date/time : 2011-07-25, 11:13:37, 934ms
computer name : PILON1
user name : Katherine <admin>
operating system : Windows XP Service Pack 2 build 2600
system language : English
system up time : 1 day 10 hours
program up time : 9 minutes 55 seconds
processors : 2x Intel(R) Pentium(R) D CPU 2.80GHz
physical memory : 1024/1024 MB (free/total)
free disk space : (C:) 274.83 GB
display mode : 1280x1024, 32 bit
process id : $ef0
allocated memory : 80.53 MB
executable : PetWorkshop.exe
exec. date/time : 2005-10-05 17:06
version : 2.0.1.0
madExcept version : 3.0a beta 2
callstack crc : $b84d7b06, $81ff3091, $08ed2c22
exception class : EWin32Error
exception message : Win32 Error. Code: 5. Access is denied.
main thread ($15b4):
004569c7 PetWorkshop.exe SysUtils RaiseLastWin32Error
004569f7 PetWorkshop.exe SysUtils Win32Check
00488ddd PetWorkshop.exe Controls TMouse.GetCursorPos
0056f84f PetWorkshop.exe mainunit 3851 +1 Tmain.petz3dpicktimerTimer
004a12d3 PetWorkshop.exe ExtCtrls TTimer.Timer
004a11b7 PetWorkshop.exe ExtCtrls TTimer.WndProc
004952e8 PetWorkshop.exe Forms StdWndProc
76e43573 user32.dll DispatchMessageA
0049dd3f PetWorkshop.exe Forms TApplication.ProcessMessage
0049dd76 PetWorkshop.exe Forms TApplication.HandleMessage
0049df81 PetWorkshop.exe Forms TApplication.Run
00571437 PetWorkshop.exe PetWorkshop 58 +21 initialization
76f51112 kernel32.dll BaseThreadInitThunk
777ab3f7 ntdll.dll RtlUserThreadStart
thread $1088 (TDummyThread): <suspended>
77796328 ntdll.dll RtlUserThreadStart
>> created by main thread ($15b4) at:
00560d1f PetWorkshop.exe GIFImage 12426 +29 initialization
thread $f20 (TWorkerThread):
77796344 ntdll.dll KiFastSystemCallRet
77795cca ntdll.dll NtWaitForSingleObject
75a71796 KERNELBASE.dll WaitForSingleObjectEx
76f4ef9e kernel32.dll WaitForSingleObjectEx
76f4ef4d kernel32.dll WaitForSingleObject
004e259a PetWorkshop.exe VirtualTrees 5125 +3 TWorkerThread.Execute
0044ce97 PetWorkshop.exe madExcept HookedTThreadExecute
00461a48 PetWorkshop.exe Classes ThreadProc
004040e8 PetWorkshop.exe System ThreadWrapper
0044cde6 PetWorkshop.exe madExcept ThreadExceptFrame
76f51112 kernel32.dll BaseThreadInitThunk
777ab3f7 ntdll.dll RtlUserThreadStart
>> created by main thread ($15b4) at:
004e24bf PetWorkshop.exe VirtualTrees 5088 +1 TWorkerThread.Create
thread $139c:
77796344 ntdll.dll KiFastSystemCallRet
77795caa ntdll.dll NtWaitForMultipleObjects
76f51112 kernel32.dll BaseThreadInitThunk
777ab3f7 ntdll.dll RtlUserThreadStart
thread $5c8:
77796344 ntdll.dll KiFastSystemCallRet
77795cda ntdll.dll NtWaitForWorkViaWorkerFactory
76f51112 kernel32.dll BaseThreadInitThunk
777ab3f7 ntdll.dll RtlUserThreadStart
thread $16c8:
77796344 ntdll.dll KiFastSystemCallRet
77795cca ntdll.dll NtWaitForSingleObject
75a71796 KERNELBASE.dll WaitForSingleObjectEx
76f4ef9e kernel32.dll WaitForSingleObjectEx
0044cde6 PetWorkshop.exe madExcept ThreadExceptFrame
76f51112 kernel32.dll BaseThreadInitThunk
777ab3f7 ntdll.dll RtlUserThreadStart
>> created by main thread ($15b4) at:
76b064f2 ole32.dll
modules:
00400000 PetWorkshop.exe 2.0.1.0 C:\Program Files\Sherlock Software\Pet Workshop
5f040000 AcXtrnal.DLL 6.1.7600.16385 C:\Windows\AppPatch
5f2a0000 AcGenral.DLL 6.1.7600.16385 C:\Windows\AppPatch
66960000 ieproxy.dll 8.0.7600.16800 C:\Program Files\Internet Explorer
6aa00000 HHCTRL.OCX 6.1.7600.16385 C:\Windows\system32
6b610000 actxprxy.dll 6.1.7600.16385 C:\Windows\system32
6b9b0000 AcLayers.dll 6.1.7600.16385 C:\Windows\AppPatch
6bbc0000 ntshrui.dll 6.1.7600.16385 C:\Windows\system32
6c760000 MPR.dll 6.1.7600.16385 C:\Windows\system32
6c7d0000 olepro32.dll 6.1.7600.16385 C:\Windows\system32
6d220000 thumbcache.dll 6.1.7600.16385 C:\Windows\system32
6d3b0000 sfc_os.DLL 6.1.7600.16385 C:\Windows\system32
6d3c0000 sfc.dll 6.1.7600.16385 C:\Windows\system32
6df80000 msxml3.dll 8.110.7600.16723 C:\Windows\System32
6e590000 CSCAPI.dll 6.1.7600.16385 C:\Windows\system32
6e920000 ieframe.DLL 8.0.7600.16800 C:\Windows\system32
6fa50000 winspool.drv 6.1.7600.16385 C:\Windows\system32
70e50000 wsock32.dll 6.1.7600.16385 C:\Windows\system32
70eb0000 MSVCR80.dll 8.0.50727.4927 C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b5
71840000 GrooveSystemServices.dll 12.0.6421.1000 C:\Program Files\Microsoft Office\Office12
71870000 GrooveShellExtensions.dll 12.0.6421.1000 C:\Program Files\Microsoft Office\Office12
71c70000 tiptsf.dll 6.1.7600.16385 C:\Program Files\Common Files\microsoft shared\ink
71f20000 cscui.dll 6.1.7600.16385 C:\Windows\System32
72120000 SHDOCVW.dll 6.1.7600.16385 C:\Windows\system32
72150000 GrooveUtil.DLL 12.0.6550.5004 C:\Program Files\Microsoft Office\Office12
724f0000 SHUNIMPL.DLL 6.1.7600.16385 C:\Windows\system32
72680000 comctl32.dll 5.82.7600.16661 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7600.16661_none_ebfb56996c72aefc
72720000 EhStorShell.dll 6.1.7600.16385 C:\Windows\system32
72910000 SearchFolder.dll 6.1.7600.16385 C:\Windows\system32
729b0000 SortServer2003Compat.dll 6.1.7600.16385 C:\Windows\system32
73640000 IconCodecService.dll 6.1.7600.16385 C:\Windows\system32
73650000 StructuredQuery.dll 7.0.7600.16587 C:\Windows\System32
736c0000 MSACM32.dll 6.1.7600.16385 C:\Windows\system32
73730000 CSCDLL.dll 6.1.7600.16385 C:\Windows\System32
73810000 slc.dll 6.1.7600.16385 C:\Windows\system32
73b00000 winmm.dll 6.1.7600.16385 C:\Windows\system32
73b40000 ntmarta.dll 6.1.7600.16385 C:\Windows\system32
73c80000 ATL80.DLL 8.0.50727.762 C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c
73d10000 OLEACC.dll 7.0.0.0 C:\Windows\system32
73df0000 MSImg32.dll 6.1.7600.16385 C:\Windows\system32
74020000 samcli.dll 6.1.7600.16385 C:\Windows\system32
740d0000 GrooveNew.DLL 12.0.6413.1000 C:\Program Files\Microsoft Office\Office12
74190000 WindowsCodecs.dll 6.1.7600.16385 C:\Windows\system32
742c0000 dwmapi.dll 6.1.7600.16385 C:\Windows\system32
745f0000 UxTheme.dll 6.1.7600.16385 C:\Windows\system32
746d0000 PROPSYS.dll 7.0.7600.16385 C:\Windows\system32
74810000 comctl32.DLL 6.10.7600.16661 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd
74d60000 version.dll 6.1.7600.16385 C:\Windows\system32
74ec0000 USERENV.dll 6.1.7600.16385 C:\Windows\system32
750c0000 rsaenh.dll 6.1.7600.16385 C:\Windows\system32
75320000 CRYPTSP.dll 6.1.7600.16385 C:\Windows\system32
75720000 srvcli.dll 6.1.7600.16385 C:\Windows\system32
75790000 Secur32.dll 6.1.7600.16385 C:\Windows\System32
757b0000 SspiCli.dll 6.1.7600.16385 C:\Windows\system32
757d0000 apphelp.dll 6.1.7600.16481 C:\Windows\system32
75820000 CRYPTBASE.dll 6.1.7600.16385 C:\Windows\system32
75890000 RpcRtRemote.dll 6.1.7600.16385 C:\Windows\system32
758a0000 profapi.dll 6.1.7600.16385 C:\Windows\system32
75910000 MSASN1.dll 6.1.7600.16415 C:\Windows\system32
75920000 CRYPT32.dll 6.1.7600.16385 C:\Windows\system32
75a40000 WINTRUST.dll 6.1.7600.16493 C:\Windows\system32
75a70000 KERNELBASE.dll 6.1.7600.16823 C:\Windows\system32
75ac0000 CFGMGR32.dll 6.1.7600.16385 C:\Windows\system32
75b80000 DEVOBJ.dll 6.1.7600.16385 C:\Windows\system32
75ba0000 advapi32.dll 6.1.7600.16385 C:\Windows\system32
75c40000 WS2_32.dll 6.1.7600.16385 C:\Windows\system32
75cb0000 WININET.dll 8.0.7600.16800 C:\Windows\system32
75db0000 shell32.dll 6.1.7600.16644 C:\Windows\system32
76a00000 MSCTF.dll 6.1.7600.16385 C:\Windows\system32
76ad0000 ole32.dll 6.1.7600.16624 C:\Windows\system32
76c90000 oleaut32.dll 6.1.7600.16722 C:\Windows\system32
76d20000 CLBCatQ.DLL 2001.12.8530.16385 C:\Windows\system32
76db0000 comdlg32.dll 6.1.7600.16385 C:\Windows\system32
76e30000 user32.dll 6.1.7600.16385 C:\Windows\system32
76f00000 kernel32.dll 6.1.7600.16816 C:\Windows\system32
76ff0000 IMM32.DLL 6.1.7600.16385 C:\Windows\system32
77010000 GDI32.dll 6.1.7600.16385 C:\Windows\system32
77060000 msvcrt.dll 7.0.7600.16385 C:\Windows\system32
77110000 RPCRT4.dll 6.1.7600.16385 C:\Windows\system32
771c0000 LPK.dll 6.1.7600.16385 C:\Windows\system32
771d0000 USP10.dll 1.626.7600.16385 C:\Windows\system32
77270000 iertutil.dll 8.0.7600.16800 C:\Windows\system32
77470000 SETUPAPI.dll 6.1.7600.16385 C:\Windows\system32
77610000 urlmon.dll 8.0.7600.16800 C:\Windows\system32
77750000 ntdll.dll 6.1.7600.16695 C:\Windows\SYSTEM32
77890000 NSI.dll 6.1.7600.16385 C:\Windows\system32
778a0000 SHLWAPI.dll 6.1.7600.16385 C:\Windows\system32
77900000 PSAPI.DLL 6.1.7600.16385 C:\Windows\system32
77910000 WLDAP32.dll 6.1.7600.16385 C:\Windows\system32
77960000 sechost.dll 6.1.7600.16385 C:\Windows\SYSTEM32
processes:
0000 Idle 0
0004 System 0
0174 smss.exe 0
01cc csrss.exe 0
0214 wininit.exe 0
0244 services.exe 0
0254 lsass.exe 0
025c lsm.exe 0
02f8 svchost.exe 0
0344 svchost.exe 0
03a0 MsMpEng.exe 0
03ec svchost.exe 0
041c svchost.exe 0
0458 svchost.exe 0
04ec svchost.exe 0
0598 svchost.exe 0
0650 spoolsv.exe 0
0674 svchost.exe 0
070c AppleMobileDeviceService.exe 0
0724 mDNSResponder.exe 0
074c svchost.exe 0
0774 LMIGuardianSvc.exe 0
07a8 ramaint.exe 0
07c4 LogMeIn.exe 0
01a0 SeaPort.exe 0
0590 WLIDSVC.EXE 0
0830 WLIDSVCM.EXE 0
0a28 svchost.exe 0
0a74 svchost.exe 0
0ba8 NisSrv.exe 0
0fec svchost.exe 0
08f4 SearchIndexer.exe 0
0adc wmpnetwk.exe 0
0fac iPodService.exe 0
12fc svchost.exe 0
15d0 dllhost.exe 0
16b8 csrss.exe 1
0c4c winlogon.exe 1
0a30 taskhost.exe 1 normal C:\Windows\system32
09ec Dwm.exe 1 high C:\Windows\system32
0ad8 Explorer.EXE 1 normal C:\Windows
0f14 GrooveMonitor.exe 1 normal C:\Program Files\Microsoft Office\Office12
01b8 hpwuSchd2.exe 1 normal C:\Program Files\HP\HP Software Update
0af0 LogMeInSystray.exe 1 normal C:\Program Files\LogMeIn\x86
14a8 PWRISOVM.EXE 1 normal C:\Program Files\PowerISO
0de8 iTunesHelper.exe 1 normal C:\Program Files\iTunes
0b10 msseces.exe 1 normal C:\Program Files\Microsoft Security Client
10cc hpqtra08.exe 1 normal C:\Program Files\HP\Digital Imaging\bin
076c ONENOTEM.EXE 1 normal C:\Program Files\Microsoft Office\Office12
121c svchost.exe 0
13cc wuauclt.exe 1 normal C:\Windows\system32
0940 hpqSTE08.exe 1 normal C:\Program Files\HP\Digital Imaging\bin
11cc hpqbam08.exe 1 normal C:\Program Files\HP\Digital Imaging\bin
13e8 svchost.exe 0
1668 hpqgpc01.exe 1 normal C:\Program Files\HP\Digital Imaging\bin
0c14 firefox.exe 1 normal C:\Program Files\Mozilla Firefox
0c68 aim.exe 1 normal C:\Program Files\AIM
0af4 hpswp_clipbook.exe 1 normal C:\Program Files\HP\Digital Imaging\smart web printing
1018 plugin-container.exe 1 normal C:\Program Files\Mozilla Firefox
1478 audiodg.exe 0
0ef0 PetWorkshop.exe 1 normal C:\Program Files\Sherlock Software\Pet Workshop
11a4 SearchProtocolHost.exe 0
0288 SearchFilterHost.exe 0 idle C:\Windows\system32
0978 consent.exe 1
hardware:
+ Computer
- ACPI x86-based PC
+ Disk drives
- WDC WD5000AADS-00M2B0 ATA Device
+ Display adapters
- LogMeIn Mirror Driver (driver 7.1.542.0)
- Radeon X1900 Series (Microsoft Corporation - WDDM) (driver 8.56.1.15)
- Radeon X1900 Series Secondary (Microsoft Corporation - WDDM) (driver 8.56.1.15)
+ DVD/CD-ROM drives
- HP DVD Writer 1140r ATA Device
- WDKJW MN4D6R8 SCSI CdRom Device
+ Human Interface Devices
- USB Input Device
- USB Input Device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 0
- ATA Channel 1
- ATA Channel 2
- ATA Channel 3
- Intel(R) 82801G (ICH7 Family) Ultra ATA Storage Controllers - 27DF
- Standard AHCI 1.0 Serial ATA Controller
+ Keyboards
- HID Keyboard Device
+ Mice and other pointing devices
- HID-compliant mouse
+ Modems
- Conexant D850 56K V.90 DFVc Modem
+ Monitors
- Generic PnP Monitor
+ Network adapters
- Intel(R) PRO/1000 PL Network Connection
- Wireless-G PCI Adapter with SRX (driver 1.5.0.86)
+ Processors
- Intel(R) Pentium(R) D CPU 2.80GHz
- Intel(R) Pentium(R) D CPU 2.80GHz
+ Sound, video and game controllers
- High Definition Audio Device
+ Storage controllers
- ABX107JB IDE Controller
+ Storage volume shadow copies
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
+ System devices
- ACPI Fixed Feature Button
- ACPI Power Button
- Composite Bus Enumerator
- Direct memory access controller
- Extended IO Bus
- File as Volume Driver
- High Definition Audio Controller
- Intel(R) 82801 PCI Bridge - 244E
- Intel(R) 82801G (ICH7 Family) PCI Express Root Port - 27D0
- Intel(R) 82801G (ICH7 Family) SMBus Controller - 27DA
- Intel(R) 82801GH (ICH7DH) LPC Interface Controller - 27B0
- Intel(R) 82801GR/GH/GHM (ICH7 Family) PCI Express Root Port - 27E0
- Intel(R) 82801GR/GH/GHM (ICH7 Family) PCI Express Root Port - 27E2
- Intel(R) 945G/GZ/GC/P/PL PCI Express Root Port - 2771
- Intel(R) 945G/GZ/GC/P/PL Processor to I/O Controller - 2770
- Microsoft ACPI-Compliant System
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator Driver
- Motherboard resources
- Numeric data processor
- PCI bus
- Plug and Play Software Device Enumerator
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- System board
- System board
- System CMOS/real time clock
- System speaker
- System timer
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- UMBus Enumerator
- UMBus Root Bus Enumerator
- Virtual PC Host Bus Driver
- Volume Manager
+ Universal Serial Bus controllers
- Intel(R) 82801G (ICH7 Family) USB Universal Host Controller - 27C8
- Intel(R) 82801G (ICH7 Family) USB Universal Host Controller - 27C9
- Intel(R) 82801G (ICH7 Family) USB Universal Host Controller - 27CA
- Intel(R) 82801G (ICH7 Family) USB Universal Host Controller - 27CB
- Intel(R) 82801G (ICH7 Family) USB2 Enhanced Host Controller - 27CC
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
+ USB Virtualization
- USB Virtualization Connector Driver
cpu registers:
eax = 01b24e28
ebx = 00000005
ecx = 00000000
edx = 004569cc
esi = 00000113
edi = 0012fe74
eip = 004569cc
esp = 0012fd20
ebp = 0012fd74
stack dump:
0012fd20 cc 69 45 00 de fa ed 0e - 01 00 00 00 07 00 00 00 .iE.............
0012fd30 34 fd 12 00 cc 69 45 00 - 28 4e b2 01 05 00 00 00 4....iE.(N......
0012fd40 13 01 00 00 74 fe 12 00 - 74 fd 12 00 50 fd 12 00 ....t...t...P...
0012fd50 8c fd 12 00 90 3a 40 00 - 74 fd 12 00 00 00 00 00 .....:@.t.......
0012fd60 00 00 00 00 05 00 00 00 - 00 c1 e3 76 68 82 b3 01 ...........vh...
0012fd70 0b 00 00 00 b4 fd 12 00 - fc 69 45 00 a4 fd 12 00 .........iE.....
0012fd80 e2
48 00 e0 d7 a9 01 - 54 f8 56 00 c4 fd 12 00 ..H.....T.V.....
0012fd90 90 3a 40 00 b4 fd 12 00 - 13 01 00 00 00 1d b4 01 .:@.............
0012fda0 00 00 00 00 93 cd 56 00 - 9b cd 56 00 01 00 00 00 ......V...V.....
0012fdb0 74 fe 12 00 e0 fd 12 00 - d6 12 4a 00 c4 12 4a 00 t.........J...J.
0012fdc0 bc 11 4a 00 8c fe 12 00 - af 38 40 00 e0 fd 12 00 ..J......8@.....
0012fdd0 74 fe 12 00 13 01 00 00 - 00 00 00 00 00 1d b4 01 t...............
0012fde0 f8 fd 12 00 ea 52 49 00 - 13 01 00 00 01 00 00 00 .....RI.........
0012fdf0 00 00 00 00 00 00 00 00 - 24 fe 12 00 ef 86 e4 76 ........$......v
0012fe00 00 03 2f 00 13 01 00 00 - 01 00 00 00 00 00 00 00 ../.............
0012fe10 13 01 00 00 cd ab ba dc - 00 00 00 00 74 fe 12 00 ............t...
0012fe20 13 01 00 00 9c fe 12 00 - 76 88 e4 76 3b 09 26 00 ........v..v;.&.
0012fe30 00 03 2f 00 13 01 00 00 - 01 00 00 00 00 00 00 00 ../.............
0012fe40 6e f5 b9 fa 34 ff 12 00 - 2c ff 12 00 c8 77 ba 00 n...4...,....w..
0012fe50 24 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 $...............
disassembling:
[...]
0056f83f push dword ptr fs:[eax]
0056f842 mov fs:[eax], esp
0056f845 3851 lea edx, [ebp-$10]
0056f848 mov eax, [$5799dc]
0056f84d mov eax, [eax]
0056f84f > call -$e6a80 ($488dd4) ; Controls.TMouse.GetCursorPos
0056f854 lea edx, [ebp-$10]
0056f857 lea ecx, [ebp-8]
0056f85a mov eax, [ebx+$5c0]
0056f860 call -$f12a5 ($47e5c0) ; Controls.TControl.ScreenToClient
0056f865 3852 mov eax, [ebp-8]
[...]