date/time         : 2011-10-08, 13:22:21, 278ms
computer name     : DRAGON-
user name         : Dr@goN <admin>
registered owner  : Microsoft / Microsoft
operating system  : Windows 7 x64 build 7600
system language   : Russian
system up time    : 2 hours 11 minutes
program up time   : 5 seconds
processors        : 3x AMD Athlon(tm) II X3 435 Processor
physical memory   : 4533/6142 MB (free/total)
free disk space   : (C:) 17,87 GB (E:) 162,66 GB
display mode      : 1600x900, 32 bit
process id        : $54c
allocated memory  : 81,23 MB
executable        : Phoenix.exe
current module    : Main.dll
module date/time  : 2011-09-04 21:33
version           : 1.0.4.27
compiled with     : Delphi 2010
madExcept version : 3.0m
callstack crc     : $c259a765, $2049a846, $d65ef6ea
exception number  : 1
exception class   : Exception
exception message : Unknown.

main thread ($1070):
027464ba +04e Main.dll     MzL_Main 1037  +4 LoadTGA
02746a00 +108 Main.dll     MzL_Main 1141 +17 @TModZList.SetIconForMod
02747553 +643 Main.dll     MzL_Main 1299 +96 @TModZList.AddMod
0274fbc9 +439 Main.dll     MzL_Main 4408 +67 @@ModZArray_AddMod
76bc7b4f +02d USER32.dll                     SetWindowTextA
76bd27b3 +031 USER32.dll                     DialogBoxIndirectParamAorW
76bfcc61 +047 USER32.dll                     DialogBoxParamA
766e3675 +010 kernel32.dll                   BaseThreadInitThunk

thread $115c:
773d1edf +0b ntdll.dll     NtWaitForWorkViaWorkerFactory
766e3675 +10 kernel32.dll  BaseThreadInitThunk

thread $96c:
773d1edf +0b ntdll.dll     NtWaitForWorkViaWorkerFactory
766e3675 +10 kernel32.dll  BaseThreadInitThunk

thread $b6c:
773d00f6 +0e ntdll.dll       NtWaitForMultipleObjects
7686095c +fa KERNELBASE.dll  WaitForMultipleObjectsEx
766e1628 +89 kernel32.dll    WaitForMultipleObjectsEx
76bc03d4 +f4 USER32.dll      MsgWaitForMultipleObjectsEx
76bc0669 +1a USER32.dll      MsgWaitForMultipleObjects
766e3675 +10 kernel32.dll    BaseThreadInitThunk

thread $fa4:
76bc4386 +0e USER32.dll                  WaitMessage
76bd27b3 +31 USER32.dll                  DialogBoxIndirectParamAorW
76bd2a9c +3a USER32.dll                  DialogBoxParamW
025ce985 +0d Main.dll     Windows        @@DialogBox
02764f13 +37 Main.dll     Banner  381 +3 @@BannerThread
766e3675 +10 kernel32.dll                BaseThreadInitThunk

thread $f48:
773d00f6 +0e ntdll.dll     NtWaitForMultipleObjects
766e3675 +10 kernel32.dll  BaseThreadInitThunk

modules:
00300000 System.dll                           D:\Temp\nsiA4F.tmp
00400000 Phoenix.exe       1.0.4.28           E:\Games\Phoenix_15beta8
004b0000 lua.dll                              E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
00530000 RainCWrapper.dll                     E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
00590000 SimDecrypt.dll                       E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
025c0000 Main.dll          1.0.4.27           E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
04880000 NSISArray.dll                        D:\Temp\nsiA4F.tmp
04af0000 unicode.dll                          E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
04ba0000 HLLib.dll         2.4.0.0            E:\Games\Phoenix_15beta8\Phx_Data\Res\SharedDLLs
04be0000 Phx_Default.dll   1.0.5.8            E:\Games\Phoenix_15beta8\Phx_Data\Plugins
04d10000 Amhooker.dll                         C:\Windows\system32
051a0000 ButtonEvent.dll                      D:\Temp\nsiA4F.tmp
051b0000 nsDialogs.dll                        D:\Temp\nsiA4F.tmp
10000000 RocketDock.dll                       C:\Program Files (x86)\RocketDock
6e0f0000 rain.dll                             E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
6fe90000 RichEd20.DLL      5.31.23.1229       C:\Windows\system32
70010000 LINKINFO.dll      6.1.7600.16385     C:\Windows\system32
711d0000 ntshrui.dll       6.1.7600.16385     C:\Windows\system32
71310000 slc.dll           6.1.7600.16385     C:\Windows\system32
71320000 cscapi.dll        6.1.7600.16385     C:\Windows\system32
717d0000 WindowsCodecs.dll 6.1.7600.16385     C:\Windows\system32
718d0000 ntmarta.dll       6.1.7600.16385     C:\Windows\system32
71900000 propsys.dll       7.0.7600.16385     C:\Windows\system32
71a70000 gdiplus.dll       6.1.7600.16385     C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca
72150000 COMCTL32.dll      6.10.7600.16385    C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc
72360000 msimg32.dll       6.1.7600.16385     C:\Windows\system32
729b0000 msvfw32.dll       6.1.7600.16385     C:\Windows\system32
72a20000 VDFParse.dll                         E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
72b80000 uxtheme.dll       6.1.7600.16385     C:\Windows\system32
72c00000 profapi.dll       6.1.7600.16385     C:\Windows\system32
72c30000 VERSION.dll       6.1.7600.16385     C:\Windows\system32
72c60000 dwmapi.dll        6.1.7600.16385     C:\Windows\system32
72c80000 winspool.drv      6.1.7600.16385     C:\Windows\system32
72d20000 winmm.dll         6.1.7600.16385     C:\Windows\system32
72d60000 srvcli.dll        6.1.7600.16385     C:\Windows\system32
72d80000 netutils.dll      6.1.7600.16385     C:\Windows\system32
72d90000 NETAPI32.dll      6.1.7600.16385     C:\Windows\system32
72e50000 MSVCR80.dll       8.0.50727.4927     C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b5
72f50000 SHFOLDER.DLL      6.1.7600.16385     C:\Windows\system32
73050000 wkscli.dll        6.1.7600.16385     C:\Windows\system32
74300000 wsock32.dll       6.1.7600.16385     C:\Windows\system32
749d0000 CRYPTBASE.dll     6.1.7600.16385     C:\Windows\syswow64
749e0000 SspiCli.dll       6.1.7600.16385     C:\Windows\syswow64
74a40000 ADVAPI32.dll      6.1.7600.16385     C:\Windows\syswow64
74ae0000 iertutil.dll      8.0.7600.16385     C:\Windows\syswow64
74d40000 DEVOBJ.dll        6.1.7600.16385     C:\Windows\syswow64
74d60000 WLDAP32.dll       6.1.7600.16385     C:\Windows\syswow64
74db0000 msvcrt.dll        7.0.7600.16385     C:\Windows\syswow64
74e60000 Normaliz.dll      6.1.7600.16385     C:\Windows\syswow64
74e70000 IMM32.DLL         6.1.7600.16385     C:\Windows\system32
74ed0000 SHLWAPI.dll       6.1.7600.16385     C:\Windows\syswow64
74f30000 wininet.dll       8.0.7600.16535     C:\Windows\syswow64
75030000 CRYPT32.dll       6.1.7600.16385     C:\Windows\syswow64
75180000 ole32.dll         6.1.7600.16385     C:\Windows\syswow64
752e0000 SHELL32.dll       6.1.7600.16460     C:\Windows\syswow64
76470000 LPK.dll           6.1.7600.16385     C:\Windows\syswow64
76510000 sechost.dll       6.1.7600.16385     C:\Windows\SysWOW64
76530000 SETUPAPI.dll      6.1.7600.16385     C:\Windows\syswow64
766d0000 kernel32.dll      6.1.7600.16385     C:\Windows\syswow64
767d0000 comdlg32.dll      6.1.7600.16385     C:\Windows\syswow64
76850000 KERNELBASE.dll    6.1.7600.16385     C:\Windows\syswow64
768d0000 CFGMGR32.dll      6.1.7600.16385     C:\Windows\syswow64
76900000 CLBCatQ.DLL       2001.12.8530.16385 C:\Windows\syswow64
76990000 GDI32.dll         6.1.7600.16385     C:\Windows\syswow64
76a20000 PSAPI.DLL         6.1.7600.16385     C:\Windows\syswow64
76a30000 USP10.dll         1.626.7600.16385   C:\Windows\syswow64
76ad0000 MSCTF.dll         6.1.7600.16385     C:\Windows\syswow64
76ba0000 USER32.dll        6.1.7600.16385     C:\Windows\syswow64
76ca0000 RPCRT4.dll        6.1.7600.16385     C:\Windows\syswow64
76d90000 MSASN1.dll        6.1.7600.16415     C:\Windows\syswow64
76da0000 urlmon.dll        8.0.7600.16535     C:\Windows\syswow64
76ee0000 OLEAUT32.dll      6.1.7600.16385     C:\Windows\syswow64
76f70000 WS2_32.dll        6.1.7600.16385     C:\Windows\syswow64
77380000 NSI.dll           6.1.7600.16385     C:\Windows\syswow64
773b0000 ntdll.dll         6.1.7600.16385     C:\Windows\SysWOW64

processes:
0000 Idle                      0 0   0
0004 System                    0 0   0
0170 smss.exe                  0 0   0
01e0 csrss.exe                 0 0   0
021c wininit.exe               0 0   0
0240 csrss.exe                 1 0   0
0258 services.exe              0 0   0
0274 lsass.exe                 0 0   0
027c lsm.exe                   0 0   0
02c4 winlogon.exe              1 0   0
030c svchost.exe               0 0   0
035c svchost.exe               0 0   0
0394 atiesrxx.exe              0 0   0
03d4 svchost.exe               0 0   0
03fc svchost.exe               0 0   0
0194 svchost.exe               0 0   0
0404 svchost.exe               0 0   0
045c svchost.exe               0 0   0
0494 atieclxx.exe              1 0   0
04c4 spoolsv.exe               0 0   0
04e4 svchost.exe               0 0   0
05a8 RAIDXpertService.exe      0 0   0
05cc RAIDXpert.exe             0 0   0
05dc conhost.exe               0 0   0
064c taskeng.exe               1 10  3   normal
0654 taskhost.exe              1 26  21  normal
0698 dwm.exe                   1 18  2   high
06f4 svchost.exe               0 0   0
072c AsSysCtrlService.exe      0 0   0
0750 avp.exe                   0 0   0
076c FourEngine.exe            1 543 81  below normal C:\Program Files (x86)\ASUS\EPU-4 Engine
07f0 DfSdkS64.exe              0 0   0
0434 DVMExportService.exe      0 0   0
0880 CDASrv.exe                1 14  11  normal
0888 LiveTuner.exe             1 62  34  normal       C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 8
0890 Amoumain.exe              1 123 46  normal       C:\Program Files\Mouse
08a0 oodtray.exe               1 142 54  normal
08a8 sidebar.exe               1 92  45  normal
08b0 RocketDock.exe            1 66  64  normal       C:\Program Files (x86)\RocketDock
08b8 IOTraf.exe                1 98  87  normal       C:\Program Files (x86)\TeachStyle\IO Traf
0980 avp.exe                   1 312 151 normal       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012
098c TurboKey.exe              1 184 53  normal       C:\Program Files\ASUS\Turbo Key
09a8 VDeck.exe                 1 962 432 normal
09d4 MOM.exe                   1 10  10  normal
080c CCC.exe                   1 103 64  normal
0968 oodag.exe                 0 0   0
0c04 svchost.exe               0 0   0
0c44 LiveTunerService.exe      0 0   0
0ed8 ServiceLayer.exe          0 0   0
0f74 SearchIndexer.exe         0 0   0
0b48 NclUSBSrv64.exe           0 0   0
0d58 NclRSSrv.exe              0 0   0
11b0 WUDFHost.exe              0 0   0
1190 PresentationFontCache.exe 0 0   0
0420 svchost.exe               0 0   0
1200 svchost.exe               0 0   0
09dc explorer.exe              1 993 400 normal
0fc0 wmpnetwk.exe              0 0   0
05b8 SMSvcHost.exe             0 0   0
125c MpCmdRun.exe              0 0   0
09ec conhost.exe               0 0   0
0630 audiodg.exe               0 0   0
04dc WmiPrvSE.exe              0 0   0
054c Phoenix.exe               1 86  98  normal       E:\Games\Phoenix_15beta8
0dc4 dllhost.exe               1 9   5   normal

cpu registers:
eax = 00000000
ebx = 085e2340
ecx = 0318a358
edx = 03189780
esi = 0836fa00
edi = 00000000
eip = 027464ba
esp = 0018eae8
ebp = 0018eb30

stack dump:
0018eae8  3c eb 18 00 b0 62 5c 02 - 30 eb 18 00 00 fa 36 08  <....b\.0.....6.
0018eaf8  40 23 5e 08 fc ec 18 00 - f6 42 5c 02 88 eb 18 00  @#^......B\.....
0018eb08  f6 42 5c 02 3c 6d 5c 02 - 4a 00 00 00 e0 2a 52 08  .B\.<m\.J....*R.
0018eb18  ac 2a 52 08 a3 6d 5c 02 - 00 00 00 00 00 00 00 00  .*R..m\.........
0018eb28  00 00 00 00 00 00 00 00 - 14 ed 18 00 05 6a 74 02  .............jt.
0018eb38  14 ed 18 00 1c ed 18 00 - b0 62 5c 02 14 ed 18 00  .........b\.....
0018eb48  40 23 5e 08 00 fa 36 08 - 98 ee 18 00 00 00 00 00  @#^...6.........
0018eb58  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018eb68  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018eb78  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018eb88  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018eb98  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018eba8  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ebb8  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ebc8  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ebd8  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ebe8  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ebf8  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ec08  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ec18  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

disassembling:
[...]
02746482        call    -$17f037 ($25c7450)    ; @.LStrAddRef
02746482
02746487        xor     eax, eax
02746489        push    ebp
0274648a        push    $27467d9               ; @.HandleFinally
0274648f        push    dword ptr fs:[eax]
02746492        mov     fs:[eax], esp
02746495 1034   call    -$48f1e ($26fd57c)     ; KOLTGA.@@NewTarga
02746495
0274649a        mov     edx, [ebp+8]
0274649d        mov     [edx-4], eax
027464a0 1035   mov     eax, [ebp+8]
027464a3        mov     eax, [eax-4]
027464a6        mov     edx, [ebp-4]
027464a9        mov     ecx, [eax]
027464ab        call    dword ptr [ecx+$20]
027464ab
027464ae 1037   mov     eax, [ebp+8]
027464b1        mov     eax, [eax-4]
027464b4        mov     eax, [eax+$fd4]
027464ba      > mov     eax, [eax+$45]
027464bd        mov     edx, [ebp+8]
027464c0        mov     edx, [edx-4]
027464c3        mov     edx, [edx+$fd8]
027464c9        cmp     eax, [edx+$45]
027464cc        jz      loc_27464de
027464cc
027464ce 1039   mov     eax, [ebp+8]
027464d1        mov     eax, [eax-4]
027464d4        call    -$f2ee5 ($26535f4)     ; KOL.@TObj.RefDec
027464d4
027464d9 1040   jmp     loc_27467a7
027464d9
027464d9      ; ---------------------------------------------------------
027464d9
027464de      loc_27464de:
027464de 1043   mov     eax, [ebp+8]
027464e1        mov     eax, [eax-4]
027464e4        mov     eax, [eax+$fd4]
027464ea        fild    dword ptr [eax+$45]
027464ed        fdiv    dword ptr [$27467e8]
[...]

date/time         : 2011-10-08, 13:22:47, 829ms
computer name     : DRAGON-
user name         : Dr@goN <admin>
registered owner  : Microsoft / Microsoft
operating system  : Windows 7 x64 build 7600
system language   : Russian
system up time    : 2 hours 11 minutes
program up time   : 32 seconds
processors        : 3x AMD Athlon(tm) II X3 435 Processor
physical memory   : 4546/6142 MB (free/total)
free disk space   : (C:) 17,87 GB (E:) 162,66 GB
display mode      : 1600x900, 32 bit
process id        : $54c
allocated memory  : 84,66 MB
executable        : Phoenix.exe
current module    : Main.dll
module date/time  : 2011-09-04 21:33
version           : 1.0.4.27
compiled with     : Delphi 2010
madExcept version : 3.0m
callstack crc     : $b498981e, $a4d7f6fc, $c7a4bb03
exception number  : 2
exception class   : EArgumentOutOfRangeException
exception message : Argument out of range.

main thread ($1070):
02763290 +020 Main.dll     @TList<GDIPOBJ           TGPBitmap>.GetItem
02754599 +ba1 Main.dll     MzL_Main       5543 +178 @@ModZArray_ByGet
76bd27b3 +031 USER32.dll                            DialogBoxIndirectParamAorW
76bfcc61 +047 USER32.dll                            DialogBoxParamA
766e3675 +010 kernel32.dll                          BaseThreadInitThunk

thread $115c:
773d1edf +0b ntdll.dll     NtWaitForWorkViaWorkerFactory
766e3675 +10 kernel32.dll  BaseThreadInitThunk

thread $96c:
773d1edf +0b ntdll.dll     NtWaitForWorkViaWorkerFactory
766e3675 +10 kernel32.dll  BaseThreadInitThunk

thread $b6c:
773d00f6 +0e ntdll.dll       NtWaitForMultipleObjects
7686095c +fa KERNELBASE.dll  WaitForMultipleObjectsEx
766e1628 +89 kernel32.dll    WaitForMultipleObjectsEx
76bc03d4 +f4 USER32.dll      MsgWaitForMultipleObjectsEx
76bc0669 +1a USER32.dll      MsgWaitForMultipleObjects
766e3675 +10 kernel32.dll    BaseThreadInitThunk

thread $fa4:
76bc4386 +0e USER32.dll                  WaitMessage
76bd27b3 +31 USER32.dll                  DialogBoxIndirectParamAorW
76bd2a9c +3a USER32.dll                  DialogBoxParamW
025ce985 +0d Main.dll     Windows        @@DialogBox
02764f13 +37 Main.dll     Banner  381 +3 @@BannerThread
766e3675 +10 kernel32.dll                BaseThreadInitThunk

thread $f48:
773d00f6 +0e ntdll.dll     NtWaitForMultipleObjects
766e3675 +10 kernel32.dll  BaseThreadInitThunk

modules:
00300000 System.dll                           D:\Temp\nsiA4F.tmp
00400000 Phoenix.exe       1.0.4.28           E:\Games\Phoenix_15beta8
004b0000 lua.dll                              E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
00530000 RainCWrapper.dll                     E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
00590000 SimDecrypt.dll                       E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
025c0000 Main.dll          1.0.4.27           E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
04880000 NSISArray.dll                        D:\Temp\nsiA4F.tmp
04af0000 unicode.dll                          E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
04ba0000 HLLib.dll         2.4.0.0            E:\Games\Phoenix_15beta8\Phx_Data\Res\SharedDLLs
04be0000 Phx_Default.dll   1.0.5.8            E:\Games\Phoenix_15beta8\Phx_Data\Plugins
04d10000 Amhooker.dll                         C:\Windows\system32
051a0000 ButtonEvent.dll                      D:\Temp\nsiA4F.tmp
051b0000 nsDialogs.dll                        D:\Temp\nsiA4F.tmp
10000000 RocketDock.dll                       C:\Program Files (x86)\RocketDock
6e0f0000 rain.dll                             E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
6fe90000 RichEd20.DLL      5.31.23.1229       C:\Windows\system32
70010000 LINKINFO.dll      6.1.7600.16385     C:\Windows\system32
711d0000 ntshrui.dll       6.1.7600.16385     C:\Windows\system32
71310000 slc.dll           6.1.7600.16385     C:\Windows\system32
71320000 cscapi.dll        6.1.7600.16385     C:\Windows\system32
717d0000 WindowsCodecs.dll 6.1.7600.16385     C:\Windows\system32
718d0000 ntmarta.dll       6.1.7600.16385     C:\Windows\system32
71900000 propsys.dll       7.0.7600.16385     C:\Windows\system32
71a70000 gdiplus.dll       6.1.7600.16385     C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca
72150000 COMCTL32.dll      6.10.7600.16385    C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc
72360000 msimg32.dll       6.1.7600.16385     C:\Windows\system32
729b0000 msvfw32.dll       6.1.7600.16385     C:\Windows\system32
72a20000 VDFParse.dll                         E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
72b80000 uxtheme.dll       6.1.7600.16385     C:\Windows\system32
72c00000 profapi.dll       6.1.7600.16385     C:\Windows\system32
72c30000 VERSION.dll       6.1.7600.16385     C:\Windows\system32
72c60000 dwmapi.dll        6.1.7600.16385     C:\Windows\system32
72c80000 winspool.drv      6.1.7600.16385     C:\Windows\system32
72d20000 winmm.dll         6.1.7600.16385     C:\Windows\system32
72d60000 srvcli.dll        6.1.7600.16385     C:\Windows\system32
72d80000 netutils.dll      6.1.7600.16385     C:\Windows\system32
72d90000 NETAPI32.dll      6.1.7600.16385     C:\Windows\system32
72e50000 MSVCR80.dll       8.0.50727.4927     C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b5
72f50000 SHFOLDER.DLL      6.1.7600.16385     C:\Windows\system32
73050000 wkscli.dll        6.1.7600.16385     C:\Windows\system32
74300000 wsock32.dll       6.1.7600.16385     C:\Windows\system32
749d0000 CRYPTBASE.dll     6.1.7600.16385     C:\Windows\syswow64
749e0000 SspiCli.dll       6.1.7600.16385     C:\Windows\syswow64
74a40000 ADVAPI32.dll      6.1.7600.16385     C:\Windows\syswow64
74ae0000 iertutil.dll      8.0.7600.16385     C:\Windows\syswow64
74d40000 DEVOBJ.dll        6.1.7600.16385     C:\Windows\syswow64
74d60000 WLDAP32.dll       6.1.7600.16385     C:\Windows\syswow64
74db0000 msvcrt.dll        7.0.7600.16385     C:\Windows\syswow64
74e60000 Normaliz.dll      6.1.7600.16385     C:\Windows\syswow64
74e70000 IMM32.DLL         6.1.7600.16385     C:\Windows\system32
74ed0000 SHLWAPI.dll       6.1.7600.16385     C:\Windows\syswow64
74f30000 wininet.dll       8.0.7600.16535     C:\Windows\syswow64
75030000 CRYPT32.dll       6.1.7600.16385     C:\Windows\syswow64
75180000 ole32.dll         6.1.7600.16385     C:\Windows\syswow64
752e0000 SHELL32.dll       6.1.7600.16460     C:\Windows\syswow64
76470000 LPK.dll           6.1.7600.16385     C:\Windows\syswow64
76510000 sechost.dll       6.1.7600.16385     C:\Windows\SysWOW64
76530000 SETUPAPI.dll      6.1.7600.16385     C:\Windows\syswow64
766d0000 kernel32.dll      6.1.7600.16385     C:\Windows\syswow64
767d0000 comdlg32.dll      6.1.7600.16385     C:\Windows\syswow64
76850000 KERNELBASE.dll    6.1.7600.16385     C:\Windows\syswow64
768d0000 CFGMGR32.dll      6.1.7600.16385     C:\Windows\syswow64
76900000 CLBCatQ.DLL       2001.12.8530.16385 C:\Windows\syswow64
76990000 GDI32.dll         6.1.7600.16385     C:\Windows\syswow64
76a20000 PSAPI.DLL         6.1.7600.16385     C:\Windows\syswow64
76a30000 USP10.dll         1.626.7600.16385   C:\Windows\syswow64
76ad0000 MSCTF.dll         6.1.7600.16385     C:\Windows\syswow64
76ba0000 USER32.dll        6.1.7600.16385     C:\Windows\syswow64
76ca0000 RPCRT4.dll        6.1.7600.16385     C:\Windows\syswow64
76d90000 MSASN1.dll        6.1.7600.16415     C:\Windows\syswow64
76da0000 urlmon.dll        8.0.7600.16535     C:\Windows\syswow64
76ee0000 OLEAUT32.dll      6.1.7600.16385     C:\Windows\syswow64
76f70000 WS2_32.dll        6.1.7600.16385     C:\Windows\syswow64
77380000 NSI.dll           6.1.7600.16385     C:\Windows\syswow64
773b0000 ntdll.dll         6.1.7600.16385     C:\Windows\SysWOW64

processes:
0000 Idle                      0 0   0
0004 System                    0 0   0
0170 smss.exe                  0 0   0
01e0 csrss.exe                 0 0   0
021c wininit.exe               0 0   0
0240 csrss.exe                 1 0   0
0258 services.exe              0 0   0
0274 lsass.exe                 0 0   0
027c lsm.exe                   0 0   0
02c4 winlogon.exe              1 0   0
030c svchost.exe               0 0   0
035c svchost.exe               0 0   0
0394 atiesrxx.exe              0 0   0
03d4 svchost.exe               0 0   0
03fc svchost.exe               0 0   0
0194 svchost.exe               0 0   0
0404 svchost.exe               0 0   0
045c svchost.exe               0 0   0
0494 atieclxx.exe              1 0   0
04c4 spoolsv.exe               0 0   0
04e4 svchost.exe               0 0   0
05a8 RAIDXpertService.exe      0 0   0
05cc RAIDXpert.exe             0 0   0
05dc conhost.exe               0 0   0
064c taskeng.exe               1 10  3   normal
0654 taskhost.exe              1 26  20  normal
0698 dwm.exe                   1 18  2   high
06f4 svchost.exe               0 0   0
072c AsSysCtrlService.exe      0 0   0
0750 avp.exe                   0 0   0
076c FourEngine.exe            1 543 81  below normal C:\Program Files (x86)\ASUS\EPU-4 Engine
07f0 DfSdkS64.exe              0 0   0
0434 DVMExportService.exe      0 0   0
0880 CDASrv.exe                1 14  11  normal
0888 LiveTuner.exe             1 62  34  normal       C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 8
0890 Amoumain.exe              1 123 46  normal       C:\Program Files\Mouse
08a0 oodtray.exe               1 142 54  normal
08a8 sidebar.exe               1 92  45  normal
08b0 RocketDock.exe            1 66  63  normal       C:\Program Files (x86)\RocketDock
08b8 IOTraf.exe                1 98  87  normal       C:\Program Files (x86)\TeachStyle\IO Traf
0980 avp.exe                   1 312 151 normal       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012
098c TurboKey.exe              1 184 53  normal       C:\Program Files\ASUS\Turbo Key
09a8 VDeck.exe                 1 962 432 normal
09d4 MOM.exe                   1 10  10  normal
080c CCC.exe                   1 103 64  normal
0968 oodag.exe                 0 0   0
0c04 svchost.exe               0 0   0
0c44 LiveTunerService.exe      0 0   0
0ed8 ServiceLayer.exe          0 0   0
0f74 SearchIndexer.exe         0 0   0
0b48 NclUSBSrv64.exe           0 0   0
0d58 NclRSSrv.exe              0 0   0
11b0 WUDFHost.exe              0 0   0
1190 PresentationFontCache.exe 0 0   0
0420 svchost.exe               0 0   0
1200 svchost.exe               0 0   0
09dc explorer.exe              1 992 392 normal
0fc0 wmpnetwk.exe              0 0   0
05b8 SMSvcHost.exe             0 0   0
125c MpCmdRun.exe              0 0   0
09ec conhost.exe               0 0   0
0630 audiodg.exe               0 0   0
04dc WmiPrvSE.exe              0 0   0
054c Phoenix.exe               1 87  104 normal       E:\Games\Phoenix_15beta8

disassembling:
[...]
02754565 5543   mov     eax, [ebp-$24]
02754568        mov     edx, [ebp-4]
0275456b        test    edx, edx
0275456d        jz      loc_2754574
0275456d
0275456f        cmp     eax, [edx-4]
02754572        jb      loc_2754579
02754572
02754574      loc_2754574:
02754574        call    -$18ee69 ($25c5710)    ; @.BoundErr
02754574
02754579      loc_2754579:
02754579        mov     edx, [edx+eax*4]
0275457c        mov     eax, [$2790e60]
02754581        mov     eax, [eax+$464]
02754587        call    -$100d4c ($2653840)    ; KOL.@TList.IndexOf
02754587
0275458c        mov     edx, eax
0275458e        mov     eax, [$2790e60]
02754593        mov     eax, [eax+$474]
02754599      > call    +$ecd2 ($2763270)      ; @TList<GDIPOBJ.TGPBitmap>.GetItem
02754599
0275459e        lea     edx, [ebp-$2c]
027545a1        call    -$10586e ($264ed38)    ; GDIPOBJ.@TGPBitmap.GetHICON
027545a1
027545a6        test    eax, eax
027545a8        jnz     loc_2754658
027545a8
027545ae 5545   xor     eax, eax
027545b0        push    ebp
027545b1        push    $27545f6               ; @.HandleAnyException
027545b6        push    dword ptr fs:[eax]
027545b9        mov     fs:[eax], esp
027545bc 5546   push    0
027545be        push    $10
027545c0        push    $10
027545c2        push    1
027545c4        mov     eax, [ebp-$2c]
027545c7        push    eax
027545c8        call    -$186475 ($25ce158)    ; Windows.@@CopyImage
027545c8
[...]

date/time         : 2011-10-08, 13:22:58, 2ms
computer name     : DRAGON-
user name         : Dr@goN <admin>
registered owner  : Microsoft / Microsoft
operating system  : Windows 7 x64 build 7600
system language   : Russian
system up time    : 2 hours 11 minutes
program up time   : 42 seconds
processors        : 3x AMD Athlon(tm) II X3 435 Processor
physical memory   : 4587/6142 MB (free/total)
free disk space   : (C:) 17,87 GB (E:) 162,66 GB
display mode      : 1600x900, 32 bit
process id        : $54c
allocated memory  : 84,58 MB
executable        : Phoenix.exe
current module    : Main.dll
module date/time  : 2011-09-04 21:33
version           : 1.0.4.27
compiled with     : Delphi 2010
madExcept version : 3.0m
callstack crc     : $086fcd7f, $85e223f7, $75bf1931
exception number  : 3
exception class   : EArgumentOutOfRangeException
exception message : Argument out of range.

main thread ($1070):
02763324 +028 Main.dll      @TList<GDIPOBJ           TGPBitmap>.DoDelete
02763846 +002 Main.dll      @TList<GDIPOBJ           TGPBitmap>.Delete
0274789d +02d Main.dll      MzL_Main       1313   +3 @TModZList.Delete
0274794c +034 Main.dll      MzL_Main       1339   +4 @TModZList.Clear
027517a5 +131 Main.dll      MzL_Main       4829  +28 @@ModZArray_CopyItemsToOldArray
76bc7b0a +016 USER32.dll                             CallWindowProcA
02749b69 +389 Main.dll      MzL_Main       2431 +105 @@ChildDlgProc
76bdef3b +047 USER32.dll                             SendMessageA
02749a8a +2aa Main.dll      MzL_Main       2402  +76 @@ChildDlgProc
76bb7df5 +00a USER32.dll                             DispatchMessageW
76bd228d +119 USER32.dll                             IsDialogMessageW
76bd70a4 +053 USER32.dll                             IsDialogMessage
051b1cab +052 nsDialogs.dll                          Show
76bd27b3 +031 USER32.dll                             DialogBoxIndirectParamAorW
76bfcc61 +047 USER32.dll                             DialogBoxParamA
766e3675 +010 kernel32.dll                           BaseThreadInitThunk

thread $115c:
773d1edf +0b ntdll.dll     NtWaitForWorkViaWorkerFactory
766e3675 +10 kernel32.dll  BaseThreadInitThunk

thread $96c:
773d1edf +0b ntdll.dll     NtWaitForWorkViaWorkerFactory
766e3675 +10 kernel32.dll  BaseThreadInitThunk

thread $b6c:
773d00f6 +0e ntdll.dll       NtWaitForMultipleObjects
7686095c +fa KERNELBASE.dll  WaitForMultipleObjectsEx
766e1628 +89 kernel32.dll    WaitForMultipleObjectsEx
76bc03d4 +f4 USER32.dll      MsgWaitForMultipleObjectsEx
76bc0669 +1a USER32.dll      MsgWaitForMultipleObjects
766e3675 +10 kernel32.dll    BaseThreadInitThunk

thread $f48:
773d00f6 +0e ntdll.dll     NtWaitForMultipleObjects
766e3675 +10 kernel32.dll  BaseThreadInitThunk

thread $e20:
773d1edf +0b ntdll.dll     NtWaitForWorkViaWorkerFactory
766e3675 +10 kernel32.dll  BaseThreadInitThunk

thread $8e0:
76bc4386 +0e USER32.dll                  WaitMessage
76bd27b3 +31 USER32.dll                  DialogBoxIndirectParamAorW
76bd2a9c +3a USER32.dll                  DialogBoxParamW
025ce985 +0d Main.dll     Windows        @@DialogBox
02764f13 +37 Main.dll     Banner  381 +3 @@BannerThread
766e3675 +10 kernel32.dll                BaseThreadInitThunk

modules:
00300000 System.dll                           D:\Temp\nsiA4F.tmp
00400000 Phoenix.exe       1.0.4.28           E:\Games\Phoenix_15beta8
004b0000 lua.dll                              E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
00530000 RainCWrapper.dll                     E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
00590000 SimDecrypt.dll                       E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
025c0000 Main.dll          1.0.4.27           E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
04880000 NSISArray.dll                        D:\Temp\nsiA4F.tmp
04af0000 unicode.dll                          E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
04ba0000 HLLib.dll         2.4.0.0            E:\Games\Phoenix_15beta8\Phx_Data\Res\SharedDLLs
04be0000 Phx_Default.dll   1.0.5.8            E:\Games\Phoenix_15beta8\Phx_Data\Plugins
04d10000 Amhooker.dll                         C:\Windows\system32
051a0000 ButtonEvent.dll                      D:\Temp\nsiA4F.tmp
051b0000 nsDialogs.dll                        D:\Temp\nsiA4F.tmp
10000000 RocketDock.dll                       C:\Program Files (x86)\RocketDock
6e0f0000 rain.dll                             E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
6fe90000 RichEd20.DLL      5.31.23.1229       C:\Windows\system32
70010000 LINKINFO.dll      6.1.7600.16385     C:\Windows\system32
711d0000 ntshrui.dll       6.1.7600.16385     C:\Windows\system32
71310000 slc.dll           6.1.7600.16385     C:\Windows\system32
71320000 cscapi.dll        6.1.7600.16385     C:\Windows\system32
717d0000 WindowsCodecs.dll 6.1.7600.16385     C:\Windows\system32
718d0000 ntmarta.dll       6.1.7600.16385     C:\Windows\system32
71900000 propsys.dll       7.0.7600.16385     C:\Windows\system32
71a70000 gdiplus.dll       6.1.7600.16385     C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca
72150000 COMCTL32.dll      6.10.7600.16385    C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc
72360000 msimg32.dll       6.1.7600.16385     C:\Windows\system32
729b0000 msvfw32.dll       6.1.7600.16385     C:\Windows\system32
72a20000 VDFParse.dll                         E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
72b80000 uxtheme.dll       6.1.7600.16385     C:\Windows\system32
72c00000 profapi.dll       6.1.7600.16385     C:\Windows\system32
72c30000 VERSION.dll       6.1.7600.16385     C:\Windows\system32
72c60000 dwmapi.dll        6.1.7600.16385     C:\Windows\system32
72c80000 winspool.drv      6.1.7600.16385     C:\Windows\system32
72d20000 winmm.dll         6.1.7600.16385     C:\Windows\system32
72d60000 srvcli.dll        6.1.7600.16385     C:\Windows\system32
72d80000 netutils.dll      6.1.7600.16385     C:\Windows\system32
72d90000 NETAPI32.dll      6.1.7600.16385     C:\Windows\system32
72e50000 MSVCR80.dll       8.0.50727.4927     C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b5
72f50000 SHFOLDER.DLL      6.1.7600.16385     C:\Windows\system32
73050000 wkscli.dll        6.1.7600.16385     C:\Windows\system32
74300000 wsock32.dll       6.1.7600.16385     C:\Windows\system32
749d0000 CRYPTBASE.dll     6.1.7600.16385     C:\Windows\syswow64
749e0000 SspiCli.dll       6.1.7600.16385     C:\Windows\syswow64
74a40000 ADVAPI32.dll      6.1.7600.16385     C:\Windows\syswow64
74ae0000 iertutil.dll      8.0.7600.16385     C:\Windows\syswow64
74d40000 DEVOBJ.dll        6.1.7600.16385     C:\Windows\syswow64
74d60000 WLDAP32.dll       6.1.7600.16385     C:\Windows\syswow64
74db0000 msvcrt.dll        7.0.7600.16385     C:\Windows\syswow64
74e60000 Normaliz.dll      6.1.7600.16385     C:\Windows\syswow64
74e70000 IMM32.DLL         6.1.7600.16385     C:\Windows\system32
74ed0000 SHLWAPI.dll       6.1.7600.16385     C:\Windows\syswow64
74f30000 wininet.dll       8.0.7600.16535     C:\Windows\syswow64
75030000 CRYPT32.dll       6.1.7600.16385     C:\Windows\syswow64
75180000 ole32.dll         6.1.7600.16385     C:\Windows\syswow64
752e0000 SHELL32.dll       6.1.7600.16460     C:\Windows\syswow64
76470000 LPK.dll           6.1.7600.16385     C:\Windows\syswow64
76510000 sechost.dll       6.1.7600.16385     C:\Windows\SysWOW64
76530000 SETUPAPI.dll      6.1.7600.16385     C:\Windows\syswow64
766d0000 kernel32.dll      6.1.7600.16385     C:\Windows\syswow64
767d0000 comdlg32.dll      6.1.7600.16385     C:\Windows\syswow64
76850000 KERNELBASE.dll    6.1.7600.16385     C:\Windows\syswow64
768d0000 CFGMGR32.dll      6.1.7600.16385     C:\Windows\syswow64
76900000 CLBCatQ.DLL       2001.12.8530.16385 C:\Windows\syswow64
76990000 GDI32.dll         6.1.7600.16385     C:\Windows\syswow64
76a20000 PSAPI.DLL         6.1.7600.16385     C:\Windows\syswow64
76a30000 USP10.dll         1.626.7600.16385   C:\Windows\syswow64
76ad0000 MSCTF.dll         6.1.7600.16385     C:\Windows\syswow64
76ba0000 USER32.dll        6.1.7600.16385     C:\Windows\syswow64
76ca0000 RPCRT4.dll        6.1.7600.16385     C:\Windows\syswow64
76d90000 MSASN1.dll        6.1.7600.16415     C:\Windows\syswow64
76da0000 urlmon.dll        8.0.7600.16535     C:\Windows\syswow64
76ee0000 OLEAUT32.dll      6.1.7600.16385     C:\Windows\syswow64
76f70000 WS2_32.dll        6.1.7600.16385     C:\Windows\syswow64
77380000 NSI.dll           6.1.7600.16385     C:\Windows\syswow64
773b0000 ntdll.dll         6.1.7600.16385     C:\Windows\SysWOW64

processes:
0000 Idle                      0 0   0
0004 System                    0 0   0
0170 smss.exe                  0 0   0
01e0 csrss.exe                 0 0   0
021c wininit.exe               0 0   0
0240 csrss.exe                 1 0   0
0258 services.exe              0 0   0
0274 lsass.exe                 0 0   0
027c lsm.exe                   0 0   0
02c4 winlogon.exe              1 0   0
030c svchost.exe               0 0   0
035c svchost.exe               0 0   0
0394 atiesrxx.exe              0 0   0
03d4 svchost.exe               0 0   0
03fc svchost.exe               0 0   0
0194 svchost.exe               0 0   0
0404 svchost.exe               0 0   0
045c svchost.exe               0 0   0
0494 atieclxx.exe              1 0   0
04c4 spoolsv.exe               0 0   0
04e4 svchost.exe               0 0   0
05a8 RAIDXpertService.exe      0 0   0
05cc RAIDXpert.exe             0 0   0
05dc conhost.exe               0 0   0
064c taskeng.exe               1 10  3   normal
0654 taskhost.exe              1 26  21  normal
0698 dwm.exe                   1 18  2   high
06f4 svchost.exe               0 0   0
072c AsSysCtrlService.exe      0 0   0
0750 avp.exe                   0 0   0
076c FourEngine.exe            1 543 81  below normal C:\Program Files (x86)\ASUS\EPU-4 Engine
07f0 DfSdkS64.exe              0 0   0
0434 DVMExportService.exe      0 0   0
0880 CDASrv.exe                1 14  11  normal
0888 LiveTuner.exe             1 62  34  normal       C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 8
0890 Amoumain.exe              1 123 46  normal       C:\Program Files\Mouse
08a0 oodtray.exe               1 142 54  normal
08a8 sidebar.exe               1 92  45  normal
08b0 RocketDock.exe            1 66  63  normal       C:\Program Files (x86)\RocketDock
08b8 IOTraf.exe                1 98  87  normal       C:\Program Files (x86)\TeachStyle\IO Traf
0980 avp.exe                   1 312 151 normal       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012
098c TurboKey.exe              1 184 53  normal       C:\Program Files\ASUS\Turbo Key
09a8 VDeck.exe                 1 962 432 normal
09d4 MOM.exe                   1 10  10  normal
080c CCC.exe                   1 103 64  normal
0968 oodag.exe                 0 0   0
0c04 svchost.exe               0 0   0
0c44 LiveTunerService.exe      0 0   0
0ed8 ServiceLayer.exe          0 0   0
0f74 SearchIndexer.exe         0 0   0
0b48 NclUSBSrv64.exe           0 0   0
0d58 NclRSSrv.exe              0 0   0
11b0 WUDFHost.exe              0 0   0
1190 PresentationFontCache.exe 0 0   0
0420 svchost.exe               0 0   0
1200 svchost.exe               0 0   0
09dc explorer.exe              1 991 394 normal
0fc0 wmpnetwk.exe              0 0   0
05b8 SMSvcHost.exe             0 0   0
125c MpCmdRun.exe              0 0   0
09ec conhost.exe               0 0   0
0630 audiodg.exe               0 0   0
04dc WmiPrvSE.exe              0 0   0
054c Phoenix.exe               1 95  110 normal       E:\Games\Phoenix_15beta8

disassembling:
02747870      public MzL_Main.@TModZList.Delete:  ; function entry point
02747870 1310   push    ebx
02747871        push    esi
02747872        mov     esi, edx
02747874        mov     ebx, eax
02747876 1311   mov     eax, [ebx+$464]
0274787c        mov     edx, esi
0274787e        call    -$f4057 ($265382c)     ; KOL.@TList.Get
0274787e
02747883        call    -$183580 ($25c4308)    ; @.FreeMem
02747883
02747888 1312   mov     eax, [ebx+$464]
0274788e        mov     edx, esi
02747890        call    -$f40e1 ($26537b4)     ; KOL.@TList.Delete
02747890
02747895 1313   mov     edx, esi
02747897        mov     eax, [ebx+$474]
0274789d      > call    +$1bfa2 ($2763844)     ; @TList<GDIPOBJ.TGPBitmap>.Delete
0274789d
027478a2 1314   mov     eax, [ebx+$464]
027478a8        cmp     dword ptr [eax+$1c], 0
027478ac        jnz     loc_27478b2
027478ac
027478ae 1315   mov     byte ptr [ebx+5], 1
027478ac 1314
027478b2      loc_27478b2:
027478b2 1316   pop     esi
027478b3        pop     ebx
027478b4        ret

date/time         : 2011-10-08, 13:23:08, 200ms
computer name     : DRAGON-
user name         : Dr@goN <admin>
registered owner  : Microsoft / Microsoft
operating system  : Windows 7 x64 build 7600
system language   : Russian
system up time    : 2 hours 12 minutes
program up time   : 52 seconds
processors        : 3x AMD Athlon(tm) II X3 435 Processor
physical memory   : 4580/6142 MB (free/total)
free disk space   : (C:) 17,87 GB (E:) 162,66 GB
display mode      : 1600x900, 32 bit
process id        : $54c
allocated memory  : 84,95 MB
executable        : Phoenix.exe
current module    : Main.dll
module date/time  : 2011-09-04 21:33
version           : 1.0.4.27
compiled with     : Delphi 2010
madExcept version : 3.0m
callstack crc     : $c259a765, $5170ccb0, $130b107d
exception number  : 4
exception class   : Exception
exception message : Unknown.

main thread ($1070):
027464ba +04e Main.dll      MzL_Main 1037   +4 LoadTGA
02746a00 +108 Main.dll      MzL_Main 1141  +17 @TModZList.SetIconForMod
02747553 +643 Main.dll      MzL_Main 1299  +96 @TModZList.AddMod
0274fbc9 +439 Main.dll      MzL_Main 4408  +67 @@ModZArray_AddMod
76bc7b0a +016 USER32.dll                       CallWindowProcA
02749b69 +389 Main.dll      MzL_Main 2431 +105 @@ChildDlgProc
76bdef3b +047 USER32.dll                       SendMessageA
02749a8a +2aa Main.dll      MzL_Main 2402  +76 @@ChildDlgProc
76bb7df5 +00a USER32.dll                       DispatchMessageW
76bd228d +119 USER32.dll                       IsDialogMessageW
76bd70a4 +053 USER32.dll                       IsDialogMessage
051b1cab +052 nsDialogs.dll                    Show
76bd27b3 +031 USER32.dll                       DialogBoxIndirectParamAorW
76bfcc61 +047 USER32.dll                       DialogBoxParamA
766e3675 +010 kernel32.dll                     BaseThreadInitThunk

thread $115c:
773d1edf +0b ntdll.dll     NtWaitForWorkViaWorkerFactory
766e3675 +10 kernel32.dll  BaseThreadInitThunk

thread $96c:
773d1edf +0b ntdll.dll     NtWaitForWorkViaWorkerFactory
766e3675 +10 kernel32.dll  BaseThreadInitThunk

thread $b6c:
773d00f6 +0e ntdll.dll       NtWaitForMultipleObjects
7686095c +fa KERNELBASE.dll  WaitForMultipleObjectsEx
766e1628 +89 kernel32.dll    WaitForMultipleObjectsEx
76bc03d4 +f4 USER32.dll      MsgWaitForMultipleObjectsEx
76bc0669 +1a USER32.dll      MsgWaitForMultipleObjects
766e3675 +10 kernel32.dll    BaseThreadInitThunk

thread $f48:
773d00f6 +0e ntdll.dll     NtWaitForMultipleObjects
766e3675 +10 kernel32.dll  BaseThreadInitThunk

thread $e20:
773d1edf +0b ntdll.dll     NtWaitForWorkViaWorkerFactory
766e3675 +10 kernel32.dll  BaseThreadInitThunk

thread $2e4:
76bc4386 +0e USER32.dll                  WaitMessage
76bd27b3 +31 USER32.dll                  DialogBoxIndirectParamAorW
76bd2a9c +3a USER32.dll                  DialogBoxParamW
025ce985 +0d Main.dll     Windows        @@DialogBox
02764f13 +37 Main.dll     Banner  381 +3 @@BannerThread
766e3675 +10 kernel32.dll                BaseThreadInitThunk

modules:
00300000 System.dll                           D:\Temp\nsiA4F.tmp
00400000 Phoenix.exe       1.0.4.28           E:\Games\Phoenix_15beta8
004b0000 lua.dll                              E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
00530000 RainCWrapper.dll                     E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
00590000 SimDecrypt.dll                       E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
025c0000 Main.dll          1.0.4.27           E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
04880000 NSISArray.dll                        D:\Temp\nsiA4F.tmp
04af0000 unicode.dll                          E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
04ba0000 HLLib.dll         2.4.0.0            E:\Games\Phoenix_15beta8\Phx_Data\Res\SharedDLLs
04be0000 Phx_Default.dll   1.0.5.8            E:\Games\Phoenix_15beta8\Phx_Data\Plugins
04d10000 Amhooker.dll                         C:\Windows\system32
051a0000 ButtonEvent.dll                      D:\Temp\nsiA4F.tmp
051b0000 nsDialogs.dll                        D:\Temp\nsiA4F.tmp
10000000 RocketDock.dll                       C:\Program Files (x86)\RocketDock
6e0f0000 rain.dll                             E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
6fe90000 RichEd20.DLL      5.31.23.1229       C:\Windows\system32
70010000 LINKINFO.dll      6.1.7600.16385     C:\Windows\system32
711d0000 ntshrui.dll       6.1.7600.16385     C:\Windows\system32
71310000 slc.dll           6.1.7600.16385     C:\Windows\system32
71320000 cscapi.dll        6.1.7600.16385     C:\Windows\system32
717d0000 WindowsCodecs.dll 6.1.7600.16385     C:\Windows\system32
718d0000 ntmarta.dll       6.1.7600.16385     C:\Windows\system32
71900000 propsys.dll       7.0.7600.16385     C:\Windows\system32
71a70000 gdiplus.dll       6.1.7600.16385     C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca
72150000 COMCTL32.dll      6.10.7600.16385    C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc
72360000 msimg32.dll       6.1.7600.16385     C:\Windows\system32
729b0000 msvfw32.dll       6.1.7600.16385     C:\Windows\system32
72a20000 VDFParse.dll                         E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
72b80000 uxtheme.dll       6.1.7600.16385     C:\Windows\system32
72c00000 profapi.dll       6.1.7600.16385     C:\Windows\system32
72c30000 VERSION.dll       6.1.7600.16385     C:\Windows\system32
72c60000 dwmapi.dll        6.1.7600.16385     C:\Windows\system32
72c80000 winspool.drv      6.1.7600.16385     C:\Windows\system32
72d20000 winmm.dll         6.1.7600.16385     C:\Windows\system32
72d60000 srvcli.dll        6.1.7600.16385     C:\Windows\system32
72d80000 netutils.dll      6.1.7600.16385     C:\Windows\system32
72d90000 NETAPI32.dll      6.1.7600.16385     C:\Windows\system32
72e50000 MSVCR80.dll       8.0.50727.4927     C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b5
72f50000 SHFOLDER.DLL      6.1.7600.16385     C:\Windows\system32
73050000 wkscli.dll        6.1.7600.16385     C:\Windows\system32
74300000 wsock32.dll       6.1.7600.16385     C:\Windows\system32
749d0000 CRYPTBASE.dll     6.1.7600.16385     C:\Windows\syswow64
749e0000 SspiCli.dll       6.1.7600.16385     C:\Windows\syswow64
74a40000 ADVAPI32.dll      6.1.7600.16385     C:\Windows\syswow64
74ae0000 iertutil.dll      8.0.7600.16385     C:\Windows\syswow64
74d40000 DEVOBJ.dll        6.1.7600.16385     C:\Windows\syswow64
74d60000 WLDAP32.dll       6.1.7600.16385     C:\Windows\syswow64
74db0000 msvcrt.dll        7.0.7600.16385     C:\Windows\syswow64
74e60000 Normaliz.dll      6.1.7600.16385     C:\Windows\syswow64
74e70000 IMM32.DLL         6.1.7600.16385     C:\Windows\system32
74ed0000 SHLWAPI.dll       6.1.7600.16385     C:\Windows\syswow64
74f30000 wininet.dll       8.0.7600.16535     C:\Windows\syswow64
75030000 CRYPT32.dll       6.1.7600.16385     C:\Windows\syswow64
75180000 ole32.dll         6.1.7600.16385     C:\Windows\syswow64
752e0000 SHELL32.dll       6.1.7600.16460     C:\Windows\syswow64
76470000 LPK.dll           6.1.7600.16385     C:\Windows\syswow64
76510000 sechost.dll       6.1.7600.16385     C:\Windows\SysWOW64
76530000 SETUPAPI.dll      6.1.7600.16385     C:\Windows\syswow64
766d0000 kernel32.dll      6.1.7600.16385     C:\Windows\syswow64
767d0000 comdlg32.dll      6.1.7600.16385     C:\Windows\syswow64
76850000 KERNELBASE.dll    6.1.7600.16385     C:\Windows\syswow64
768d0000 CFGMGR32.dll      6.1.7600.16385     C:\Windows\syswow64
76900000 CLBCatQ.DLL       2001.12.8530.16385 C:\Windows\syswow64
76990000 GDI32.dll         6.1.7600.16385     C:\Windows\syswow64
76a20000 PSAPI.DLL         6.1.7600.16385     C:\Windows\syswow64
76a30000 USP10.dll         1.626.7600.16385   C:\Windows\syswow64
76ad0000 MSCTF.dll         6.1.7600.16385     C:\Windows\syswow64
76ba0000 USER32.dll        6.1.7600.16385     C:\Windows\syswow64
76ca0000 RPCRT4.dll        6.1.7600.16385     C:\Windows\syswow64
76d90000 MSASN1.dll        6.1.7600.16415     C:\Windows\syswow64
76da0000 urlmon.dll        8.0.7600.16535     C:\Windows\syswow64
76ee0000 OLEAUT32.dll      6.1.7600.16385     C:\Windows\syswow64
76f70000 WS2_32.dll        6.1.7600.16385     C:\Windows\syswow64
77380000 NSI.dll           6.1.7600.16385     C:\Windows\syswow64
773b0000 ntdll.dll         6.1.7600.16385     C:\Windows\SysWOW64

processes:
0000 Idle                      0 0   0
0004 System                    0 0   0
0170 smss.exe                  0 0   0
01e0 csrss.exe                 0 0   0
021c wininit.exe               0 0   0
0240 csrss.exe                 1 0   0
0258 services.exe              0 0   0
0274 lsass.exe                 0 0   0
027c lsm.exe                   0 0   0
02c4 winlogon.exe              1 0   0
030c svchost.exe               0 0   0
035c svchost.exe               0 0   0
0394 atiesrxx.exe              0 0   0
03d4 svchost.exe               0 0   0
03fc svchost.exe               0 0   0
0194 svchost.exe               0 0   0
0404 svchost.exe               0 0   0
045c svchost.exe               0 0   0
0494 atieclxx.exe              1 0   0
04c4 spoolsv.exe               0 0   0
04e4 svchost.exe               0 0   0
05a8 RAIDXpertService.exe      0 0   0
05cc RAIDXpert.exe             0 0   0
05dc conhost.exe               0 0   0
064c taskeng.exe               1 10  3   normal
0654 taskhost.exe              1 26  21  normal
0698 dwm.exe                   1 18  2   high
06f4 svchost.exe               0 0   0
072c AsSysCtrlService.exe      0 0   0
0750 avp.exe                   0 0   0
076c FourEngine.exe            1 543 81  below normal C:\Program Files (x86)\ASUS\EPU-4 Engine
07f0 DfSdkS64.exe              0 0   0
0434 DVMExportService.exe      0 0   0
0880 CDASrv.exe                1 14  11  normal
0888 LiveTuner.exe             1 62  34  normal       C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 8
0890 Amoumain.exe              1 123 46  normal       C:\Program Files\Mouse
08a0 oodtray.exe               1 142 54  normal
08a8 sidebar.exe               1 92  45  normal
08b0 RocketDock.exe            1 66  63  normal       C:\Program Files (x86)\RocketDock
08b8 IOTraf.exe                1 98  87  normal       C:\Program Files (x86)\TeachStyle\IO Traf
0980 avp.exe                   1 312 151 normal       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012
098c TurboKey.exe              1 184 53  normal       C:\Program Files\ASUS\Turbo Key
09a8 VDeck.exe                 1 962 432 normal
09d4 MOM.exe                   1 10  10  normal
080c CCC.exe                   1 103 64  normal
0968 oodag.exe                 0 0   0
0c04 svchost.exe               0 0   0
0c44 LiveTunerService.exe      0 0   0
0ed8 ServiceLayer.exe          0 0   0
0f74 SearchIndexer.exe         0 0   0
0b48 NclUSBSrv64.exe           0 0   0
0d58 NclRSSrv.exe              0 0   0
11b0 WUDFHost.exe              0 0   0
1190 PresentationFontCache.exe 0 0   0
0420 svchost.exe               0 0   0
1200 svchost.exe               0 0   0
09dc explorer.exe              1 994 399 normal
0fc0 wmpnetwk.exe              0 0   0
05b8 SMSvcHost.exe             0 0   0
125c MpCmdRun.exe              0 0   0
09ec conhost.exe               0 0   0
0630 audiodg.exe               0 0   0
04dc WmiPrvSE.exe              0 0   0
054c Phoenix.exe               1 104 111 normal       E:\Games\Phoenix_15beta8
0af4 dllhost.exe               1 9   5   high

cpu registers:
eax = 00000000
ebx = 085e2340
ecx = 0318a358
edx = 03189780
esi = 0836fa00
edi = 00000000
eip = 027464ba
esp = 0018e15c
ebp = 0018e1a4

stack dump:
0018e15c  b0 e1 18 00 b0 62 5c 02 - a4 e1 18 00 00 fa 36 08  .....b\.......6.
0018e16c  40 23 5e 08 70 e3 18 00 - f6 42 5c 02 fc e1 18 00  @#^.p....B\.....
0018e17c  f6 42 5c 02 3c 6d 5c 02 - 4a 00 00 00 d0 2b 52 08  .B\.<m\.J....+R.
0018e18c  9c 2b 52 08 a3 6d 5c 02 - 00 00 00 00 00 00 00 00  .+R..m\.........
0018e19c  00 00 00 00 00 00 00 00 - 88 e3 18 00 05 6a 74 02  .............jt.
0018e1ac  88 e3 18 00 90 e3 18 00 - b0 62 5c 02 88 e3 18 00  .........b\.....
0018e1bc  40 23 5e 08 00 fa 36 08 - 0c e5 18 00 00 00 00 00  @#^...6.........
0018e1cc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018e1dc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018e1ec  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018e1fc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018e20c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018e21c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018e22c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018e23c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018e24c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018e25c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018e26c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018e27c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018e28c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

disassembling:
[...]
02746482        call    -$17f037 ($25c7450)    ; @.LStrAddRef
02746482
02746487        xor     eax, eax
02746489        push    ebp
0274648a        push    $27467d9               ; @.HandleFinally
0274648f        push    dword ptr fs:[eax]
02746492        mov     fs:[eax], esp
02746495 1034   call    -$48f1e ($26fd57c)     ; KOLTGA.@@NewTarga
02746495
0274649a        mov     edx, [ebp+8]
0274649d        mov     [edx-4], eax
027464a0 1035   mov     eax, [ebp+8]
027464a3        mov     eax, [eax-4]
027464a6        mov     edx, [ebp-4]
027464a9        mov     ecx, [eax]
027464ab        call    dword ptr [ecx+$20]
027464ab
027464ae 1037   mov     eax, [ebp+8]
027464b1        mov     eax, [eax-4]
027464b4        mov     eax, [eax+$fd4]
027464ba      > mov     eax, [eax+$45]
027464bd        mov     edx, [ebp+8]
027464c0        mov     edx, [edx-4]
027464c3        mov     edx, [edx+$fd8]
027464c9        cmp     eax, [edx+$45]
027464cc        jz      loc_27464de
027464cc
027464ce 1039   mov     eax, [ebp+8]
027464d1        mov     eax, [eax-4]
027464d4        call    -$f2ee5 ($26535f4)     ; KOL.@TObj.RefDec
027464d4
027464d9 1040   jmp     loc_27467a7
027464d9
027464d9      ; ---------------------------------------------------------
027464d9
027464de      loc_27464de:
027464de 1043   mov     eax, [ebp+8]
027464e1        mov     eax, [eax-4]
027464e4        mov     eax, [eax+$fd4]
027464ea        fild    dword ptr [eax+$45]
027464ed        fdiv    dword ptr [$27467e8]
[...]

date/time         : 2011-10-08, 13:24:02, 765ms
computer name     : DRAGON-
user name         : Dr@goN <admin>
registered owner  : Microsoft / Microsoft
operating system  : Windows 7 x64 build 7600
system language   : Russian
system up time    : 2 hours 12 minutes
program up time   : 493 milliseconds
processors        : 3x AMD Athlon(tm) II X3 435 Processor
physical memory   : 4563/6142 MB (free/total)
free disk space   : (C:) 17,87 GB (E:) 162,66 GB
display mode      : 1600x900, 32 bit
process id        : $2d0
allocated memory  : 56,90 MB
executable        : Phoenix.exe
current module    : Main.dll
module date/time  : 2011-09-04 21:33
version           : 1.0.4.27
compiled with     : Delphi 2010
madExcept version : 3.0m
contact name      : Dr@goN
contact email     : roma_astafev@spaces.ru
callstack crc     : $c259a765, $35c082c0, $ac2a1bd2
exception number  : 1
exception class   : Exception
exception message : Unknown.

main thread ($9cc):
026a64ba +04e Main.dll     MzL_Main 1037   +4 LoadTGA
026a6a00 +108 Main.dll     MzL_Main 1141  +17 @TModZList.SetIconForMod
026a7553 +643 Main.dll     MzL_Main 1299  +96 @TModZList.AddMod
026a5cf1 +7a5 Main.dll     MzL_Main  984 +125 @TModZList.Create
026af47a +062 Main.dll     MzL_Main 4282   +7 @@ModZArray_Init
773c00e3 +02b ntdll.dll                       KiUserCallbackDispatcher
76bd27b3 +031 USER32.dll                      DialogBoxIndirectParamAorW
76bfcc61 +047 USER32.dll                      DialogBoxParamA
766e3675 +010 kernel32.dll                    BaseThreadInitThunk

thread $d44:
773d1edf +0b ntdll.dll     NtWaitForWorkViaWorkerFactory
766e3675 +10 kernel32.dll  BaseThreadInitThunk

thread $fac:
773d1edf +0b ntdll.dll     NtWaitForWorkViaWorkerFactory
766e3675 +10 kernel32.dll  BaseThreadInitThunk

thread $858:
773d00f6 +0e ntdll.dll       NtWaitForMultipleObjects
7686095c +fa KERNELBASE.dll  WaitForMultipleObjectsEx
766e1628 +89 kernel32.dll    WaitForMultipleObjectsEx
76bc03d4 +f4 USER32.dll      MsgWaitForMultipleObjectsEx
76bc0669 +1a USER32.dll      MsgWaitForMultipleObjects
766e3675 +10 kernel32.dll    BaseThreadInitThunk

thread $dec:
76bc4386 +0e USER32.dll                  WaitMessage
76bd27b3 +31 USER32.dll                  DialogBoxIndirectParamAorW
76bd2a9c +3a USER32.dll                  DialogBoxParamW
0252e985 +0d Main.dll     Windows        @@DialogBox
026c4f13 +37 Main.dll     Banner  381 +3 @@BannerThread
766e3675 +10 kernel32.dll                BaseThreadInitThunk

modules:
003e0000 System.dll                           D:\Temp\nsoB01F.tmp
00400000 Phoenix.exe       1.0.4.28           E:\Games\Phoenix_15beta8
00840000 lua.dll                              E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
02520000 Main.dll          1.0.4.27           E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
02d30000 RainCWrapper.dll                     E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
02d80000 SimDecrypt.dll                       E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
04520000 Amhooker.dll                         C:\Windows\system32
04630000 NSISArray.dll                        D:\Temp\nsoB01F.tmp
047a0000 HLLib.dll         2.4.0.0            E:\Games\Phoenix_15beta8\Phx_Data\Res\SharedDLLs
047f0000 Phx_Default.dll   1.0.5.8            E:\Games\Phoenix_15beta8\Phx_Data\Plugins
04820000 Phx_SourceSDK.dll 1.0.2.2            E:\Games\Phoenix_15beta8\Phx_Data\Plugins
10000000 RocketDock.dll                       C:\Program Files (x86)\RocketDock
6de20000 rain.dll                             E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
6fe90000 RichEd20.DLL      5.31.23.1229       C:\Windows\system32
717d0000 WindowsCodecs.dll 6.1.7600.16385     C:\Windows\system32
718d0000 ntmarta.dll       6.1.7600.16385     C:\Windows\system32
71900000 propsys.dll       7.0.7600.16385     C:\Windows\system32
71a70000 gdiplus.dll       6.1.7600.16385     C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca
72150000 COMCTL32.dll      6.10.7600.16385    C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc
72360000 msimg32.dll       6.1.7600.16385     C:\Windows\system32
729c0000 VDFParse.dll                         E:\Games\Phoenix_15beta8\Phx_data\Res\SharedDLLs
72a10000 msvfw32.dll       6.1.7600.16385     C:\Windows\system32
72b80000 uxtheme.dll       6.1.7600.16385     C:\Windows\system32
72c00000 profapi.dll       6.1.7600.16385     C:\Windows\system32
72c30000 VERSION.dll       6.1.7600.16385     C:\Windows\system32
72c60000 dwmapi.dll        6.1.7600.16385     C:\Windows\system32
72c80000 winspool.drv      6.1.7600.16385     C:\Windows\system32
72d20000 winmm.dll         6.1.7600.16385     C:\Windows\system32
72d60000 srvcli.dll        6.1.7600.16385     C:\Windows\system32
72d80000 netutils.dll      6.1.7600.16385     C:\Windows\system32
72d90000 NETAPI32.dll      6.1.7600.16385     C:\Windows\system32
72e50000 MSVCR80.dll       8.0.50727.4927     C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b5
72f50000 SHFOLDER.DLL      6.1.7600.16385     C:\Windows\system32
73050000 wkscli.dll        6.1.7600.16385     C:\Windows\system32
74300000 wsock32.dll       6.1.7600.16385     C:\Windows\system32
749d0000 CRYPTBASE.dll     6.1.7600.16385     C:\Windows\syswow64
749e0000 SspiCli.dll       6.1.7600.16385     C:\Windows\syswow64
74a40000 ADVAPI32.dll      6.1.7600.16385     C:\Windows\syswow64
74ae0000 iertutil.dll      8.0.7600.16385     C:\Windows\syswow64
74d40000 DEVOBJ.dll        6.1.7600.16385     C:\Windows\syswow64
74d60000 WLDAP32.dll       6.1.7600.16385     C:\Windows\syswow64
74db0000 msvcrt.dll        7.0.7600.16385     C:\Windows\syswow64
74e60000 Normaliz.dll      6.1.7600.16385     C:\Windows\syswow64
74e70000 IMM32.DLL         6.1.7600.16385     C:\Windows\system32
74ed0000 SHLWAPI.dll       6.1.7600.16385     C:\Windows\syswow64
74f30000 wininet.dll       8.0.7600.16535     C:\Windows\syswow64
75030000 CRYPT32.dll       6.1.7600.16385     C:\Windows\syswow64
75180000 ole32.dll         6.1.7600.16385     C:\Windows\syswow64
752e0000 SHELL32.dll       6.1.7600.16460     C:\Windows\syswow64
76470000 LPK.dll           6.1.7600.16385     C:\Windows\syswow64
76510000 sechost.dll       6.1.7600.16385     C:\Windows\SysWOW64
76530000 SETUPAPI.dll      6.1.7600.16385     C:\Windows\syswow64
766d0000 kernel32.dll      6.1.7600.16385     C:\Windows\syswow64
767d0000 comdlg32.dll      6.1.7600.16385     C:\Windows\syswow64
76850000 KERNELBASE.dll    6.1.7600.16385     C:\Windows\syswow64
768d0000 CFGMGR32.dll      6.1.7600.16385     C:\Windows\syswow64
76900000 CLBCatQ.DLL       2001.12.8530.16385 C:\Windows\syswow64
76990000 GDI32.dll         6.1.7600.16385     C:\Windows\syswow64
76a20000 PSAPI.DLL         6.1.7600.16385     C:\Windows\syswow64
76a30000 USP10.dll         1.626.7600.16385   C:\Windows\syswow64
76ad0000 MSCTF.dll         6.1.7600.16385     C:\Windows\syswow64
76ba0000 USER32.dll        6.1.7600.16385     C:\Windows\syswow64
76ca0000 RPCRT4.dll        6.1.7600.16385     C:\Windows\syswow64
76d90000 MSASN1.dll        6.1.7600.16415     C:\Windows\syswow64
76da0000 urlmon.dll        8.0.7600.16535     C:\Windows\syswow64
76ee0000 OLEAUT32.dll      6.1.7600.16385     C:\Windows\syswow64
76f70000 WS2_32.dll        6.1.7600.16385     C:\Windows\syswow64
77380000 NSI.dll           6.1.7600.16385     C:\Windows\syswow64
773b0000 ntdll.dll         6.1.7600.16385     C:\Windows\SysWOW64

processes:
0000 Idle                      0 0    0
0004 System                    0 0    0
0170 smss.exe                  0 0    0
01e0 csrss.exe                 0 0    0
021c wininit.exe               0 0    0
0240 csrss.exe                 1 0    0
0258 services.exe              0 0    0
0274 lsass.exe                 0 0    0
027c lsm.exe                   0 0    0
02c4 winlogon.exe              1 0    0
030c svchost.exe               0 0    0
035c svchost.exe               0 0    0
0394 atiesrxx.exe              0 0    0
03d4 svchost.exe               0 0    0
03fc svchost.exe               0 0    0
0194 svchost.exe               0 0    0
0404 svchost.exe               0 0    0
045c svchost.exe               0 0    0
0494 atieclxx.exe              1 0    0
04c4 spoolsv.exe               0 0    0
04e4 svchost.exe               0 0    0
05a8 RAIDXpertService.exe      0 0    0
05cc RAIDXpert.exe             0 0    0
05dc conhost.exe               0 0    0
064c taskeng.exe               1 10   3   normal
0654 taskhost.exe              1 26   21  normal
0698 dwm.exe                   1 18   2   high
06f4 svchost.exe               0 0    0
072c AsSysCtrlService.exe      0 0    0
0750 avp.exe                   0 0    0
076c FourEngine.exe            1 543  81  below normal C:\Program Files (x86)\ASUS\EPU-4 Engine
07f0 DfSdkS64.exe              0 0    0
0434 DVMExportService.exe      0 0    0
0880 CDASrv.exe                1 14   11  normal
0888 LiveTuner.exe             1 65   36  normal       C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 8
0890 Amoumain.exe              1 123  46  normal       C:\Program Files\Mouse
08a0 oodtray.exe               1 142  54  normal
08a8 sidebar.exe               1 92   45  normal
08b0 RocketDock.exe            1 66   63  normal       C:\Program Files (x86)\RocketDock
08b8 IOTraf.exe                1 98   87  normal       C:\Program Files (x86)\TeachStyle\IO Traf
0980 avp.exe                   1 312  151 normal       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012
098c TurboKey.exe              1 184  53  normal       C:\Program Files\ASUS\Turbo Key
09a8 VDeck.exe                 1 962  432 normal
09d4 MOM.exe                   1 10   10  normal
080c CCC.exe                   1 103  64  normal
0968 oodag.exe                 0 0    0
0c04 svchost.exe               0 0    0
0c44 LiveTunerService.exe      0 0    0
0ed8 ServiceLayer.exe          0 0    0
0f74 SearchIndexer.exe         0 0    0
0b48 NclUSBSrv64.exe           0 0    0
0d58 NclRSSrv.exe              0 0    0
11b0 WUDFHost.exe              0 0    0
1190 PresentationFontCache.exe 0 0    0
0420 svchost.exe               0 0    0
1200 svchost.exe               0 0    0
09dc explorer.exe              1 1002 399 normal
0fc0 wmpnetwk.exe              0 0    0
05b8 SMSvcHost.exe             0 0    0
125c MpCmdRun.exe              0 0    0
09ec conhost.exe               0 0    0
0630 audiodg.exe               0 0    0
04dc WmiPrvSE.exe              0 0    0
0c1c svchost.exe               0 0    0
02d0 Phoenix.exe               1 75   76  high         E:\Games\Phoenix_15beta8

cpu registers:
eax = 00000000
ebx = 0655e630
ecx = 0326e348
edx = 0326d770
esi = 05856d30
edi = 00000000
eip = 026a64ba
esp = 0018e98c
ebp = 0018e9d4

stack dump:
0018e98c  e0 e9 18 00 b0 62 52 02 - d4 e9 18 00 30 6d 85 05  .....bR.....0m..
0018e99c  30 e6 55 06 a0 eb 18 00 - f6 42 52 02 2c ea 18 00  0.U......BR.,...
0018e9ac  f6 42 52 02 3c 6d 52 02 - 4a 00 00 00 e0 1b 4a 06  .BR.<mR.J.....J.
0018e9bc  ac 1b 4a 06 a3 6d 52 02 - 00 00 00 00 00 00 00 00  ..J..mR.........
0018e9cc  00 00 00 00 00 00 00 00 - b8 eb 18 00 05 6a 6a 02  .............jj.
0018e9dc  b8 eb 18 00 c0 eb 18 00 - b0 62 52 02 b8 eb 18 00  .........bR.....
0018e9ec  30 e6 55 06 30 6d 85 05 - 44 ed 18 00 00 00 00 00  0.U.0m..D.......
0018e9fc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ea0c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ea1c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ea2c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ea3c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ea4c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ea5c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ea6c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ea7c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ea8c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018ea9c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018eaac  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018eabc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

disassembling:
[...]
026a6482        call    -$17f037 ($2527450)    ; @.LStrAddRef
026a6482
026a6487        xor     eax, eax
026a6489        push    ebp
026a648a        push    $26a67d9               ; @.HandleFinally
026a648f        push    dword ptr fs:[eax]
026a6492        mov     fs:[eax], esp
026a6495 1034   call    -$48f1e ($265d57c)     ; KOLTGA.@@NewTarga
026a6495
026a649a        mov     edx, [ebp+8]
026a649d        mov     [edx-4], eax
026a64a0 1035   mov     eax, [ebp+8]
026a64a3        mov     eax, [eax-4]
026a64a6        mov     edx, [ebp-4]
026a64a9        mov     ecx, [eax]
026a64ab        call    dword ptr [ecx+$20]
026a64ab
026a64ae 1037   mov     eax, [ebp+8]
026a64b1        mov     eax, [eax-4]
026a64b4        mov     eax, [eax+$fd4]
026a64ba      > mov     eax, [eax+$45]
026a64bd        mov     edx, [ebp+8]
026a64c0        mov     edx, [edx-4]
026a64c3        mov     edx, [edx+$fd8]
026a64c9        cmp     eax, [edx+$45]
026a64cc        jz      loc_26a64de
026a64cc
026a64ce 1039   mov     eax, [ebp+8]
026a64d1        mov     eax, [eax-4]
026a64d4        call    -$f2ee5 ($25b35f4)     ; KOL.@TObj.RefDec
026a64d4
026a64d9 1040   jmp     loc_26a67a7
026a64d9
026a64d9      ; ---------------------------------------------------------
026a64d9
026a64de      loc_26a64de:
026a64de 1043   mov     eax, [ebp+8]
026a64e1        mov     eax, [eax-4]
026a64e4        mov     eax, [eax+$fd4]
026a64ea        fild    dword ptr [eax+$45]
026a64ed        fdiv    dword ptr [$26a67e8]
[...]

