EurekaLog 6.1.04 Application: ------------------------------------------------------- 1.1 Start Date : Sun, 15 Oct 2017 19:13:30 +0700 1.2 Name/Description: SASPlanet.3276.exe 1.3 Version Number : 1.0.0.0 1.4 Parameters : 1.5 Compilation Date: Sun, 15 Oct 2017 18:46:25 +0700 1.6 Up Time : 7 minutes, 47 seconds Exception: ----------------------------------------------------- 2.1 Date : Sun, 15 Oct 2017 19:21:18 +0700 2.2 Address : 0048A226 2.3 Module Name : SASPlanet.3276.exe 2.4 Module Version: 1.0.0.0 2.5 Type : EMultiFree 2.6 Message : Multi Free memory leak. 2.7 ID : 3000 2.8 Count : 1 2.9 Status : New 2.10 Note : User: ------------------------------------------------------- 3.5 Privileges: SeIncreaseQuotaPrivilege - OFF SeSecurityPrivilege - OFF SeTakeOwnershipPrivilege - OFF SeLoadDriverPrivilege - OFF SeSystemProfilePrivilege - OFF SeSystemtimePrivilege - OFF SeProfileSingleProcessPrivilege - OFF SeIncreaseBasePriorityPrivilege - OFF SeCreatePagefilePrivilege - OFF SeBackupPrivilege - OFF SeRestorePrivilege - OFF SeShutdownPrivilege - OFF SeDebugPrivilege - OFF SeSystemEnvironmentPrivilege - OFF SeChangeNotifyPrivilege - ON SeRemoteShutdownPrivilege - OFF SeUndockPrivilege - OFF SeManageVolumePrivilege - OFF SeImpersonatePrivilege - ON SeCreateGlobalPrivilege - ON SeIncreaseWorkingSetPrivilege - OFF SeTimeZonePrivilege - OFF SeCreateSymbolicLinkPrivilege - OFF Computer: ---------------------------------------------------------------------------------- 5.3 Free Memory : 2796 Mb 5.5 Free Disk : 92.14 Gb 5.7 Processor : Intel(R) Core(TM) M-5Y71 CPU @ 1.20GHz 5.8 Display Mode: 1280 x 720, 32 bit 5.9 Display DPI : 96 5.10 Video Card : Intel(R) HD Graphics 5300 (driver 20.19.15.4531 - RAM 1024 MB) Operating System: ---------------------------------------------- 6.1 Type : Microsoft Windows 6.2 (64 bit) 6.2 Build # : 9200 6.3 Update : 6.4 Language: English 6.5 Charset : 0 Call Stack Information: ---------------------------------------------------------------------------------------------------------------------- |Address |Module |Unit |Class |Procedure/Method |Line | ---------------------------------------------------------------------------------------------------------------------- |*Exception Thread: ID=9728; Priority=2147483647; Class=Tvsagps_Packet_Thread | |--------------------------------------------------------------------------------------------------------------------| |0048A226|SASPlanet.3276.exe| | | | | |00710DB2|SASPlanet.3276.exe|vsagps_object.pas |Tvsagps_Packet_Thread |Destroy |683[17] | |767A7C02|KERNEL32.DLL | | |LoadResource | | |--------------------------------------------------------------------------------------------------------------------| |Calling Thread: ID=10488; Priority=1; Class=; [Main] | |--------------------------------------------------------------------------------------------------------------------| |00710D0A|SASPlanet.3276.exe|vsagps_object.pas |Tvsagps_object |InternalCreateRuntimeObjects|633[8] | |00710B5D|SASPlanet.3276.exe|vsagps_object.pas |Tvsagps_object |GPSConnect |554[49] | |00710A38|SASPlanet.3276.exe|vsagps_object.pas |Tvsagps_object |GPSConnect |505[0] | |00714EC6|SASPlanet.3276.exe|u_GPSModuleByVSAGPS.pas|TGPSModuleByVSAGPS |Connect |663[117] | |767A6FB0|KERNEL32.DLL | | |FindActCtxSectionGuid | | |0071A3F7|SASPlanet.3276.exe|u_GpsSystem.pas |TGpsSystem |OnConfigChange |321[4] | |0071A378|SASPlanet.3276.exe|u_GpsSystem.pas |TGpsSystem |OnConfigChange |317[0] | |0071AB25|SASPlanet.3276.exe|u_GpsSystem.pas |TGpsSystem |StartThreads |608[2] | |0071AB10|SASPlanet.3276.exe|u_GpsSystem.pas |TGpsSystem |StartThreads |606[0] | |0071A36E|SASPlanet.3276.exe|u_GpsSystem.pas |TGpsSystem |OnAppStarted |313[1] | |005701FF|SASPlanet.3276.exe|u_ListenerByEvent.pas |TNotifyNoMmgEventListener|Notification |155[1] | |00570DC5|SASPlanet.3276.exe|u_Notifier.pas |TNotifierBase |Notify |106[11] | |00571716|SASPlanet.3276.exe|u_NotifierOperation.pas|TNotifierOneOperation |ExecuteOperation |180[10] | |00A903B5|SASPlanet.3276.exe|u_GlobalState.pas |TGlobalState |StartThreads |1060[1] | |00A9038C|SASPlanet.3276.exe|u_GlobalState.pas |TGlobalState |StartThreads |1059[0] | |00B61BDD|SASPlanet.3276.exe|frm_Main.pas |TfrmMain |FormActivate |1999[267]| |767A22B2|KERNEL32.DLL | | |BaseSetLastNTError | | |767A22A0|KERNEL32.DLL | | |BaseSetLastNTError | | |74FE8E3B|user32.dll | | |CallNextHookEx | | |7501518B|user32.dll | | |CharLowerW | | |75015140|user32.dll | | |CharLowerW | | |768DB010|msvcrt.dll | | |memcmp | | |7649403A|MSCTF.dll | | |CtfImeDispatchDefImeMessage | | |74FECDC0|user32.dll | | |SetFocus | | |74FEDA00|user32.dll | | |ShowWindow | | |74FE8E3B|user32.dll | | |CallNextHookEx | | |74FF4E57|user32.dll | | |MonitorFromWindow | | |74FE8D9C|user32.dll | | |CharUpperA | | |00B7C75A|SASPlanet.3276.exe|SASPlanet.dpr | | |1494[34] | |767A7C02|KERNEL32.DLL | | |LoadResource | | ---------------------------------------------------------------------------------------------------------------------- Modules Information: --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Handle |Name |Description |Version |Size |Modified |Path | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |00370000|zlib1.dll |zlib data compression library |1.2.8.0 |92672 |2016-06-11 02:34:42|C:\Users\Diederik\Downloads\SASplanetNightly171012 | |00400000|SASPlanet.3276.exe | |1.0.0.0 |9214976 |2017-10-15 19:03:16|C:\Users\Diederik\Downloads\SASplanetNightly171012 | |10000000|libpng16.dll |PNG image compression library |1.6.22.0 |200192 |2016-06-11 02:34:42|C:\Users\Diederik\Downloads\SASplanetNightly171012 | |61E00000|sqlite3.dll |SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.|3.20.1.0 |851887 |2017-10-09 00:33:38|C:\Users\Diederik\Downloads\SASplanetNightly171012 | |62D40000|fwpuclnt.dll |FWP/IPsec User-Mode API |6.3.9600.18229 |272384 |2016-02-05 22:07:48|C:\windows\System32 | |670E0000|MSVCP90.dll |Microsoft® C++ Runtime Library |9.0.30729.8387 |570512 |2013-08-03 11:40:18|C:\windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.8387_none_5094ca96bcb6b2bb | |68540000|geodesic.dll | |1.46.1.0 |53760 |2016-11-19 19:10:02|C:\Users\Diederik\Downloads\SASplanetNightly171012 | |693D0000|ieframe.dll |Internet Browser |11.0.9600.18817 |13677568|2017-09-08 01:17:14|C:\Windows\SYSTEM32 | |6A560000|MSVCR90.dll |Microsoft® C Runtime Library |9.0.30729.8387 |653968 |2013-08-03 11:40:18|C:\windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.8387_none_5094ca96bcb6b2bb | |6AD80000|jpeg62.dll | | |581941 |2016-11-10 03:46:34|C:\Users\Diederik\Downloads\SASplanetNightly171012 | |6B0A0000|ondemandconnroutehelper.dll|On Demand Connctiond Route Helper |6.3.9600.17415 |27648 |2014-10-29 08:05:04|C:\windows\SYSTEM32 | |6CC60000|comctl32.dll |User Experience Controls Library |6.10.9600.18006 |2105856 |2015-08-07 00:20:32|C:\windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.18006_none_a9ec6aab013aafee| |6E8E0000|olepro32.dll | |6.3.9600.18508 |86016 |2016-10-05 03:08:22|C:\windows\SYSTEM32 | |6E900000|SHFolder.dll |Shell Folder Service |6.3.9600.17415 |8192 |2014-10-29 08:57:12|C:\windows\SYSTEM32 | |6E910000|FreeImage.dll |FreeImage library |3.17.0.0 |341504 |2016-06-11 02:34:42|C:\Users\Diederik\Downloads\SASplanetNightly171012 | |6E970000|CityHash.dll | | |14336 |2013-08-25 14:29:28|C:\Users\Diederik\Downloads\SASplanetNightly171012 | |6FC30000|sxs.dll |Fusion 2.5 |6.3.9600.17415 |499200 |2014-10-29 08:56:42|C:\windows\SYSTEM32 | |6FDA0000|rasadhlp.dll |Remote Access AutoDial Helper |6.3.9600.17415 |12288 |2014-10-29 08:05:34|C:\Windows\System32 | |70090000|DNSAPI.dll |DNS Client API DLL |6.3.9600.18817 |499200 |2017-09-08 01:24:56|C:\windows\SYSTEM32 | |73350000|mswsock.dll |Microsoft Windows Sockets 2.0 Service Provider |6.3.9600.18340 |286208 |2016-05-14 04:35:18|C:\windows\SYSTEM32 | |73530000|DEVOBJ.dll |Device Information Set DLL |6.3.9600.17415 |127552 |2014-10-29 10:18:42|C:\windows\SYSTEM32 | |73560000|WINMMBASE.dll |Base Multimedia Extension API DLL |6.3.9600.17415 |134280 |2014-10-29 10:07:02|C:\windows\SYSTEM32 | |73590000|wininet.dll |Internet Extensions for Win32 |11.0.9600.18817 |2767872 |2017-09-08 01:01:26|C:\windows\SYSTEM32 | |73840000|iertutil.dll |Run time utility for Internet Explorer |11.0.9600.18817 |2292736 |2017-09-08 02:04:00|C:\windows\SYSTEM32 | |73A80000|winmm.dll |MCI API DLL |6.3.9600.17415 |136840 |2014-10-29 10:07:02|C:\windows\SYSTEM32 | |73C20000|uxtheme.dll |Microsoft UxTheme Library |6.3.9600.17415 |949760 |2014-10-29 07:48:30|C:\windows\system32 | |73DA0000|kernel.appcore.dll |AppModel API Host |6.3.9600.17415 |29920 |2014-10-29 10:18:48|C:\windows\SYSTEM32 | |73DB0000|oleacc.dll |Active Accessibility Core Component |7.2.9600.17415 |306688 |2014-10-29 07:58:06|C:\windows\SYSTEM32 | |73E00000|dwmapi.dll |Microsoft Desktop Window Manager API |6.3.9600.17415 |102728 |2014-10-29 10:12:04|C:\windows\system32 | |73E20000|winspool.drv |Windows Spooler Driver |6.3.9600.18467 |397824 |2016-09-03 22:58:08|C:\windows\SYSTEM32 | |73E90000|msimg32.dll |GDIEXT Client DLL |6.3.9600.17415 |6144 |2014-10-29 08:05:52|C:\windows\SYSTEM32 | |73EA0000|URLMON.DLL |OLE32 Extensions for Win32 |11.0.9600.18817 |1316864 |2017-09-08 00:57:42|C:\windows\SYSTEM32 | |740C0000|wsock32.dll |Windows Socket 32-Bit DLL |6.3.9600.17415 |16384 |2014-10-29 08:59:52|C:\windows\SYSTEM32 | |740D0000|apphelp.dll |Application Compatibility Client Library |6.3.9600.17415 |642560 |2014-10-29 09:00:14|C:\windows\system32 | |741A0000|WINNSI.DLL |Network Store Information RPC interface |6.3.9600.17415 |26304 |2014-10-29 10:05:16|C:\windows\SYSTEM32 | |741B0000|SHCORE.DLL |SHCORE |6.3.9600.17666 |560392 |2015-01-23 12:02:34|C:\windows\SYSTEM32 | |742A0000|USERENV.dll |Userenv |6.3.9600.17415 |98152 |2014-10-29 10:15:38|C:\windows\SYSTEM32 | |742C0000|winhttp.dll |Windows HTTP Services |6.3.9600.18378 |626176 |2016-06-11 23:16:22|C:\windows\SYSTEM32 | |74360000|IPHLPAPI.DLL |IP Helper API |6.3.9600.18264 |121912 |2016-03-12 07:47:36|C:\windows\SYSTEM32 | |74720000|version.dll |Version Checking and File Installation Libraries |6.3.9600.17415 |26304 |2014-10-29 10:10:56|C:\windows\SYSTEM32 | |74730000|tiptsf.dll |Touch Keyboard and Handwriting Panel Text Services Framework |6.3.9600.17415 |493056 |2014-10-29 07:49:14|C:\Program Files (x86)\Common Files\microsoft shared\ink | |747B0000|profapi.dll |User Profile Basic API |6.3.9600.17415 |52152 |2014-10-29 10:05:16|C:\windows\SYSTEM32 | |74820000|secur32.dll |Security Support Provider Interface |6.3.9600.17415 |24064 |2014-10-29 08:06:20|C:\windows\SYSTEM32 | |74830000|bcrypt.dll |Windows Cryptographic Primitives Library |6.3.9600.18541 |111104 |2016-11-20 00:22:22|C:\windows\SYSTEM32 | |74850000|rsaenh.dll |Microsoft Enhanced Cryptographic Provider |6.3.9600.18191 |192120 |2016-01-09 08:49:44|C:\windows\system32 | |74880000|CRYPTSP.dll |Cryptographic Service Provider API |6.3.9600.17415 |96032 |2014-10-29 10:15:32|C:\windows\SYSTEM32 | |748A0000|bcryptPrimitives.dll |Windows Cryptographic Primitives Library |6.3.9600.18344 |340880 |2016-05-19 05:28:36|C:\windows\SYSTEM32 | |74900000|CRYPTBASE.dll |Base cryptographic API DLL |6.3.9600.17415 |30984 |2014-10-29 10:05:16|C:\windows\SYSTEM32 | |74910000|PSAPI.DLL |Process Status Helper |6.3.9600.17415 |16504 |2014-10-29 10:18:44|C:\windows\SYSTEM32 | |74920000|MSASN1.dll |ASN.1 Runtime APIs |6.3.9600.17415 |51608 |2014-10-29 10:15:34|C:\windows\SYSTEM32 | |74990000|combase.dll |Microsoft COM for Windows |6.3.9600.18666 |1566032 |2017-04-16 16:07:10|C:\windows\SYSTEM32 | |74B50000|advapi32.dll |Advanced Windows 32 Base API |6.3.9600.18155 |507176 |2015-12-09 02:07:50|C:\windows\SYSTEM32 | |74BD0000|cfgmgr32.dll |Configuration Manager DLL |6.3.9600.17415 |241168 |2014-10-29 10:18:48|C:\windows\SYSTEM32 | |74C10000|imm32.dll |Multi-User Windows IMM32 API Client DLL |6.3.9600.17415 |141312 |2014-10-29 08:59:50|C:\windows\SYSTEM32 | |74C40000|oleaut32.dll | |6.3.9600.18666 |612096 |2017-04-16 16:06:00|C:\windows\SYSTEM32 | |74CE0000|WS2_32.dll |Windows Socket 2.0 32-Bit DLL |6.3.9600.18340 |320720 |2016-05-15 03:01:28|C:\windows\SYSTEM32 | |74D40000|NSI.dll |NSI User-mode interface DLL |6.3.9600.17415 |20120 |2014-10-29 10:05:16|C:\windows\SYSTEM32 | |74D50000|shlwapi.dll |Shell Light-weight Utility Library |6.3.9600.17415 |278352 |2014-10-29 10:10:56|C:\windows\SYSTEM32 | |74F10000|SspiCli.dll |Security Support Provider Interface |6.3.9600.18454 |104960 |2016-08-21 05:55:20|C:\windows\SYSTEM32 | |74FE0000|user32.dll |Multi-User Windows USER API Client DLL |6.3.9600.18535 |1376768 |2016-11-10 00:25:06|C:\windows\SYSTEM32 | |75140000|clbcatq.dll |COM+ Configuration Catalog |2001.12.10530.17415|569128 |2014-10-29 10:10:02|C:\windows\SYSTEM32 | |751D0000|shell32.dll |Windows Shell Common Dll |6.3.9600.18819 |19790760|2017-09-10 00:55:48|C:\windows\SYSTEM32 | |76490000|MSCTF.dll |MSCTF Server DLL |6.3.9600.18819 |1124384 |2017-09-14 08:14:24|C:\windows\SYSTEM32 | |765B0000|KERNELBASE.dll |Windows NT BASE API Client DLL |6.3.9600.18666 |862720 |2017-04-16 15:16:06|C:\windows\SYSTEM32 | |766F0000|comdlg32.dll |Common Dialogs DLL |6.3.9600.17415 |609280 |2014-10-29 08:14:56|C:\windows\SYSTEM32 | |76790000|KERNEL32.DLL |Windows NT BASE API Client DLL |6.3.9600.17415 |1040384 |2014-10-29 08:58:24|C:\windows\SYSTEM32 | |768D0000|msvcrt.dll |Windows NT CRT DLL |7.0.9600.17415 |800008 |2014-10-29 10:06:30|C:\windows\SYSTEM32 | |769B0000|gdi32.dll |GDI Client DLL |6.3.9600.18818 |1084928 |2017-09-08 23:57:44|C:\windows\SYSTEM32 | |76AC0000|ole32.dll |Microsoft OLE for Windows |6.3.9600.18666 |1213792 |2017-04-16 16:07:10|C:\windows\SYSTEM32 | |76BF0000|Crypt32.dll |Crypto API32 |6.3.9600.18653 |1612504 |2017-04-01 04:59:40|C:\windows\SYSTEM32 | |76F40000|sechost.dll |Host for SCM/SDDL/LSA Lookup APIs |6.3.9600.17734 |257216 |2015-03-24 04:45:06|C:\windows\SYSTEM32 | |76F90000|RPCRT4.dll |Remote Procedure Call Runtime |6.3.9600.18292 |747520 |2016-03-31 10:40:26|C:\windows\SYSTEM32 | |77120000|ntdll.dll |NT Layer DLL |6.3.9600.18821 |1502000 |2017-09-15 02:29:56|C:\windows\SYSTEM32 | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Processes Information: --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |ID |Name |Description |Version |Memory|Priority |Threads|Path | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |0 |[System Process] | | |0 | |4 | | |4 |System | | |0 |Normal |127 | | |320 |smss.exe | | |0 |Above-Normal|2 | | |356 |igfxCUIService.exe | | |0 |Normal |6 | | |372 |taskhostex.exe | | |0 |Normal |7 | | |508 |svchost.exe |Host Process for Windows Services |6.3.9600.17415|0 |Normal |31 | | |512 |McCSPServiceHost.exe | | |0 |Normal |15 | | |532 |dwm.exe | | |0 |High |6 | | |572 |csrss.exe | | |0 |High |9 | | |620 |wininit.exe | | |0 |High |1 | | |636 |csrss.exe | | |0 |High |11 | | |680 |winlogon.exe | | |0 |High |2 | | |720 |services.exe | | |0 |Normal |3 | | |728 |lsass.exe | | |0 |Normal |6 | | |752 |WSHost.exe | | |0 |Normal |5 | | |808 |svchost.exe |Host Process for Windows Services |6.3.9600.17415|0 |Normal |8 | | |852 |svchost.exe |Host Process for Windows Services |6.3.9600.17415|0 |Normal |11 | | |928 |svchost.exe |Host Process for Windows Services |6.3.9600.17415|0 |Normal |25 | | |956 |svchost.exe |Host Process for Windows Services |6.3.9600.17415|0 |Normal |44 | | |1012 |svchost.exe |Host Process for Windows Services |6.3.9600.17415|0 |Normal |22 | | |1052 |Creative Cloud.exe |Adobe Creative Cloud |4.3.0.256 |0 |Normal |36 |C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC | |1068 |svchost.exe |Host Process for Windows Services |6.3.9600.17415|0 |Normal |17 | | |1084 |mcsacore.exe | | |0 |Normal |46 | | |1144 |wlanext.exe |Windows Wireless LAN 802.11 Extensibility Framework |6.3.9600.17415|0 |Normal |3 | | |1168 |conhost.exe | | |0 |Normal |1 | | |1216 |McAWFwk.exe | | |0 |Normal |5 | | |1276 |spoolsv.exe | | |0 |Normal |9 | | |1324 |svchost.exe |Host Process for Windows Services |6.3.9600.17415|0 |Normal |23 | | |1332 |McUICnt.exe | | |0 |Normal |36 | | |1472 |AGSService.exe | | |0 |Normal |4 | | |1544 |btwdins.exe |Bluetooth Support Server |12.0.0.9800 |0 |Normal |4 | | |1572 |McSvHost.exe | | |0 |Normal |98 | | |1576 |svchost.exe |Host Process for Windows Services |6.3.9600.17415|0 |Normal |10 | | |1592 |dasHost.exe | | |0 |Normal |3 | | |1612 |esif_uf.exe |Intel(R) Dynamic Platform and Thermal Framework |8.0.10002.14 |0 |Normal |4 | | |1656 |FBService.exe | | |0 |Normal |3 | | |1680 |HarmonyPicksService.exe | | |0 |Normal |7 | | |1748 |Coresync.exe |Core Sync |2.4.3.114 |0 |Normal |37 |C:\Program Files (x86)\Adobe\Adobe Sync\Coresync | |1756 |HarmonySettingService.exe | | |0 |Normal |9 | | |1836 |OKOUpdataService.exe | | |0 |Normal |4 | | |1880 |mfemms.exe | | |0 |Normal |11 | | |1888 |SettingsService.exe | | |0 |Normal |11 | | |1936 |SystemAgentService.exe | | |0 |Normal |4 | | |1952 |LPAWDService.exe | | |0 |Normal |7 | | |1992 |LenovoSetSvr.exe | | |0 |Normal |3 | | |2012 |LenovoWiFiHotspotSvr.exe | | |0 |Normal |10 | | |2020 |mcautoreg.exe | | |0 |Normal |2 | | |2084 |mfevtps.exe | | |0 |Normal |3 | | |2152 |ModuleCoreService.exe | | |0 |Normal |58 | | |2160 |mfevtps.exe | | |0 |Normal |5 | | |2216 |NitroPDFDriverService9x64.exe| | |0 |Normal |4 | | |2256 |NLSSRV32.EXE |This service enables products that use the Nalpeiron Licensing System |7.3.4.0 |0 |Normal |2 | | |2280 |OKOControlSvc.exe | | |0 |Normal |2 | | |2332 |PaperLookingSrv.exe | | |0 |Normal |2 | | |2404 |PEFService.exe | | |0 |Normal |3 | | |2428 |PGService.exe |Lenovo Motion Control |2.6.0.5844 |0 |Normal |6 | | |2524 |PG_Service_Launcher.exe |Lenovo Motion Control |2.6.0.5844 |0 |Normal |10 | | |2588 |PhoneCompanionPusher.exe | | |0 |Normal |2 | | |2604 |chrome.exe | | |0 |Low |13 | | |2616 |SearchIndexer.exe |Microsoft Windows Search Indexer |7.0.9600.18722|0 |Normal |19 | | |2624 |PLHotkeyService.exe | | |0 |Normal |7 | | |2640 |WebcamSplitterServer.exe |Lenovo Motion Control |2.6.0.5844 |0 |Normal |5 | | |2716 |SynTPEnhService.exe | | |0 |Normal |2 | | |2764 |VfConnectorService.exe | | |0 |Normal |5 | | |2816 |ymc.exe | | |0 |Normal |11 | | |2900 |MfeAVSvc.exe | | |0 |Normal |75 | | |2904 |WmiPrvSE.exe |WMI Provider Host |6.3.9600.18264|0 |Normal |4 | | |2968 |unsecapp.exe | | |0 |Normal |3 | | |3012 |WmiPrvSE.exe |WMI Provider Host |6.3.9600.18264|0 |Normal |6 | | |3188 |WUDFHost.exe | | |0 |Normal |14 | | |3296 |mfefire.exe | | |0 |Normal |8 | | |3312 |mcapexe.exe | | |0 |Normal |8 | | |3340 |mfefire.exe | | |0 |Normal |3 | | |3604 |svchost.exe |Host Process for Windows Services |6.3.9600.17415|0 |Normal |22 | | |3680 |svchost.exe |Host Process for Windows Services |6.3.9600.17415|0 |Normal |3 | | |3872 |WUDFHost.exe | | |0 |Normal |12 | | |4072 |RunDll32.exe |Windows host process (Rundll32) |6.3.9600.17415|0 |Normal |1 |C:\windows\SysWOW64 | |4156 |WUDFHost.exe | | |0 |Normal |6 | | |4212 |WUDFHost.exe | | |0 |Normal |5 | | |4360 |PresentationFontCache.exe | | |0 |Normal |4 | | |4488 |saUI.exe | | |0 |Normal |3 | | |4520 |Adobe Installer.exe |Adobe Installer |4.3.0.256 |0 |Normal |5 |C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager| |4648 |SettingSyncHost.exe |Host Process for Setting Synchronization |6.3.9600.18231|0 |Below-Normal|9 | | |4668 |svchost.exe |Host Process for Windows Services |6.3.9600.17415|0 |Normal |9 | | |4740 |SynTPEnh.exe | | |0 |Above-Normal|8 | | |4788 |SASPlanet.3276.exe | |1.0.0.0 |0 |Normal |8 |C:\Users\Diederik\Downloads\SASplanetNightly171012 | |4960 |chrome.exe | | |0 |Low |13 | | |4984 |esif_assist.exe |Intel(R) Dynamic Platform and Thermal Framework Utility Application |8.0.10002.14 |0 |Normal |3 |C:\windows\TEMP\DPTF | |5092 |chrome.exe | | |0 |Normal |11 | | |5100 |dllhost.exe |COM Surrogate |6.3.9600.17415|0 |Normal |3 | | |5228 |igfxEM.exe | | |0 |Normal |3 | | |5236 |igfxHK.exe | | |0 |Normal |2 | | |5244 |igfxTray.exe | | |0 |Normal |2 | | |5300 |SynTPHelper.exe | | |0 |Above-Normal|1 | | |5356 |OneKeyOptimizer.exe | | |0 |Normal |29 | | |5844 |RuntimeBroker.exe | | |0 |Normal |4 | | |5888 |TabTip.exe | | |0 |High |11 | | |5900 |chrome.exe | | |0 |Normal |11 | | |5928 |TabTip32.exe |Touch Keyboard and Handwriting Panel Helper |6.3.9600.17415|0 |Normal |1 |C:\Program Files (x86)\Common Files\Microsoft Shared\Ink | |6048 |jhi_service.exe |Intel(R) Dynamic Application Loader Host Interface |10.0.25.1048 |0 |Normal |2 | | |6088 |GoogleCrashHandler.exe | | |0 |Low |3 | | |6096 |GoogleCrashHandler64.exe | | |0 |Low |3 | | |6212 |AdobeUpdateService.exe | | |0 |Normal |5 | | |6312 |chrome.exe | | |0 |Normal |11 | | |6368 |chrome.exe | | |0 |Normal |11 | | |6420 |chrome.exe | | |0 |Normal |2 | | |6472 |chrome.exe | | |0 |Normal |11 | | |6536 |RAVCpl64.exe | | |0 |Normal |6 | | |6560 |chrome.exe | | |0 |Normal |6 | | |6684 |chrome.exe | | |0 |Normal |11 | | |6688 |chrome.exe | | |0 |Normal |40 | | |6720 |RAVBg64.exe | | |0 |Normal |4 | | |6752 |RAVBg64.exe | | |0 |Normal |5 | | |6788 |RAVBg64.exe | | |0 |Normal |4 | | |6828 |chrome.exe | | |0 |Normal |14 | | |6836 |RAVBg64.exe | | |0 |Normal |4 | | |6860 |WavesSvc64.exe | | |0 |Normal |1 | | |6868 |UMonit64.exe |ChangeIcon MFC Application |14.0.0.0 |0 |Below-Normal|1 |C:\windows\SysWOW64 | |6880 |adb.exe | | |0 |Normal |2 | | |6932 |AdobeIPCBroker.exe |Adobe IPC Broker |5.4.0.12 |0 |Normal |14 |C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC | |6936 |utility.exe | | |0 |Normal |3 | | |6964 |Adobe CEF Helper.exe |Adobe CEF Helper |4.3.0.256 |0 |Normal |15 |C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX | |6972 |TransitionServer.exe | | |0 |Normal |2 |C:\Program Files (x86)\Lenovo\LenovoTransition | |6984 |Phone Companion.exe | | |0 |Normal |4 | | |7024 |chrome.exe | | |0 |Normal |11 | | |7044 |OneKeyOptimizerTray.exe | | |0 |Normal |1 | | |7108 |OnekeyOptimizerUpdata.exe | | |0 |Normal |5 | | |7192 |chrome.exe | | |0 |Normal |11 | | |7216 |chrome.exe | | |0 |Normal |11 | | |7252 |chrome.exe | | |0 |Normal |11 | | |7268 |chrome.exe | | |0 |Normal |13 | | |7652 |chrome.exe | | |0 |Normal |10 | | |7740 |BTTray.exe |Bluetooth Tray Application |12.0.0.9800 |0 |Normal |8 | | |7816 |WWAHost.exe |Microsoft WWA Host |6.3.9600.17415|0 |Normal |26 | | |7860 |Lenovo.HarmonyPicks.exe | | |0 |Normal |16 | | |7908 |McUICnt.exe | | |0 |Normal |1 | | |7924 |chrome.exe | | |0 |Normal |14 | | |7948 |ModuleCoreService.exe | | |0 |Normal |33 | | |7968 |conhost.exe | | |0 |Normal |1 | | |8040 |BTStackServer.exe |Bluetooth Stack COM Server |12.0.0.9800 |0 |Normal |23 | | |8060 |Lenovo.HarmonySetting.exe |Lenovo.HarmonySetting |1.0.0.0 |0 |Normal |16 |C:\Program Files (x86)\Lenovo\Harmony\Setting | |8268 |chrome.exe | | |0 |Low |15 | | |8316 |SearchProtocolHost.exe |Microsoft Windows Search Protocol Host |7.0.9600.18722|0 |Low |6 | | |8560 |IAStorIcon.exe |IAStorIcon |13.2.0.1016 |0 |Normal |5 |C:\Program Files\Intel\Intel(R) Rapid Storage Technology | |8660 |explorer.exe |Windows Explorer |6.3.9600.18460|0 |Normal |67 | | |8804 |iumsvc.exe | | |0 |Normal |6 | | |9172 |Adobe Desktop Service.exe |Creative Cloud |4.3.0.256 |0 |Normal |30 |C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS | |9332 |CCSDK.exe | | |0 |Normal |10 | | |9384 |updateui.exe |Intel(R) Update Manager | |0 |Normal |6 |C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\ui | |9400 |LMS.exe | | |0 |Normal |4 | | |9480 |wmpnetwk.exe | | |0 |Normal |8 | | |9488 |mcautoreg.exe | | |0 |Normal |2 | | |9588 |CltMngSvc.exe | | |0 |Normal |5 | | |9604 |WinGather.exe | |1.0.3.4 |0 |Normal |2 |C:\Program Files (x86)\Lenovo\CCSDK | |9644 |tpknrres.exe |Lenovo® AVFramework Native 32-Bit Server |4.3.5.0 |0 |Normal |38 |C:\Program Files\Lenovo\Communications Utility | |10080|IAStorDataMgrSvc.exe | | |0 |Normal |5 | | |10112|SearchFilterHost.exe |Microsoft Windows Search Filter Host |7.0.9600.17415|0 |Low |8 | | |10144|chrome.exe | | |0 |Low |13 | | |10160|IntelMeFWService.exe | | |0 |Normal |2 | | |10204|McUICnt.exe | | |0 |Normal |1 | | |10616|CCXProcess.exe |CCXProcess |2.1.0.426 |0 |Normal |1 |C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess | |10624|node.exe |Node.js: Server-side JavaScript |6.9.2.0 |0 |Normal |21 |C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs | |10632|conhost.exe | | |0 |Normal |1 | | |10832|conhost.exe | | |0 |Normal |1 | | |11032|CCLibrary.exe |CCLibraries |2.11.0.966 |0 |Normal |1 |C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary | |11072|node.exe |Node.js: Server-side JavaScript |6.9.2.0 |0 |Normal |22 |C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Assembler Information: --------------------------------------------------------------- 0048A1FB add [ebx+$B848C00D], cl 0048A201 add [edx+$1778A101], dh 0048A207 inc esi 0048A208 add al, ch 0048A20A and dh, byte ptr [esi+$95E8FFF8] 0048A210 mov edx, $8BC3FFF7 ; ''... 0048A215 or eax, $00B848BC ; 'Xlj.øjj.' 0048A21A mov dl, $01 0048A21C mov eax, dword ptr [EMultiFree] 0048A221 call -$000749F6 0048A226 call -$00084583 ; <-- EXCEPTION 0048A22B ret Registers: ----------------------------- EAX: 0450CC80 EDI: 0040629C EBX: 0CF07370 ESI: 00000000 ECX: 0450CC00 ESP: 0D09FF18 EDX: 0048A22B EIP: 0048A226 Stack: Memory Dump: ------------------ --------------------------------------------------------------------------- 0D09FF18: 0040B1AF 08240160: E8 7D BA F7 FF C3 68 84 2D BB 00 E8 FA F1 F7 FF .}....h.-....... 0D09FF1C: 0D09FF2C 08240170: C3 90 55 8B EC 6A 00 33 C0 55 68 BF A2 48 00 64 ..U..j.3.Uh..H.d 0D09FF20: 0040B267 08240180: FF 30 64 89 20 A1 98 9B BA 00 C7 00 3C 99 48 00 .0d. .......<.H. 0D09FF24: 025C6A09 08240190: A1 EC 9A BA 00 C7 00 BC 9B 48 00 A1 CC 9D BA 00 .........H...... 0D09FF28: 0CF07240 082401A0: C7 00 40 9D 48 00 A1 E0 9C BA 00 C7 00 FC A1 48 ..@.H..........H 0D09FF2C: 0D09FF4C 082401B0: 00 A1 94 A3 BA 00 C7 00 14 A2 48 00 8D 45 FC E8 ..........H..E.. 0D09FF30: 004034AA 082401C0: F2 0F FE FF 8B 45 FC E8 7A C5 F7 FF 8B D0 B8 84 .....E..z....... 0D09FF34: 004052ED 082401D0: 2D BB 00 E8 9A 57 F8 FF A1 48 A9 BA 00 C7 00 2C -....W...H....., 0D09FF38: 00000001 082401E0: A2 48 00 33 C0 5A 59 59 64 89 10 68 C6 A2 48 00 .H.3.ZYYd..h..H. 0D09FF3C: 004056E9 082401F0: 8D 45 FC E8 92 C0 F7 FF C3 E9 40 B8 F7 FF EB F0 .E........@..... 0D09FF40: 00710DB7 08240200: 59 5D C3 8D 40 00 55 8B EC 33 C9 51 51 51 51 51 Y]..@.U..3.QQQQQ 0D09FF44: 01000000 08240210: 53 56 8B 75 08 33 C0 55 68 F6 A3 48 00 64 FF 30 SV.u.3.Uh..H.d.0 0D09FF48: 0CF07370 08240220: 64 89 20 E8 56 E5 FF FF 84 C0 0F 84 DC 00 00 00 d. .V........... 0D09FF4C: 0D09FF6C 08240230: E8 F5 E1 FF FF 84 C0 0F 84 CF 00 00 00 C6 05 98 ................ 0D09FF50: 00405333 08240240: 2A BB 00 01 33 DB E8 67 92 F7 FF 8B 15 1C CC 40 *...3..g.......@ 0D09FF54: 00432A07 08240250: 00 E8 A0 B1 F7 FF 84 C0 74 07 E8 53 92 F7 FF 8B ........t..S....