You are on page 1of 32

date/time : 2017-10-01, 22:41:47, 725ms

computer name : STUDIO6SMK


user name : multimedia
registered owner : multimedia
operating system : Windows NT New Tablet PC x64 build 9200
system language : English
system up time : 30 minutes 18 seconds
program up time : 1 minute 43 seconds
processors : 4x AMD A6-1450 APU with Radeon(TM) HD Graphics
physical memory : 4052/5579 MB (free/total)
free disk space : (C:) 23,54 GB
display mode : 1366x768, 32 bit
process id : $13fc
allocated memory : 110,42 MB
executable : IncardexDesigner.exe
current module : icProject.dll
module date/time : 2015-06-04 13:47
version : 1.6.2.138
compiled with : Delphi 7
madExcept version : 3.0g
callstack crc : $2dd4ddce, $7f93d803, $d0f22418
exception number : 1
exception class : EOleException
exception message : OLE error 800AC472.

main thread ($eac):


06e1a629 +031 icProject.dll ExcelXP TExcelApplication.Quit
06e19bd4 +024 icProject.dll ExcelXP
TExcelApplication.Disconnect
06d9b987 +00f icProject.dll OleServer TOleServer.Destroy
06e19c5a +012 icProject.dll ExcelXP
TExcelApplication.Destroy
06d13136 +046 icProject.dll Classes
TComponent.DestroyComponents
06d12f3b +047 icProject.dll Classes TComponent.Destroy
06d14149 +065 icProject.dll Classes TDataModule.Destroy
06ca3e84 +008 icProject.dll System TObject.Free
06e28f7b +013 icProject.dll iD_DBStructure 1934 +1 TformDB.FormDestroy
06d684f5 +031 icProject.dll Forms TCustomForm.DoDestroy
06d6835b +05f icProject.dll Forms
TCustomForm.BeforeDestruction
06ca4265 +009 icProject.dll System @BeforeDestruction
06d6836a +006 icProject.dll Forms TCustomForm.Destroy
06ca3e84 +008 icProject.dll System TObject.Free
06e3e387 +22f icProject.dll iD_ProjectWindow 1540 +47 TProjectWindow.ShowDB
06e49260 +00c icProject.dll icProject 431 +0 d_ShowDB
0059a0ee +0fa IncardexDesigner.exe iD_main 1667 +14
TformMain.aDBSetupDBExecute
004a619a +036 IncardexDesigner.exe Controls 4560 +5 TControl.Perform
00470350 +014 IncardexDesigner.exe Classes StdWndProc
77b80594 +034 ntdll.dll
KiUserCallbackDispatcher
0046fcbb +00f IncardexDesigner.exe Classes TBasicAction.Execute
004b43f1 +031 IncardexDesigner.exe ActnList
TContainedAction.Execute
004b5093 +04f IncardexDesigner.exe ActnList TCustomAction.Execute
0046fb8f +013 IncardexDesigner.exe Classes
TBasicActionLink.Execute
004baaeb +08f IncardexDesigner.exe Menus TMenuItem.Click
004bbd9f +013 IncardexDesigner.exe Menus TMenu.DispatchCommand
004c41b7 +01f IncardexDesigner.exe Forms TCustomForm.WMCommand
004a648f +1df IncardexDesigner.exe Controls 4653 +53 TControl.WndProc
004aa1be +18e IncardexDesigner.exe Controls 6350 +33 TWinControl.WndProc
004c2215 +421 IncardexDesigner.exe Forms TCustomForm.WndProc
004a9d90 +034 IncardexDesigner.exe Controls 6245 +3
TWinControl.MainWndProc
00470350 +014 IncardexDesigner.exe Classes StdWndProc
75365d3b +00b user32.dll DispatchMessageA
004c8917 +083 IncardexDesigner.exe Forms
TApplication.ProcessMessage
004c894e +00a IncardexDesigner.exe Forms
TApplication.HandleMessage
004c8b7e +096 IncardexDesigner.exe Forms TApplication.Run
0059b906 +23a IncardexDesigner.exe IncardexDesigner 133 +64 initialization
776a7c02 +022 KERNEL32.DLL BaseThreadInitThunk

thread $a54:
760a28bd +000 KERNELBASE.dll WaitForMultipleObjectsEx
7533de8d +15d user32.dll MsgWaitForMultipleObjectsEx
7533dbda +01a user32.dll MsgWaitForMultipleObjects
776a7c02 +022 KERNEL32.DLL BaseThreadInitThunk

thread $794 (TEventWaitThread):


760a28bd +000 KERNELBASE.dll WaitForMultipleObjectsEx
776a7b83 +013 KERNEL32.DLL WaitForMultipleObjects
0055688e +02a IncardexDesigner.exe reinit 551 +3 TEventWaitThread.Execute
0044e7d3 +02b IncardexDesigner.exe madExcept HookedTThreadExecute
0046ee10 +034 IncardexDesigner.exe Classes ThreadProc
00404c20 +028 IncardexDesigner.exe System ThreadWrapper
0044e6b5 +00d IncardexDesigner.exe madExcept CallThreadProcSafe
0044e71f +037 IncardexDesigner.exe madExcept ThreadExceptFrame
776a7c02 +022 KERNEL32.DLL BaseThreadInitThunk
>> created by main thread ($eac) at:
00594938 +268 IncardexDesigner.exe iD_main 596 +49 TformMain.FormCreate

thread $1170:
776a7c02 +22 KERNEL32.DLL BaseThreadInitThunk

thread $e78:
760a28bd +00 KERNELBASE.dll WaitForMultipleObjectsEx
0044e6b5 +0d IncardexDesigner.exe madExcept CallThreadProcSafe
0044e71f +37 IncardexDesigner.exe madExcept ThreadExceptFrame
776a7c02 +22 KERNEL32.DLL BaseThreadInitThunk
>> created by main thread ($eac) at:
757f9e7e +00 combase.dll

thread $ba4:
776a7c02 +22 KERNEL32.DLL BaseThreadInitThunk

thread $c88:
776a7c02 +22 KERNEL32.DLL BaseThreadInitThunk

thread $ca8:
776a7c02 +22 KERNEL32.DLL BaseThreadInitThunk

thread $968:
776a7c02 +22 KERNEL32.DLL BaseThreadInitThunk
thread $10cc:
776a7c02 +22 KERNEL32.DLL BaseThreadInitThunk

thread $200:
776a7c02 +22 KERNEL32.DLL BaseThreadInitThunk

modules:
00400000 IncardexDesigner.exe 1.6.10.122 C:\Program Files (x86)\Mars
Systems\Incardex
03be0000 icProtect.dll 1.6.0.79 C:\Program Files (x86)\Mars
Systems\Incardex
06ca0000 icProject.dll 1.6.2.138 C:\Program Files (x86)\Mars
Systems\Incardex
083e0000 icPreview.dll 1.6.0.137 C:\Program Files (x86)\Mars
Systems\Incardex
09d30000 barcodex.ocx 5.4.0.177 C:\PROGRA~2\MARSSY~1\Incardex
09ed0000 pdf417enc.dll C:\Program Files (x86)\Mars
Systems\Incardex
10000000 idmmkb.dll 6.19.9.1 C:\Program Files (x86)\Internet
Download Manager
602c0000 GrooveIntlResource.dll 15.0.4907.1000
C:\PROGRA~2\MICROS~2\Office15\1033
60b40000 ATL100.DLL 10.0.40219.325 C:\Windows\SYSTEM32
60b70000 GROOVEEX.DLL 15.0.4907.1000 C:\PROGRA~2\MICROS~2\Office15
614d0000 SearchFolder.dll 6.3.9600.17415 C:\Windows\system32
615d0000 StructuredQuery.dll 7.0.9600.18334 C:\Windows\System32
69b10000 msxml4.dll 4.20.9818.0 C:\Windows\SYSTEM32
6cd80000 thumbcache.dll 6.3.9600.17415 C:\Windows\SYSTEM32
6ced0000 actxprxy.dll 6.3.9600.18460 C:\Windows\SYSTEM32
707d0000 WindowsCodecs.dll 6.3.9600.18302 C:\Windows\SYSTEM32
70d30000 mssprxy.dll 7.0.9600.17415 C:\Windows\system32
70d40000 atlthunk.dll 6.3.9600.17670 C:\Windows\SYSTEM32
70e60000 MSVCR100.dll 10.0.40219.325 C:\Windows\SYSTEM32
70f20000 msado15.dll 6.3.9600.17415 C:\Program Files (x86)\Common
Files\System\ado
72860000 ntshrui.dll 6.3.9600.18458 C:\Windows\SYSTEM32
72d50000 urlmon.dll 11.0.9600.18500 C:\Windows\SYSTEM32
72ea0000 PROPSYS.dll 7.0.9600.17415 C:\Windows\SYSTEM32
73000000 MSVCP100.dll 10.0.40219.325 C:\Windows\SYSTEM32
73170000 MSDART.DLL 6.3.9600.17415 C:\Windows\SYSTEM32
73190000 oleacc.dll 7.2.9600.17415 C:\Windows\SYSTEM32
731e0000 tiptsf.dll 6.3.9600.17415 C:\Program Files (x86)\Common
Files\microsoft shared\ink
73260000 uxtheme.dll 6.3.9600.17415 C:\Windows\system32
73420000 cscapi.dll 6.3.9600.17415 C:\Windows\SYSTEM32
73430000 olepro32.dll 6.3.9600.18227 C:\Windows\SYSTEM32
734e0000 msimg32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
73790000 gdiplus.dll 6.3.9600.18468
C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.18470_non
e_dadee7b65bc6429b
73920000 dwmapi.dll 6.3.9600.17415 C:\Windows\system32
73bd0000 sxs.dll 6.3.9600.17415 C:\Windows\SYSTEM32
73cf0000 srvcli.dll 6.3.9600.17415 C:\Windows\SYSTEM32
740c0000 apphelp.dll 6.3.9600.17415 C:\Windows\SYSTEM32
741a0000 iertutil.dll 11.0.9600.18500 C:\Windows\SYSTEM32
743e0000 wininet.dll 11.0.9600.18500 C:\Windows\SYSTEM32
74740000 comctl32.dll 6.10.9600.18006
C:\Windows\WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.9600.18006_none_a9ec6aab013aafee
74950000 SHCORE.DLL 6.3.9600.17666 C:\Windows\SYSTEM32
74ab0000 msi.dll 5.0.9600.17415 C:\Windows\SYSTEM32
74e70000 bcrypt.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74e90000 rsaenh.dll 6.3.9600.18191 C:\Windows\system32
74ec0000 CRYPTSP.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74ee0000 kernel.appcore.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74ef0000 wsock32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74f00000 version.dll 6.3.9600.17415 C:\Windows\SYSTEM32
750e0000 WINMMBASE.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75130000 winmm.dll 6.3.9600.17415 C:\Windows\SYSTEM32
751f0000 DEVOBJ.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75220000 profapi.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75230000 winspool.drv 6.3.9600.17415 C:\Windows\SYSTEM32
752a0000 USERENV.dll 6.3.9600.17415 C:\Windows\SYSTEM32
752c0000 bcryptPrimitives.dll 6.3.9600.18344 C:\Windows\SYSTEM32
75320000 CRYPTBASE.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75330000 user32.dll 6.3.9600.18439 C:\Windows\SYSTEM32
75490000 gdi32.dll 6.3.9600.18344 C:\Windows\SYSTEM32
757b0000 combase.dll 6.3.9600.18202 C:\Windows\SYSTEM32
75930000 cfgmgr32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75970000 comdlg32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75a10000 ole32.dll 6.3.9600.18403 C:\Windows\SYSTEM32
75b40000 sechost.dll 6.3.9600.17734 C:\Windows\SYSTEM32
75ba0000 SspiCli.dll 6.3.9600.18454 C:\Windows\SYSTEM32
75c50000 imm32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75ca0000 clbcatq.dll 2001.12.10530.17415 C:\Windows\SYSTEM32
75ea0000 msvcrt.dll 7.0.9600.17415 C:\Windows\SYSTEM32
75f70000 MSCTF.dll 6.3.9600.17664 C:\Windows\SYSTEM32
76090000 KERNELBASE.dll 6.3.9600.18264 C:\Windows\SYSTEM32
76180000 shell32.dll 6.3.9600.18458 C:\Windows\SYSTEM32
77480000 SHLWAPI.dll 6.3.9600.17415 C:\Windows\SYSTEM32
774d0000 SETUPAPI.dll 6.3.9600.17415 C:\Windows\SYSTEM32
77690000 KERNEL32.DLL 6.3.9600.17415 C:\Windows\SYSTEM32
77830000 oleaut32.dll 6.3.9600.18434 C:\Windows\SYSTEM32
778d0000 WS2_32.dll 6.3.9600.18340 C:\Windows\SYSTEM32
77920000 advapi32.dll 6.3.9600.18155 C:\Windows\SYSTEM32
779a0000 RPCRT4.dll 6.3.9600.18292 C:\Windows\SYSTEM32
77a60000 NSI.dll 6.3.9600.17415 C:\Windows\SYSTEM32
77b40000 ntdll.dll 6.3.9600.18233 C:\Windows\SYSTEM32

processes:
0000 Idle 0
0004 System 0
016c smss.exe 0
01fc csrss.exe 0
0260 wininit.exe 0
0270 csrss.exe 1
029c winlogon.exe 1
02cc services.exe 0
02dc lsass.exe 0
0330 svchost.exe 0
0360 svchost.exe 0
03c0 dwm.exe 1
03f0 atiesrxx.exe 0
0188 svchost.exe 0
01c0 svchost.exe 0
01f0 svchost.exe 0
0218 atieclxx.exe 1
0238 svchost.exe 0
04cc svchost.exe 0
04ec svchost.exe 0
0590 spoolsv.exe 0
0640 FI_Eject.exe 0
06b0 ChgService.exe 0
06d0 svchost.exe 0
06e4 dasHost.exe 0
0708 ENAgent.exe 0
072c HWDeviceService64.exe 0
0770 FrameworkService.exe 0
07a4 VsTskMgr.exe 0
07c4 mfevtps.exe 0
07e0 mfeann.exe 0
07f8 conhost.exe 0
066c naPrdMgr.exe 0
07d4 ouc.exe 0
0690 NitroPDFDriverService8x64.exe 0
0820 nlssrv32.exe 0
086c scsiaccess.exe 0
087c SOFTFO~1.EXE 0
08c8 svchost.exe 0
0944 WEBCAC~1.EXE 0
0988 WifiService.exe 0
09b4 escsvc64.exe 0
09d0 mcshield.exe 0
09bc svchost.exe 0
09ec svchost.exe 0
0f80 SM?RTP.exe 1
0f8c taskhostex.exe 1 normal
04a4 explorer.exe 1 normal
0174 DCSHelper.exe 1 normal C:\ProgramData\DatacardService
10c0 TabTip.exe 1
1100 TabTip32.exe 1
117c SearchIndexer.exe 0
128c AMDQuickStream.exe 1 normal
1294 IDMan.exe 1 normal C:\Program Files (x86)\Internet
Download Manager
12a4 E_YATII2E.EXE 1 normal
12ac E_IATIFEP.EXE 1 normal
12d0 laragon.exe 1 normal C:\laragon
12f4 UdaterUI.exe 1 normal C:\Program Files (x86)\McAfee\Common
Framework
132c EEventManager.exe 1 normal C:\Program Files (x86)\Epson
Software\Event Manager
1334 jusched.exe 1 normal C:\Program Files (x86)\Common
Files\Java\Java Update
1340 WSHelper.exe 1 normal C:\Program Files (x86)\Common
Files\Wondershare\Wondershare Helper Compact
1358 MOM.exe 1 normal
06d8 McTray.exe 1 normal C:\Program Files (x86)\McAfee\Common
Framework
0918 CCC.exe 1 normal
0a30 IEMonitor.exe 1 normal C:\Program Files (x86)\Internet
Download Manager
0a38 SHSTAT.EXE 1 normal C:\Program Files (x86)\McAfee\VirusScan
Enterprise
1038 NASvc.exe 0
0fc4 GoogleCrashHandler.exe 0
0f00 GoogleCrashHandler64.exe 0
12f0 wmpnetwk.exe 0
0d9c SmadavProtect64.exe 1
0c58 EXCEL.EXE 1 normal C:\Program Files (x86)\Microsoft
Office\Office15
06f8 php-cgi.exe 1 normal
0a7c conhost.exe 1 normal
1390 dllhost.exe 0
1018 audiodg.exe 0
13fc IncardexDesigner.exe 1 normal C:\Program Files (x86)\Mars
Systems\Incardex
0bb4 EXCEL.EXE 1 normal C:\Program Files (x86)\Microsoft
Office\Office15
0b10 SearchProtocolHost.exe 0
0f54 SearchFilterHost.exe 0

hardware:
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
- \\RPIIL-PC\EPSON L210 Series
- EPSON T1100 Series (Copy 1)
- Fax
- Microsoft XPS Document Writer
- Nitro PDF Creator (Pro 8)
- Root Print Queue
- Send To OneNote 2013
- Softfoundry Virtual Printer
+ {36fc9e60-c465-11cf-8056-444553540000}
- AMD USB 3.0 eXtensible Host Controller - 0100 (Microsoft)
- HUAWEI Mobile Connect - Bus Enumerate Device (driver 2.6.2.1605)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- Standard OpenHCD USB Host Controller
- Standard OpenHCD USB Host Controller
- USB Composite Device
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub (xHCI)
+ {4d36e966-e325-11ce-bfc1-08002be10318}
- ACPI x64-based PC
+ {4d36e967-e325-11ce-bfc1-08002be10318}
- TOSHIBA MQ01ABF050
+ {4d36e968-e325-11ce-bfc1-08002be10318}
- AMD Radeon HD 8250 (driver 13.152.1.3000)
- Softfoundry Display Mirror Device (driver 2-4-2010)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
- Standard SATA AHCI Controller
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
- Standard PS/2 Keyboard
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
- AMD High Definition Audio Device (driver 9.0.0.9902)
- AnvSoft Virtual Sound Device (driver 1.2.0.0)
- High Definition Audio Device
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
- Generic PnP Monitor
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
- HID-compliant mouse
- PS/2 Compatible Mouse
+ {4d36e972-e325-11ce-bfc1-08002be10318}
- Bluetooth Device (Personal Area Network)
- Qualcomm Atheros AR956x Wireless Network Adapter
- VirtualBox Host-Only Ethernet Adapter (driver 5.0.12.0)
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
- Microsoft Storage Spaces Controller
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Power Button
- ACPI Sleep Button
- ACPI Thermal Zone
- ACPI Thermal Zone
- AMD SMBus (driver 5.12.0.31)
- Composite Bus Enumerator
- Direct memory access controller
- High Definition Audio Controller
- High Definition Audio Controller
- High precision event timer
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft Basic Display Driver
- Microsoft Basic Render Driver
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator
- Microsoft Windows Management Interface for ACPI
- Microsoft Windows Management Interface for ACPI
- Motherboard resources
- Motherboard resources
- Motherboard resources
- NDIS Virtual Network Adapter Enumerator
- Numeric data processor
- PCI Express Root Complex
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- Plug and Play Software Device Enumerator
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- System board
- System CMOS/real time clock
- System speaker
- System timer
- UMBus Root Bus Enumerator
- Volume Manager
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
- AMD A6-1450 APU with Radeon(TM) HD Graphics
- AMD A6-1450 APU with Radeon(TM) HD Graphics
- AMD A6-1450 APU with Radeon(TM) HD Graphics
- AMD A6-1450 APU with Radeon(TM) HD Graphics
+ {533c5b84-ec70-11d2-9505-00c04f79deaf}
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
+ {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
- Microsoft Device Association Root Enumerator
- Microsoft IPv4 IPv6 Transition Adapter Bus
- Microsoft RRAS Root Enumerator
- STUDIO6SMK: multimedia:
+ {6bdd1fc6-810f-11d0-bec7-08002be2092f}
- HD WebCam
+ {72631e54-78a4-11d0-bcf7-00aa00b7b32a}
- Microsoft AC Adapter
- Microsoft ACPI-Compliant Control Method Battery
+ {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
- HID-compliant system controller
- HID-compliant touch screen
- HID-compliant vendor-defined device
- HID-compliant vendor-defined device
- USB Input Device
- USB Input Device
+ {a0a588a4-c46f-4b37-b7ea-c82fe89870c6}
- SDA Standard Compliant SD Host Controller
+ {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
- Microphone (High Definition Audio Device)
- Speakers (AnvSoft Virtual Sound Device)
- Speakers (High Definition Audio Device)
+ {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
- Generic Bluetooth Adapter
- Microsoft Bluetooth Enumerator
- Microsoft Bluetooth LE Enumerator

cpu registers:
eax = 06f05520
ebx = 800ac472
ecx = 00000000
edx = 06e1a629
esi = 06e1a629
edi = 06f0d814
eip = 06e1a629
esp = 0018f5f4
ebp = 0018f658

stack dump:
0018f5f4 29 a6 e1 06 de fa ed 0e - 01 00 00 00 07 00 00 00 )...............
0018f604 08 f6 18 00 29 a6 e1 06 - 20 55 f0 06 72 c4 0a 80 ....)....U..r...
0018f614 29 a6 e1 06 14 d8 f0 06 - 58 f6 18 00 24 f6 18 00 ).......X...$...
0018f624 64 f6 18 00 54 46 ca 06 - 58 f6 18 00 14 d8 f0 06 d...TF..X.......
0018f634 14 d8 f0 06 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f644 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f654 00 00 00 00 78 f6 18 00 - 63 70 ca 06 29 a6 e1 06 ....x...cp..)...
0018f664 c0 f6 18 00 54 46 ca 06 - 78 f6 18 00 14 d8 f0 06 ....TF..x.......
0018f674 00 00 00 00 d4 f6 18 00 - d9 9b e1 06 00 d8 f0 06 ................
0018f684 8a b9 d9 06 14 d8 f0 06 - 01 d8 f0 06 5f 9c e1 06 ............_...
0018f694 d0 c6 ef 06 7c d1 f0 06 - 39 31 d1 06 fc 8c 2b 00 ....|...91....+.
0018f6a4 78 47 4b 00 d0 c6 ef 06 - 40 2f d1 06 00 00 00 00 xGK.....@/......
0018f6b4 78 47 4b 00 54 c2 ef 06 - 4e 41 d1 06 f0 f6 18 00 xGK.T...NA......
0018f6c4 54 46 ca 06 d4 f6 18 00 - 94 0d f0 01 d0 c6 ef 06 TF..............
0018f6d4 e8 f6 18 00 87 3e ca 06 - 80 8f e2 06 54 c2 ef 06 .....>......T...
0018f6e4 54 c2 ef 06 0c f7 18 00 - fb 84 d6 06 40 f7 18 00 T...........@...
0018f6f4 74 44 ca 06 0c f7 18 00 - fc 8c 2b 00 78 47 4b 00 tD........+.xGK.
0018f704 54 c2 ef 06 54 c2 ef 06 - 30 f7 18 00 61 83 d6 06 T...T...0...a...
0018f714 8c c3 2b 00 68 42 ca 06 - 01 f7 18 00 54 c2 ef 06 ..+.hB......T...
0018f724 6f 83 d6 06 54 c2 ef 06 - 5c f7 18 00 5c f7 18 00 o...T...\...\...

disassembling:
06e28f68 public iD_DBStructure.TformDB.FormDestroy: ; function entry point
06e28f68 1933 push ebp
06e28f69 mov ebp, esp
06e28f6b add esp, -8
06e28f6e mov [ebp-8], edx
06e28f71 mov [ebp-4], eax
06e28f74 1934 mov eax, [$6e52204]
06e28f79 mov eax, [eax]
06e28f7b > call -$185104 ($6ca3e7c) ; System.TObject.Free
06e28f7b
06e28f80 1935 pop ecx
06e28f81 pop ecx
06e28f82 pop ebp
06e28f83 ret

date/time : 2017-10-01, 22:47:49, 72ms


computer name : STUDIO6SMK
user name : multimedia
registered owner : multimedia
operating system : Windows NT New Tablet PC x64 build 9200
system language : English
system up time : 36 minutes 20 seconds
program up time : 2 seconds
processors : 4x AMD A6-1450 APU with Radeon(TM) HD Graphics
physical memory : 4057/5579 MB (free/total)
free disk space : (C:) 23,54 GB
display mode : 1366x768, 32 bit
process id : $868
allocated memory : 51,06 MB
executable : IncardexProducer.exe
exec. date/time : 2016-03-26 00:53
version : 1.6.10.146
compiled with : Delphi 7
madExcept version : 3.0g
callstack crc : $760a4357, $4a4ad93c, $024f24fd
exception number : 1
exception class : EAccessViolation
exception message : Access violation at address 760A4357 in module
'KERNELBASE.dll'. Read of address 0000007B.

main thread ($a54):


760a4357 +000 KERNELBASE.dll
711fb810 +170 wiadss.dll LoadImportDS
71099061 +181 twain_32.dll DSM_Entry
005f317b +063 IncardexProducer.exe AcquireImage 555 +4
TAcquireImage.CloseTwainSession
006087fc +0b0 IncardexProducer.exe ip_main 2266 +13
TformMain.UpdateImgSources
00609037 +00f IncardexProducer.exe ip_main 2436 +1
TformMain.timerTWAINrefreshTimer
004895d7 +00f IncardexProducer.exe ExtCtrls TTimer.Timer
004894bb +02b IncardexProducer.exe ExtCtrls TTimer.WndProc
00474e30 +014 IncardexProducer.exe Classes StdWndProc
75365d3b +00b user32.dll DispatchMessageA
004dc403 +083 IncardexProducer.exe Forms
TApplication.ProcessMessage
004dc43a +00a IncardexProducer.exe Forms
TApplication.HandleMessage
004dc66a +096 IncardexProducer.exe Forms TApplication.Run
00611be7 +35b IncardexProducer.exe IncardexProducer 164 +70 initialization
776a7c02 +022 KERNEL32.DLL BaseThreadInitThunk

thread $d2c:
760a28bd +000 KERNELBASE.dll WaitForMultipleObjectsEx
7533de8d +15d user32.dll MsgWaitForMultipleObjectsEx
7533dbda +01a user32.dll MsgWaitForMultipleObjects
776a7c02 +022 KERNEL32.DLL BaseThreadInitThunk

thread $458 (TEventWaitThread):


760a28bd +000 KERNELBASE.dll WaitForMultipleObjectsEx
776a7b83 +013 KERNEL32.DLL WaitForMultipleObjects
0053c802 +02a IncardexProducer.exe reinit 551 +3 TEventWaitThread.Execute
0044ec53 +02b IncardexProducer.exe madExcept HookedTThreadExecute
00473238 +034 IncardexProducer.exe Classes ThreadProc
00404da0 +028 IncardexProducer.exe System ThreadWrapper
0044eb35 +00d IncardexProducer.exe madExcept CallThreadProcSafe
0044eb9f +037 IncardexProducer.exe madExcept ThreadExceptFrame
776a7c02 +022 KERNEL32.DLL BaseThreadInitThunk
>> created by main thread ($a54) at:
00604253 +427 IncardexProducer.exe ip_main 1102 +91 TformMain.FormCreate

thread $89c:
776a7c02 +22 KERNEL32.DLL BaseThreadInitThunk

thread $f54:
776a7c02 +22 KERNEL32.DLL BaseThreadInitThunk

thread $10cc:
760a28bd +00 KERNELBASE.dll WaitForMultipleObjectsEx
0044eb35 +0d IncardexProducer.exe madExcept CallThreadProcSafe
0044eb9f +37 IncardexProducer.exe madExcept ThreadExceptFrame
776a7c02 +22 KERNEL32.DLL BaseThreadInitThunk
>> created by main thread ($a54) at:
757f9e7e +00 combase.dll

modules:
00400000 IncardexProducer.exe 1.6.10.146 C:\Program Files (x86)\Mars
Systems\Incardex
03d30000 icProtect.dll 1.6.0.79 C:\Program Files (x86)\Mars
Systems\Incardex
06d20000 ProcessImageWin.dll 1.6.0.100 C:\Program Files (x86)\Mars
Systems\Incardex
08220000 icProject.dll 1.6.2.138 C:\Program Files (x86)\Mars
Systems\Incardex
099f0000 icPreview.dll 1.6.0.137 C:\Program Files (x86)\Mars
Systems\Incardex
0afa0000 icWDM.dll 1.6.0.98 C:\Program Files (x86)\Mars
Systems\Incardex
0c500000 icFingerprint.dll 1.6.0.100 C:\Program Files (x86)\Mars
Systems\Incardex
0c5e0000 ftrScanAPI.DLL 6.7.1.1 C:\Program Files (x86)\Mars
Systems\Incardex
0dd30000 idmmkb.dll 6.19.9.1 C:\Program Files (x86)\Internet
Download Manager
10000000 WDMLib.dll 0.9.0.2 C:\Program Files (x86)\Mars
Systems\Incardex
69b10000 msxml4.dll 4.20.9818.0 C:\Windows\SYSTEM32
70f20000 msado15.dll 6.3.9600.17415 C:\Program Files (x86)\Common
Files\System\ado
71090000 twain_32.dll 1.7.1.3 C:\Windows
711a0000 wiatrace.dll 6.3.9600.17415 C:\Windows\SYSTEM32
711b0000 sti.dll 6.3.9600.17415 C:\Windows\SYSTEM32
711f0000 wiadss.dll 6.3.9600.17415 C:\Windows\system32
72d50000 urlmon.dll 11.0.9600.18500 C:\Windows\SYSTEM32
73170000 MSDART.DLL 6.3.9600.17415 C:\Windows\SYSTEM32
731e0000 tiptsf.dll 6.3.9600.17415 C:\Program Files (x86)\Common
Files\microsoft shared\ink
73260000 uxtheme.dll 6.3.9600.17415 C:\Windows\system32
73430000 olepro32.dll 6.3.9600.18227 C:\Windows\SYSTEM32
734e0000 msimg32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
73790000 gdiplus.dll 6.3.9600.18468
C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.18470_non
e_dadee7b65bc6429b
73920000 dwmapi.dll 6.3.9600.17415 C:\Windows\system32
740c0000 apphelp.dll 6.3.9600.17415 C:\Windows\SYSTEM32
741a0000 iertutil.dll 11.0.9600.18500 C:\Windows\SYSTEM32
743e0000 wininet.dll 11.0.9600.18500 C:\Windows\SYSTEM32
74740000 comctl32.dll 6.10.9600.18006
C:\Windows\WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.9600.18006_none_a9ec6aab013aafee
74950000 SHCORE.DLL 6.3.9600.17666 C:\Windows\SYSTEM32
74e70000 bcrypt.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74e90000 rsaenh.dll 6.3.9600.18191 C:\Windows\system32
74ec0000 CRYPTSP.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74ee0000 kernel.appcore.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74ef0000 wsock32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74f00000 version.dll 6.3.9600.17415 C:\Windows\SYSTEM32
750e0000 WINMMBASE.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75130000 winmm.dll 6.3.9600.17415 C:\Windows\SYSTEM32
751f0000 DEVOBJ.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75220000 profapi.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75230000 winspool.drv 6.3.9600.17415 C:\Windows\SYSTEM32
752a0000 USERENV.dll 6.3.9600.17415 C:\Windows\SYSTEM32
752c0000 bcryptPrimitives.dll 6.3.9600.18344 C:\Windows\SYSTEM32
75320000 CRYPTBASE.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75330000 user32.dll 6.3.9600.18439 C:\Windows\SYSTEM32
75490000 gdi32.dll 6.3.9600.18344 C:\Windows\SYSTEM32
757b0000 combase.dll 6.3.9600.18202 C:\Windows\SYSTEM32
75930000 cfgmgr32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75970000 comdlg32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75a10000 ole32.dll 6.3.9600.18403 C:\Windows\SYSTEM32
75b40000 sechost.dll 6.3.9600.17734 C:\Windows\SYSTEM32
75ba0000 SspiCli.dll 6.3.9600.18454 C:\Windows\SYSTEM32
75c50000 imm32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75ca0000 clbcatq.dll 2001.12.10530.17415 C:\Windows\SYSTEM32
75ea0000 msvcrt.dll 7.0.9600.17415 C:\Windows\SYSTEM32
75f70000 MSCTF.dll 6.3.9600.17664 C:\Windows\SYSTEM32
76090000 KERNELBASE.dll 6.3.9600.18264 C:\Windows\SYSTEM32
76180000 shell32.dll 6.3.9600.18458 C:\Windows\SYSTEM32
77480000 SHLWAPI.dll 6.3.9600.17415 C:\Windows\SYSTEM32
77690000 KERNEL32.DLL 6.3.9600.17415 C:\Windows\SYSTEM32
77830000 oleaut32.dll 6.3.9600.18434 C:\Windows\SYSTEM32
778d0000 WS2_32.dll 6.3.9600.18340 C:\Windows\SYSTEM32
77920000 advapi32.dll 6.3.9600.18155 C:\Windows\SYSTEM32
779a0000 RPCRT4.dll 6.3.9600.18292 C:\Windows\SYSTEM32
77a60000 NSI.dll 6.3.9600.17415 C:\Windows\SYSTEM32
77b40000 ntdll.dll 6.3.9600.18233 C:\Windows\SYSTEM32

processes:
0000 Idle 0
0004 System 0
016c smss.exe 0
01fc csrss.exe 0
0260 wininit.exe 0
0270 csrss.exe 1
029c winlogon.exe 1
02cc services.exe 0
02dc lsass.exe 0
0330 svchost.exe 0
0360 svchost.exe 0
03c0 dwm.exe 1
03f0 atiesrxx.exe 0
0188 svchost.exe 0
01c0 svchost.exe 0
01f0 svchost.exe 0
0218 atieclxx.exe 1
0238 svchost.exe 0
04cc svchost.exe 0
04ec svchost.exe 0
0590 spoolsv.exe 0
0640 FI_Eject.exe 0
06b0 ChgService.exe 0
06d0 svchost.exe 0
06e4 dasHost.exe 0
0708 ENAgent.exe 0
072c HWDeviceService64.exe 0
0770 FrameworkService.exe 0
07a4 VsTskMgr.exe 0
07c4 mfevtps.exe 0
07e0 mfeann.exe 0
07f8 conhost.exe 0
066c naPrdMgr.exe 0
07d4 ouc.exe 0
0690 NitroPDFDriverService8x64.exe 0
0820 nlssrv32.exe 0
086c scsiaccess.exe 0
087c SOFTFO~1.EXE 0
08c8 svchost.exe 0
0944 WEBCAC~1.EXE 0
0988 WifiService.exe 0
09b4 escsvc64.exe 0
09d0 mcshield.exe 0
09bc svchost.exe 0
09ec svchost.exe 0
0f80 SM?RTP.exe 1
0f8c taskhostex.exe 1 normal
04a4 explorer.exe 1 normal
0174 DCSHelper.exe 1 normal C:\ProgramData\DatacardService
10c0 TabTip.exe 1
1100 TabTip32.exe 1
117c SearchIndexer.exe 0
128c AMDQuickStream.exe 1 normal
1294 IDMan.exe 1 normal C:\Program Files (x86)\Internet
Download Manager
12a4 E_YATII2E.EXE 1 normal
12ac E_IATIFEP.EXE 1 normal
12d0 laragon.exe 1 normal C:\laragon
12f4 UdaterUI.exe 1 normal C:\Program Files (x86)\McAfee\Common
Framework
132c EEventManager.exe 1 normal C:\Program Files (x86)\Epson
Software\Event Manager
1334 jusched.exe 1 normal C:\Program Files (x86)\Common
Files\Java\Java Update
1340 WSHelper.exe 1 normal C:\Program Files (x86)\Common
Files\Wondershare\Wondershare Helper Compact
1358 MOM.exe 1 normal
06d8 McTray.exe 1 normal C:\Program Files (x86)\McAfee\Common
Framework
0918 CCC.exe 1 normal
0a30 IEMonitor.exe 1 normal C:\Program Files (x86)\Internet
Download Manager
0a38 SHSTAT.EXE 1 normal C:\Program Files (x86)\McAfee\VirusScan
Enterprise
1038 NASvc.exe 0
0fc4 GoogleCrashHandler.exe 0
0f00 GoogleCrashHandler64.exe 0
12f0 wmpnetwk.exe 0
0d9c SmadavProtect64.exe 1
0c58 EXCEL.EXE 1 normal C:\Program Files (x86)\Microsoft
Office\Office15
06f8 php-cgi.exe 1 normal
0a7c conhost.exe 1 normal
1390 dllhost.exe 0
1018 audiodg.exe 0
0bb4 EXCEL.EXE 1 normal C:\Program Files (x86)\Microsoft
Office\Office15
0b10 SearchProtocolHost.exe 0
0fdc SearchFilterHost.exe 0
0538 EXCEL.EXE 1 normal C:\Program Files (x86)\Microsoft
Office\Office15
0678 splwow64.exe 1 normal
0f24 svchost.exe 0
0868 IncardexProducer.exe 1 normal C:\Program Files (x86)\Mars
Systems\Incardex

hardware:
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
- \\RPIIL-PC\EPSON L210 Series
- EPSON L210 Series (Copy 1)
- EPSON T1100 Series (Copy 1)
- Fax
- Microsoft XPS Document Writer
- Nitro PDF Creator (Pro 8)
- Root Print Queue
- Send To OneNote 2013
- Softfoundry Virtual Printer
+ {36fc9e60-c465-11cf-8056-444553540000}
- AMD USB 3.0 eXtensible Host Controller - 0100 (Microsoft)
- HUAWEI Mobile Connect - Bus Enumerate Device (driver 2.6.2.1605)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- Standard OpenHCD USB Host Controller
- Standard OpenHCD USB Host Controller
- USB Composite Device
- USB Composite Device
- USB Printing Support
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub (xHCI)
+ {4d36e966-e325-11ce-bfc1-08002be10318}
- ACPI x64-based PC
+ {4d36e967-e325-11ce-bfc1-08002be10318}
- TOSHIBA MQ01ABF050
+ {4d36e968-e325-11ce-bfc1-08002be10318}
- AMD Radeon HD 8250 (driver 13.152.1.3000)
- Softfoundry Display Mirror Device (driver 2-4-2010)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
- Standard SATA AHCI Controller
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
- Standard PS/2 Keyboard
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
- AMD High Definition Audio Device (driver 9.0.0.9902)
- AnvSoft Virtual Sound Device (driver 1.2.0.0)
- High Definition Audio Device
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
- Generic PnP Monitor
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
- HID-compliant mouse
- PS/2 Compatible Mouse
+ {4d36e972-e325-11ce-bfc1-08002be10318}
- Bluetooth Device (Personal Area Network)
- Qualcomm Atheros AR956x Wireless Network Adapter
- VirtualBox Host-Only Ethernet Adapter (driver 5.0.12.0)
+ {4d36e979-e325-11ce-bfc1-08002be10318}
- EPSON L210 Series (driver 1.54.0.0)
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
- Microsoft Storage Spaces Controller
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Power Button
- ACPI Sleep Button
- ACPI Thermal Zone
- ACPI Thermal Zone
- AMD SMBus (driver 5.12.0.31)
- Composite Bus Enumerator
- Direct memory access controller
- High Definition Audio Controller
- High Definition Audio Controller
- High precision event timer
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft Basic Display Driver
- Microsoft Basic Render Driver
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator
- Microsoft Windows Management Interface for ACPI
- Microsoft Windows Management Interface for ACPI
- Motherboard resources
- Motherboard resources
- Motherboard resources
- NDIS Virtual Network Adapter Enumerator
- Numeric data processor
- PCI Express Root Complex
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- Plug and Play Software Device Enumerator
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- System board
- System CMOS/real time clock
- System speaker
- System timer
- UMBus Root Bus Enumerator
- Volume Manager
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
- AMD A6-1450 APU with Radeon(TM) HD Graphics
- AMD A6-1450 APU with Radeon(TM) HD Graphics
- AMD A6-1450 APU with Radeon(TM) HD Graphics
- AMD A6-1450 APU with Radeon(TM) HD Graphics
+ {533c5b84-ec70-11d2-9505-00c04f79deaf}
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
+ {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
- Microsoft Device Association Root Enumerator
- Microsoft IPv4 IPv6 Transition Adapter Bus
- Microsoft RRAS Root Enumerator
- STUDIO6SMK: multimedia:
+ {6bdd1fc6-810f-11d0-bec7-08002be2092f}
- EPSON L210/L350 (driver 3.7.9.1)
- HD WebCam
+ {72631e54-78a4-11d0-bcf7-00aa00b7b32a}
- Microsoft AC Adapter
- Microsoft ACPI-Compliant Control Method Battery
+ {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
- HID-compliant system controller
- HID-compliant touch screen
- HID-compliant vendor-defined device
- HID-compliant vendor-defined device
- USB Input Device
- USB Input Device
+ {a0a588a4-c46f-4b37-b7ea-c82fe89870c6}
- SDA Standard Compliant SD Host Controller
+ {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
- Microphone (High Definition Audio Device)
- Speakers (AnvSoft Virtual Sound Device)
- Speakers (High Definition Audio Device)
+ {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
- Generic Bluetooth Adapter
- Microsoft Bluetooth Enumerator
- Microsoft Bluetooth LE Enumerator

cpu registers:
eax = 0000007b
ebx = ffffffff
ecx = 7fffffff
edx = 000000ff
esi = 0000007b
edi = 00000000
eip = 760a4357
esp = 0018f478
ebp = 0018f4b8

stack dump:
0018f478 01 00 00 00 08 00 00 00 - 01 00 00 00 00 00 00 00 ................
0018f488 00 00 00 00 00 00 00 00 - f4 f4 18 00 ff 00 00 00 ................
0018f498 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f4a8 00 00 00 00 00 00 00 00 - 00 00 00 00 29 52 95 2f ............)R./
0018f4b8 f8 f7 18 00 69 ac 1f 71 - 00 00 00 00 00 00 00 00 ....i..q........
0018f4c8 7b 00 00 00 ff ff ff ff - f4 f4 18 00 ff 00 00 00 {...............
0018f4d8 00 00 00 00 f0 ab 1f 71 - d8 8a 34 00 10 8b 2c 00 .......q..4...,.
0018f4e8 08 00 00 00 80 f8 18 00 - 01 00 00 00 00 00 00 00 ................
0018f4f8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f508 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f518 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f528 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f538 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f548 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f558 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f568 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f578 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f588 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f598 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f5a8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

disassembling:
[...]
005f316f push 0
005f3171 mov eax, [ebp-4]
005f3174 add eax, $44
005f3177 push eax
005f3178 mov eax, [ebp-4]
005f317b > call dword ptr [eax+$40]
005f317e 556 mov eax, [ebp-4]
005f3181 add eax, $184
005f3186 push eax
005f3187 push $302
005f318c push 4
[...]
date/time : 2017-10-01, 22:53:57, 456ms
computer name : STUDIO6SMK
user name : multimedia
registered owner : multimedia
operating system : Windows NT New Tablet PC x64 build 9200
system language : English
system up time : 5 minutes 9 seconds
program up time : 1 second
processors : 4x AMD A6-1450 APU with Radeon(TM) HD Graphics
physical memory : 4215/5579 MB (free/total)
free disk space : (C:) 23,63 GB
display mode : 1366x768, 32 bit
process id : $9f4
allocated memory : 50,76 MB
executable : IncardexProducer.exe
exec. date/time : 2016-03-26 00:53
version : 1.6.10.146
compiled with : Delphi 7
madExcept version : 3.0g
callstack crc : $75234357, $f11edb39, $b471f2f5
count : 6
exception number : 1
exception class : EAccessViolation
exception message : Access violation at address 75234357 in module
'KERNELBASE.dll'. Read of address 0000007B.

main thread ($edc):


75234357 +000 KERNELBASE.dll
722bb810 +170 wiadss.dll LoadImportDS
72199061 +181 twain_32.dll DSM_Entry
005f317b +063 IncardexProducer.exe AcquireImage 555 +4
TAcquireImage.CloseTwainSession
006087fc +0b0 IncardexProducer.exe ip_main 2266 +13
TformMain.UpdateImgSources
00609037 +00f IncardexProducer.exe ip_main 2436 +1
TformMain.timerTWAINrefreshTimer
004895d7 +00f IncardexProducer.exe ExtCtrls TTimer.Timer
004894bb +02b IncardexProducer.exe ExtCtrls TTimer.WndProc
00474e30 +014 IncardexProducer.exe Classes StdWndProc
75405d3b +00b user32.dll DispatchMessageA
004dc403 +083 IncardexProducer.exe Forms
TApplication.ProcessMessage
004dc43a +00a IncardexProducer.exe Forms
TApplication.HandleMessage
004dc66a +096 IncardexProducer.exe Forms TApplication.Run
00611be7 +35b IncardexProducer.exe IncardexProducer 164 +70 initialization
75e77c02 +022 KERNEL32.DLL BaseThreadInitThunk

thread $1348:
752328bd +000 KERNELBASE.dll WaitForMultipleObjectsEx
753dde8d +15d user32.dll MsgWaitForMultipleObjectsEx
753ddbda +01a user32.dll MsgWaitForMultipleObjects
75e77c02 +022 KERNEL32.DLL BaseThreadInitThunk

thread $da8 (TEventWaitThread):


752328bd +000 KERNELBASE.dll WaitForMultipleObjectsEx
75e77b83 +013 KERNEL32.DLL WaitForMultipleObjects
0053c802 +02a IncardexProducer.exe reinit 551 +3 TEventWaitThread.Execute
0044ec53 +02b IncardexProducer.exe madExcept HookedTThreadExecute
00473238 +034 IncardexProducer.exe Classes ThreadProc
00404da0 +028 IncardexProducer.exe System ThreadWrapper
0044eb35 +00d IncardexProducer.exe madExcept CallThreadProcSafe
0044eb9f +037 IncardexProducer.exe madExcept ThreadExceptFrame
75e77c02 +022 KERNEL32.DLL BaseThreadInitThunk
>> created by main thread ($edc) at:
00604253 +427 IncardexProducer.exe ip_main 1102 +91 TformMain.FormCreate

thread $a6c:
75e77c02 +22 KERNEL32.DLL BaseThreadInitThunk

thread $f8c:
75e77c02 +22 KERNEL32.DLL BaseThreadInitThunk

thread $c08:
752328bd +00 KERNELBASE.dll WaitForMultipleObjectsEx
0044eb35 +0d IncardexProducer.exe madExcept CallThreadProcSafe
0044eb9f +37 IncardexProducer.exe madExcept ThreadExceptFrame
75e77c02 +22 KERNEL32.DLL BaseThreadInitThunk
>> created by main thread ($edc) at:
75579e7e +00 combase.dll

modules:
00400000 IncardexProducer.exe 1.6.10.146 C:\Program Files (x86)\Mars
Systems\Incardex
03d30000 icProtect.dll 1.6.0.79 C:\Program Files (x86)\Mars
Systems\Incardex
06d20000 ProcessImageWin.dll 1.6.0.100 C:\Program Files (x86)\Mars
Systems\Incardex
08220000 icProject.dll 1.6.2.138 C:\Program Files (x86)\Mars
Systems\Incardex
09a70000 icPreview.dll 1.6.0.137 C:\Program Files (x86)\Mars
Systems\Incardex
0afa0000 icWDM.dll 1.6.0.98 C:\Program Files (x86)\Mars
Systems\Incardex
0c500000 icFingerprint.dll 1.6.0.100 C:\Program Files (x86)\Mars
Systems\Incardex
0c5e0000 ftrScanAPI.DLL 6.7.1.1 C:\Program Files (x86)\Mars
Systems\Incardex
0c720000 idmmkb.dll 6.19.9.1 C:\Program Files (x86)\Internet
Download Manager
10000000 WDMLib.dll 0.9.0.2 C:\Program Files (x86)\Mars
Systems\Incardex
69b10000 msxml4.dll 4.20.9818.0 C:\Windows\SYSTEM32
70b60000 msado15.dll 6.3.9600.17415 C:\Program Files (x86)\Common
Files\System\ado
72190000 twain_32.dll 1.7.1.3 C:\Windows
721a0000 MSDART.DLL 6.3.9600.17415 C:\Windows\SYSTEM32
72260000 wiatrace.dll 6.3.9600.17415 C:\Windows\SYSTEM32
72270000 sti.dll 6.3.9600.17415 C:\Windows\SYSTEM32
722b0000 wiadss.dll 6.3.9600.17415 C:\Windows\system32
72710000 msimg32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
72730000 urlmon.dll 11.0.9600.18500 C:\Windows\SYSTEM32
73240000 tiptsf.dll 6.3.9600.17415 C:\Program Files (x86)\Common
Files\microsoft shared\ink
732c0000 olepro32.dll 6.3.9600.18227 C:\Windows\SYSTEM32
732e0000 uxtheme.dll 6.3.9600.17415 C:\Windows\system32
73680000 gdiplus.dll 6.3.9600.18468
C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.18470_non
e_dadee7b65bc6429b
73810000 dwmapi.dll 6.3.9600.17415 C:\Windows\system32
73fb0000 apphelp.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74090000 iertutil.dll 11.0.9600.18500 C:\Windows\SYSTEM32
742d0000 wininet.dll 11.0.9600.18500 C:\Windows\SYSTEM32
74630000 SHCORE.DLL 6.3.9600.17666 C:\Windows\SYSTEM32
746d0000 comctl32.dll 6.10.9600.18006
C:\Windows\WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.9600.18006_none_a9ec6aab013aafee
74d60000 bcrypt.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74d80000 rsaenh.dll 6.3.9600.18191 C:\Windows\system32
74db0000 CRYPTSP.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74dd0000 kernel.appcore.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74de0000 wsock32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74df0000 version.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74fd0000 WINMMBASE.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75020000 winmm.dll 6.3.9600.17415 C:\Windows\SYSTEM32
750e0000 DEVOBJ.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75110000 profapi.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75120000 winspool.drv 6.3.9600.17415 C:\Windows\SYSTEM32
75190000 USERENV.dll 6.3.9600.17415 C:\Windows\SYSTEM32
751b0000 bcryptPrimitives.dll 6.3.9600.18344 C:\Windows\SYSTEM32
75210000 CRYPTBASE.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75220000 KERNELBASE.dll 6.3.9600.18264 C:\Windows\SYSTEM32
75310000 NSI.dll 6.3.9600.17415 C:\Windows\SYSTEM32
753b0000 SspiCli.dll 6.3.9600.18454 C:\Windows\SYSTEM32
753d0000 user32.dll 6.3.9600.18439 C:\Windows\SYSTEM32
75530000 combase.dll 6.3.9600.18202 C:\Windows\SYSTEM32
756b0000 ole32.dll 6.3.9600.18403 C:\Windows\SYSTEM32
757e0000 clbcatq.dll 2001.12.10530.17415 C:\Windows\SYSTEM32
75870000 gdi32.dll 6.3.9600.18344 C:\Windows\SYSTEM32
75980000 SHLWAPI.dll 6.3.9600.17415 C:\Windows\SYSTEM32
759f0000 imm32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75a20000 WS2_32.dll 6.3.9600.18340 C:\Windows\SYSTEM32
75ab0000 MSCTF.dll 6.3.9600.17664 C:\Windows\SYSTEM32
75e60000 KERNEL32.DLL 6.3.9600.17415 C:\Windows\SYSTEM32
75fa0000 sechost.dll 6.3.9600.17734 C:\Windows\SYSTEM32
75ff0000 cfgmgr32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
761b0000 comdlg32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
763e0000 advapi32.dll 6.3.9600.18155 C:\Windows\SYSTEM32
76460000 msvcrt.dll 7.0.9600.17415 C:\Windows\SYSTEM32
76530000 oleaut32.dll 6.3.9600.18434 C:\Windows\SYSTEM32
765d0000 shell32.dll 6.3.9600.18458 C:\Windows\SYSTEM32
778a0000 RPCRT4.dll 6.3.9600.18292 C:\Windows\SYSTEM32
77a30000 ntdll.dll 6.3.9600.18233 C:\Windows\SYSTEM32

processes:
0000 Idle 0
0004 System 0
016c smss.exe 0
021c csrss.exe 0
027c wininit.exe 0
028c csrss.exe 1
02b8 winlogon.exe 1
02dc services.exe 0
02e4 lsass.exe 0
0334 svchost.exe 0
035c svchost.exe 0
03c4 dwm.exe 1
03d4 atiesrxx.exe 0
010c svchost.exe 0
015c svchost.exe 0
0224 svchost.exe 0
0290 atieclxx.exe 1
02e8 svchost.exe 0
0488 svchost.exe 0
04b0 svchost.exe 0
05fc spoolsv.exe 0
0680 FI_Eject.exe 0
0694 ChgService.exe 0
06b4 svchost.exe 0
06c4 dasHost.exe 0
06d8 ENAgent.exe 0
0700 HWDeviceService64.exe 0
073c FrameworkService.exe 0
0764 VsTskMgr.exe 0
079c mfevtps.exe 0
07b8 mfeann.exe 0
07d0 conhost.exe 0
04e0 naPrdMgr.exe 0
06b0 ouc.exe 0
062c NitroPDFDriverService8x64.exe 0
07b0 nlssrv32.exe 0
0838 scsiaccess.exe 0
084c SOFTFO~1.EXE 0
088c svchost.exe 0
08bc WEBCAC~1.EXE 0
0944 WifiService.exe 0
0998 escsvc64.exe 0
09b4 mcshield.exe 0
0b28 WmiPrvSE.exe 0
0be4 svchost.exe 0
0870 svchost.exe 0
0dd4 taskhostex.exe 1 normal
0e60 SM?RTP.exe 1
0e74 explorer.exe 1 normal
0ebc DCSHelper.exe 1 normal C:\ProgramData\DatacardService
0fd4 TabTip.exe 1
0984 TabTip32.exe 1
0dfc SearchIndexer.exe 0
0fec SearchProtocolHost.exe 0
102c AMDQuickStream.exe 1 normal
1058 IDMan.exe 1 normal C:\Program Files (x86)\Internet
Download Manager
1070 E_YATII2E.EXE 1 normal
1080 E_IATIFEP.EXE 1 normal
10d8 IEMonitor.exe 1 normal C:\Program Files (x86)\Internet
Download Manager
10ec laragon.exe 1 normal C:\laragon
1108 UdaterUI.exe 1 normal C:\Program Files (x86)\McAfee\Common
Framework
115c McTray.exe 1 normal C:\Program Files (x86)\McAfee\Common
Framework
11f0 EEventManager.exe 1 normal C:\Program Files (x86)\Epson
Software\Event Manager
12dc jusched.exe 1 normal C:\Program Files (x86)\Common
Files\Java\Java Update
135c WSHelper.exe 1 normal C:\Program Files (x86)\Common
Files\Wondershare\Wondershare Helper Compact
13d0 MOM.exe 1 normal
0514 SHSTAT.EXE 1 normal C:\Program Files (x86)\McAfee\VirusScan
Enterprise
1188 CCC.exe 1 normal
0e98 audiodg.exe 0
0c60 GoogleCrashHandler.exe 0
0a54 GoogleCrashHandler64.exe 0
0e20 SmadavProtect64.exe 1
0abc svchost.exe 0
08f0 NASvc.exe 0
117c wmpnetwk.exe 0
0924 SearchFilterHost.exe 0
08cc WMIADAP.exe 0
09f4 IncardexProducer.exe 1 normal C:\Program Files (x86)\Mars
Systems\Incardex
06f0 dllhost.exe 1 normal

hardware:
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
- \\RPIIL-PC\EPSON L210 Series
- EPSON L210 Series (Copy 1)
- EPSON T1100 Series (Copy 1)
- Fax
- Microsoft XPS Document Writer
- Nitro PDF Creator (Pro 8)
- Root Print Queue
- Send To OneNote 2013
- Softfoundry Virtual Printer
+ {36fc9e60-c465-11cf-8056-444553540000}
- AMD USB 3.0 eXtensible Host Controller - 0100 (Microsoft)
- HUAWEI Mobile Connect - Bus Enumerate Device (driver 2.6.2.1605)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- Standard OpenHCD USB Host Controller
- Standard OpenHCD USB Host Controller
- USB Composite Device
- USB Composite Device
- USB Printing Support
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub (xHCI)
+ {4d36e966-e325-11ce-bfc1-08002be10318}
- ACPI x64-based PC
+ {4d36e967-e325-11ce-bfc1-08002be10318}
- TOSHIBA MQ01ABF050
+ {4d36e968-e325-11ce-bfc1-08002be10318}
- AMD Radeon HD 8250 (driver 13.152.1.3000)
- Softfoundry Display Mirror Device (driver 2-4-2010)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
- Standard SATA AHCI Controller
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
- Standard PS/2 Keyboard
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
- AMD High Definition Audio Device (driver 9.0.0.9902)
- AnvSoft Virtual Sound Device (driver 1.2.0.0)
- High Definition Audio Device
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
- Generic PnP Monitor
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
- HID-compliant mouse
- PS/2 Compatible Mouse
+ {4d36e972-e325-11ce-bfc1-08002be10318}
- Bluetooth Device (Personal Area Network)
- Qualcomm Atheros AR956x Wireless Network Adapter
- VirtualBox Host-Only Ethernet Adapter (driver 5.0.12.0)
+ {4d36e979-e325-11ce-bfc1-08002be10318}
- EPSON L210 Series (driver 1.54.0.0)
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
- Microsoft Storage Spaces Controller
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Power Button
- ACPI Sleep Button
- ACPI Thermal Zone
- ACPI Thermal Zone
- AMD SMBus (driver 5.12.0.31)
- Composite Bus Enumerator
- Direct memory access controller
- High Definition Audio Controller
- High Definition Audio Controller
- High precision event timer
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft Basic Display Driver
- Microsoft Basic Render Driver
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator
- Microsoft Windows Management Interface for ACPI
- Microsoft Windows Management Interface for ACPI
- Motherboard resources
- Motherboard resources
- Motherboard resources
- NDIS Virtual Network Adapter Enumerator
- Numeric data processor
- PCI Express Root Complex
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- Plug and Play Software Device Enumerator
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- System board
- System CMOS/real time clock
- System speaker
- System timer
- UMBus Root Bus Enumerator
- Volume Manager
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
- AMD A6-1450 APU with Radeon(TM) HD Graphics
- AMD A6-1450 APU with Radeon(TM) HD Graphics
- AMD A6-1450 APU with Radeon(TM) HD Graphics
- AMD A6-1450 APU with Radeon(TM) HD Graphics
+ {533c5b84-ec70-11d2-9505-00c04f79deaf}
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
+ {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
- Microsoft Device Association Root Enumerator
- Microsoft IPv4 IPv6 Transition Adapter Bus
- Microsoft RRAS Root Enumerator
- STUDIO6SMK: multimedia:
+ {6bdd1fc6-810f-11d0-bec7-08002be2092f}
- EPSON L210/L350 (driver 3.7.9.1)
- HD WebCam
+ {72631e54-78a4-11d0-bcf7-00aa00b7b32a}
- Microsoft AC Adapter
- Microsoft ACPI-Compliant Control Method Battery
+ {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant device
- HID-compliant system controller
- HID-compliant touch screen
- HID-compliant vendor-defined device
- HID-compliant vendor-defined device
- USB Input Device
- USB Input Device
+ {a0a588a4-c46f-4b37-b7ea-c82fe89870c6}
- SDA Standard Compliant SD Host Controller
+ {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
- Microphone (High Definition Audio Device)
- Speakers (AnvSoft Virtual Sound Device)
- Speakers (High Definition Audio Device)
+ {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
- Generic Bluetooth Adapter
- Microsoft Bluetooth Enumerator
- Microsoft Bluetooth LE Enumerator

cpu registers:
eax = 0000007b
ebx = ffffffff
ecx = 7fffffff
edx = 000000ff
esi = 0000007b
edi = 00000000
eip = 75234357
esp = 0018f478
ebp = 0018f4b8

stack dump:
0018f478 01 00 00 00 08 00 00 00 - 01 00 00 00 00 00 00 00 ................
0018f488 00 00 00 00 00 00 00 00 - f4 f4 18 00 ff 00 00 00 ................
0018f498 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f4a8 00 00 00 00 00 00 00 00 - 00 00 00 00 02 02 fc 71 ...............q
0018f4b8 f8 f7 18 00 69 ac 2b 72 - 00 00 00 00 00 00 00 00 ....i.+r........
0018f4c8 7b 00 00 00 ff ff ff ff - f4 f4 18 00 ff 00 00 00 {...............
0018f4d8 00 00 00 00 f0 ab 2b 72 - 58 73 89 00 18 8b 1f 00 ......+rXs......
0018f4e8 08 00 00 00 80 f8 18 00 - 01 00 00 00 00 00 00 00 ................
0018f4f8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f508 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f518 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f528 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f538 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f548 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f558 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f568 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f578 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f588 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f598 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f5a8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

disassembling:
[...]
005f316f push 0
005f3171 mov eax, [ebp-4]
005f3174 add eax, $44
005f3177 push eax
005f3178 mov eax, [ebp-4]
005f317b > call dword ptr [eax+$40]
005f317e 556 mov eax, [ebp-4]
005f3181 add eax, $184
005f3186 push eax
005f3187 push $302
005f318c push 4
[...]

date/time : 2017-10-08, 01:21:43, 610ms


computer name : STUDIO6SMK
user name : multimedia
registered owner : multimedia
operating system : Windows NT New Tablet PC x64 build 9200
system language : English
system up time : 6 days 2 hours
program up time : 1 second
processors : 4x AMD A6-1450 APU with Radeon(TM) HD Graphics
physical memory : 3618/5579 MB (free/total)
free disk space : (C:) 21,40 GB
display mode : 1366x768, 32 bit
process id : $2df0
allocated memory : 51,37 MB
executable : IncardexProducer.exe
exec. date/time : 2016-03-26 00:53
version : 1.6.10.146
compiled with : Delphi 7
madExcept version : 3.0g
callstack crc : $75e44357, $4ed831bb, $912a07e6
count : 7
exception number : 1
exception class : EAccessViolation
exception message : Access violation at address 75E44357 in module
'KERNELBASE.dll'. Read of address 0000007B.

main thread ($2d1c):


75e44357 +000 KERNELBASE.dll
7263b810 +170 wiadss.dll LoadImportDS
73df9061 +181 twain_32.dll DSM_Entry
005f317b +063 IncardexProducer.exe AcquireImage 555 +4
TAcquireImage.CloseTwainSession
006087fc +0b0 IncardexProducer.exe ip_main 2266 +13
TformMain.UpdateImgSources
00609037 +00f IncardexProducer.exe ip_main 2436 +1
TformMain.timerTWAINrefreshTimer
004895d7 +00f IncardexProducer.exe ExtCtrls TTimer.Timer
004894bb +02b IncardexProducer.exe ExtCtrls TTimer.WndProc
00474e30 +014 IncardexProducer.exe Classes StdWndProc
776a5d3b +00b user32.dll DispatchMessageA
004dc403 +083 IncardexProducer.exe Forms
TApplication.ProcessMessage
004dc43a +00a IncardexProducer.exe Forms
TApplication.HandleMessage
004dc66a +096 IncardexProducer.exe Forms TApplication.Run
00611be7 +35b IncardexProducer.exe IncardexProducer 164 +70 initialization
778a7c02 +022 KERNEL32.DLL BaseThreadInitThunk

thread $1dd4:
75e428bd +000 KERNELBASE.dll WaitForMultipleObjectsEx
7767de8d +15d user32.dll MsgWaitForMultipleObjectsEx
7767dbda +01a user32.dll MsgWaitForMultipleObjects
778a7c02 +022 KERNEL32.DLL BaseThreadInitThunk

thread $171c (TEventWaitThread):


75e428bd +000 KERNELBASE.dll WaitForMultipleObjectsEx
778a7b83 +013 KERNEL32.DLL WaitForMultipleObjects
0053c802 +02a IncardexProducer.exe reinit 551 +3 TEventWaitThread.Execute
0044ec53 +02b IncardexProducer.exe madExcept HookedTThreadExecute
00473238 +034 IncardexProducer.exe Classes ThreadProc
00404da0 +028 IncardexProducer.exe System ThreadWrapper
0044eb35 +00d IncardexProducer.exe madExcept CallThreadProcSafe
0044eb9f +037 IncardexProducer.exe madExcept ThreadExceptFrame
778a7c02 +022 KERNEL32.DLL BaseThreadInitThunk
>> created by main thread ($2d1c) at:
00604253 +427 IncardexProducer.exe ip_main 1102 +91 TformMain.FormCreate

thread $21d4:
778a7c02 +22 KERNEL32.DLL BaseThreadInitThunk

thread $2d70:
778a7c02 +22 KERNEL32.DLL BaseThreadInitThunk

thread $25c8:
75e428bd +00 KERNELBASE.dll WaitForMultipleObjectsEx
0044eb35 +0d IncardexProducer.exe madExcept CallThreadProcSafe
0044eb9f +37 IncardexProducer.exe madExcept ThreadExceptFrame
778a7c02 +22 KERNEL32.DLL BaseThreadInitThunk
>> created by main thread ($2d1c) at:
75bb9e7e +00 combase.dll

modules:
00400000 IncardexProducer.exe 1.6.10.146 C:\Program Files (x86)\Mars
Systems\Incardex
03e20000 icProtect.dll 1.6.0.79 C:\Program Files (x86)\Mars
Systems\Incardex
06cd0000 ProcessImageWin.dll 1.6.0.100 C:\Program Files (x86)\Mars
Systems\Incardex
08210000 icProject.dll 1.6.2.138 C:\Program Files (x86)\Mars
Systems\Incardex
09a40000 icPreview.dll 1.6.0.137 C:\Program Files (x86)\Mars
Systems\Incardex
0afe0000 icWDM.dll 1.6.0.98 C:\Program Files (x86)\Mars
Systems\Incardex
0c510000 icFingerprint.dll 1.6.0.100 C:\Program Files (x86)\Mars
Systems\Incardex
0c5f0000 ftrScanAPI.DLL 6.7.1.1 C:\Program Files (x86)\Mars
Systems\Incardex
0dd40000 idmmkb.dll 6.19.9.1 C:\Program Files (x86)\Internet
Download Manager
10000000 WDMLib.dll 0.9.0.2 C:\Program Files (x86)\Mars
Systems\Incardex
69b10000 msxml4.dll 4.20.9818.0 C:\Windows\SYSTEM32
71970000 msado15.dll 6.3.9600.17415 C:\Program Files (x86)\Common
Files\System\ado
72100000 MSDART.DLL 6.3.9600.17415 C:\Windows\SYSTEM32
725b0000 wiatrace.dll 6.3.9600.17415 C:\Windows\SYSTEM32
725c0000 sti.dll 6.3.9600.17415 C:\Windows\SYSTEM32
72630000 wiadss.dll 6.3.9600.17415 C:\Windows\system32
72e30000 oleacc.dll 7.2.9600.17415 C:\Windows\SYSTEM32
730a0000 tiptsf.dll 6.3.9600.17415 C:\Program Files (x86)\Common
Files\microsoft shared\ink
73120000 msimg32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
73180000 urlmon.dll 11.0.9600.18500 C:\Windows\SYSTEM32
732d0000 uxtheme.dll 6.3.9600.17415 C:\Windows\system32
73690000 gdiplus.dll 6.3.9600.18468
C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.18470_non
e_dadee7b65bc6429b
73950000 dwmapi.dll 6.3.9600.17415 C:\Windows\system32
73df0000 twain_32.dll 1.7.1.3 C:\Windows
740b0000 apphelp.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74150000 olepro32.dll 6.3.9600.18227 C:\Windows\SYSTEM32
74180000 iertutil.dll 11.0.9600.18500 C:\Windows\SYSTEM32
743c0000 wininet.dll 11.0.9600.18500 C:\Windows\SYSTEM32
74730000 comctl32.dll 6.10.9600.18006
C:\Windows\WinSxS\x86_microsoft.windows.common-
controls_6595b64144ccf1df_6.0.9600.18006_none_a9ec6aab013aafee
74940000 SHCORE.DLL 6.3.9600.17666 C:\Windows\SYSTEM32
74e60000 bcrypt.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74e80000 rsaenh.dll 6.3.9600.18191 C:\Windows\system32
74eb0000 CRYPTSP.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74ed0000 kernel.appcore.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74ee0000 wsock32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
74ef0000 version.dll 6.3.9600.17415 C:\Windows\SYSTEM32
750d0000 WINMMBASE.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75120000 winmm.dll 6.3.9600.17415 C:\Windows\SYSTEM32
751e0000 DEVOBJ.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75210000 profapi.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75220000 winspool.drv 6.3.9600.17415 C:\Windows\SYSTEM32
75290000 USERENV.dll 6.3.9600.17415 C:\Windows\SYSTEM32
752b0000 bcryptPrimitives.dll 6.3.9600.18344 C:\Windows\SYSTEM32
75310000 CRYPTBASE.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75320000 oleaut32.dll 6.3.9600.18434 C:\Windows\SYSTEM32
753e0000 MSCTF.dll 6.3.9600.17664 C:\Windows\SYSTEM32
75540000 ole32.dll 6.3.9600.18403 C:\Windows\SYSTEM32
75670000 gdi32.dll 6.3.9600.18344 C:\Windows\SYSTEM32
75780000 SHLWAPI.dll 6.3.9600.17415 C:\Windows\SYSTEM32
757e0000 cfgmgr32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75ad0000 comdlg32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75b70000 combase.dll 6.3.9600.18202 C:\Windows\SYSTEM32
75cf0000 msvcrt.dll 7.0.9600.17415 C:\Windows\SYSTEM32
75de0000 sechost.dll 6.3.9600.17734 C:\Windows\SYSTEM32
75e30000 KERNELBASE.dll 6.3.9600.18264 C:\Windows\SYSTEM32
75f10000 NSI.dll 6.3.9600.17415 C:\Windows\SYSTEM32
75f20000 RPCRT4.dll 6.3.9600.18292 C:\Windows\SYSTEM32
76170000 shell32.dll 6.3.9600.18458 C:\Windows\SYSTEM32
77490000 WS2_32.dll 6.3.9600.18340 C:\Windows\SYSTEM32
77650000 SspiCli.dll 6.3.9600.18454 C:\Windows\SYSTEM32
77670000 user32.dll 6.3.9600.18439 C:\Windows\SYSTEM32
777d0000 advapi32.dll 6.3.9600.18155 C:\Windows\SYSTEM32
77850000 imm32.dll 6.3.9600.17415 C:\Windows\SYSTEM32
77890000 KERNEL32.DLL 6.3.9600.17415 C:\Windows\SYSTEM32
779d0000 clbcatq.dll 2001.12.10530.17415 C:\Windows\SYSTEM32
77b30000 ntdll.dll 6.3.9600.18233 C:\Windows\SYSTEM32

processes:
0000 Idle 0
0004 System 0
016c smss.exe 0
0208 csrss.exe 0
0268 wininit.exe 0
02c8 services.exe 0
02d8 lsass.exe 0
0320 svchost.exe 0
034c svchost.exe 0
03c4 atiesrxx.exe 0
03f8 svchost.exe 0
0148 svchost.exe 0
01a8 svchost.exe 0
02c4 svchost.exe 0
0478 svchost.exe 0
049c svchost.exe 0
0568 spoolsv.exe 0
0630 FI_Eject.exe 0
0648 ChgService.exe 0
066c svchost.exe 0
067c dasHost.exe 0
06a8 ENAgent.exe 0
06ec HWDeviceService64.exe 0
0738 FrameworkService.exe 0
0778 VsTskMgr.exe 0
07f8 mfevtps.exe 0
0440 mfeann.exe 0
0668 naPrdMgr.exe 0
0524 conhost.exe 0
06d8 ouc.exe 0
07a8 NitroPDFDriverService8x64.exe 0
083c nlssrv32.exe 0
0888 scsiaccess.exe 0
0898 SOFTFO~1.EXE 0
08dc svchost.exe 0
0ac8 WEBCAC~1.EXE 0
0b00 WifiService.exe 0
0b50 escsvc64.exe 0
0b68 mcshield.exe 0
0d2c svchost.exe 0
0d7c svchost.exe 0
0434 SearchIndexer.exe 0
121c GoogleCrashHandler.exe 0
1044 GoogleCrashHandler64.exe 0
0be8 NASvc.exe 0
10cc wmpnetwk.exe 0
0378 svchost.exe 0
1e74 dllhost.exe 0
0578 csrss.exe 12
2e8c winlogon.exe 12
2cb0 dwm.exe 12
2f14 atieclxx.exe 12
2998 SM?RTP.exe 12
2538 taskhostex.exe 12 normal
2c48 explorer.exe 12 normal
2a70 TabTip.exe 12
1b60 TabTip32.exe 12
2dac AMDQuickStream.exe 12 normal
2180 IDMan.exe 12 normal C:\Program Files (x86)\Internet
Download Manager
2658 E_YATII2E.EXE 12 normal
262c E_IATIFEP.EXE 12 normal
2ddc IEMonitor.exe 12 normal C:\Program Files (x86)\Internet
Download Manager
22d4 UdaterUI.exe 12 normal C:\Program Files (x86)\McAfee\Common
Framework
1bac laragon.exe 12 normal C:\laragon
2fa0 EEventManager.exe 12 normal C:\Program Files (x86)\Epson
Software\Event Manager
18c0 SmadavProtect64.exe 12
2eec jusched.exe 12 normal C:\Program Files (x86)\Common
Files\Java\Java Update
2ec8 McTray.exe 12 normal C:\Program Files (x86)\McAfee\Common
Framework
05f4 WSHelper.exe 12 normal C:\Program Files (x86)\Common
Files\Wondershare\Wondershare Helper Compact
2a28 MOM.exe 12 normal
2100 SHSTAT.EXE 12 normal C:\Program Files
(x86)\McAfee\VirusScan Enterprise
1240 CCC.exe 12 normal
1880 WiFiUpg.exe 12
2584 php-cgi.exe 12 normal
25c4 conhost.exe 12 normal
2cd4 taskhost.exe 0
1278 chrome.exe 12 normal
2a90 chrome.exe 12 normal
1c30 chrome.exe 12 normal
2fec chrome.exe 12 normal
2f08 chrome.exe 12 normal
2068 chrome.exe 12 idle
2fcc SearchProtocolHost.exe 0
1550 audiodg.exe 0
2640 svchost.exe 0
1840 SearchFilterHost.exe 0
2ec4 sppsvc.exe 0
1a50 dllhost.exe 12 normal
2df0 IncardexProducer.exe 12 normal C:\Program Files (x86)\Mars
Systems\Incardex

hardware:
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
- \\RPIIL-PC\EPSON L210 Series
- EPSON L210 Series
- EPSON T1100 Series (Copy 1)
- Fax
- Microsoft XPS Document Writer
- Nitro PDF Creator (Pro 8)
- Root Print Queue
- Send To OneNote 2013
- Softfoundry Virtual Printer
+ {36fc9e60-c465-11cf-8056-444553540000}
- AMD USB 3.0 eXtensible Host Controller - 0100 (Microsoft)
- HUAWEI Mobile Connect - Bus Enumerate Device (driver 2.6.2.1605)
- Standard Enhanced PCI to USB Host Controller
- Standard Enhanced PCI to USB Host Controller
- Standard OpenHCD USB Host Controller
- Standard OpenHCD USB Host Controller
- USB Composite Device
- USB Composite Device
- USB Composite Device
- USB Printing Support
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub
- USB Root Hub (xHCI)
+ {4d36e966-e325-11ce-bfc1-08002be10318}
- ACPI x64-based PC
+ {4d36e967-e325-11ce-bfc1-08002be10318}
- TOSHIBA MQ01ABF050
+ {4d36e968-e325-11ce-bfc1-08002be10318}
- AMD Radeon HD 8250 (driver 13.152.1.3000)
- Softfoundry Display Mirror Device (driver 2-4-2010)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
- Standard SATA AHCI Controller
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
- HID Keyboard Device
- Standard PS/2 Keyboard
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
- AMD High Definition Audio Device (driver 9.0.0.9902)
- AnvSoft Virtual Sound Device (driver 1.2.0.0)
- High Definition Audio Device
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
- Generic PnP Monitor
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
- HID-compliant mouse
- PS/2 Compatible Mouse
+ {4d36e972-e325-11ce-bfc1-08002be10318}
- Bluetooth Device (Personal Area Network)
- Qualcomm Atheros AR956x Wireless Network Adapter
- VirtualBox Host-Only Ethernet Adapter (driver 5.0.12.0)
+ {4d36e979-e325-11ce-bfc1-08002be10318}
- EPSON L210 Series (driver 1.54.0.0)
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
- Microsoft Storage Spaces Controller
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Power Button
- ACPI Sleep Button
- ACPI Thermal Zone
- ACPI Thermal Zone
- AMD SMBus (driver 5.12.0.31)
- Composite Bus Enumerator
- Direct memory access controller
- High Definition Audio Controller
- High Definition Audio Controller
- High precision event timer
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft Basic Display Driver
- Microsoft Basic Render Driver
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator
- Microsoft Windows Management Interface for ACPI
- Microsoft Windows Management Interface for ACPI
- Motherboard resources
- Motherboard resources
- Motherboard resources
- NDIS Virtual Network Adapter Enumerator
- Numeric data processor
- PCI Express Root Complex
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard host CPU bridge
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- Plug and Play Software Device Enumerator
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- System board
- System CMOS/real time clock
- System speaker
- System timer
- UMBus Root Bus Enumerator
- Volume Manager
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
- AMD A6-1450 APU with Radeon(TM) HD Graphics
- AMD A6-1450 APU with Radeon(TM) HD Graphics
- AMD A6-1450 APU with Radeon(TM) HD Graphics
- AMD A6-1450 APU with Radeon(TM) HD Graphics
+ {533c5b84-ec70-11d2-9505-00c04f79deaf}
- Generic volume shadow copy
- Generic volume shadow copy
- Generic volume shadow copy
+ {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
- Microsoft Device Association Root Enumerator
- Microsoft IPv4 IPv6 Transition Adapter Bus
- Microsoft RRAS Root Enumerator
- STUDIO6SMK: Lomba TIK:
- STUDIO6SMK: multimedia:
+ {6bdd1fc6-810f-11d0-bec7-08002be2092f}
- EPSON L210/L350 (driver 3.7.9.1)
- HD WebCam
+ {72631e54-78a4-11d0-bcf7-00aa00b7b32a}
- Microsoft AC Adapter
- Microsoft ACPI-Compliant Control Method Battery
+ {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
- HID-compliant consumer control device
- HID-compliant device
- HID-compliant system controller
- HID-compliant touch screen
- HID-compliant vendor-defined device
- HID-compliant vendor-defined device
- USB Input Device
- USB Input Device
- USB Input Device
- USB Input Device
+ {a0a588a4-c46f-4b37-b7ea-c82fe89870c6}
- SDA Standard Compliant SD Host Controller
+ {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
- Microphone (High Definition Audio Device)
- Speakers (AnvSoft Virtual Sound Device)
- Speakers (High Definition Audio Device)
+ {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
- Generic Bluetooth Adapter
- Microsoft Bluetooth Enumerator
- Microsoft Bluetooth LE Enumerator

cpu registers:
eax = 0000007b
ebx = ffffffff
ecx = 7fffffff
edx = 000000ff
esi = 0000007b
edi = 00000000
eip = 75e44357
esp = 0018f478
ebp = 0018f4b8

stack dump:
0018f478 01 00 00 00 08 00 00 00 - 01 00 00 00 00 00 00 00 ................
0018f488 00 00 00 00 00 00 00 00 - f4 f4 18 00 ff 00 00 00 ................
0018f498 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f4a8 00 00 00 00 00 00 00 00 - 00 00 00 00 77 28 06 e0 ............w(..
0018f4b8 f8 f7 18 00 69 ac 63 72 - 00 00 00 00 00 00 00 00 ....i.cr........
0018f4c8 7b 00 00 00 ff ff ff ff - f4 f4 18 00 ff 00 00 00 {...............
0018f4d8 00 00 00 00 f0 ab 63 72 - c8 db 29 00 c0 8c 90 00 ......cr..).....
0018f4e8 08 00 00 00 80 f8 18 00 - 01 00 00 00 00 00 00 00 ................
0018f4f8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f508 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f518 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f528 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f538 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f548 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f558 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f568 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f578 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f588 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f598 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0018f5a8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

disassembling:
[...]
005f316f push 0
005f3171 mov eax, [ebp-4]
005f3174 add eax, $44
005f3177 push eax
005f3178 mov eax, [ebp-4]
005f317b > call dword ptr [eax+$40]
005f317e 556 mov eax, [ebp-4]
005f3181 add eax, $184
005f3186 push eax
005f3187 push $302
005f318c push 4
[...]

You might also like