You are on page 1of 19

date/time

computer name
user name
registered owner
operating system
system language
system up time
program up time
processors
physical memory
free disk space
display mode
process id
allocated memory
executable
exec. date/time
version
compiled with
madExcept version
callstack crc
count
exception number
exception class
exception message

:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:

2016-11-30, 12:36:49, 595ms


DESKTOP-QLMG0TU
Andi Indira
Windows User
Windows NT New x64 build 9200
Indonesian
6 days 4 hours
2 minutes 51 seconds
2x Intel(R) Celeron(R) CPU N3050 @ 1.60GHz
542/1967 MB (free/total)
(C:) 14,49 GB
1366x768, 32 bit
$29ac
120,19 MB
IncardexDesigner.exe
2016-03-26 00:53
1.6.10.122
Delphi 7
3.0g
$29a96981, $a94e1f6d, $29721f43
2
2
EListError
List index out of bounds (0).

main thread ($13d0):


05d099e9 +019 icProject.dll
05e41f99 +015 icProject.dll
rentProject
05e49287 +00b icProject.dll
0059ad9d +039 IncardexDesigner.exe
urrentProject
004a410d +011 IncardexDesigner.exe
idth
00550037 +017 IncardexDesigner.exe
uttonRect
0054ee80 +030 IncardexDesigner.exe
oPageClose
00553655 +0c5 IncardexDesigner.exe
eUp
004a6bc1 +041 IncardexDesigner.exe
004a6c48 +07c IncardexDesigner.exe
p
004a648f +1df IncardexDesigner.exe
004aa1be +18e IncardexDesigner.exe
004a9d90 +034 IncardexDesigner.exe
Proc
00470350 +014 IncardexDesigner.exe
77a9bc0b +00b user32.dll
004c8917 +083 IncardexDesigner.exe
sMessage
004c894e +00a IncardexDesigner.exe
Message
004c8b7e +096 IncardexDesigner.exe
0059b906 +23a IncardexDesigner.exe
749562c2 +022 KERNEL32.DLL

Classes
iD_ProjectList

TList.Get
67 +1 TProjectList.GetCur

icProject
iD_main

441 +1 d_IsModified
1955 +1 TformMain.TryCloseC

Controls

3573 +1 TControl.GetClientW

NxPageControl

1027 +2 TNxPageControl.GetB

NxPageControl

548 +1 TNxCustomNotebook.D

NxPageControl

1906 +13 TNxPageControl.Mous

Controls
Controls

4839 +2 TControl.DoMouseUp
4851 +8 TControl.WMLButtonU

Controls
Controls
Controls

4653 +53 TControl.WndProc


6350 +33 TWinControl.WndProc
6245 +3 TWinControl.MainWnd

Classes
Forms

StdWndProc
DispatchMessageA
TApplication.Proces

Forms

TApplication.Handle

Forms
TApplication.Run
IncardexDesigner 133 +64 initialization
BaseThreadInitThunk

thread $1ea8:
749562c2 +22 KERNEL32.DLL BaseThreadInitThunk

thread $2028:
749562c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $250:
758f1a5a +ea KERNELBASE.dll
WaitForMultipleObjectsEx
0044e6b5 +0d IncardexDesigner.exe madExcept CallThreadProcSafe
0044e71f +37 IncardexDesigner.exe madExcept ThreadExceptFrame
749562c2 +22 KERNEL32.DLL
BaseThreadInitThunk
>> created by main thread ($13d0) at:
74dbd533 +00 combase.dll
thread $1fac:
758f1a5a +ea KERNELBASE.dll WaitForMultipleObjectsEx
77a88ed3 +63 user32.dll
MsgWaitForMultipleObjects
749562c2 +22 KERNEL32.DLL
BaseThreadInitThunk
thread $25ec (TEventWaitThread):
758f1a5a +0ea KERNELBASE.dll
758f1953 +013 KERNELBASE.dll
0055688e +02a IncardexDesigner.exe reinit
551 +3
0044e7d3 +02b IncardexDesigner.exe madExcept
0046ee10 +034 IncardexDesigner.exe Classes
00404c20 +028 IncardexDesigner.exe System
0044e6b5 +00d IncardexDesigner.exe madExcept
0044e71f +037 IncardexDesigner.exe madExcept
749562c2 +022 KERNEL32.DLL
>> created by main thread ($13d0) at:
00594938 +268 IncardexDesigner.exe iD_main 596 +49

WaitForMultipleObjectsEx
WaitForMultipleObjects
TEventWaitThread.Execute
HookedTThreadExecute
ThreadProc
ThreadWrapper
CallThreadProcSafe
ThreadExceptFrame
BaseThreadInitThunk
TformMain.FormCreate

thread $2adc:
749562c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $2b64:
749562c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $25f0:
77a9a786 +26 user32.dll
GetMessageW
0044e6b5 +0d IncardexDesigner.exe madExcept CallThreadProcSafe
0044e71f +37 IncardexDesigner.exe madExcept ThreadExceptFrame
749562c2 +22 KERNEL32.DLL
BaseThreadInitThunk
>> created by main thread ($13d0) at:
7752a62c +00 shcore.dll
thread $2b68:
749562c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $20f4:
749562c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $1b60:
749562c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $864:
749562c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $1e28:
749562c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $ea0:
758eacb3 +93 KERNELBASE.dll

WaitForSingleObjectEx

758eac0d +0d KERNELBASE.dll


WaitForSingleObject
0044e6b5 +0d IncardexDesigner.exe madExcept CallThreadProcSafe
0044e71f +37 IncardexDesigner.exe madExcept ThreadExceptFrame
749562c2 +22 KERNEL32.DLL
BaseThreadInitThunk
>> created by main thread ($13d0) at:
7752a62c +00 shcore.dll
thread $1370:
749562c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $310:
749562c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $2274:
749562c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $2828:
758eacb3 +93 KERNELBASE.dll
WaitForSingleObjectEx
758eac0d +0d KERNELBASE.dll
WaitForSingleObject
0044e6b5 +0d IncardexDesigner.exe madExcept CallThreadProcSafe
0044e71f +37 IncardexDesigner.exe madExcept ThreadExceptFrame
749562c2 +22 KERNEL32.DLL
BaseThreadInitThunk
>> created by thread $1c4c at:
7752a62c +00 shcore.dll
thread $10ac:
758eacb3 +93 KERNELBASE.dll
WaitForSingleObjectEx
758eac0d +0d KERNELBASE.dll
WaitForSingleObject
0044e6b5 +0d IncardexDesigner.exe madExcept CallThreadProcSafe
0044e71f +37 IncardexDesigner.exe madExcept ThreadExceptFrame
749562c2 +22 KERNEL32.DLL
BaseThreadInitThunk
>> created by thread $1c4c at:
7752a62c +00 shcore.dll
thread $398:
758eacb3 +93 KERNELBASE.dll WaitForSingleObjectEx
758eac0d +0d KERNELBASE.dll WaitForSingleObject
749562c2 +22 KERNEL32.DLL
BaseThreadInitThunk
thread $1104:
758f1a5a +ea KERNELBASE.dll WaitForMultipleObjectsEx
749562c2 +22 KERNEL32.DLL
BaseThreadInitThunk
thread $2608:
749562c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $7f4:
749562c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $fbc:
758f1a5a +ea KERNELBASE.dll
WaitForMultipleObjectsEx
0044e6b5 +0d IncardexDesigner.exe madExcept CallThreadProcSafe
0044e71f +37 IncardexDesigner.exe madExcept ThreadExceptFrame
749562c2 +22 KERNEL32.DLL
BaseThreadInitThunk
>> created by thread $2798 at:
74dbd533 +00 combase.dll
modules:
00400000 IncardexDesigner.exe
Mars Systems\Incardex

1.6.10.122

C:\Program Files (x86)\

04850000 icProtect.dll
1.6.0.79
Mars Systems\Incardex
05ca0000 icProject.dll
1.6.2.138
Mars Systems\Incardex
08570000 icPreview.dll
1.6.0.137
Mars Systems\Incardex
0e640000 GrooveIntlResource.dll
16.0.7426.1015
Microsoft Office\root\Office16\1033
10000000 idmmkb.dll
6.19.9.1
Internet Download Manager
656d0000 OneCoreCommonProxyStub.dll 6.2.14393.0
65700000 browcli.dll
6.2.14393.0
65710000 ATL.DLL
3.5.2284.0
65730000 wcnapi.dll
6.2.14393.0
65750000 fdwcn.dll
6.2.14393.0
65770000 FunDisc.dll
6.2.14393.0
657a0000 FirewallAPI.dll
6.2.14393.0
65800000 msi.dll
5.0.14393.321
65b90000 GROOVEEX.DLL
16.0.7426.1015
Microsoft Office\root\Office16
66110000 dfscli.dll
6.2.14393.0
66120000 NetworkExplorer.dll
6.2.14393.0
662b0000 fdWNet.dll
6.2.14393.0
662c0000 FWPolicyIOMgr.dll
6.2.14393.0
662f0000 windowscodecsext.dll
6.2.14393.0
66340000 PhotoMetadataHandler.dll
6.2.14393.0
663a0000 provsvc.dll
6.2.14393.0
66410000 MrmCoreR.dll
6.2.14393.0
66660000 fdproxy.dll
6.2.14393.0
66670000 npmproxy.dll
6.2.14393.0
66680000 PlayToDevice.dll
6.2.14393.206
666e0000 MSVCP140.dll
14.0.23919.0
66750000 FileSyncShell.dll
17.3.6517.809
pData\Local\Microsoft\OneDrive\17.3.6517.0809
66900000 Windows.Storage.Search.dll 6.2.14393.0
669b0000 StructuredQuery.dll
7.0.14393.0
66b20000 cscapi.dll
6.2.14393.0
66b30000 srvcli.dll
6.2.14393.0
66b50000 ntshrui.dll
6.2.14393.351
66c20000 LINKINFO.dll
6.2.14393.0
66c30000 msvcp110_win.dll
6.2.14393.0
66ca0000 policymanager.dll
6.2.14393.0
66ce0000 thumbcache.dll
6.2.14393.0
68330000 RTWorkQ.DLL
6.2.14393.0
68360000 MFPlat.DLL
6.2.14393.351
68590000 PortableDeviceApi.dll
6.2.14393.0
6afc0000 apphelp.dll
6.2.14393.0
6b070000 MMDevApi.dll
6.2.14393.0
6b0d0000 DEVOBJ.dll
6.2.14393.0
6c4c0000 fwbase.dll
6.2.14393.0
6ce00000 dtsh.dll
6.2.14393.0
6ce30000 DevDispItemProvider.dll
6.2.14393.0
6ce50000 NetworkItemFactory.dll
6.2.14393.0
6ce60000 mssprxy.dll
7.0.14393.0
6ce80000 VCRUNTIME140.dll
14.0.23919.0
6cea0000 IconCodecService.dll
6.2.14393.0
6ceb0000 dlnashext.dll
6.2.14393.206
6cf00000 DAVHLPR.dll
6.2.14393.0
6cf10000 davclnt.dll
6.2.14393.0
6d0c0000 msxml3.dll
8.110.14393.0

C:\Program Files (x86)\


C:\Program Files (x86)\
C:\Program Files (x86)\
C:\Program Files (x86)\
C:\Program Files (x86)\
C:\Windows\System32
C:\Windows\SYSTEM32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\system32
C:\Windows\SYSTEM32
C:\Program Files (x86)\
C:\Windows\System32
C:\Windows\system32
C:\Windows\System32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\System32
C:\Windows\SYSTEM32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\SYSTEM32
C:\Users\Andi Indira\Ap
C:\Windows\system32
C:\Windows\System32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\System32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\System32
C:\Windows\system32
C:\Windows\System32
C:\Windows\System32
C:\Windows\system32
C:\Windows\system32
C:\Windows\System32
C:\Windows\system32
C:\Windows\system32
C:\Windows\SYSTEM32
C:\Windows\system32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32

6d330000 drprov.dll
6.2.14393.0
C:\Windows\System32
6d340000 tiptsf.dll
6.2.14393.206
C:\Program Files (x86)\
Common Files\microsoft shared\ink
6d510000 ntlanman.dll
6.2.14393.0
C:\Windows\System32
6d740000 msxml6.dll
6.30.14393.321
C:\Windows\System32
6e950000 WindowsCodecs.dll
6.2.14393.206
C:\Windows\SYSTEM32
6eac0000 twinapi.appcore.dll
6.2.14393.206
C:\Windows\system32
6ebc0000 dxgi.dll
6.2.14393.0
C:\Windows\system32
6ec50000 d3d11.dll
6.2.14393.351
C:\Windows\system32
6ee80000 dcomp.dll
6.2.14393.0
C:\Windows\system32
6efa0000 dataexchange.dll
6.2.14393.206
C:\Windows\system32
6f050000 fastprox.dll
6.2.14393.0
C:\Windows\system32\wbe
m
6f120000 wbemsvc.dll
6.2.14393.0
C:\Windows\system32\wbe
m
6f150000 WINMMBASE.dll
6.2.14393.0
C:\Windows\SYSTEM32
6f690000 winspool.drv
6.2.14393.0
C:\Windows\SYSTEM32
6f700000 wbemprox.dll
6.2.14393.0
C:\Windows\system32\wbe
m
70ab0000 wbemcomn.dll
6.2.14393.0
C:\Windows\SYSTEM32
70b60000 edputil.dll
6.2.14393.0
C:\Windows\SYSTEM32
71490000 MPR.dll
6.2.14393.0
C:\Windows\SYSTEM32
71ec0000 winmm.dll
6.2.14393.0
C:\Windows\SYSTEM32
72c30000 Cabinet.dll
5.0.1.1
C:\Windows\SYSTEM32
72c60000 propsys.dll
7.0.14393.0
C:\Windows\system32
73040000 ClientTelemetry.dll
1.3.210.1
C:\Users\Andi Indira\Ap
pData\Local\Microsoft\OneDrive\17.3.6517.0809
731a0000 comctl32.dll
6.10.14393.351
C:\Windows\WinSxS\x86_m
icrosoft.windows.common-controls_6595b64144ccf1df_6.0.14393.351_none_89c04962db0
40fd9
733b0000 wkscli.dll
6.2.14393.0
C:\Windows\System32
733c0000 Telemetry.dll
17.3.6517.809
C:\Users\Andi Indira\Ap
pData\Local\Microsoft\OneDrive\17.3.6517.0809
73410000 XmlLite.dll
6.2.14393.0
C:\Windows\SYSTEM32
734f0000 netutils.dll
6.2.14393.0
C:\Windows\System32
73500000 olepro32.dll
6.2.14393.351
C:\Windows\SYSTEM32
735f0000 MSVCR120.dll
12.0.21005.1
C:\Users\Andi Indira\Ap
pData\Local\Microsoft\OneDrive\17.3.6517.0809
736e0000 MSVCP120.dll
12.0.21005.1
C:\Users\Andi Indira\Ap
pData\Local\Microsoft\OneDrive\17.3.6517.0809
73760000 wsock32.dll
6.2.14393.0
C:\Windows\SYSTEM32
73770000 LoggingPlatform.DLL
17.3.6517.809
C:\Users\Andi Indira\Ap
pData\Local\Microsoft\OneDrive\17.3.6517.0809
73a10000 dwmapi.dll
6.2.14393.206
C:\Windows\system32
73a30000 uxtheme.dll
6.2.14393.0
C:\Windows\system32
73ab0000 msimg32.dll
6.2.14393.0
C:\Windows\SYSTEM32
73ac0000 gdiplus.dll
6.2.14393.321
C:\Windows\WinSxS\x86_m
icrosoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.321_none_baab3cb4359688b4
73d70000 WINSTA.dll
6.2.14393.0
C:\Windows\System32
73f30000 urlmon.dll
11.0.14393.351
C:\Windows\SYSTEM32
740d0000 DNSAPI.dll
6.2.14393.206
C:\Windows\SYSTEM32
74150000 WINNSI.DLL
6.2.14393.0
C:\Windows\SYSTEM32
74160000 mswsock.dll
6.2.14393.0
C:\Windows\system32
741b0000 ondemandconnroutehelper.dll 6.2.14393.0
C:\Windows\SYSTEM32
741c0000 dhcpcsvc.DLL
6.2.14393.0
C:\Windows\SYSTEM32
741e0000 dhcpcsvc6.DLL
6.2.14393.0
C:\Windows\SYSTEM32
74200000 iertutil.dll
11.0.14393.351
C:\Windows\SYSTEM32
74430000 winhttp.dll
6.2.14393.351
C:\Windows\SYSTEM32
744e0000 IPHLPAPI.DLL
6.2.14393.0
C:\Windows\SYSTEM32
74570000 bcrypt.dll
6.2.14393.0
C:\Windows\System32

745e0000
74620000
74900000
74910000
74930000
74940000
74a20000
74a40000
74b20000
74c60000
74cd0000
74ef0000
74fe0000
75170000
751c0000
751f0000
75220000
75630000
756e0000
75730000
75820000
75b40000
760b0000
774f0000
77580000
77590000
775a0000
775f0000
77670000
77760000
77770000
77840000
77920000
779c0000
77a10000
77a70000
77c30000
77cb0000
77cf0000
77e50000

version.dll
wininet.dll
CRYPTBASE.dll
SspiCli.dll
kernel.appcore.dll
KERNEL32.DLL
win32u.dll
ucrtbase.dll
MSCTF.dll
WS2_32.dll
combase.dll
ole32.dll
CRYPT32.dll
WINTRUST.dll
GDI32.dll
imm32.dll
SETUPAPI.dll
NSI.dll
sechost.dll
clbcatq.dll
KERNELBASE.dll
windows.storage.dll
shell32.dll
shcore.dll
profapi.dll
MSASN1.dll
shlwapi.dll
msvcp_win.dll
comdlg32.dll
PSAPI.DLL
RPCRT4.dll
msvcrt.dll
oleaut32.dll
powrprof.dll
bcryptPrimitives.dll
user32.dll
advapi32.dll
cfgmgr32.dll
gdi32full.dll
ntdll.dll

processes:
0000 Idle
0004 System
012c smss.exe
0200 csrss.exe
0254 wininit.exe
02d0 services.exe
02d8 lsass.exe
0328 svchost.exe
035c svchost.exe
01a0 svchost.exe
01bc svchost.exe
01e8 svchost.exe
01dc svchost.exe
0338 svchost.exe
0430 WUDFHost.exe
051c igfxCUIService.exe
0560 svchost.exe
05c8 svchost.exe

6.2.14393.0
11.0.14393.351
6.2.14393.0
6.2.14393.187
6.2.14393.0
6.2.14393.0
6.2.14393.51
6.2.14393.0
6.2.14393.351
6.2.14393.206
6.2.14393.351
6.2.14393.351
6.2.14393.351
6.2.14393.351
6.2.14393.206
6.2.14393.0
6.2.14393.0
6.2.14393.0
6.2.14393.0
2001.12.10941.16384
6.2.14393.321
6.2.14393.206
6.2.14393.351
6.2.14393.0
6.2.14393.0
6.2.14393.0
6.2.14393.0
6.2.14393.0
6.2.14393.0
6.2.14393.0
6.2.14393.82
7.0.14393.0
6.2.14393.351
6.2.14393.0
6.2.14393.0
6.2.14393.351
6.2.14393.0
6.2.14393.0
6.2.14393.206
6.2.14393.351
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0

C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\SYSTEM32

066c svchost.exe
0740 svchost.exe
07b4 spoolsv.exe
0584 svchost.exe
083c svchost.exe
087c armsvc.exe
0894 svchost.exe
08d4 esif_uf.exe
08f8 knshAE14.tmpfs
0940 svchost.exe
0950 svchost.exe
0958 Service_KMS.exe
0960 ScreenShotServ.exe
09a0 winsecurity.exe
09a8 MsMpEng.exe
09c4 WMPNetworkAcSvc.exe
09d4 XBLive.exe
0a9c Memory Compression
0d38 WmiPrvSE.exe
1090 NisSrv.exe
1770 dasHost.exe
0e40 mDNSResponder.exe
0750 AppleMobileDeviceService.exe
19b0 iPodService.exe
19e4 svchost.exe
2668 OfficeClickToRun.exe
171c SearchIndexer.exe
2418 csrss.exe
056c winlogon.exe
28a0 dwm.exe
1d30 esif_assist_64.exe
2064 sihost.exe
23dc svchost.exe
0e44 taskhostw.exe
26a0 explorer.exe
2240 RuntimeBroker.exe
1f04 igfxEM.exe
2108 ShellExperienceHost.exe
eHost_cw5n1h2txyewy
29f4 igfxHK.exe
1ba0 igfxTray.exe
1994 SearchUI.exe
ows.Cortana_cw5n1h2txyewy
15a0 QuickCapture.exe
1.1.0.3000053
2160 sysnetwk.exe
0a90 RAVCpl64.exe
1790 MSASCuiL.exe
0b30 iTunesHelper.exe
0288 OneDrive.exe
icrosoft\OneDrive
1d68 IDMan.exe
load Manager
04e8 SM?RTP.exe
0f70 IEMonitor.exe
load Manager
0f90 mshta.exe
071c dllhost.exe
0e78 fontdrvhost.exe
2194 ApplicationFrameHost.exe

0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
11
11
11
11
11
11
11
11
11
11
11

normal
normal
normal
normal
normal
normal
normal
normal

C:\Windows\Temp\DPTF
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows
C:\Windows\System32
C:\Windows\System32
C:\Windows\SystemApps\ShellExperienc

11 normal C:\Windows\System32
11 normal C:\Windows\System32
11 normal C:\Windows\SystemApps\Microsoft.Wind
11 normal C:\Program Files (x86)\QuickCapture\
11
11
11
11
11

normal
normal
normal
normal

C:\Program Files\Realtek\Audio\HDA
C:\Program Files\Windows Defender
C:\Program Files\iTunes
C:\Users\Andi Indira\AppData\Local\M

11 normal C:\Program Files (x86)\Internet Down


11 normal C:\Program Files (x86)\SMADAV
11 normal C:\Program Files (x86)\Internet Down
11 normal C:\Windows\SysWOW64
11 normal C:\Windows\System32
11
11 normal C:\Windows\System32

28b0 firefox.exe
ox
0afc InstallAgent.exe
11ec InstallAgentUserBroker.exe
147c WinRAR.exe
21fc audiodg.exe
2bfc dllhost.exe
29ac IncardexDesigner.exe
Incardex
1388 SearchProtocolHost.exe
0100 SearchFilterHost.exe

11 normal C:\Program Files (x86)\Mozilla Firef


11
11
11
0
11
11

normal C:\Windows\System32
normal C:\Windows\System32
normal C:\Program Files (x86)\WinRAR
normal C:\Program Files (x86)\Mars Systems\

0
0

hardware:
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
- Fax
- Microsoft Print to PDF
- Microsoft XPS Document Writer
- Root Print Queue
- Send To OneNote 2016
+ {36fc9e60-c465-11cf-8056-444553540000}
- Intel(R) USB 3.0 eXtensible Host Controller - 1.0 (Microsoft)
- USB Composite Device
- USB Root Hub (xHCI)
+ {4d36e966-e325-11ce-bfc1-08002be10318}
- ACPI x64-based PC
- Intel(R) Serial IO DMA Controller
+ {4d36e967-e325-11ce-bfc1-08002be10318}
- WDC WD5000LPCX-21VHAT0
+ {4d36e968-e325-11ce-bfc1-08002be10318}
- Intel(R) HD Graphics (driver 20.19.15.4360)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
- Standard SATA AHCI Controller
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
- Standard PS/2 Keyboard
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
- Intel(R) Display Audio (driver 6.16.0.3191)
- Realtek High Definition Audio (driver 6.0.1.7720)
+ {4d36e96d-e325-11ce-bfc1-08002be10318}
- Standard Modem over Bluetooth link
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
- Generic PnP Monitor
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
- HID-compliant mouse
+ {4d36e972-e325-11ce-bfc1-08002be10318}
- Bluetooth Device (Personal Area Network)
- Qualcomm Atheros AR956x Wireless Network Adapter (driver 3.0.2.201)
- Realtek PCIe GBE Family Controller (driver 8.43.1001.2015)
+ {4d36e978-e325-11ce-bfc1-08002be10318}
- Standard Serial over Bluetooth link (COM4)
- Standard Serial over Bluetooth link (COM5)
- Standard Serial over Bluetooth link (COM6)
- Standard Serial over Bluetooth link (COM8)
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
- Microsoft Storage Spaces Controller
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Power Button
- ACPI Sleep Button
- ACPI Thermal Zone

+
+

+
+
+

+
+
+

- Composite Bus Enumerator


- High Definition Audio Controller
- Intel 28F320C3 Flash Update Device Driver v6.4 (driver 6.4.0.0)
- Intel Serial IO GPIO Controller (driver 604.10146.3023.12819)
- Intel Serial IO GPIO Controller (driver 604.10146.3023.12819)
- Intel(R) Serial IO I2C ES Controller (driver 604.10146.3024.12813)
- Intel(R) Trusted Execution Engine Interface (driver 2.0.0.1094)
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft Basic Display Driver
- Microsoft Basic Render Driver
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator
- Microsoft Windows Management Interface for ACPI
- Motherboard resources
- Motherboard resources
- Motherboard resources
- NDIS Virtual Network Adapter Enumerator
- PCI Express Root Complex
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI-to-PCI Bridge
- PCI-to-PCI Bridge
- PCI-to-PCI Bridge
- Plug and Play Software Device Enumerator
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- SMBus Controller Device (driver 1.3.0.530)
- System CMOS/real time clock
- System timer
- UMBus Root Bus Enumerator
- Volume Manager
{50127dc3-0f36-415e-a6cc-4cb3be910b65}
- Intel(R) Celeron(R) CPU N3050 @ 1.60GHz
- Intel(R) Celeron(R) CPU N3050 @ 1.60GHz
{62f9c741-b25a-46ce-b54c-9bccce08b6f2}
- Bluetooth
- Microsoft Device Association Root Enumerator
- Microsoft GS Wavetable Synth
- Microsoft Radio Device Enumeration Bus
- Microsoft RRAS Root Enumerator
- Wi-Fi
{6bdd1fc6-810f-11d0-bec7-08002be2092f}
- VGA Webcam
{72631e54-78a4-11d0-bcf7-00aa00b7b32a}
- Microsoft AC Adapter
- Microsoft Surface ACPI-Compliant Control Method Battery
{745a17a0-74d3-11d0-b6fe-00a0c90f57da}
- HID-compliant touch pad
- I2C HID Device
- Microsoft Input Configuration Device
- PROVS. Sakir Audio/Video Remote Control HID
{a0a588a4-c46f-4b37-b7ea-c82fe89870c6}
- Intel SD Host Controller
- Intel SD Host Controller
{c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
- Microphone (Realtek High Definition Audio)
- Speakers (Realtek High Definition Audio)
{c3077fcd-9c3c-482f-9317-460712f23efd}
- Intel(R) Dynamic Platform and Thermal Framework Generic Participant (driver

8.1.10603.192)
- Intel(R) Dynamic Platform and Thermal Framework Manager (driver 8.1.10605.22
1)
- Intel(R) Dynamic Platform and Thermal Framework Processor Participant (drive
r 8.1.10605.221)
+ {d94ee5d8-d189-4994-83d2-f68d7d41b0e6}
- Trusted Platform Module 2.0
+ {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
- Audio Source Service
- AV Remote Target Service
- Handsfree Audio Gateway Service
- Headset Audio Gateway Service
- Microsoft Bluetooth Enumerator
- Microsoft Bluetooth LE Enumerator
- Obex File Transfer Service
- Object Push Service
- Personal Area Network NAP Service
- Phonebook Access Pse Service
- PROVS. Sakir
- Qualcomm Atheros Bluetooth 4.0 (driver 10.0.1.5)
- Sim Access Service
disassembling:
05e41f84
public iD_ProjectList.TProjectList.GetCurrentProject: ; function en
try point
05e41f84 66 push
ebp
05e41f85
mov
ebp, esp
05e41f87
add
esp, -8
05e41f8a
mov
[ebp-4], eax
05e41f8d 67 mov
eax, [ebp-4]
05e41f90
mov
edx, [eax+8]
05e41f93
mov
eax, [ebp-4]
05e41f96
mov
eax, [eax+4]
05e41f99
> call
-$1385ce ($5d099d0)
; Classes.TList.Get (icProject.dll)
05e41f99
05e41f9e
mov
[ebp-8], eax
05e41fa1
mov
eax, [ebp-8]
05e41fa4 68 pop
ecx
05e41fa5
pop
ecx
05e41fa6
pop
ebp
05e41fa7
ret
date/time
computer name
user name
registered owner
operating system
system language
system up time
program up time
processors
physical memory
free disk space
display mode
process id
allocated memory
executable
exec. date/time
version
compiled with

:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:
:

2016-12-07, 07:19:32, 127ms


DESKTOP-QLMG0TU
Andi Indira
Windows User
Windows NT New x64 build 9200
Indonesian
3 days 10 hours
31 seconds
2x Intel(R) Celeron(R) CPU N3050 @ 1.60GHz
634/1967 MB (free/total)
(C:) 16,41 GB
1366x768, 32 bit
$1028
112,36 MB
IncardexDesigner.exe
2016-03-26 00:53
1.6.10.122
Delphi 7

madExcept
callstack
exception
exception
exception

version
crc
number
class
message

:
:
:
:
:

3.0g
$29a96981, $d32ceb5b, $a9e4f235
1
EListError
List index out of bounds (0).

main thread ($1104):


072299e9 +019 icProject.dll
07361f99 +015 icProject.dll
rentProject
07369287 +00b icProject.dll
0059ad9d +039 IncardexDesigner.exe
urrentProject
0059af39 +055 IncardexDesigner.exe
Query
004c513d +055 IncardexDesigner.exe
ery
004c5065 +021 IncardexDesigner.exe
004c431c +000 IncardexDesigner.exe
004a648f +1df IncardexDesigner.exe
004aa1be +18e IncardexDesigner.exe
004c2215 +421 IncardexDesigner.exe
004a9d90 +034 IncardexDesigner.exe
Proc
00470350 +014 IncardexDesigner.exe
779e0004 +034 ntdll.dll
tcher
76da1156 +016 user32.dll
004c3683 +04b IncardexDesigner.exe
Handler
004abe95 +0ad IncardexDesigner.exe
mmand
004c43fd +055 IncardexDesigner.exe
mmand
004a648f +1df IncardexDesigner.exe
004aa1be +18e IncardexDesigner.exe
004c2215 +421 IncardexDesigner.exe
004a9d90 +034 IncardexDesigner.exe
Proc
00470350 +014 IncardexDesigner.exe
779e0004 +034 ntdll.dll
tcher
76da1156 +016 user32.dll
004c3683 +04b IncardexDesigner.exe
Handler
004a685b +01f IncardexDesigner.exe
nDown
004c412d +085 IncardexDesigner.exe
ttonDown
004a648f +1df IncardexDesigner.exe
004aa1be +18e IncardexDesigner.exe
004c2215 +421 IncardexDesigner.exe
004a9d90 +034 IncardexDesigner.exe
Proc
00470350 +014 IncardexDesigner.exe
76d4bc0b +00b user32.dll
004c8917 +083 IncardexDesigner.exe
sMessage
004c894e +00a IncardexDesigner.exe
Message

Classes
iD_ProjectList

TList.Get
67 +1 TProjectList.GetCur

icProject
iD_main

441 +1 d_IsModified
1955 +1 TformMain.TryCloseC

iD_main

1984 +5 TformMain.FormClose

Forms
Forms
Forms
Controls
Controls
Forms
Controls

TCustomForm.CloseQu
TCustomForm.Close
TCustomForm.WMClose
4653 +53 TControl.WndProc
6350 +33 TWinControl.WndProc
TCustomForm.WndProc
6245 +3 TWinControl.MainWnd

Classes

StdWndProc
KiUserCallbackDispa

Forms

DefFrameProcA
TCustomForm.Default

Controls
Forms
Controls
Controls
Forms
Controls

7180 +16 TWinControl.WMSysCo


TCustomForm.WMSysCo
4653 +53 TControl.WndProc
6350 +33 TWinControl.WndProc
TCustomForm.WndProc
6245 +3 TWinControl.MainWnd

Classes

StdWndProc
KiUserCallbackDispa

Forms

DefFrameProcA
TCustomForm.Default

Controls
Forms
Controls
Controls
Forms
Controls
Classes

4751 +2 TControl.WMNCLButto
TCustomForm.WMNCLBu
4653 +53 TControl.WndProc
6350 +33 TWinControl.WndProc
TCustomForm.WndProc
6245 +3 TWinControl.MainWnd

Forms

StdWndProc
DispatchMessageA
TApplication.Proces

Forms

TApplication.Handle

004c8b7e +096 IncardexDesigner.exe Forms


TApplication.Run
0059b906 +23a IncardexDesigner.exe IncardexDesigner 133 +64 initialization
767362c2 +022 KERNEL32.DLL
BaseThreadInitThunk
thread $fd0:
767362c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $1388:
767362c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $172c:
767362c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $f80:
767362c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $1428:
76a21a5a +ea KERNELBASE.dll
WaitForMultipleObjectsEx
0044e6b5 +0d IncardexDesigner.exe madExcept CallThreadProcSafe
0044e71f +37 IncardexDesigner.exe madExcept ThreadExceptFrame
767362c2 +22 KERNEL32.DLL
BaseThreadInitThunk
>> created by main thread ($1104) at:
7480d533 +00 combase.dll
thread $1310:
76a21a5a +ea KERNELBASE.dll WaitForMultipleObjectsEx
76d38ed3 +63 user32.dll
MsgWaitForMultipleObjects
767362c2 +22 KERNEL32.DLL
BaseThreadInitThunk
thread $cb4 (TEventWaitThread):
76a21a5a +0ea KERNELBASE.dll
76a21953 +013 KERNELBASE.dll
0055688e +02a IncardexDesigner.exe reinit
551 +3
0044e7d3 +02b IncardexDesigner.exe madExcept
0046ee10 +034 IncardexDesigner.exe Classes
00404c20 +028 IncardexDesigner.exe System
0044e6b5 +00d IncardexDesigner.exe madExcept
0044e71f +037 IncardexDesigner.exe madExcept
767362c2 +022 KERNEL32.DLL
>> created by main thread ($1104) at:
00594938 +268 IncardexDesigner.exe iD_main 596 +49
thread $8f0:
767362c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $1494:
767362c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $1030:
767362c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $14fc:
767362c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $f98:
767362c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $18ac:
767362c2 +22 KERNEL32.DLL BaseThreadInitThunk

WaitForMultipleObjectsEx
WaitForMultipleObjects
TEventWaitThread.Execute
HookedTThreadExecute
ThreadProc
ThreadWrapper
CallThreadProcSafe
ThreadExceptFrame
BaseThreadInitThunk
TformMain.FormCreate

thread $c4:
767362c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $dc0:
76d4a786 +26 user32.dll
GetMessageW
0044e6b5 +0d IncardexDesigner.exe madExcept CallThreadProcSafe
0044e71f +37 IncardexDesigner.exe madExcept ThreadExceptFrame
767362c2 +22 KERNEL32.DLL
BaseThreadInitThunk
>> created by thread $1494 at:
7648a62c +00 shcore.dll
thread $129c:
76d4a786 +26 user32.dll
GetMessageW
0044e6b5 +0d IncardexDesigner.exe madExcept CallThreadProcSafe
0044e71f +37 IncardexDesigner.exe madExcept ThreadExceptFrame
767362c2 +22 KERNEL32.DLL
BaseThreadInitThunk
>> created by thread $1030 at:
7648a62c +00 shcore.dll
thread $c38:
767362c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $ca8:
767362c2 +22 KERNEL32.DLL BaseThreadInitThunk
thread $724:
76a21a5a +ea KERNELBASE.dll
WaitForMultipleObjectsEx
0044e6b5 +0d IncardexDesigner.exe madExcept CallThreadProcSafe
0044e71f +37 IncardexDesigner.exe madExcept ThreadExceptFrame
767362c2 +22 KERNEL32.DLL
BaseThreadInitThunk
>> created by thread $169c at:
7480d533 +00 combase.dll
thread $6a0:
76a21a5a +ea KERNELBASE.dll
WaitForMultipleObjectsEx
0044e6b5 +0d IncardexDesigner.exe madExcept CallThreadProcSafe
0044e71f +37 IncardexDesigner.exe madExcept ThreadExceptFrame
767362c2 +22 KERNEL32.DLL
BaseThreadInitThunk
>> created by thread $169c at:
7480d533 +00 combase.dll
modules:
001d0000 WINMMBASE.dll
00400000 IncardexDesigner.exe
Mars Systems\Incardex
04850000 icProtect.dll
Mars Systems\Incardex
071c0000 icProject.dll
Mars Systems\Incardex
089e0000 icPreview.dll
Mars Systems\Incardex
0e620000 GrooveIntlResource.dll
Microsoft Office\root\Office16\1033
10000000 idmmkb.dll
Internet Download Manager
61da0000 PortableDeviceApi.dll
65e30000 GRA32A~1.DLL
fice12
661c0000 GR469A~1.DLL
fice12

6.2.14393.0
1.6.10.122

C:\Windows\SYSTEM32
C:\Program Files (x86)\

1.6.0.79

C:\Program Files (x86)\

1.6.2.138

C:\Program Files (x86)\

1.6.0.137

C:\Program Files (x86)\

16.0.7426.1015

C:\Program Files (x86)\

6.19.9.1

C:\Program Files (x86)\

6.2.14393.0
12.0.4518.1014

C:\Windows\System32
C:\PROGRA~2\MICROS~1\Of

12.0.4518.1014

C:\PROGRA~2\MICROS~1\Of

66f60000 DevDispItemProvider.dll
6.2.14393.0
C:\Windows\System32
66fe0000 dlnashext.dll
6.2.14393.206
C:\Windows\System32
67030000 ActXPrxy.dll
6.2.14393.0
C:\Windows\System32
671c0000 tiptsf.dll
6.2.14393.206
C:\Program Files (x86)\
Common Files\microsoft shared\ink
67240000 ntshrui.dll
6.2.14393.351
C:\Windows\SYSTEM32
676b0000 thumbcache.dll
6.2.14393.0
C:\Windows\System32
67b50000 DAVHLPR.dll
6.2.14393.0
C:\Windows\System32
67b60000 davclnt.dll
6.2.14393.0
C:\Windows\System32
67b80000 drprov.dll
6.2.14393.0
C:\Windows\System32
67b90000 ntlanman.dll
6.2.14393.0
C:\Windows\System32
67bb0000 srvcli.dll
6.2.14393.0
C:\Windows\SYSTEM32
67bd0000 LINKINFO.dll
6.2.14393.0
C:\Windows\SYSTEM32
68ef0000 GrooveUtil.DLL
12.0.4518.1014
C:\PROGRA~2\MICROS~1\Of
fice12
68ff0000 GrooveNew.DLL
12.0.4518.1014
C:\PROGRA~2\MICROS~1\Of
fice12
6a830000 RTWorkQ.DLL
6.2.14393.0
C:\Windows\SYSTEM32
6a860000 MFPlat.DLL
6.2.14393.351
C:\Windows\SYSTEM32
6ac00000 provsvc.dll
6.2.14393.0
C:\Windows\System32
6ac70000 PlayToDevice.dll
6.2.14393.206
C:\Windows\System32
6acd0000 msi.dll
5.0.14393.321
C:\Windows\SYSTEM32
6b060000 GROOVEEX.DLL
16.0.7426.1015
C:\Program Files (x86)\
Microsoft Office\root\Office16
6b2f0000 mssprxy.dll
7.0.14393.0
C:\Windows\system32
6b310000 MMDevApi.dll
6.2.14393.0
C:\Windows\System32
6b370000 DEVOBJ.dll
6.2.14393.0
C:\Windows\System32
6b3b0000 MSVCR80.dll
8.0.50727.9268
C:\Windows\WinSxS\x86_m
icrosoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9268_none_d08e1538442a243e
6b450000 MSVCP140.dll
14.0.23919.0
C:\Windows\SYSTEM32
6b4c0000 FileSyncShell.dll
17.3.6517.809
C:\Users\Andi Indira\Ap
pData\Local\Microsoft\OneDrive\17.3.6517.0809
6b670000 Windows.Storage.Search.dll 6.2.14393.0
C:\Windows\system32
6b720000 StructuredQuery.dll
7.0.14393.0
C:\Windows\System32
6b7b0000 msvcp110_win.dll
6.2.14393.0
C:\Windows\SYSTEM32
6b820000 policymanager.dll
6.2.14393.0
C:\Windows\SYSTEM32
6b860000 apphelp.dll
6.2.14393.0
C:\Windows\SYSTEM32
6bab0000 msxml3.dll
8.110.14393.0
C:\Windows\System32
6fa40000 ATL80.DLL
8.0.50727.6195
C:\Windows\WinSxS\x86_m
icrosoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d1cb102c435421de
6fa60000 cscapi.dll
6.2.14393.0
C:\Windows\SYSTEM32
6fa70000 VCRUNTIME140.dll
14.0.23919.0
C:\Windows\SYSTEM32
6fa90000 IconCodecService.dll
6.2.14393.0
C:\Windows\system32
6fad0000 winspool.drv
6.2.14393.0
C:\Windows\SYSTEM32
6fbd0000 WindowsCodecs.dll
6.2.14393.206
C:\Windows\SYSTEM32
6ff60000 winmm.dll
6.2.14393.0
C:\Windows\SYSTEM32
70090000 twinapi.appcore.dll
6.2.14393.206
C:\Windows\system32
70190000 dxgi.dll
6.2.14393.0
C:\Windows\system32
70220000 dcomp.dll
6.2.14393.0
C:\Windows\system32
70340000 d3d11.dll
6.2.14393.351
C:\Windows\system32
70570000 dataexchange.dll
6.2.14393.206
C:\Windows\system32
71a20000 MPR.dll
6.2.14393.0
C:\Windows\SYSTEM32
71c00000 edputil.dll
6.2.14393.0
C:\Windows\SYSTEM32
72460000 wkscli.dll
6.2.14393.0
C:\Windows\System32
72470000 netutils.dll
6.2.14393.0
C:\Windows\System32
72710000 Cabinet.dll
5.0.1.1
C:\Windows\SYSTEM32
72740000 Telemetry.dll
17.3.6517.809
C:\Users\Andi Indira\Ap
pData\Local\Microsoft\OneDrive\17.3.6517.0809
72790000 propsys.dll
7.0.14393.0
C:\Windows\system32
728e0000 XmlLite.dll
6.2.14393.0
C:\Windows\SYSTEM32

72d10000 ClientTelemetry.dll
1.3.210.1
C:\Users\Andi Indira\Ap
pData\Local\Microsoft\OneDrive\17.3.6517.0809
72e70000 MSVCR120.dll
12.0.21005.1
C:\Users\Andi Indira\Ap
pData\Local\Microsoft\OneDrive\17.3.6517.0809
72f60000 MSVCP120.dll
12.0.21005.1
C:\Users\Andi Indira\Ap
pData\Local\Microsoft\OneDrive\17.3.6517.0809
72fe0000 wsock32.dll
6.2.14393.0
C:\Windows\SYSTEM32
72ff0000 LoggingPlatform.DLL
17.3.6517.809
C:\Users\Andi Indira\Ap
pData\Local\Microsoft\OneDrive\17.3.6517.0809
730f0000 comctl32.dll
6.10.14393.351
C:\Windows\WinSxS\x86_m
icrosoft.windows.common-controls_6595b64144ccf1df_6.0.14393.351_none_89c04962db0
40fd9
73350000 olepro32.dll
6.2.14393.351
C:\Windows\SYSTEM32
73570000 dwmapi.dll
6.2.14393.206
C:\Windows\system32
73590000 uxtheme.dll
6.2.14393.0
C:\Windows\system32
73610000 msimg32.dll
6.2.14393.0
C:\Windows\SYSTEM32
73620000 gdiplus.dll
6.2.14393.321
C:\Windows\WinSxS\x86_m
icrosoft.windows.gdiplus_6595b64144ccf1df_1.1.14393.321_none_baab3cb4359688b4
73830000 urlmon.dll
11.0.14393.351
C:\Windows\SYSTEM32
73a40000 DNSAPI.dll
6.2.14393.206
C:\Windows\SYSTEM32
73ac0000 dhcpcsvc.DLL
6.2.14393.0
C:\Windows\SYSTEM32
73ae0000 dhcpcsvc6.DLL
6.2.14393.0
C:\Windows\SYSTEM32
73b00000 WINNSI.DLL
6.2.14393.0
C:\Windows\SYSTEM32
73b10000 mswsock.dll
6.2.14393.0
C:\Windows\system32
73bc0000 ondemandconnroutehelper.dll 6.2.14393.0
C:\Windows\SYSTEM32
73bd0000 WINSTA.dll
6.2.14393.0
C:\Windows\System32
73c90000 IPHLPAPI.DLL
6.2.14393.0
C:\Windows\SYSTEM32
73dc0000 iertutil.dll
11.0.14393.351
C:\Windows\SYSTEM32
73ff0000 winhttp.dll
6.2.14393.351
C:\Windows\SYSTEM32
74090000 bcrypt.dll
6.2.14393.0
C:\Windows\System32
740b0000 rsaenh.dll
6.2.14393.0
C:\Windows\system32
740e0000 CRYPTSP.dll
6.2.14393.0
C:\Windows\SYSTEM32
74100000 version.dll
6.2.14393.0
C:\Windows\SYSTEM32
74140000 wininet.dll
11.0.14393.351
C:\Windows\SYSTEM32
74420000 CRYPTBASE.dll
6.2.14393.0
C:\Windows\System32
74430000 SspiCli.dll
6.2.14393.187
C:\Windows\System32
74510000 CRYPT32.dll
6.2.14393.351
C:\Windows\System32
746a0000 advapi32.dll
6.2.14393.0
C:\Windows\System32
74720000 combase.dll
6.2.14393.351
C:\Windows\System32
74940000 msvcrt.dll
7.0.14393.0
C:\Windows\System32
74a00000 shell32.dll
6.2.14393.351
C:\Windows\System32
75de0000 cfgmgr32.dll
6.2.14393.0
C:\Windows\System32
75e20000 powrprof.dll
6.2.14393.0
C:\Windows\System32
75f70000 SETUPAPI.dll
6.2.14393.0
C:\Windows\System32
76380000 oleaut32.dll
6.2.14393.351
C:\Windows\System32
76420000 GDI32.dll
6.2.14393.206
C:\Windows\System32
76450000 shcore.dll
6.2.14393.0
C:\Windows\System32
764e0000 shlwapi.dll
6.2.14393.0
C:\Windows\System32
76530000 sechost.dll
6.2.14393.0
C:\Windows\System32
76580000 bcryptPrimitives.dll
6.2.14393.0
C:\Windows\System32
765e0000 MSCTF.dll
6.2.14393.351
C:\Windows\System32
76720000 KERNEL32.DLL
6.2.14393.0
C:\Windows\System32
76800000 imm32.dll
6.2.14393.0
C:\Windows\System32
76850000 kernel.appcore.dll
6.2.14393.0
C:\Windows\System32
76860000 comdlg32.dll
6.2.14393.0
C:\Windows\System32
76950000 KERNELBASE.dll
6.2.14393.321
C:\Windows\System32
76b00000 msvcp_win.dll
6.2.14393.0
C:\Windows\System32
76b80000 PSAPI.DLL
6.2.14393.0
C:\Windows\System32
76b90000 clbcatq.dll
2001.12.10941.16384 C:\Windows\System32
76c20000 RPCRT4.dll
6.2.14393.82
C:\Windows\System32

76cf0000
76d00000
76d20000
76ff0000
77000000
77570000
775c0000
77720000
77800000
77870000
77960000
77970000

NSI.dll
win32u.dll
user32.dll
MSASN1.dll
windows.storage.dll
WINTRUST.dll
gdi32full.dll
ucrtbase.dll
WS2_32.dll
ole32.dll
profapi.dll
ntdll.dll

processes:
0000 Idle
0004 System
012c smss.exe
0204 csrss.exe
025c wininit.exe
02d8 services.exe
02f0 lsass.exe
0344 svchost.exe
0380 svchost.exe
01ec svchost.exe
01e8 svchost.exe
03cc WUDFHost.exe
0468 svchost.exe
0470 svchost.exe
049c svchost.exe
0560 igfxCUIService.exe
05c4 svchost.exe
060c svchost.exe
0624 svchost.exe
06d0 svchost.exe
0754 spoolsv.exe
04c0 svchost.exe
05f0 armsvc.exe
0654 OfficeClickToRun.exe
06e0 svchost.exe
0804 AppleMobileDeviceService.exe
080c mDNSResponder.exe
0834 esif_uf.exe
08e4 knshAE14.tmpfs
0960 Service_KMS.exe
0968 XBLive.exe
0970 ScreenShotServ.exe
0978 winsecurity.exe
0980 WMPNetworkAcSvc.exe
09ac svchost.exe
0a10 svchost.exe
0a18 MsMpEng.exe
0a4c Memory Compression
0e14 NisSrv.exe
0eb0 WmiPrvSE.exe
1328 SearchIndexer.exe
1570 iPodService.exe
1238 svchost.exe
1a58 dasHost.exe
048c csrss.exe
124c winlogon.exe

6.2.14393.0
6.2.14393.51
6.2.14393.351
6.2.14393.0
6.2.14393.206
6.2.14393.351
6.2.14393.206
6.2.14393.0
6.2.14393.206
6.2.14393.351
6.2.14393.0
6.2.14393.351
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
8
8

C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\SYSTEM32

0ac0 dwm.exe
8
1670 esif_assist_64.exe
8 normal
15f4 QuickCapture.exe
8 normal
ture\1.1.0.3000053
0950 sihost.exe
8 normal
16cc svchost.exe
8 normal
04a4 taskhostw.exe
8 normal
1658 SM?RTP.exe
8
0830 rundll32.exe
8 normal
1ae0 igfxEM.exe
8 normal
0330 igfxHK.exe
8 normal
0bc8 igfxTray.exe
8 normal
0cec explorer.exe
8 normal
0550 RuntimeBroker.exe
8 normal
0f70 ShellExperienceHost.exe
8 normal
rienceHost_cw5n1h2txyewy
12b8 SearchUI.exe
8 normal
.Windows.Cortana_cw5n1h2txyewy
12f4 sysnetwk.exe
8
068c RAVCpl64.exe
8 normal
HDA
0478 MSASCuiL.exe
8 normal
er
0580 iTunesHelper.exe
8 normal
1818 OneDrive.exe
8 normal
cal\Microsoft\OneDrive
1480 IDMan.exe
8 normal
Download Manager
1990 IEMonitor.exe
8 normal
Download Manager
18bc mshta.exe
8 normal
148c dllhost.exe
8 normal
0cd8 ApplicationFrameHost.exe
8 normal
1498 InstallAgent.exe
8 normal
14d8 InstallAgentUserBroker.exe 8 normal
1024 SystemSettingsBroker.exe
8 above normal
0b78 firefox.exe
8 normal
Firefox
1408 WinRAR.exe
8 normal
0b44 SkypeHost.exe
8 normal
crosoft.SkypeApp_11.4.86.0_x64__kzf8qxf38zg5c
191c WinRAR.exe
8 normal
1028 IncardexDesigner.exe
8 normal
tems\Incardex
1a3c audiodg.exe
0

C:\Windows\Temp\DPTF
C:\Program Files (x86)\QuickCap
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows
C:\Windows\System32
C:\Windows\SystemApps\ShellExpe
C:\Windows\SystemApps\Microsoft
C:\Program Files\Realtek\Audio\
C:\Program Files\Windows Defend
C:\Program Files\iTunes
C:\Users\Andi Indira\AppData\Lo
C:\Program Files (x86)\Internet
C:\Program Files (x86)\Internet
C:\Windows\SysWOW64
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
C:\Program Files (x86)\Mozilla
C:\Program Files (x86)\WinRAR
C:\Program Files\WindowsApps\Mi
C:\Program Files (x86)\WinRAR
C:\Program Files (x86)\Mars Sys

hardware:
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
- Fax
- Microsoft Print to PDF
- Microsoft XPS Document Writer
- Root Print Queue
- Send To OneNote 2016
+ {36fc9e60-c465-11cf-8056-444553540000}
- Intel(R) USB 3.0 eXtensible Host Controller - 1.0 (Microsoft)
- USB Composite Device
- USB Root Hub (xHCI)
+ {4d36e966-e325-11ce-bfc1-08002be10318}
- ACPI x64-based PC
- Intel(R) Serial IO DMA Controller

+ {4d36e967-e325-11ce-bfc1-08002be10318}
- WDC WD5000LPCX-21VHAT0
+ {4d36e968-e325-11ce-bfc1-08002be10318}
- Intel(R) HD Graphics (driver 20.19.15.4360)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
- Standard SATA AHCI Controller
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
- Standard PS/2 Keyboard
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
- Intel(R) Display Audio (driver 6.16.0.3191)
- Realtek High Definition Audio (driver 6.0.1.7720)
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
- Generic PnP Monitor
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
- HID-compliant mouse
+ {4d36e972-e325-11ce-bfc1-08002be10318}
- Qualcomm Atheros AR956x Wireless Network Adapter (driver 3.0.2.201)
- Realtek PCIe GBE Family Controller (driver 8.43.1001.2015)
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
- Microsoft Storage Spaces Controller
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Power Button
- ACPI Sleep Button
- ACPI Thermal Zone
- Composite Bus Enumerator
- High Definition Audio Controller
- Intel 28F320C3 Flash Update Device Driver v6.4 (driver 6.4.0.0)
- Intel Serial IO GPIO Controller (driver 604.10146.3023.12819)
- Intel Serial IO GPIO Controller (driver 604.10146.3023.12819)
- Intel(R) Serial IO I2C ES Controller (driver 604.10146.3024.12813)
- Intel(R) Trusted Execution Engine Interface (driver 2.0.0.1094)
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft Basic Display Driver
- Microsoft Basic Render Driver
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator
- Microsoft Windows Management Interface for ACPI
- Motherboard resources
- Motherboard resources
- Motherboard resources
- NDIS Virtual Network Adapter Enumerator
- PCI Express Root Complex
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI-to-PCI Bridge
- PCI-to-PCI Bridge
- PCI-to-PCI Bridge
- Plug and Play Software Device Enumerator
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- SMBus Controller Device (driver 1.3.0.530)
- System CMOS/real time clock
- System timer
- UMBus Root Bus Enumerator
- Volume Manager
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
- Intel(R) Celeron(R) CPU N3050 @ 1.60GHz

- Intel(R) Celeron(R) CPU N3050 @ 1.60GHz


+ {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
- Bluetooth
- Microsoft Device Association Root Enumerator
- Microsoft GS Wavetable Synth
- Microsoft Radio Device Enumeration Bus
- Microsoft RRAS Root Enumerator
- Wi-Fi
+ {6bdd1fc6-810f-11d0-bec7-08002be2092f}
- VGA Webcam
+ {72631e54-78a4-11d0-bcf7-00aa00b7b32a}
- Microsoft AC Adapter
- Microsoft Surface ACPI-Compliant Control Method Battery
+ {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
- HID-compliant touch pad
- I2C HID Device
- Microsoft Input Configuration Device
+ {a0a588a4-c46f-4b37-b7ea-c82fe89870c6}
- Intel SD Host Controller
- Intel SD Host Controller
+ {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
- Microphone (Realtek High Definition Audio)
- Speakers (Realtek High Definition Audio)
+ {c3077fcd-9c3c-482f-9317-460712f23efd}
- Intel(R) Dynamic Platform and Thermal Framework Generic Participant (driver
8.1.10603.192)
- Intel(R) Dynamic Platform and Thermal Framework Manager (driver 8.1.10605.22
1)
- Intel(R) Dynamic Platform and Thermal Framework Processor Participant (drive
r 8.1.10605.221)
+ {d94ee5d8-d189-4994-83d2-f68d7d41b0e6}
- Trusted Platform Module 2.0
+ {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
- Qualcomm Atheros Bluetooth 4.0 (driver 10.0.1.5)
disassembling:
07361f84
public iD_ProjectList.TProjectList.GetCurrentProject: ; function en
try point
07361f84 66 push
ebp
07361f85
mov
ebp, esp
07361f87
add
esp, -8
07361f8a
mov
[ebp-4], eax
07361f8d 67 mov
eax, [ebp-4]
07361f90
mov
edx, [eax+8]
07361f93
mov
eax, [ebp-4]
07361f96
mov
eax, [eax+4]
07361f99
> call
-$1385ce ($72299d0)
; Classes.TList.Get (icProject.dll)
07361f99
07361f9e
mov
[ebp-8], eax
07361fa1
mov
eax, [ebp-8]
07361fa4 68 pop
ecx
07361fa5
pop
ecx
07361fa6
pop
ebp
07361fa7
ret

You might also like