date/time : 2011-09-29, 18:20:14, 687ms
computer name : PILON1
user name : Katherine <admin>
operating system : Windows XP Service Pack 2 build 2600
system language : English
system up time : 4 days 1 hour
program up time : 54 seconds
processors : 2x Intel(R) Pentium(R) D CPU 2.80GHz
physical memory : 1024/1024 MB (free/total)
free disk space : (C:) 272.64 GB
display mode : 1280x1024, 32 bit
process id : $1440
allocated memory : 39.76 MB
executable : PetWorkshop.exe
exec. date/time : 2005-10-05 17:06
version : 2.0.1.0
madExcept version : 3.0a beta 2
callstack crc : $b84d7b06, $9ba6f4d2, $9670b626
exception class : EWin32Error
exception message : Win32 Error. Code: 5. Access is denied.
main thread ($83c):
004569c7 PetWorkshop.exe SysUtils RaiseLastWin32Error
004569f7 PetWorkshop.exe SysUtils Win32Check
00488ddd PetWorkshop.exe Controls TMouse.GetCursorPos
0056f84f PetWorkshop.exe mainunit 3851 +1 Tmain.petz3dpicktimerTimer
004a12d3 PetWorkshop.exe ExtCtrls TTimer.Timer
004a11b7 PetWorkshop.exe ExtCtrls TTimer.WndProc
004952e8 PetWorkshop.exe Forms StdWndProc
75ca2e3c user32.dll DispatchMessageA
0049dd3f PetWorkshop.exe Forms TApplication.ProcessMessage
0049dd76 PetWorkshop.exe Forms TApplication.HandleMessage
0049df81 PetWorkshop.exe Forms TApplication.Run
00571437 PetWorkshop.exe PetWorkshop 58 +21 initialization
7745ed6a kernel32.dll BaseThreadInitThunk
thread $2e0 (TDummyThread): <suspended>
77307098 ntdll.dll RtlUserThreadStart
>> created by main thread ($83c) at:
00560d1f PetWorkshop.exe GIFImage 12426 +29 initialization
thread $1708 (TWorkerThread):
773070b4 ntdll.dll KiFastSystemCallRet
77306a22 ntdll.dll NtWaitForSingleObject
75691796 KERNELBASE.dll WaitForSingleObjectEx
7745c2ee kernel32.dll WaitForSingleObjectEx
7745c29d kernel32.dll WaitForSingleObject
004e259a PetWorkshop.exe VirtualTrees 5125 +3 TWorkerThread.Execute
0044ce97 PetWorkshop.exe madExcept HookedTThreadExecute
00461a48 PetWorkshop.exe Classes ThreadProc
004040e8 PetWorkshop.exe System ThreadWrapper
0044cde6 PetWorkshop.exe madExcept ThreadExceptFrame
7745ed6a kernel32.dll BaseThreadInitThunk
773237c3 ntdll.dll RtlUserThreadStart
>> created by main thread ($83c) at:
004e24bf PetWorkshop.exe VirtualTrees 5088 +1 TWorkerThread.Create
thread $1e64:
773070b4 ntdll.dll KiFastSystemCallRet
77306a02 ntdll.dll NtWaitForMultipleObjects
7745ed6a kernel32.dll BaseThreadInitThunk
773237c3 ntdll.dll RtlUserThreadStart
thread $1954:
773070b4 ntdll.dll KiFastSystemCallRet
77306a32 ntdll.dll NtWaitForWorkViaWorkerFactory
7745ed6a kernel32.dll BaseThreadInitThunk
773237c3 ntdll.dll RtlUserThreadStart
thread $1b34:
773070b4 ntdll.dll KiFastSystemCallRet
77306a32 ntdll.dll NtWaitForWorkViaWorkerFactory
7745ed6a kernel32.dll BaseThreadInitThunk
773237c3 ntdll.dll RtlUserThreadStart
thread $1724:
773070b4 ntdll.dll KiFastSystemCallRet
77306a32 ntdll.dll NtWaitForWorkViaWorkerFactory
7745ed6a kernel32.dll BaseThreadInitThunk
773237c3 ntdll.dll RtlUserThreadStart
modules:
00400000 PetWorkshop.exe 2.0.1.0 C:\Program Files\Sherlock Software\Pet Workshop
65da0000 AcGenral.DLL 6.1.7601.17514 C:\Windows\AppPatch
672b0000 AcXtrnal.DLL 6.1.7600.16385 C:\Windows\AppPatch
67d30000 HHCTRL.OCX 6.1.7600.16385 C:\Windows\system32
6a8c0000 GrooveShellExtensions.dll 12.0.6421.1000 C:\Program Files\Microsoft Office\Office12
6b230000 ntshrui.dll 6.1.7601.17514 C:\Windows\system32
6b4d0000 olepro32.dll 6.1.7601.17514 C:\Windows\system32
6c9e0000 MPR.dll 6.1.7600.16385 C:\Windows\system32
6cae0000 SortServer2003Compat.dll 6.1.7600.16385 C:\Windows\system32
6cdb0000 sfc_os.DLL 6.1.7600.16385 C:\Windows\system32
6cdc0000 sfc.dll 6.1.7600.16385 C:\Windows\system32
6db40000 CSCAPI.dll 6.1.7601.17514 C:\Windows\system32
6f100000 winspool.drv 6.1.7601.17514 C:\Windows\system32
6f770000 SHUNIMPL.DLL 6.1.7601.17514 C:\Windows\system32
6fdf0000 AcLayers.dll 6.1.7601.17514 C:\Windows\AppPatch
71080000 MSVCR80.dll 8.0.50727.4940 C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc
71240000 wsock32.dll 6.1.7600.16385 C:\Windows\system32
716c0000 GrooveUtil.DLL 12.0.6562.5000 C:\Program Files\Microsoft Office\Office12
71d10000 cscui.dll 6.1.7601.17514 C:\Windows\System32
71fd0000 EhStorShell.dll 6.1.7600.16385 C:\Windows\system32
72d00000 ATL80.DLL 8.0.50727.762 C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c
73110000 CSCDLL.dll 6.1.7601.17514 C:\Windows\System32
73210000 MSACM32.dll 6.1.7600.16385 C:\Windows\system32
73280000 MSImg32.dll 6.1.7600.16385 C:\Windows\system32
73350000 slc.dll 6.1.7600.16385 C:\Windows\system32
73610000 winmm.dll 6.1.7601.17514 C:\Windows\system32
736b0000 GrooveNew.DLL 12.0.6413.1000 C:\Program Files\Microsoft Office\Office12
73a60000 samcli.dll 6.1.7601.17514 C:\Windows\system32
73ac0000 comctl32.dll 5.82.7601.17514 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af
73bc0000 WindowsCodecs.dll 6.1.7601.17514 C:\Windows\system32
73e30000 dwmapi.dll 6.1.7600.16385 C:\Windows\system32
74160000 UxTheme.dll 6.1.7600.16385 C:\Windows\system32
741a0000 PROPSYS.dll 7.0.7601.17514 C:\Windows\system32
742e0000 comctl32.DLL 6.10.7601.17514 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2
747e0000 version.dll 6.1.7600.16385 C:\Windows\system32
74a30000 USERENV.dll 6.1.7601.17514 C:\Windows\system32
74c30000 rsaenh.dll 6.1.7600.16385 C:\Windows\system32
74e90000 CRYPTSP.dll 6.1.7600.16385 C:\Windows\system32
75260000 srvcli.dll 6.1.7601.17514 C:\Windows\system32
75320000 SspiCli.dll 6.1.7601.17514 C:\Windows\system32
75340000 apphelp.dll 6.1.7601.17514 C:\Windows\system32
75390000 CRYPTBASE.dll 6.1.7600.16385 C:\Windows\system32
75410000 profapi.dll 6.1.7600.16385 C:\Windows\system32
75480000 MSASN1.dll 6.1.7601.17514 C:\Windows\system32
75520000 CRYPT32.dll 6.1.7601.17514 C:\Windows\system32
75640000 CFGMGR32.dll 6.1.7601.17514 C:\Windows\system32
75670000 DEVOBJ.dll 6.1.7600.16385 C:\Windows\system32
75690000 KERNELBASE.dll 6.1.7601.17651 C:\Windows\system32
75710000 RPCRT4.dll 6.1.7601.17514 C:\Windows\system32
757c0000 WS2_32.dll 6.1.7601.17514 C:\Windows\system32
75810000 GDI32.dll 6.1.7601.17514 C:\Windows\system32
75860000 NSI.dll 6.1.7600.16385 C:\Windows\system32
75870000 iertutil.dll 8.0.7601.17638 C:\Windows\system32
75a70000 sechost.dll 6.1.7600.16385 C:\Windows\SYSTEM32
75a90000 MSCTF.dll 6.1.7600.16385 C:\Windows\system32
75b60000 WININET.dll 8.0.7601.17638 C:\Windows\system32
75c90000 user32.dll 6.1.7601.17514 C:\Windows\system32
75d60000 advapi32.dll 6.1.7601.17514 C:\Windows\system32
75e00000 comdlg32.dll 6.1.7601.17514 C:\Windows\system32
75e80000 IMM32.DLL 6.1.7601.17514 C:\Windows\system32
75ea0000 msvcrt.dll 7.0.7600.16385 C:\Windows\system32
75f50000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\system32
75fe0000 LPK.dll 6.1.7600.16385 C:\Windows\system32
76050000 shell32.dll 6.1.7601.17514 C:\Windows\system32
76ca0000 oleaut32.dll 6.1.7601.17567 C:\Windows\system32
76d30000 SETUPAPI.dll 6.1.7601.17514 C:\Windows\system32
76f20000 SHLWAPI.dll 6.1.7601.17514 C:\Windows\system32
76f80000 USP10.dll 1.626.7601.17514 C:\Windows\system32
77020000 urlmon.dll 8.0.7601.17638 C:\Windows\system32
77160000 ole32.dll 6.1.7601.17514 C:\Windows\system32
772c0000 ntdll.dll 6.1.7601.17514 C:\Windows\SYSTEM32
77410000 kernel32.dll 6.1.7601.17651 C:\Windows\system32
processes:
0000 Idle 0
0004 System 0
0178 smss.exe 0
01d0 csrss.exe 0
0210 wininit.exe 0
0248 services.exe 0
0258 lsass.exe 0
0264 lsm.exe 0
02f8 svchost.exe 0
0348 svchost.exe 0
0384 MsMpEng.exe 0
03e8 svchost.exe 0
0424 svchost.exe 0
046c svchost.exe 0
04f8 svchost.exe 0
0578 svchost.exe 0
061c spoolsv.exe 0
0638 svchost.exe 0
06a0 AppleMobileDeviceService.exe 0
06d8 mDNSResponder.exe 0
06f8 fsssvc.exe 0
0774 svchost.exe 0
07bc LMIGuardianSvc.exe 0
01d8 ramaint.exe 0
02c8 LogMeIn.exe 0
0730 SeaPort.exe 0
0790 svchost.exe 0
0194 WLIDSVC.EXE 0
09d4 WLIDSVCM.EXE 0
0ba8 NisSrv.exe 0
0be8 svchost.exe 0
0c48 svchost.exe 0
0cf8 svchost.exe 0
0a80 SearchIndexer.exe 0
0420 svchost.exe 0
01bc wmpnetwk.exe 0
02a8 iPodService.exe 0
1460 dllhost.exe 0
02ec WUDFHost.exe 0
144c svchost.exe 0
13d8 csrss.exe 1
0440 winlogon.exe 1
0aa0 taskhost.exe 1
1590 dwm.exe 1
0a58 explorer.exe 1
0d20 GrooveMonitor.exe 1
134c hpwuSchd2.exe 1
170c LogMeInSystray.exe 1
1120 AdobeARM.exe 1
14c0 PWRISOVM.EXE 1
0510 iTunesHelper.exe 1
02ac msseces.exe 1
0fac jusched.exe 1
0300 fsui.exe 1
12b0 uTorrent.exe 1
0da4 hpqtra08.exe 1
16cc ONENOTEM.EXE 1
17f0 hpqste08.exe 1
17d4 hpqbam08.exe 1
0c64 hpqgpc01.exe 1
0d98 Steam.exe 1
10ac SteamService.exe 0
1f00 chrome.exe 1
1f68 chrome.exe 1
1ae8 chrome.exe 1
16a0 chrome.exe 1
17bc chrome.exe 1
1a1c chrome.exe 1
1138 chrome.exe 1
1d44 chrome.exe 1
065c chrome.exe 1
11c8 chrome.exe 1
13dc rundll32.exe 1
1408 chrome.exe 1
1824 csrss.exe 6
0df4 winlogon.exe 6
1230 Dwm.exe 6 high C:\Windows\system32
13ac Explorer.EXE 6 normal C:\Windows
182c taskhost.exe 6 normal C:\Windows\system32
10d4 GrooveMonitor.exe 6 normal C:\Program Files\Microsoft Office\Office12
1d08 hpwuSchd2.exe 6 normal C:\Program Files\HP\HP Software Update
0600 LogMeInSystray.exe 6 normal C:\Program Files\LogMeIn\x86
1a38 PWRISOVM.EXE 6 normal C:\Program Files\PowerISO
1a18 iTunesHelper.exe 6 normal C:\Program Files\iTunes
0ce8 msseces.exe 6 normal C:\Program Files\Microsoft Security Client
1a44 jusched.exe 6 normal C:\Program Files\Common Files\Java\Java Update
0c08 fsui.exe 6 normal C:\Program Files\Windows Live\Family Safety
1564 hpqtra08.exe 6 normal C:\Program Files\HP\Digital Imaging\bin
0e98 ONENOTEM.EXE 6 normal C:\Program Files\Microsoft Office\Office12
17dc hpqSTE08.exe 6 normal C:\Program Files\HP\Digital Imaging\bin
1a54 hpqbam08.exe 6 normal C:\Program Files\HP\Digital Imaging\bin
108c hpqgpc01.exe 6 normal C:\Program Files\HP\Digital Imaging\bin
0070 firefox.exe 6 normal C:\Program Files\Mozilla Firefox
1e24 hpswp_clipbook.exe 6 normal C:\Program Files\HP\Digital Imaging\smart web printing
1a7c plugin-container.exe 6 normal C:\Program Files\Mozilla Firefox
0ff0 audiodg.exe 0
1440 PetWorkshop.exe 6 normal C:\Program Files\Sherlock Software\Pet Workshop
1c2c consent.exe 6
hardware:
+ Computer
- ACPI x86-based PC
+ Disk drives
- HP Photosmart C3180 USB Device
- WDC WD5000AADS-00M2B0 ATA Device
+ Display adapters
- LogMeIn Mirror Driver (driver 7.1.542.0)
- Radeon X1900 Series (Microsoft Corporation - WDDM) (driver 8.56.1.16)
- Radeon X1900 Series Secondary (Microsoft Corporation - WDDM) (driver 8.56.1.16)
+ DVD/CD-ROM drives
- WDKJW MN4D6R8 SCSI CdRom Device
+ Human Interface Devices
- USB Input Device
- USB Input Device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 0
- ATA Channel 1
- ATA Channel 2
- ATA Channel 3
- Intel(R) 82801G (ICH7 Family) Ultra ATA Storage Controllers - 27DF
- Standard AHCI 1.0 Serial ATA Controller
+ IEEE 1284.4 compatible printer
- IEEE 1284.4 compatible printer
- Photosmart C3100 (DOT4PRINT) (driver 61.64.212.0)
+ Imaging devices
- HP Photosmart C3100 (driver 8.0.0.1)
+ Keyboards
- HID Keyboard Device
+ Mice and other pointing devices
- HID-compliant mouse
+ Modems
- Conexant D850 56K V.90 DFVc Modem
+ Monitors
- Generic PnP Monitor
+ Network adapters
- Intel(R) PRO/1000 PL Network Connection
- Wireless-G PCI Adapter with SRX (driver 1.5.0.86)
+ Portable Devices
- H:\
+ Printers
- HP Photosmart C3100 series (driver 6.1.7600.16385)
+ Processors
- Intel(R) Pentium(R) D CPU 2.80GHz
- Intel(R) Pentium(R) D CPU 2.80GHz
+ Sound, video and game controllers
- High Definition Audio Device
+ Storage controllers
- ADYKTZYA IDE Controller
+ Storage volume shadow copies
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
+ System devices
- ACPI Fixed Feature Button
- ACPI Power Button
- Composite Bus Enumerator
- Direct memory access controller
- Extended IO Bus
- File as Volume Driver
- High Definition Audio Controller
- Intel(R) 82801 PCI Bridge - 244E
- Intel(R) 82801G (ICH7 Family) PCI Express Root Port - 27D0
- Intel(R) 82801G (ICH7 Family) SMBus Controller - 27DA
- Intel(R) 82801GH (ICH7DH) LPC Interface Controller - 27B0
- Intel(R) 82801GR/GH/GHM (ICH7 Family) PCI Express Root Port - 27E0
- Intel(R) 82801GR/GH/GHM (ICH7 Family) PCI Express Root Port - 27E2
- Intel(R) 945G/GZ/GC/P/PL PCI Express Root Port - 2771
- Intel(R) 945G/GZ/GC/P/PL Processor to I/O Controller - 2770
- Microsoft ACPI-Compliant System
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator Driver
- Motherboard resources
- Numeric data processor
- PCI bus
- Plug and Play Software Device Enumerator
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- System board
- System board
- System CMOS/real time clock
- System speaker
- System timer
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- UMBus Enumerator
- UMBus Enumerator
- UMBus Root Bus Enumerator
- Virtual PC Host Bus Driver
- Volume Manager
+ Universal Serial Bus controllers
- HP Photosmart C3100 series (DOT4USB) (driver 1.0.0.0)
- Intel(R) 82801G (ICH7 Family) USB Universal Host Controller - 27C8
- Intel(R) 82801G (ICH7 Family) USB Universal Host Controller - 27C9
- Intel(R) 82801G (ICH7 Family) USB Universal Host Controller - 27CA
- Intel(R) 82801G (ICH7 Family) USB Universal Host Controller - 27CB
- Intel(R) 82801G (ICH7 Family) USB2 Enhanced Host Controller - 27CC
- USB Composite Device
- USB Mass Storage Device
- USB Printing Support
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
+ USB Virtualization
- USB Virtualization Connector Driver
cpu registers:
eax = 01e76040
ebx = 00000005
ecx = 00000000
edx = 004569cc
esi = 00000113
edi = 0012fe74
eip = 004569cc
esp = 0012fd20
ebp = 0012fd74
stack dump:
0012fd20 cc 69 45 00 de fa ed 0e - 01 00 00 00 07 00 00 00 .iE.............
0012fd30 34 fd 12 00 cc 69 45 00 - 40 60 e7 01 05 00 00 00 4....iE.@`......
0012fd40 13 01 00 00 74 fe 12 00 - 74 fd 12 00 50 fd 12 00 ....t...t...P...
0012fd50 8c fd 12 00 90 3a 40 00 - 74 fd 12 00 00 00 00 00 .....:@.t.......
0012fd60 00 00 00 00 05 00 00 00 - 00 a4 c9 75 c8 15 dd 01 ...........u....
0012fd70 0b 00 00 00 b4 fd 12 00 - fc 69 45 00 a4 fd 12 00 .........iE.....
0012fd80 e2
48 00 e0 d7 de 01 - 54 f8 56 00 c4 fd 12 00 ..H.....T.V.....
0012fd90 90 3a 40 00 b4 fd 12 00 - 13 01 00 00 00 1d e9 01 .:@.............
0012fda0 00 00 00 00 fe c5 ca 75 - 0e 05
81 01 00 00 00 .......u........
0012fdb0 74 fe 12 00 e0 fd 12 00 - d6 12 4a 00 c4 12 4a 00 t.........J...J.
0012fdc0 bc 11 4a 00 8c fe 12 00 - af 38 40 00 e0 fd 12 00 ..J......8@.....
0012fdd0 74 fe 12 00 13 01 00 00 - 00 00 00 00 00 1d e9 01 t...............
0012fde0 f8 fd 12 00 ea 52 49 00 - 13 01 00 00 01 00 00 00 .....RI.........
0012fdf0 00 00 00 00 00 00 00 00 - 24 fe 12 00 e7 c4 ca 75 ........$......u
0012fe00 78 02 13 00 13 01 00 00 - 01 00 00 00 00 00 00 00 x...............
0012fe10 13 01 00 00 cd ab ba dc - 00 00 00 00 74 fe 12 00 ............t...
0012fe20 13 01 00 00 9c fe 12 00 - e7 c5 ca 75 3b 09 9e 00 ...........u;...
0012fe30 78 02 13 00 13 01 00 00 - 01 00 00 00 00 00 00 00 x...............
0012fe40 96 05
81 34 ff 12 00 - 2c ff 12 00 20 e5 db 00 ....4...,.......
0012fe50 24 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 $...............
disassembling:
[...]
0056f83f push dword ptr fs:[eax]
0056f842 mov fs:[eax], esp
0056f845 3851 lea edx, [ebp-$10]
0056f848 mov eax, [$5799dc]
0056f84d mov eax, [eax]
0056f84f > call -$e6a80 ($488dd4) ; Controls.TMouse.GetCursorPos
0056f854 lea edx, [ebp-$10]
0056f857 lea ecx, [ebp-8]
0056f85a mov eax, [ebx+$5c0]
0056f860 call -$f12a5 ($47e5c0) ; Controls.TControl.ScreenToClient
0056f865 3852 mov eax, [ebp-8]
[...]