You are on page 1of 10

date/time : 2022-11-03, 16:43:21, 213ms

computer name : DESKTOP-E01SE3A


user name : LUPIS
registered owner : LUPIS
operating system : Windows Vista x64 build 6000
system language : Spanish
system up time : 9 hours 33 minutes
program up time : 58 seconds
processors : 4x Intel(R) Core(TM) i3-2100 CPU @ 3.10GHz
physical memory : 1378/4004 MB (free/total)
free disk space : (C:) 67.19 GB (D:) 0 Bytes
display mode : 1366x768, 32 bit
process id : $3174
allocated memory : 76.15 MB
executable : !ISRE1.EXE
exec. date/time : 2010-11-04 00:24
version : 13.0.0.23
compiled with : Delphi 2007
madExcept version : 3.0e
callstack crc : $149b21b8, $0dd7b886, $33693f64
exception number : 8
exception class : Exception
exception message : ICDecompressOpen.

main thread ($2a38):


006f17df +01b !ISRE1.EXE VideoPlay 888 +1TVideoPlayer.RaiseError
006f18c1 +0d9 !ISRE1.EXE VideoPlay 908 +13TVideoPlayer.OpenVideoDecompressor
006f0bba +59e !ISRE1.EXE VideoPlay 520 +98TVideoPlayer.Open
00724df2 +3ea !ISRE1.EXE VidIF 286 +70TVideoInterface.PlayMediaFile
0072496d +165 !ISRE1.EXE VidIF 200 +32TVideoInterface.PlayMedia
007255d3 +123 !ISRE1.EXE VidMgr 210 +16TVideoManager.PlayQueue
00725827 +1bb !ISRE1.EXE VidMgr 288 +37TVideoManager.Play
0079c94d +2d5 !ISRE1.EXE Exercise 3279 +77TExerciseForm.IntroTimerHandler
004a68fb +00f !ISRE1.EXE ExtCtrls TTimer.Timer
004a67df +02b !ISRE1.EXE ExtCtrls TTimer.WndProc
0047aed4 +014 !ISRE1.EXE Classes StdWndProc
7760838b +00b USER32.dll DispatchMessageA
004bd1c8 +0fc !ISRE1.EXE Forms TApplication.ProcessMessage
004bd202 +00a !ISRE1.EXE Forms TApplication.HandleMessage
004bd4f7 +0b3 !ISRE1.EXE Forms TApplication.Run
00851245 +3f9 !ISRE1.EXE Player 175 +83 initialization
779bfa27 +017 KERNEL32.DLL BaseThreadInitThunk
7788f177 +237 KERNELBASE.dll CompareStringW
779bfa27 +017 KERNEL32.DLL BaseThreadInitThunk

thread $20f8:
77e8482c +0c ntdll.dll NtWaitForWorkViaWorkerFactory
779bfa27 +17 KERNEL32.DLL BaseThreadInitThunk

thread $5b4:
77e8482c +0c ntdll.dll NtWaitForWorkViaWorkerFactory
779bfa27 +17 KERNEL32.DLL BaseThreadInitThunk

thread $470:
77e8482c +0c ntdll.dll NtWaitForWorkViaWorkerFactory
779bfa27 +17 KERNEL32.DLL BaseThreadInitThunk

thread $818:
77e82e3c +0c ntdll.dll NtDelayExecution
778a76a5 +45 KERNELBASE.dll SleepEx
778a764a +0a KERNELBASE.dll Sleep
779bfa27 +17 KERNEL32.DLL BaseThreadInitThunk

thread $fb0:
77e8482c +0c ntdll.dll NtWaitForWorkViaWorkerFactory
779bfa27 +17 KERNEL32.DLL BaseThreadInitThunk

thread $1bf0:
77e8482c +0c ntdll.dll NtWaitForWorkViaWorkerFactory
779bfa27 +17 KERNEL32.DLL BaseThreadInitThunk

thread $25e8:
77e830ac +0c ntdll.dll NtWaitForMultipleObjects
7789dead +fd KERNELBASE.dll WaitForMultipleObjectsEx
0045067d +0d !ISRE1.EXE madExcept CallThreadProcSafe
004506e7 +37 !ISRE1.EXE madExcept ThreadExceptFrame
779bfa27 +17 KERNEL32.DLL BaseThreadInitThunk
>> created by main thread ($2a38) at:
76c25f41 +00 combase.dll

thread $abc:
77e8482c +0c ntdll.dll NtWaitForWorkViaWorkerFactory
779bfa27 +17 KERNEL32.DLL BaseThreadInitThunk

thread $d34:
77e8482c +0c ntdll.dll NtWaitForWorkViaWorkerFactory
779bfa27 +17 KERNEL32.DLL BaseThreadInitThunk

thread $5c4: <priority:14>


77e830ac +0c ntdll.dll NtWaitForMultipleObjects
7789dead +fd KERNELBASE.dll WaitForMultipleObjectsEx
779bfa27 +17 KERNEL32.DLL BaseThreadInitThunk

thread $3040:
77e8482c +0c ntdll.dll NtWaitForWorkViaWorkerFactory
779bfa27 +17 KERNEL32.DLL BaseThreadInitThunk

thread $2968 (TWaveInCBThread):


77e82b1c +0c ntdll.dll NtWaitForSingleObject
77893d63 +93 KERNELBASE.dll WaitForSingleObjectEx
77893cbd +0d KERNELBASE.dll WaitForSingleObject
006fc0ce +16 !ISRE1.EXE Recognizer 1237 +4 TWaveInCBThread.Execute
0045079b +2b !ISRE1.EXE madExcept HookedTThreadExecute
00479124 +34 !ISRE1.EXE Classes ThreadProc
00405638 +28 !ISRE1.EXE System 91 +0 ThreadWrapper
0045067d +0d !ISRE1.EXE madExcept CallThreadProcSafe
004506e7 +37 !ISRE1.EXE madExcept ThreadExceptFrame
779bfa27 +17 KERNEL32.DLL BaseThreadInitThunk
>> created by main thread ($2a38) at:
004791ea +52 !ISRE1.EXE Classes TThread.Create

thread $2790 (TWorkerThread):


77e82b1c +0c ntdll.dll NtWaitForSingleObject
77893d63 +93 KERNELBASE.dll WaitForSingleObjectEx
77893cbd +0d KERNELBASE.dll WaitForSingleObject
005d696e +16 !ISRE1.EXE VirtualTrees 4484 +3 TWorkerThread.Execute
0045079b +2b !ISRE1.EXE madExcept HookedTThreadExecute
00479124 +34 !ISRE1.EXE Classes ThreadProc
00405638 +28 !ISRE1.EXE System 91 +0 ThreadWrapper
0045067d +0d !ISRE1.EXE madExcept CallThreadProcSafe
004506e7 +37 !ISRE1.EXE madExcept ThreadExceptFrame
779bfa27 +17 KERNEL32.DLL BaseThreadInitThunk
>> created by main thread ($2a38) at:
004791ea +52 !ISRE1.EXE Classes TThread.Create

hardware:
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
- Cola de impresi�n ra�z
- Fax
- Microsoft Print to PDF
- Microsoft XPS Document Writer
- OneNote for Windows 10
- Send To OneNote 2016
+ {36fc9e60-c465-11cf-8056-444553540000}
- Concentrador ra�z USB
- Concentrador ra�z USB
- Controladora de host mejorada USB de la familia Chipset Intel(R) serie 6/serie
C200 - 1C26
- Controladora de host mejorada USB de la familia Chipset Intel(R) serie 6/serie
C200 - 1C2D
- Dispositivo compuesto USB
- Dispositivo compuesto USB
- Generic USB Hub
- Generic USB Hub
+ {4d36e965-e325-11ce-bfc1-08002be10318}
- hp DVD A DH16AAL
+ {4d36e966-e325-11ce-bfc1-08002be10318}
- Equipo basado en x64 ACPI
+ {4d36e967-e325-11ce-bfc1-08002be10318}
- ADATA SU650
+ {4d36e968-e325-11ce-bfc1-08002be10318}
- Intel(R) HD Graphics (driver 9.17.10.4459)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
- Controladora SATA AHCI est�ndar
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
- Dispositivo de teclado HID
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
- Dispositivo de High Definition Audio
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
- Monitor PnP gen�rico
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
- Mouse compatible con HID
+ {4d36e972-e325-11ce-bfc1-08002be10318}
- Intel(R) 82579LM Gigabit Network Connection
- Kaspersky VPN (driver 30.854.0.240)
+ {4d36e978-e325-11ce-bfc1-08002be10318}
- Puerto de comunicaciones (COM1)
- Puerto de impresora (LPT1)
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
- Controladora de espacios de almacenamiento de Microsoft
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
- Administrador de vol�menes
- Altavoz del sistema
- Bot�n de caracter�stica fija ACPI
- Bot�n de inicio/apagado ACPI
- Bus del Redirector de dispositivos de Escritorio remoto
- Complejo ra�z PCI Express
- Controlador BIOS de Microsoft System Management
- Controlador de infraestructura de virtualizaci�n de Microsoft Hyper-V
- Controlador de pantalla b�sica de Microsoft
- Controlador de representaci�n b�sica de Microsoft
- Controladora de acceso directo a memoria
- Controladora de bus SM
- Controladora de High Definition Audio
- Controladora de memoria
- Controladora LPC
- Controladora programable de interrupciones
- Enumerador de adaptador de red virtual NDIS
- Enumerador de bus compuesto
- Enumerador de bus ra�z de UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador de unidades virtuales de Microsoft
- Interfaz l�gica de puerto de impresora
- Placa del sistema
- Placa del sistema
- Placa del sistema
- Procesador de datos num�ricos
- Puente PCI Express a PCI/PCI-X
- Puerto ra�z PCI Express
- Recursos de la placa base
- Recursos de la placa base
- Recursos de la placa base
- Recursos de la placa base
- Sistema CMOS/reloj en tiempo real
- Sistema Microsoft compatible con ACPI
- Temporizador de eventos de alta precisi�n
- Temporizador del sistema
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
- Intel(R) Core(TM) i3-2100 CPU @ 3.10GHz
- Intel(R) Core(TM) i3-2100 CPU @ 3.10GHz
- Intel(R) Core(TM) i3-2100 CPU @ 3.10GHz
- Intel(R) Core(TM) i3-2100 CPU @ 3.10GHz
+ {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
- Microsoft Radio Device Enumeration Bus
- Microsoft RRAS Root Enumerator
- Sintetizador por software GS de tabla de onda de
+ {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
- Controlador del sistema compatible con HID
- Dispositivo de control del consumidor compatible con HID
- Dispositivo de entrada USB
- Dispositivo de entrada USB
- Dispositivo de entrada USB
- Dispositivo definido por el proveedor compatible con HID
+ {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
- Altavoces (High Definition Audio Device)
- Digital Audio (S/PDIF) (High Definition Audio Device)
- Headphones (High Definition Audio Device)
- Microphone (High Definition Audio Device)
- Microphone (High Definition Audio Device)
+ {ca3e7ab9-b4c3-4ae6-8251-579ef933890f}
- Integrated Camera

modules:
00400000 !ISRE1.EXE 13.0.0.23 D:
54ad0000 l3codeca.acm 1.9.0.401 C:\Windows\System32
54af0000 msgsm32.acm 6.2.19041.1 C:\Windows\SYSTEM32
54b00000 msg711.acm 6.2.19041.1 C:\Windows\SYSTEM32
54b10000 msadp32.acm 6.2.19041.1 C:\Windows\SYSTEM32
54b20000 imaadp32.acm 6.2.19041.1 C:\Windows\SYSTEM32
54b30000 midimap.dll 6.2.19041.488 C:\Windows\SYSTEM32
54b40000 AUDIOSES.DLL 6.2.19041.1741 C:\Windows\SYSTEM32
54c80000 wdmaud.drv 6.2.19041.1 C:\Windows\SYSTEM32
54dd0000 msacm32.drv 6.2.19041.488 C:\Windows\SYSTEM32
54de0000 AVRT.dll 6.2.19041.546 C:\Windows\SYSTEM32
54df0000 ksuser.dll 6.2.19041.1 C:\Windows\SYSTEM32
54e00000 hhctrl.ocx 6.2.19041.746 C:\Windows\SYSTEM32
54eb0000 winmmbase.dll 6.2.19041.1 C:\Windows\SYSTEM32
54ed0000 msacm32.dll 6.2.19041.1 C:\Windows\SYSTEM32
54ef0000 MSVFW32.DLL 6.2.19041.1 C:\Windows\SYSTEM32
54f20000 AcSpecfc.DLL 6.2.19041.423 C:\Windows\SYSTEM32
54fa0000 AcLayers.DLL 6.2.19041.1266 C:\Windows\SYSTEM32
553b0000 TextShaping.dll C:\Windows\SYSTEM32
58e00000 DDRAW.dll 6.2.19041.1 C:\Windows\SYSTEM32
59e20000 MMDevAPI.DLL 6.2.19041.2075 C:\Windows\SYSTEM32
59e90000 mscms.dll 6.2.19041.746 C:\Windows\SYSTEM32
59f30000 InputHost.dll 6.2.19041.1741 C:\Windows\System32
5a020000 Windows.UI.dll 6.2.19041.746 C:\Windows\System32
5ce50000 d3d9.dll 6.2.19041.2075 C:\Windows\SYSTEM32
66680000 sfc.dll 6.2.19041.2075 C:\Windows\SYSTEM32
68d40000 WINMM.dll 6.2.19041.546 C:\Windows\SYSTEM32
69970000 apphelp.dll 6.2.19041.2075 C:\Windows\SYSTEM32
69ad0000 usp10.dll 6.2.19041.546 C:\Windows\SYSTEM32
69af0000 dwmapi.dll 6.2.19041.746 C:\Windows\SYSTEM32
69d90000 DCIMAN32.dll 6.2.19041.2075 C:\Windows\SYSTEM32
69da0000 ColorAdapterClient.dll 6.2.19041.546 C:\Windows\SYSTEM32
69db0000 WindowManagementAPI.dll C:\Windows\System32
6a230000 DEVOBJ.dll 6.2.19041.1620 C:\Windows\SYSTEM32
6b5c0000 sfc_os.DLL 6.2.19041.2075 C:\Windows\SYSTEM32
6b820000 propsys.dll 7.0.19041.1741 C:\Windows\system32
6cc60000 olepro32.dll 6.2.19041.84 C:\Windows\SYSTEM32
6cc90000 wininet.dll 11.0.19041.2075 C:\Windows\SYSTEM32
6d0f0000 wsock32.dll 6.2.19041.1 C:\Windows\SYSTEM32
6d6e0000 MPR.dll 6.2.19041.1806 C:\Windows\SYSTEM32
6d8c0000 msi.dll 5.0.19041.1766 C:\Windows\SYSTEM32
6e3c0000 twinapi.appcore.dll 6.2.19041.1865 C:\Windows\SYSTEM32
6e550000 dcomp.dll 6.2.19041.2075 C:\Windows\system32
6e6c0000 dataexchange.dll 6.2.19041.1387 C:\Windows\system32
6f6b0000 d3d11.dll 6.2.19041.2075 C:\Windows\system32
6f890000 dxgi.dll 6.2.19041.2075 C:\Windows\SYSTEM32
703c0000 COMCTL32.dll 6.10.19041.1110 C:\Windows\WinSxS\
x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.19041.1110_none_a8625c1886757984
705d0000 srvcli.dll 6.2.19041.1645 C:\Windows\SYSTEM32
705f0000 URLMON.DLL 11.0.19041.2075 C:\Windows\SYSTEM32
70870000 iertutil.dll 11.0.19041.2130 C:\Windows\SYSTEM32
72b90000 WindowsCodecs.dll 6.2.19041.1706 C:\Windows\SYSTEM32
72d10000 UMPDC.dll C:\Windows\SYSTEM32
72d20000 powrprof.dll 6.2.19041.546 C:\Windows\SYSTEM32
72da0000 netutils.dll 6.2.19041.1466 C:\Windows\SYSTEM32
73070000 rasadhlp.dll 6.2.19041.546 C:\Windows\System32
73080000 DNSAPI.dll 6.2.19041.1865 C:\Windows\SYSTEM32
73190000 dhcpcsvc.DLL 6.2.19041.2130 C:\Windows\SYSTEM32
731d0000 mswsock.dll 6.2.19041.546 C:\Windows\System32
733e0000 wintypes.dll 6.2.19041.2130 C:\Windows\SYSTEM32
734d0000 CoreMessaging.dll 6.2.19041.867 C:\Windows\SYSTEM32
73570000 CoreUIComponents.dll 6.2.19041.546 C:\Windows\SYSTEM32
73840000 textinputframework.dll 6.2.19041.2075 C:\Windows\SYSTEM32
739b0000 uxtheme.dll 6.2.19041.2130 C:\Windows\system32
73aa0000 MSASN1.dll 6.2.19041.546 C:\Windows\SYSTEM32
73b40000 msimg32.dll 6.2.19041.1466 C:\Windows\SYSTEM32
74580000 SspiCli.dll 6.2.19041.2130 C:\Windows\SYSTEM32
74860000 ntmarta.dll 6.2.19041.546 C:\Windows\SYSTEM32
74dc0000 profapi.dll 6.2.19041.844 C:\Windows\SYSTEM32
74e50000 Wldp.dll 6.2.19041.2075 C:\Windows\SYSTEM32
74ec0000 windows.storage.dll 6.2.19041.2130 C:\Windows\SYSTEM32
75560000 kernel.appcore.dll 6.2.19041.546 C:\Windows\SYSTEM32
756f0000 version.dll 6.2.19041.546 C:\Windows\SYSTEM32
75bd0000 IPHLPAPI.DLL 6.2.19041.546 C:\Windows\SYSTEM32
75c10000 WINSPOOL.DRV 6.2.19041.2075 C:\Windows\SYSTEM32
75c90000 USERENV.dll 6.2.19041.572 C:\Windows\SYSTEM32
75cd0000 RPCRT4.dll 6.2.19041.1806 C:\Windows\System32
75d90000 COMDLG32.dll 6.2.19041.1806 C:\Windows\System32
75e40000 SHLWAPI.dll 6.2.19041.2075 C:\Windows\System32
75e90000 crypt32.dll 6.2.19041.1889 C:\Windows\System32
76160000 psapi.dll 6.2.19041.546 C:\Windows\System32
76170000 cfgmgr32.dll 6.2.19041.1620 C:\Windows\System32
761b0000 SHELL32.dll 6.2.19041.2075 C:\Windows\System32
76770000 ucrtbase.dll 6.2.19041.789 C:\Windows\System32
76890000 ole32.dll 6.2.19041.1202 C:\Windows\System32
76980000 shcore.dll 6.2.19041.1645 C:\Windows\System32
76aa0000 NSI.dll 6.2.19041.610 C:\Windows\System32
76ab0000 GDI32.dll 6.2.19041.2130 C:\Windows\System32
76b00000 clbcatq.dll 2001.12.10941.16384 C:\Windows\System32
76b90000 combase.dll 6.2.19041.2130 C:\Windows\System32
76e10000 wintrust.dll 6.2.19041.2075 C:\Windows\System32
76ec0000 IMM32.dll 6.2.19041.546 C:\Windows\System32
76f00000 msvcp_win.dll 6.2.19041.789 C:\Windows\System32
76f80000 bcrypt.dll 6.2.19041.1023 C:\Windows\System32
76fa0000 msvcrt.dll 7.0.19041.546 C:\Windows\System32
77060000 bcryptPrimitives.dll 6.2.19041.1415 C:\Windows\System32
770c0000 SETUPAPI.dll 6.2.19041.1741 C:\Windows\System32
77500000 MSCTF.dll 6.2.19041.2075 C:\Windows\System32
775e0000 USER32.dll 6.2.19041.2130 C:\Windows\System32
77780000 KERNELBASE.dll 6.2.19041.2130 C:\Windows\System32
779a0000 KERNEL32.DLL 6.2.19041.1889 C:\Windows\System32
77a90000 OLEAUT32.dll 6.2.19041.985 C:\Windows\System32
77b30000 sechost.dll 6.2.19041.1865 C:\Windows\System32
77bb0000 WS2_32.dll 6.2.19041.546 C:\Windows\System32
77c20000 ADVAPI32.dll 6.2.19041.2130 C:\Windows\System32
77ca0000 gdi32full.dll 6.2.19041.2130 C:\Windows\System32
77d80000 win32u.dll 6.2.19041.2130 C:\Windows\System32
77e10000 ntdll.dll 6.2.19041.2130 C:\Windows\SYSTEM32

processes:
0000 Idle 0
0004 System 0
0064 Registry 0
018c smss.exe 0
0204 csrss.exe 0
0260 wininit.exe 0
02dc services.exe 0
02f8 lsass.exe 0
0380 svchost.exe 0
039c fontdrvhost.exe 0
03fc svchost.exe 0
021c svchost.exe 0
0454 svchost.exe 0
0474 svchost.exe 0
04a4 svchost.exe 0
04cc svchost.exe 0
04e8 svchost.exe 0
0538 svchost.exe 0
0540 svchost.exe 0
05a0 svchost.exe 0
062c svchost.exe 0
0670 svchost.exe 0
0688 svchost.exe 0
0698 svchost.exe 0
06a0 svchost.exe 0
06ac svchost.exe 0
074c svchost.exe 0
0754 svchost.exe 0
0764 svchost.exe 0
076c Memory Compression 0
07b8 svchost.exe 0
07d0 svchost.exe 0
01f8 svchost.exe 0
05e4 svchost.exe 0
084c svchost.exe 0
08d8 svchost.exe 0
092c svchost.exe 0
0934 svchost.exe 0
093c svchost.exe 0
0970 svchost.exe 0
0a00 svchost.exe 0
09fc svchost.exe 0
0a0c svchost.exe 0
0a48 svchost.exe 0
0a5c spoolsv.exe 0
0afc svchost.exe 0
0b58 svchost.exe 0
0b8c svchost.exe 0
0ba0 svchost.exe 0
0bac avp.exe 0
0bbc svchost.exe 0
0bc8 svchost.exe 0
0bd4 OfficeClickToRun.exe 0
0bec HuaweiHiSuiteService64.exe 0
0878 mepService.exe 0
0a58 Nitro_UpdateService.exe 0
0960 NitroPDFDriverService9x64.exe 0
0c0c svchost.exe 0
0c18 svchost.exe 0
0c60 svchost.exe 0
0c70 svchost.exe 0
0cc0 svchost.exe 0
0d7c svchost.exe 0
0e14 svchost.exe 0
0ef0 svchost.exe 0
1138 MicrosoftEdgeUpdate.exe 0
11ac svchost.exe 0
1200 svchost.exe 0
12ac svchost.exe 0
1828 SearchIndexer.exe 0
1a68 svchost.exe 0
1a48 svchost.exe 0
1e4c svchost.exe 0
2140 SecurityHealthService.exe 0
2500 svchost.exe 0
2580 svchost.exe 0
2a50 WmiPrvSE.exe 0
2a9c svchost.exe 0
32d0 svchost.exe 0
0398 svchost.exe 0
2180 svchost.exe 0
31c0 ksde.exe 0
3280 SgrmBroker.exe 0
2330 svchost.exe 0
1c98 svchost.exe 0
32a0 csrss.exe 2
2988 winlogon.exe 2
27c4 dwm.exe 2
23fc fontdrvhost.exe 2
1fc8 mep.exe 2 normal C:\Program Files (x86)\EPSON\
MyEpson Portal
1850 sihost.exe 2 normal C:\Windows\System32
3218 svchost.exe 2 normal C:\Windows\System32
0a78 svchost.exe 2 normal C:\Windows\System32
1390 taskhostw.exe 2 normal C:\Windows\System32
24fc explorer.exe 2 normal C:\Windows
253c ctfmon.exe 2
23d8 ksdeui.exe 2 normal C:\Program Files (x86)\Kaspersky
Lab\Kaspersky VPN 5.8
23cc avpui.exe 2 normal C:\Program Files (x86)\Kaspersky
Lab\Kaspersky Security Cloud 21.3
1ec4 svchost.exe 2 normal C:\Windows\System32
13c4 dllhost.exe 2 normal C:\Windows\System32
25d4 StartMenuExperienceHost.exe 2 normal C:\Windows\SystemApps\
Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy
0658 RuntimeBroker.exe 2 normal C:\Windows\System32
127c SearchApp.exe 2 normal C:\Windows\SystemApps\
Microsoft.Windows.Search_cw5n1h2txyewy
2a4c RuntimeBroker.exe 2 normal C:\Windows\System32
2644 RuntimeBroker.exe 2 normal C:\Windows\System32
16ec PhoneExperienceHost.exe 2 normal C:\Program Files\WindowsApps\
Microsoft.YourPhone_1.22082.119.0_x64__8wekyb3d8bbwe
2efc RuntimeBroker.exe 2 normal C:\Windows\System32
2ee4 TextInputHost.exe 2 normal C:\Windows\SystemApps\
MicrosoftWindows.Client.CBS_cw5n1h2txyewy
2cec smartscreen.exe 2 normal C:\Windows\System32
313c SecurityHealthSystray.exe 2 normal C:\Windows\System32
19dc igfxtray.exe 2 normal C:\Windows\System32
27b4 hkcmd.exe 2 normal C:\Windows\System32
1fbc igfxpers.exe 2 normal C:\Windows\System32
124c OneDrive.exe 2 normal C:\Users\LUPIS\AppData\Local\
Microsoft\OneDrive
186c DropboxUpdate.exe 2 normal C:\Users\LUPIS\AppData\Local\
Dropbox\Update
0a30 msedge.exe 2 normal C:\Program Files (x86)\Microsoft\
Edge\Application
261c msedge.exe 2 normal C:\Program Files (x86)\Microsoft\
Edge\Application
10ac Dropbox.exe 2 normal C:\Users\LUPIS\AppData\Roaming\
Dropbox\bin
1d84 msedge.exe 2 above normal C:\Program Files (x86)\Microsoft\
Edge\Application
1de0 msedge.exe 2 normal C:\Program Files (x86)\Microsoft\
Edge\Application
1ecc msedge.exe 2 normal C:\Program Files (x86)\Microsoft\
Edge\Application
0d10 Dropbox.exe 2 normal C:\Users\LUPIS\AppData\Roaming\
Dropbox\bin
205c Dropbox.exe 2 normal C:\Users\LUPIS\AppData\Roaming\
Dropbox\bin
2e18 msedge.exe 2 idle C:\Program Files (x86)\Microsoft\
Edge\Application
0774 msedge.exe 2 idle C:\Program Files (x86)\Microsoft\
Edge\Application
1e00 Dropbox.exe 2 normal C:\Users\LUPIS\AppData\Roaming\
Dropbox\bin
334c Dropbox.exe 2 above normal C:\Users\LUPIS\AppData\Roaming\
Dropbox\bin
2634 Dropbox.exe 2 normal C:\Users\LUPIS\AppData\Roaming\
Dropbox\bin
24c0 Dropbox.exe 2 normal C:\Users\LUPIS\AppData\Roaming\
Dropbox\bin
1a8c SystemSettings.exe 2 normal C:\Windows\ImmersiveControlPanel
05ac ApplicationFrameHost.exe 2 normal C:\Windows\System32
2ff8 UserOOBEBroker.exe 2 normal C:\Windows\System32\oobe
12b8 HxOutlook.exe 2 normal C:\Program Files\WindowsApps\
microsoft.windowscommunicationsapps_16005.14326.20970.0_x64__8wekyb3d8bbwe
108c RuntimeBroker.exe 2 normal C:\Windows\System32
2134 HxTsr.exe 2 normal C:\Program Files\WindowsApps\
microsoft.windowscommunicationsapps_16005.14326.20970.0_x64__8wekyb3d8bbwe
19c8 HxAccounts.exe 2 normal C:\Program Files\WindowsApps\
microsoft.windowscommunicationsapps_16005.14326.20970.0_x64__8wekyb3d8bbwe
13fc svchost.exe 2 normal C:\Windows\System32
0448 dllhost.exe 2 normal C:\Windows\System32
2058 WhatsApp.exe 2 normal C:\Program Files\WindowsApps\
5319275A.WhatsAppDesktop_2.2243.11.0_x64__cv1g1gvanyjgm
1258 RuntimeBroker.exe 2 normal C:\Windows\System32
1988 audiodg.exe 0
1b38 ShellExperienceHost.exe 2 normal C:\Windows\SystemApps\
ShellExperienceHost_cw5n1h2txyewy
160c RuntimeBroker.exe 2 normal C:\Windows\System32
0394 WmiPrvSE.exe 0
2e30 svchost.exe 0
25a0 svchost.exe 0
1298 svchost.exe 0
2e78 svchost.exe 0
283c SearchProtocolHost.exe 0
22bc SearchFilterHost.exe 0
3174 !ISRE1.EXE 2 normal D:

cpu registers:
eax = 0a84eb70
ebx = 00000000
ecx = 0a84eb70
edx = 006f17e4
esi = 0e4aba40
edi = 0e4aba14
eip = 006f17e4
esp = 01fcefe8
ebp = 01fcf020

stack dump:
01fcefe8 e4 17 6f 00 de fa ed 0e - 01 00 00 00 07 00 00 00 ..o.............
01fceff8 fc ef fc 01 e4 17 6f 00 - 70 eb 84 0a 00 00 00 00 ......o.p.......
01fcf008 40 ba 4a 0e 14 ba 4a 0e - 20 f0 fc 01 18 f0 fc 01 @.J...J.........
01fcf018 50 19 6f 00 20 b9 4a 0e - 68 f2 fc 01 c6 18 6f 00 P.o...J.h.....o.
01fcf028 c0 7b 1c 10 00 00 00 00 - 98 00 00 00 00 00 00 00 .{..............
01fcf038 00 00 28 02 00 00 0b 00 - 02 00 00 00 03 00 00 00 ..(.............
01fcf048 09 00 00 00 00 00 0b 00 - dc 01 0b 00 a0 00 00 00 ................
01fcf058 d0 07 0b 00 64 00 00 00 - 01 00 00 00 a0 00 00 00 ....d...........
01fcf068 01 00 00 00 c8 81 1b 10 - 90 67 1c 10 00 00 00 00 .........g......
01fcf078 00 00 00 00 00 00 0b 00 - 02 00 00 00 00 00 00 00 ................
01fcf088 14 00 00 00 00 00 0b 00 - 08 02 0b 00 08 00 14 00 ................
01fcf098 96 00 00 00 d4 16 0b 00 - 00 00 00 00 00 00 28 02 ..............(.
01fcf0a8 fe ff ff ff fe ff ff ff - 01 00 00 00 04 00 00 00 ................
01fcf0b8 01 00 00 00 14 7c 1c 10 - 20 15 b1 54 46 7c 1c 10 .....|.....TF|..
01fcf0c8 14 7c 1c 10 f6 1a b1 54 - ec 7b 1c 10 14 7c 1c 10 .|.....T.{...|..
01fcf0d8 fc f0 fc 01 4f 1b b1 54 - 46 7c 1c 10 4c 60 00 00 ....O..TF|..L`..
01fcf0e8 08 00 00 00 10 1e b1 54 - 30 33 44 02 14 00 00 00 .......T03D.....
01fcf0f8 c8 1e b1 54 28 f1 fc 01 - bf 57 eb 54 30 33 44 02 ...T(....W.T03D.
01fcf108 14 00 00 00 4c 60 00 00 - ec 7b 1c 10 00 00 00 00 ....L`...{......
01fcf118 d8 7b 1c 10 00 00 00 00 - 80 60 1d 10 4c 60 00 00 .{.......`..L`..

disassembling:
[...]
006f17cd mov [ebp-4], eax
006f17d0 888 mov ecx, [ebp-8]
006f17d3 mov dl, 1
006f17d5 mov eax, [$455160]
006f17da call -$294677 ($45d168) ; SysUtils.Exception.Create
006f17df > call -$2ec7cc ($405018) ; System.@RaiseExcept
006f17e4 889 pop ecx
006f17e5 pop ecx
006f17e6 pop ebp
006f17e7 ret

You might also like