
698e0000 wbemsvc.dll 6.2.9200.16384 C:\Windows\system32\wbem
69a20000 fastprox.dll 6.2.9200.16384 C:\Windows\system32\wbem
6a740000 wbemprox.dll 6.2.9200.16384 C:\Windows\system32\wbem
6ad30000 ieproxy.dll 10.0.9200.16859 C:\Program Files\Internet Ex
plorer
6ad80000 SearchFolder.dll 6.2.9200.16384 C:\Windows\system32
6b630000 wbemcomn.dll 6.2.9200.16384 C:\Windows\SYSTEM32
6b9e0000 mpr.dll 6.2.9200.16384 C:\Windows\SYSTEM32
6be70000 MLANG.dll 6.2.9200.16384 C:\Windows\SYSTEM32
6bf20000 StructuredQuery.dll 7.0.9200.16433 C:\Windows\System32
6c030000 GrooveIntlResource.dll 14.0.4761.1000 C:\PROGRA~1\Microsoft Office
\Office14\1033
6d110000 office.odf 14.0.4738.1000 C:\PROGRA~1\COMMON~1\MICROS~
1\OFFICE14\Cultures
6d520000 GROOVEEX.DLL 14.0.6106.5000 C:\PROGRA~1\Microsoft Office
\Office14
6d9b0000 mssprxy.dll 7.0.9200.16578 C:\Windows\system32
6da50000 cscapi.dll 6.2.9200.16384 C:\Windows\SYSTEM32
6daa0000 CSCDLL.dll 6.2.9200.16384 C:\Windows\System32
6dab0000 cscui.dll 6.2.9200.16384 C:\Windows\System32
6e070000 ATL90.DLL 9.0.30729.6161 C:\Windows\WinSxS\x86_micros
oft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.6161_none_51cd0a7abbe4e19b
6e0a0000 MSVCP90.dll 9.0.30729.6871 C:\Windows\WinSxS\x86_micros
oft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_50944e7cbcb706e5
6e130000 EhStorShell.dll 6.2.9200.16384 C:\Windows\System32
6e5b0000 ashShell.dll 9.0.2013.292 C:\Program Files\AVAST Softw
are\Avast
6f220000 Secur32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
6f890000 WINMMBASE.dll 6.2.9200.16645 C:\Windows\SYSTEM32
6f8c0000 winmm.dll 6.2.9200.16642 C:\Windows\SYSTEM32
6f940000 winspool.drv 6.2.9200.16384 C:\Windows\SYSTEM32
6fa10000 msimg32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
6fd40000 MrmCoreR.dll 6.2.9200.16384 C:\Windows\SYSTEM32
6fdb0000 MSVCR90.dll 9.0.30729.6871 C:\Windows\WinSxS\x86_micros
oft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_50944e7cbcb706e5
6fe60000 apphelp.dll 6.2.9200.16420 C:\Windows\system32
700a0000 PROPSYS.dll 7.0.9200.16420 C:\Windows\SYSTEM32
70d70000 XmlLite.dll 6.2.9200.16384 C:\Windows\SYSTEM32
72480000 taskschd.dll 6.2.9200.16384 C:\Windows\System32
72860000 WindowsCodecs.dll 6.2.9200.16809 C:\Windows\SYSTEM32
729b0000 oleacc.dll 7.2.9200.16384 C:\Windows\SYSTEM32
72de0000 Bcp47Langs.dll 6.2.9200.16604 C:\Windows\SYSTEM32
730c0000 ntmarta.dll 6.2.9200.16384 C:\Windows\SYSTEM32
731b0000 dwmapi.dll 6.2.9200.16384 C:\Windows\SYSTEM32
73700000 uxtheme.dll 6.2.9200.16750 C:\Windows\system32
73c10000 rsaenh.dll 6.2.9200.16553 C:\Windows\system32
73d20000 version.dll 6.2.9200.16384 C:\Windows\SYSTEM32
73d30000 wsock32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
743c0000 comctl32.dll 6.10.9200.16578 C:\Windows\WinSxS\x86_micros
oft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f
5
745c0000 bcryptPrimitives.dll 6.2.9200.16384 C:\Windows\SYSTEM32
74620000 CRYPTBASE.dll 6.2.9200.16384 C:\Windows\SYSTEM32
74630000 sxs.dll 6.2.9200.16384 C:\Windows\SYSTEM32
746d0000 CRYPTSP.dll 6.2.9200.16384 C:\Windows\SYSTEM32
74a00000 shdocvw.dll 6.2.9200.16680 C:\Windows\System32
74a70000 srvcli.dll 6.2.9200.16384 C:\Windows\SYSTEM32
74ae0000 SspiCli.dll 6.2.9200.16420 C:\Windows\SYSTEM32
74c30000 MSASN1.dll 6.2.9200.16384 C:\Windows\system32
74c50000 profapi.dll 6.2.9200.16384 C:\Windows\system32
74c70000 DEVOBJ.dll 6.2.9200.16384 C:\Windows\system32
74c90000 CRYPT32.dll 6.2.9200.16727 C:\Windows\system32
74e20000 USERENV.dll 6.2.9200.16384 C:\Windows\system32
74e40000 KERNELBASE.dll 6.2.9200.16815 C:\Windows\system32
74f00000 WINTRUST.dll 6.2.9200.16666 C:\Windows\system32
74fe0000 cfgmgr32.dll 6.2.9200.16384 C:\Windows\SYSTEM32
75030000 NSI.dll 6.2.9200.16384 C:\Windows\system32
75040000 user32.dll 6.2.9200.16420 C:\Windows\system32
75170000 sechost.dll 6.2.9200.16384 C:\Windows\SYSTEM32
751b0000 MSCTF.dll 6.2.9200.16578 C:\Windows\system32
75290000 SHCORE.DLL 6.2.9200.16751 C:\Windows\system32
75310000 psapi.dll 6.2.9200.16384 C:\Windows\system32
75380000 oleaut32.dll 6.2.9200.16726 C:\Windows\system32
75410000 urlmon.dll 10.0.9200.16859 C:\Windows\system32
75540000 msvcrt.dll 7.0.9200.16384 C:\Windows\system32
75600000 iertutil.dll 10.0.9200.16859 C:\Windows\system32
75800000 ole32.dll 6.2.9200.16451 C:\Windows\system32
75920000 clbcatq.dll 2001.12.10130.16384 C:\Windows\SYSTEM32
759a0000 gdi32.dll 6.2.9200.16728 C:\Windows\system32
75ab0000 KERNEL32.DLL 6.2.9200.16815 C:\Windows\system32
75bb0000 SETUPAPI.dll 6.2.9200.16496 C:\Windows\system32
75d60000 shlwapi.dll 6.2.9200.16384 C:\Windows\system32
75da0000 comdlg32.dll 6.2.9200.16384 C:\Windows\system32
75e30000 IMM32.DLL 6.2.9200.16384 C:\Windows\system32
75e60000 combase.dll 6.2.9200.16420 C:\Windows\SYSTEM32
75fa0000 RPCRT4.dll 6.2.9200.16622 C:\Windows\system32
76080000 advapi32.dll 6.2.9200.16384 C:\Windows\system32
76130000 WS2_32.dll 6.2.9200.16384 C:\Windows\system32
76180000 wininet.dll 10.0.9200.16862 C:\Windows\system32
763a0000 shell32.dll 6.2.9200.16807 C:\Windows\system32
77470000 IMAGEHLP.DLL 6.2.9200.16745 C:\Windows\system32
77610000 ntdll.dll 6.2.9200.16578 C:\Windows\SYSTEM32
processes:
000 Idle 0 0 0
004 System 0 0 0
1a8 smss.exe 0 0 0
218 csrss.exe 0 0 0
254 wininit.exe 0 0 0
25c csrss.exe 1 0 0
298 winlogon.exe 1 0 0
2a8 services.exe 0 0 0
2c0 lsass.exe 0 0 0
330 svchost.exe 0 0 0
378 svchost.exe 0 0 0
3b4 svchost.exe 0 0 0
3d4 dwm.exe 1 0 0
3f0 svchost.exe 0 0 0
45c svchost.exe 0 0 0
48c svchost.exe 0 0 0
4f8 svchost.exe 0 0 0
538 AvastSvc.exe 0 0 0
62c spoolsv.exe 0 0 0
660 svchost.exe 0 0 0
6c4 armsvc.exe 0 0 0
6dc DevSvc.exe 0 0 0
728 ijplmsvc.exe 0 0 0
788 NBService.exe 0 0 0
1f0 NitroPDFDriverService9.exe 0 0 0
368 IoctlSvc.exe 0 0 0
5a8 taskhostex.exe 1 13 18 normal C:\Windows\system32
5a4 taskhost.exe 1 9 6 normal C:\Windows\system32
528 Explorer.EXE 1 440 417 normal C:\Windows
828 svchost.exe 0 0 0
83c svchost.exe 0 0 0
868 SynTPEnh.exe 1 88 40 above normal C:\Program Files\Synaptics
\SynTP
874 SM?RTP.exe 1 68 44 below normal C:\Program Files\Smadav
934 svchost.exe 0 0 0
b20 svchost.exe 0 0 0
b7c SYNTPHELPER.EXE 1 9 3 above normal C:\PROGRAM FILES\SYNAPTICS
\SYNTP
c18 SearchIndexer.exe 0 0 0
d04 WmiPrvSE.exe 0 0 0
d0c WmiPrvSE.exe 0 0 0
d58 OSPPSVC.EXE 0 0 0
df0 AvastUI.exe 1 140 52 normal C:\Program Files\AVAST Sof
tware\Avast
e00 IDMan.exe 1 92 71 normal C:\Program Files\Internet
Download Manager
ef4 IEMonitor.exe 1 17 17 normal C:\Program Files\Internet
Download Manager
fe0 WmiPrvSE.exe 0 0 0
8d8 audiodg.exe 0 0 0
954 JetClean.exe 1 490 254 normal D:\Extract\JetClean
f24 SearchProtocolHost.exe 1 5 6 idle C:\Windows\system32
54c SearchFilterHost.exe 0 0 0 idle C:\Windows\system32
hardware:
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
- Fax
- Microsoft XPS Document Writer
- Nitro PDF Creator (Pro 9)
- Root Print Queue
- Send To OneNote 2010
+ {36fc9e60-c465-11cf-8056-444553540000}
- Intel(R) ICH9 Family USB Universal Host Controller - 2934
- Intel(R) ICH9 Family USB Universal Host Controller - 2935
- Intel(R) ICH9 Family USB Universal Host Controller - 2936
- Intel(R) ICH9 Family USB Universal Host Controller - 2937
- Intel(R) ICH9 Family USB Universal Host Controller - 2938
- Intel(R) ICH9 Family USB Universal Host Controller - 2939
- Intel(R) ICH9 Family USB2 Enhanced Host Controller - 293A
- Intel(R) ICH9 Family USB2 Enhanced Host Controller - 293C
- USB Composite Device
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
+ {4d36e965-e325-11ce-bfc1-08002be10318}
- TSSTcorp CDDVDW TS-L633A
+ {4d36e966-e325-11ce-bfc1-08002be10318}
- ACPI x86-based PC
+ {4d36e967-e325-11ce-bfc1-08002be10318}
- TOSHIBA MK3263GSX
+ {4d36e968-e325-11ce-bfc1-08002be10318}
- Mobile Intel(R) 4 Series Express Chipset Family (Microsoft Corporation - WDD
M 1.1) (driver 8.15.10.2702)
- Mobile Intel(R) 4 Series Express Chipset Family (Microsoft Corporation - WDD
M 1.1) (driver 8.15.10.2702)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
- Standard SATA AHCI Controller
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
- Standard PS/2 Keyboard
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
- High Definition Audio Device
- High Definition Audio Device
+ {4d36e96d-e325-11ce-bfc1-08002be10318}
- Standard Modem over Bluetooth link
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
- Generic PnP Monitor
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
- HID-compliant mouse
- Synaptics PS/2 Port TouchPad (driver 17.0.8.21)
+ {4d36e972-e325-11ce-bfc1-08002be10318}
- Bluetooth Device (Personal Area Network)
- Realtek PCIe FE Family Controller
- Realtek RTL8191SE Wireless LAN 802.11n PCI-E NIC
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
- Microsoft Storage Spaces Controller
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
- ACPI Fan
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Power Button
- ACPI Thermal Zone
- Bluetooth ACPI (driver 10.0.1031.0)
- Composite Bus Enumerator
- Direct Application Launch Button
- Direct memory access controller
- High Definition Audio Controller
- High precision event timer
- Intel(R) 82801 PCI Bridge - 2448
- Intel(R) ICH9 Family PCI Express Root Port 1 - 2940
- Intel(R) ICH9 Family PCI Express Root Port 2 - 2942
- Intel(R) ICH9 Family PCI Express Root Port 5 - 2948
- Intel(R) ICH9 Family SMBus Controller - 2930
- Intel(R) ICH9M LPC Interface Controller - 2919
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft Basic Display Driver
- Microsoft Basic Render Driver
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator
- Mobile Intel(R) 4 Series Chipset Processor to DRAM Controller - 2A40
- Motherboard resources
- Numeric data processor
- PCI Express Root Complex
- Plug and Play Software Device Enumerator
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- System CMOS/real time clock
- System timer
- TOSHIBA x86 ACPI-Compliant Value Added Logical and General Purpose Device (d
river 3.0.0.0)
- UMBus Root Bus Enumerator
- Volume Manager
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
- Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
- Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
+ {533c5b84-ec70-11d2-9505-00c04f79deaf}
- Generic volume shadow copy
- Generic volume shadow copy
+ {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
- Microsoft Device Association Root Enumerator
+ {6bdd1fc6-810f-11d0-bec7-08002be2092f}
- USB2.0 UVC WebCam
+ {72631e54-78a4-11d0-bcf7-00aa00b7b32a}
- Microsoft AC Adapter
- Microsoft ACPI-Compliant Control Method Battery
+ {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
- HID-compliant consumer control device
- HID-compliant consumer control device
- HID-compliant device
- Toshiba Hotkey Driver (driver 8.0.0.4)
- USB Input Device
+ {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
- Microphone (High Definition Audio Device)
- Microphone (High Definition Audio Device)
- Speakers (High Definition Audio Device)
+ {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
- Audio Source Service
- AV Remote Target Service
- Generic Bluetooth Adapter
- Handsfree Audio Gateway Service
- Headset Audio Gateway Service
- Microsoft Bluetooth Enumerator
- Object Push Service
- Personal Area Network NAP Service
- Phonebook Access Pse Service
- Z130
disassembling:
[...]
0043baa8 jz loc_43babd
0043baaa mov ecx, ebx
0043baac mov dl, 1
0043baae mov eax, [$438158]
0043bab3 call -$385c ($43825c) ; GdiPlus.EGdipError.Create (Jet
Clean.exe)
0043bab8 > call -$3a91d ($4011a0) ; System.@RaiseExcept (rtl120.bp
l)
0043babd 12593 mov eax, [ebp-4]
0043bac0 pop ebx
0043bac1 pop ecx
0043bac2 pop ebp
0043bac3 ret

S-ar putea să vă placă și