Documentos de Académico
Documentos de Profesional
Documentos de Cultura
:
computer name
:
user name
:
registered owner :
operating system :
system language
:
system up time
:
program up time
:
processor
:
physical memory
:
free disk space
:
display mode
:
process id
:
allocated memory :
largest free block :
executable
:
exec. date/time
:
version
:
compiled with
:
madExcept version :
contact name
:
contact email
:
callstack crc
:
exception number :
exception class
:
exception message :
l'. Write of address
MVDavconv
CreateProcessW
156 +42 TThreadConvert.Ex
MVDavconv
295 +0 TThreadConvert.Ex
madExcept
HookedTThreadExec
System.Classes
ThreadProc
System
637 +0 ThreadWrapper
madExcept
CallThreadProcSaf
madExcept
ThreadExceptFrame
System.Classes
TThread.Create
Vcl.Forms
WaitMessage
TApplication.I
Vcl.Forms
TApplication.H
Vcl.Forms
TApplication.R
thread $aac:
7c91d218 +a ntdll.dll NtDelayExecution
thread $fb8: <priority:1>
CreateProcessInte
NtWaitForSingleObj
WaitForSingleObjec
WaitForSingleObjec
OtlTaskControl 2345 +2 TOmniTaskExecutor.
OtlTaskControl 1782 +12 TOmniTaskExecutor.
OtlTaskControl 1801 +12 TOmniTaskExecutor.
OtlTaskControl 2151 +2 TOmniTaskExecutor.
OtlTaskControl 1851 +21 TOmniTaskExecutor.
OtlTaskControl 1638 +16 TOmniTaskExecutor.
OtlTaskControl 1356 +18 TOmniTask.Internal
OtlTaskControl 1276 +0 TOmniTask.Execute
OtlTaskControl 3094 +4 TOmniThread.Execut
System
madExcept
madExcept
637 +0 ThreadWrapper
CallThreadProcSafe
ThreadExceptFrame
NtWaitForMultipleO
WaitForMultipleObj
WaitForMultipleObj
1951 +3 DSiWaitForTwoObjec
477 +8 TOmniCommunication
625 +11 TOTPWorkerThread.E
HookedTThreadExecu
ThreadProc
637 +0 ThreadWrapper
CallThreadProcSafe
ThreadExceptFrame
537 +1 TOTPWorkerThread.C
NtWaitForMult
WaitForMultip
MsgWaitForMul
MsgWaitForMul
3493 +8 THttpCli.DoRe
4577 +1 THttpCli.Post
70 +11 HttpSend
89 +0 SendStat$202$
1634 +0 Parallel.Asyn
1632 +10 TOmniTaskExec
1356 +18 TOmniTask.Int
1276 +0 TOmniTask.Exe
662 +9 TOTPWorkerThr
628 +14 TOTPWorkerThr
HookedTThread
ThreadProc
637 +0 ThreadWrapper
CallThreadPro
ThreadExceptF
537 +1 TOTPWorkerThr
ntdll.dll
NtRequestWaitReplyPort
RPCRT4.dll
I_RpcSendReceive
RPCRT4.dll
NdrSendReceive
RPCRT4.dll
NdrClientCall2
DNSAPI.dll
DnsQuery_W
ntdll.dll
bsearch
WS2_32.dll
WSALookupServiceNextW
WS2_32.dll
WSALookupServiceNextA
WS2_32.dll
gethostbyname
UmmyVideoDownloader.exe madExcept CallThreadProcSafe
UmmyVideoDownloader.exe madExcept ThreadExceptFrame
thread $b2c (TOTPWorkerThread) at:
WS2_32.dll
NtWaitForMultipleO
WaitForMultipleObj
WaitForMultipleObj
1951 +3 DSiWaitForTwoObjec
477 +8 TOmniCommunication
625 +11 TOTPWorkerThread.E
HookedTThreadExecu
ThreadProc
637 +0 ThreadWrapper
CallThreadProcSafe
ThreadExceptFrame
537 +1 TOTPWorkerThread.C
NtWaitForMultipleO
WaitForMultipleObj
WaitForMultipleObj
1951 +3 DSiWaitForTwoObjec
477 +8 TOmniCommunication
625 +11 TOTPWorkerThread.E
HookedTThreadExecu
ThreadProc
637 +0 ThreadWrapper
CallThreadProcSafe
ThreadExceptFrame
537 +1 TOTPWorkerThread.C
NtWaitForMultipleO
WaitForMultipleObj
WaitForMultipleObj
1951 +3 DSiWaitForTwoObjec
477 +8 TOmniCommunication
625 +11 TOTPWorkerThread.E
HookedTThreadExecu
ThreadProc
637 +0 ThreadWrapper
CallThreadProcSafe
ThreadExceptFrame
537 +1 TOTPWorkerThread.C
reate
thread $cc4:
7c91daa8 +0a ntdll.dll
NtReplyWaitReceivePortEx
004a84e9 +0d UmmyVideoDownloader.exe madExcept CallThreadProcSafe
004a854e +32 UmmyVideoDownloader.exe madExcept ThreadExceptFrame
>> created by main thread ($8e8) at:
77e5d105 +00 RPCRT4.dll
thread $a0c:
7c91daa8 +0a ntdll.dll
NtReplyWaitReceivePortEx
004a84e9 +0d UmmyVideoDownloader.exe madExcept CallThreadProcSafe
004a854e +32 UmmyVideoDownloader.exe madExcept ThreadExceptFrame
>> created by thread $cc4 at:
77e5d105 +00 RPCRT4.dll
modules:
00390000 Normaliz.dll
6.0.5441.0
C:\WINDOWS\system32
00400000 UmmyVideoDownloader.exe 1.3.0.4
C:\Documents and Settings\Bode
ga\Configuracin local\Datos de programa\UmmyVideoDownloader
03510000 xpsp2res.dll
5.1.2600.5512
C:\WINDOWS\system32
1f840000 odbcint.dll
3.525.1117.0
C:\WINDOWS\system32
20000000 xpsp3res.dll
5.1.2600.5512
C:\WINDOWS\system32
3fa00000 wininet.dll
8.0.6001.23580 C:\WINDOWS\system32
400a0000 iertutil.dll
8.0.6001.23580 C:\WINDOWS\system32
44430000 urlmon.dll
8.0.6001.23580 C:\WINDOWS\system32
4eba0000 gdiplus.dll
5.2.6002.23084 C:\WINDOWS\WinSxS\x86_Microsof
t.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.23084_x-ww_f3f35550
4eee0000 wiashext.dll
5.1.2600.5512
C:\WINDOWS\system32
597f0000 NETAPI32.dll
5.1.2600.6260
C:\WINDOWS\system32
5b150000 uxtheme.dll
6.0.2900.5512
C:\WINDOWS\system32
5f1f0000 olepro32.dll
5.1.2600.5512
C:\WINDOWS\system32
66740000 hnetcfg.dll
5.1.2600.5512
C:\WINDOWS\system32
719d0000 mswsock.dll
5.1.2600.5625
C:\WINDOWS\system32
71a10000 wshtcpip.dll
5.1.2600.5512
C:\WINDOWS\System32
71a20000 WS2HELP.dll
5.1.2600.5512
C:\WINDOWS\system32
71a30000 WS2_32.dll
5.1.2600.5512
C:\WINDOWS\system32
71a50000 wsock32.dll
5.1.2600.5512
C:\WINDOWS\system32
71aa0000 MPR.dll
5.1.2600.5512
C:\WINDOWS\system32
71b90000 SAMLIB.dll
5.1.2600.5512
C:\WINDOWS\system32
71bb0000 ntlanman.dll
5.1.2600.5512
C:\WINDOWS\System32
71c20000 NETRAP.dll
5.1.2600.5512
C:\WINDOWS\System32
71c30000 NETUI1.dll
5.1.2600.5512
C:\WINDOWS\System32
71c70000 NETUI0.dll
5.1.2600.5512
C:\WINDOWS\System32
72250000 sensapi.dll
5.1.2600.5512
C:\WINDOWS\system32
72f80000 winspool.drv
5.1.2600.5512
C:\WINDOWS\system32
73b20000 sti.dll
5.1.2600.5512
C:\WINDOWS\system32
73cf0000 shgina.dll
6.0.2900.5512
C:\WINDOWS\system32
745e0000 ODBC32.dll
3.525.3012.0
C:\WINDOWS\system32
746b0000 MSCTF.dll
5.1.2600.5512
C:\WINDOWS\system32
74a70000 CFGMGR32.dll
5.1.2600.5512
C:\WINDOWS\system32
75160000 msctfime.ime
5.1.2600.5512
C:\WINDOWS\system32
75920000 MSGINA.dll
5.1.2600.5512
C:\WINDOWS\system32
75dd0000 MLANG.dll
6.0.2900.5512
C:\WINDOWS\system32
75f10000 drprov.dll
5.1.2600.5512
C:\WINDOWS\System32
75f20000 davclnt.dll
5.1.2600.5512
C:\WINDOWS\System32
76310000 WINSTA.dll
5.1.2600.5512
C:\WINDOWS\system32
76330000 msimg32.dll
5.1.2600.5512
C:\WINDOWS\system32
76340000 IMM32.DLL
5.1.2600.5512
C:\WINDOWS\system32
76360000 comdlg32.dll
6.0.2900.5512
C:\WINDOWS\system32
765b0000 CSCDLL.dll
5.1.2600.5512
C:\WINDOWS\System32
76630000 USERENV.dll
5.1.2600.5512
C:\WINDOWS\system32
76750000 cryptdll.dll
5.1.2600.5512
C:\WINDOWS\system32
76890000 CRYPTUI.dll
5.131.2600.5512 C:\WINDOWS\system32
76950000 ntshrui.dll
5.1.2600.5512
C:\WINDOWS\system32
76ae0000 ATL.DLL
3.5.2284.2
C:\WINDOWS\system32
76b00000 winmm.dll
5.1.2600.6160
C:\WINDOWS\system32
76bb0000 psapi.dll
5.1.2600.5512
C:\WINDOWS\system32
76bf0000 wintrust.dll
5.131.2600.6285 C:\WINDOWS\system32
76c50000 IMAGEHLP.dll
5.1.2600.6198
C:\WINDOWS\system32
76d20000 iphlpapi.dll
5.1.2600.5512
C:\WINDOWS\system32
76e40000 rtutils.dll
5.1.2600.5512
C:\WINDOWS\system32
76e50000 rasman.dll
5.1.2600.5512
C:\WINDOWS\system32
76e70000 TAPI32.dll
5.1.2600.5512
C:\WINDOWS\system32
76ea0000 RASAPI32.dll
5.1.2600.5512
C:\WINDOWS\system32
76ee0000 DNSAPI.dll
5.1.2600.6089
C:\WINDOWS\system32
76f10000 wtsapi32.dll
5.1.2600.5512
C:\WINDOWS\system32
76f20000 WLDAP32.dll
5.1.2600.5512
C:\WINDOWS\system32
76f70000 winrnr.dll
5.1.2600.5512
C:\WINDOWS\System32
76f80000 rasadhlp.dll
5.1.2600.5512
C:\WINDOWS\system32
76f90000 CLBCATQ.DLL
2001.12.4414.700 C:\WINDOWS\system32
77010000 COMRes.dll
2001.12.4414.700 C:\WINDOWS\system32
770f0000 oleaut32.dll
5.1.2600.6341
C:\WINDOWS\system32
773a0000 comctl32.dll
6.0.2900.6028
C:\WINDOWS\WinSxS\x86_Microsof
t.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
774b0000 ole32.dll
5.1.2600.6168
C:\WINDOWS\system32
77660000 NTMARTA.DLL
5.1.2600.5512
C:\WINDOWS\system32
778f0000 SETUPAPI.dll
5.1.2600.5512
C:\WINDOWS\system32
779f0000 cscui.dll
5.1.2600.5512
C:\WINDOWS\System32
77a50000 CRYPT32.dll
5.131.2600.6239 C:\WINDOWS\system32
77af0000 MSASN1.dll
5.1.2600.5875
C:\WINDOWS\system32
77b10000 appHelp.dll
5.1.2600.5512
C:\WINDOWS\system32
77bd0000 version.dll
5.1.2600.5512
C:\WINDOWS\system32
77be0000 msvcrt.dll
7.0.2600.5512
C:\WINDOWS\system32
77c40000 msv1_0.dll
5.1.2600.5876
C:\WINDOWS\system32
77da0000 ADVAPI32.dll
5.1.2600.5755
C:\WINDOWS\system32
77e50000 RPCRT4.dll
5.1.2600.6399
C:\WINDOWS\system32
77ef0000 GDI32.dll
5.1.2600.5698
C:\WINDOWS\system32
77f40000 SHLWAPI.dll
6.0.2900.5912
C:\WINDOWS\system32
77fc0000 Secur32.dll
5.1.2600.5834
C:\WINDOWS\system32
7c800000 kernel32.dll
5.1.2600.6293
C:\WINDOWS\system32
7c910000 ntdll.dll
5.1.2600.6055
C:\WINDOWS\system32
7e210000 shdocvw.dll
6.0.2900.6425
C:\WINDOWS\system32
7e390000 USER32.dll
5.1.2600.5512
C:\WINDOWS\system32
7e6a0000 shell32.dll
6.0.2900.6242
C:\WINDOWS\system32
processes:
000 Idle
004 System
234 smss.exe
274 CSRSS.EXE
28c winlogon.exe
2b8 services.exe
2c4 lsass.exe
360 svchost.exe
3ac SVCHOST.EXE
424 svchost.exe
450 SVCHOST.EXE
4c4 SVCHOST.EXE
5bc spoolsv.exe
0
0
0
0
50
4
4
4
0
11
0
0
4
0
0
0
0
16
2
2
1
0
27
0
0
5
normal
normal C:\WINDOWS\system32
high
normal
normal
normal
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
C:\WINDOWS\system32
normal C:\WINDOWS\System32
normal C:\WINDOWS\system32
788 SVCHOST.EXE
0
0
7b4 EPCP.exe
4
5 normal C:\Archivos de programa\EPSON\EpsonC
ustomerParticipation
0dc svchost.exe
4
2 normal C:\WINDOWS\system32
634 ALG.EXE
0
0
710 WgaTray.exe
55 34 normal C:\WINDOWS\system32
720 Explorer.EXE
516 358 normal C:\WINDOWS
134 ctfmon.exe
28 11 normal C:\WINDOWS\system32
18c E_FATILDE.EXE
25 8 normal C:\WINDOWS\System32\spool\DRIVERS\W3
2X86\3
1a4 E_TATII2E.EXE
24 10 normal C:\WINDOWS\System32\spool\DRIVERS\W3
2X86\3
ac0 cmd.exe
8
1 normal C:\WINDOWS\system32
83c cmd.exe
8
1 normal C:\WINDOWS\system32
530 cmd.exe
8
1 normal C:\WINDOWS\system32
3d8 cmd.exe
8
1 normal C:\WINDOWS\system32
b00 cmd.exe
8
1 normal C:\WINDOWS\system32
6cc firefox.exe
207 83 normal C:\Archivos de programa\Mozilla Fire
fox
cc8 adb.exe
4
1 normal C:\Documents and Settings\Bodega\Dat
os de programa\Mozilla\Firefox\Profiles\1upxdue9.default\extensions\adbhelper@mo
zilla.org\win32
0a8 UmmyVideoDownloader.exe 1296 188 normal C:\Documents and Settings\Bodega\Con
figuracin local\Datos de programa\UmmyVideoDownloader
hardware:
+ Adaptadores de red
- Adaptador Fast Ethernet compatible VIA
- Adaptador Fast Ethernet compatible VIA - Minipuerto del administrador de paq
uetes
- Minipuerto WAN (IP)
- Minipuerto WAN (IP) - Minipuerto del administrador de paquetes
- Minipuerto WAN (L2TP)
- Minipuerto WAN (PPPOE)
- Minipuerto WAN (PPTP)
- Paralelo directo
+ Controladoras de bus serie universal (USB)
- Compatibilidad con impresoras USB
- Concentrador raz USB
- Concentrador raz USB
- Concentrador raz USB
- Concentrador raz USB
- Concentrador raz USB
- Controlador de host mejorado USB VIA
- Controlador de host universal USB VIA Rev 5 o posterior
- Controlador de host universal USB VIA Rev 5 o posterior
- Controlador de host universal USB VIA Rev 5 o posterior
- Controlador de host universal USB VIA Rev 5 o posterior
- Dispositivo compuesto USB
- Dispositivo de almacenamiento masivo USB
+ Controladoras IDE ATA/ATAPI
- Canal IDE principal
- Canal IDE principal
- Canal IDE secundario
- Canal IDE secundario
- Controladora estndar PCI IDE de doble canal
- Controladora IDE principal de bus VIA
+ Controladores de disquete
- Controlador estndar de disquetes
+ Dispositivos de imgenes
+ Teclados
- Teclado estndar de 101/102 teclas o Microsoft Natural PS/2 Keyboard
+ Unidades de disco
- Kingston DT 101 G2 USB Device
- WDC WD100BA
+ Unidades de disquete
- Unidad de disquete
+ Unidades de DVD/CD-ROM
- ATAPI DVD D DH16D2S
cpu
eax
ebx
ecx
edx
esi
edi
eip
esp
ebp
registers:
= 0040ae70
= 00000000
= 7c920000
= 00b20004
= 0236fde0
= 0040ae70
= 7c8309b9
= 0236f268
= 0236fc8c
stack dump:
0236f268 08
0236f278 00
0236f288 00
0236f298 00
0236f2a8 00
0236f2b8 00
0236f2c8 00
0236f2d8 00
0236f2e8 00
0236f2f8 00
0236f308 00
0236f318 00
0236f328 00
0236f338 00
0236f348 00
0236f358 00
0236f368 b4
0236f378 9c
0236f388 00
0236f398 00
fe
00
00
00
00
00
00
00
00
00
00
e0
00
e0
00
00
f9
fd
00
00
disassembling:
[...]
007b1cc9
007b1ccc
007b1ccf
007b1cd4
007b1cd5
007b1cd7
>
007b1cdc
007b1cde
007b1ce0 166
007b1ce5
007b1ceb
[...]
36
00
00
00
00
00
00
00
00
00
00
fd
00
fd
00
00
36
36
00
00
02
00
00
00
00
00
00
00
00
00
00
7f
00
7f
00
00
02
02
00
00
mov
mov
call
push
push
call
test
jnz
call
lea
call
error details:
no se pudo convertir
a0
00
00
00
00
00
00
00
00
00
00
00
00
00
00
d8
fc
00
00
00
75
00
00
00
00
00
00
e0
00
00
00
00
00
00
00
f9
f9
00
00
00
b6
00
00
00
00
00
00
fd
00
00
00
00
00
00
00
36
36
00
00
00
01
00
00
00
00
00
00
7f
00
00
00
00
00
00
00
02
02
00
00
00
a0
00
00
00
00
00
00
00
00
00
00
00
00
00
00
20
00
00
00
00
75
00
00
00
00
00
00
e0
00
00
00
00
e0
00
00
fa
00
00
00
00
eax, [eax+$c]
eax, [eax+$40]
-$3a69cc ($40b308)
eax
0
-$39e484 ($413858)
eax, eax
loc_7b1d1d
-$39e241 ($413aa4)
edx, [ebp-$194]
-$35b178 ($456b78)
b6
00
00
00
00
00
00
fd
00
00
00
00
fd
00
00
36
00
00
00
00
01
00
00
00
00
00
00
7f
00
00
00
00
7f
00
00
02
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
44
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
fa
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
36
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
02
00
00
00
00
..6..u...u......
................
................
................
................
................
................
................
................
................
................
................
................
................
................
......6. .6.D.6.
..6...6.........
..6.............
................
................
; System.@UStrToPWChar
; Winapi.Windows.CreateProcessW
; Winapi.Windows.GetLastError
; System.SysUtils.SysErrorMessage