date/time         : 2012-02-10, 23:49:24, 781ms
computer name     : DEEPBBS-1129
user name         : Administrator <admin>
registered owner  : ΢û / ΢й
operating system  : Windows XP Service Pack 3 (5.1.2600) build 2600
system language   : Chinese
system up time    : 4 hours 50 minutes
program up time   : 40 minutes 37 seconds
processors        : 2x AMD Athlon(tm) 64 X2 Dual Core Processor 5000+
physical memory   : 1497/2046 MB (free/total)
free disk space   : (C:) 15.31 GB (G:) 21.20 GB
display mode      : 1440x900, 32 bit
process id        : $16b4
allocated memory  : 24.08 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $eb093fce, $c2b716d3, $c2b716d3
exception number  : 1
exception class   : EAccessViolation
exception message : Access violation at address 004CFD49 in module 'FlashFXP.exe'. ȡ of address 0000002C.

main thread ($358):
004cfd49 +0035 FlashFXP.exe IniFiles32  937   +7 TIniFile32.ReadString
007040d3 +0083 FlashFXP.exe Update      875   +3 TFrmUpdate.FormDestroy
00445c5d +0031 FlashFXP.exe Forms      2755   +3 TCustomForm.DoDestroy
00445ac1 +005d FlashFXP.exe Forms      2719   +7 TCustomForm.BeforeDestruction
00403771 +0009 FlashFXP.exe System               @BeforeDestruction
00445ace +0006 FlashFXP.exe Forms      2723   +0 TCustomForm.Destroy
0041c40a +001e FlashFXP.exe Classes              TComponent.DestroyComponents
0041c242 +004e FlashFXP.exe Classes              TComponent.Destroy
00452039 +0095 FlashFXP.exe Controls             TControl.Destroy
00454ef3 +00bb FlashFXP.exe Controls             TWinControl.Destroy
00444f10 +0028 FlashFXP.exe Forms      2259   +3 TScrollingWinControl.Destroy
00445b7f +00b7 FlashFXP.exe Forms      2734  +11 TCustomForm.Destroy
0041c40a +001e FlashFXP.exe Classes              TComponent.DestroyComponents
004436ab +002f FlashFXP.exe Forms      1261   +3 DoneApplication
0040a9b6 +0026 FlashFXP.exe SysUtils             DoExitProc
00403f50 +0028 FlashFXP.exe System               @Halt0
00796548 +1cc4 FlashFXP.exe FlashFXP    939 +649 initialization

thread $147c:
7c92d218 +0a ntdll.dll     NtDelayExecution
7c8023eb +4b kernel32.dll  SleepEx
7c802450 +0a kernel32.dll  Sleep

thread $13a0:
7c92d218 +a ntdll.dll  NtDelayExecution

thread $260:
7c92daa8 +a ntdll.dll  NtReplyWaitReceivePortEx

thread $1020: <priority:1>
7c92da48 +a ntdll.dll  NtRemoveIoCompletion

modules:
00400000 FlashFXP.exe          4.0.0.1534       G:\Program Files\flashftp
00fc0000 safemon.dll           7.0.1.1040       C:\Program Files\360\360Safe\safemon
029c0000 360UDiskGuard.dll     2.0.0.1007       C:\Program Files\360\360Safe\safemon
038c0000 libeay32.dll          1.0.0.3          G:\Program Files\flashftp
03a10000 ssleay32.dll          1.0.0.3          G:\Program Files\flashftp
04580000 xpsp2res.dll          5.1.2600.5512    C:\WINDOWS\system32
07160000 audiodev.dll          5.2.5721.5262    C:\WINDOWS\system32
10000000 Sync115Ext.dll        1.0.0.2          C:\Documents and Settings\Administrator\Application Data\115\Box
10930000 PortableDeviceApi.dll 5.2.5721.5262    C:\WINDOWS\system32
11c70000 WMASF.DLL             11.0.5721.5262   C:\WINDOWS\system32
15110000 WMVCore.DLL           11.0.5721.5275   C:\WINDOWS\system32
16500000 wpdshext.dll          5.2.5721.5262    C:\WINDOWS\system32
1f840000 odbcint.dll           3.525.1117.0     C:\WINDOWS\system32
325c0000 msohev.dll            11.0.5510.0      G:\Program Files\Office2003\OFFICE11
4ae90000 gdiplus.dll           5.2.6002.22509   C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22509_x-ww_c7dad023
5a540000 wiashext.dll          5.1.2600.5512    C:\WINDOWS\system32
5adc0000 UxTheme.dll           6.0.2900.5512    C:\WINDOWS\system32
5efe0000 olepro32.dll          5.1.2600.5512    C:\WINDOWS\system32
5fdd0000 NETAPI32.dll          5.1.2600.5694    C:\WINDOWS\system32
60fd0000 hnetcfg.dll           5.1.2600.5512    C:\WINDOWS\system32
62c20000 LPK.DLL               5.1.2600.5512    C:\WINDOWS\system32
68000000 rsaenh.dll            5.1.2600.5507    C:\WINDOWS\system32
68100000 dssenh.dll            5.1.2600.5507    C:\WINDOWS\system32
719c0000 mswsock.dll           5.1.2600.5625    C:\WINDOWS\system32
71a00000 wshtcpip.dll          5.1.2600.5512    C:\WINDOWS\System32
71a10000 WS2HELP.dll           5.1.2600.5512    C:\WINDOWS\system32
71a20000 WS2_32.dll            5.1.2600.5512    C:\WINDOWS\system32
71a40000 wsock32.dll           5.1.2600.5512    C:\WINDOWS\system32
71a90000 MPR.dll               5.1.2600.5512    C:\WINDOWS\system32
71b70000 SAMLIB.dll            5.1.2600.5512    C:\WINDOWS\System32
71b90000 ntlanman.dll          5.1.2600.5512    C:\WINDOWS\System32
71c00000 NETRAP.dll            5.1.2600.5512    C:\WINDOWS\System32
71c10000 NETUI1.dll            5.1.2600.5512    C:\WINDOWS\System32
71c50000 NETUI0.dll            5.1.2600.5512    C:\WINDOWS\System32
72f70000 winspool.drv          5.1.2600.5512    C:\WINDOWS\system32
73540000 ODBC32.dll            3.525.3012.0     C:\WINDOWS\system32
73640000 msctfime.ime          5.1.2600.5768    C:\WINDOWS\system32
73b10000 sti.dll               5.1.2600.5512    C:\WINDOWS\system32
73ce0000 shgina.dll            6.0.2900.5512    C:\WINDOWS\system32
73fa0000 USP10.dll             1.420.2600.5969  C:\WINDOWS\system32
74680000 MSCTF.dll             5.1.2600.5512    C:\WINDOWS\system32
74a40000 CFGMGR32.dll          5.1.2600.5512    C:\WINDOWS\system32
74cf0000 MLANG.dll             6.0.2900.5512    C:\WINDOWS\system32
75430000 CRYPTUI.dll           5.131.2600.5512  C:\WINDOWS\system32
758d0000 MSGINA.dll            5.1.2600.5512    C:\WINDOWS\system32
759d0000 USERENV.dll           5.1.2600.5512    C:\WINDOWS\system32
75ed0000 drprov.dll            5.1.2600.5512    C:\WINDOWS\System32
75ee0000 davclnt.dll           5.1.2600.5512    C:\WINDOWS\System32
75ef0000 browseui.dll          6.0.2900.6126    C:\WINDOWS\system32
75ff0000 MSVCP60.dll           6.2.3104.0       C:\WINDOWS\system32
76060000 SETUPAPI.dll          5.1.2600.5512    C:\WINDOWS\system32
762d0000 WINSTA.dll            5.1.2600.5512    C:\WINDOWS\system32
76300000 IMM32.DLL             5.1.2600.5512    C:\WINDOWS\system32
76320000 comdlg32.dll          6.0.2900.5512    C:\WINDOWS\system32
76570000 CSCDLL.dll            5.1.2600.5512    C:\WINDOWS\System32
76590000 cscui.dll             5.1.2600.5512    C:\WINDOWS\System32
765e0000 crypt32.dll           5.131.2600.6149  C:\WINDOWS\system32
76680000 WININET.dll           6.0.2900.6126    C:\WINDOWS\system32
76760000 cryptdll.dll          5.1.2600.5512    C:\WINDOWS\system32
76960000 ntshrui.dll           5.1.2600.5512    C:\WINDOWS\system32
76990000 ole32.dll             5.1.2600.6010    C:\WINDOWS\system32
76af0000 ATL.DLL               3.5.2284.2       C:\WINDOWS\system32
76b10000 winmm.dll             5.1.2600.6160    C:\WINDOWS\system32
76bc0000 PSAPI.DLL             5.1.2600.5512    C:\WINDOWS\system32
76c00000 WINTRUST.dll          5.131.2600.5922  C:\WINDOWS\system32
76c60000 IMAGEHLP.dll          5.1.2600.5512    C:\WINDOWS\system32
76d30000 iphlpapi.dll          5.1.2600.5512    C:\WINDOWS\system32
76d70000 appHelp.dll           5.1.2600.5512    C:\WINDOWS\system32
76db0000 MSASN1.dll            5.1.2600.5875    C:\WINDOWS\system32
76e50000 rtutils.dll           5.1.2600.5512    C:\WINDOWS\system32
76e60000 rasman.dll            5.1.2600.5512    C:\WINDOWS\system32
76e80000 TAPI32.dll            5.1.2600.5512    C:\WINDOWS\system32
76eb0000 RASAPI32.DLL          5.1.2600.5512    C:\WINDOWS\system32
76f30000 WLDAP32.dll           5.1.2600.5512    C:\WINDOWS\system32
76fa0000 CLBCATQ.DLL           2001.12.4414.700 C:\WINDOWS\system32
77020000 COMRes.dll            2001.12.4414.700 C:\WINDOWS\system32
770f0000 oleaut32.dll          5.1.2600.6058    C:\WINDOWS\system32
77180000 comctl32.dll          6.0.2900.6028    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
77bd0000 version.dll           5.1.2600.5512    C:\WINDOWS\system32
77be0000 msvcrt.dll            7.0.2600.5512    C:\WINDOWS\system32
77c40000 msv1_0.dll            5.1.2600.5876    C:\WINDOWS\system32
77d10000 user32.dll            5.1.2600.5512    C:\WINDOWS\system32
77da0000 advapi32.dll          5.1.2600.5755    C:\WINDOWS\system32
77e50000 RPCRT4.dll            5.1.2600.6022    C:\WINDOWS\system32
77ef0000 GDI32.dll             5.1.2600.5698    C:\WINDOWS\system32
77f40000 SHLWAPI.dll           6.0.2900.5912    C:\WINDOWS\system32
77fc0000 Secur32.dll           5.1.2600.5834    C:\WINDOWS\system32
7c800000 kernel32.dll          5.1.2600.5781    C:\WINDOWS\system32
7c920000 ntdll.dll             5.1.2600.6055    C:\WINDOWS\system32
7d590000 shell32.dll           6.0.2900.6072    C:\WINDOWS\system32
7e550000 shdocvw.dll           6.0.2900.6126    C:\WINDOWS\system32

processes:
0000 Idle              0   0
0004 System            0   0   normal
0330 smss.exe          0   0   normal C:\WINDOWS\system32
0364 csrss.exe         0   0
037c winlogon.exe      44  14  high   C:\WINDOWS\system32
03b0 services.exe      4   2   normal C:\WINDOWS\system32
03bc lsass.exe         6   4   normal C:\WINDOWS\system32
0460 svchost.exe       4   1   normal C:\WINDOWS\system32
04a4 svchost.exe       0   0
059c svchost.exe       11  26  normal C:\WINDOWS\System32
0634 svchost.exe       0   0
065c svchost.exe       0   0
066c zhudongfangyu.exe 4   5   normal C:\Program Files\360\360Safe\deepscan
00dc spoolsv.exe       4   4   normal C:\WINDOWS\system32
0228 Explorer.EXE      586 392 normal C:\WINDOWS
0264 360Tray.exe       212 78  normal C:\Program Files\360\360Safe\safemon
0274 ctfmon.exe        18  12  normal C:\WINDOWS\system32
071c hnserv.exe        11  9   normal C:\Program Files\Hellonet6.0
073c inetinfo.exe      5   12  normal C:\WINDOWS\system32\inetsrv
074c sqlservr.exe      0   0
0778 sqlservr.exe      5   1   normal C:\PROGRA~1\MICROS~2\MSSQL\binn
015c mysqld-nt.exe     4   2   normal C:\MySQL\bin
07e8 sqlbrowser.exe    0   0
04e0 svchost.exe       5   4   normal C:\WINDOWS\system32
0b44 svchost.exe       5   2   normal C:\WINDOWS\system32
16b4 FlashFXP.exe      142 87  normal G:\Program Files\flashftp
0a74 SogouCloud.exe    5   1   normal C:\Program Files\SogouInput\6.1.0.6700
0324 notepad.exe       22  21  normal C:\WINDOWS\system32
1148 dllhost.exe       5   3   normal C:\WINDOWS\system32

hardware:
+ DVD/CD-ROM 
  - PIONEER DVD-RW  DVR-219L
+ IDE ATA/ATAPI 
  - ׼˫ͨ PCI IDE 
  - ׼˫ͨ PCI IDE 
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
+ 
  - AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ (driver 1.3.2.0)
  - AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ (driver 1.3.2.0)
+ 
  - Kingston DT 101 G2 USB Device
  - ST3250310AS
+ ˿ (COM  LPT)
  - ͨѶ˿ (COM1)
+ 
  - 弴ü
+ 
  - ACPI Multiprocessor PC
+ 
  - Standard 101/102-Key or Microsoft Natural PS/2 Keyboard with HP QLB (driver 1.0.0.1)
+ ƵϷ
  - Realtek High Definition Audio (driver 5.10.0.6132)
  - ͳƵ׽豸
  - ͳƵ
  - ý豸
  - Ƶ
  - Ƶ
+ ָ豸
  - PS/2 Compatible Mouse
+ ͨô߿
  - Generic USB Hub
  - Standard Enhanced PCI to USB Host Controller
  - Standard Enhanced PCI to USB Host Controller
  - Standard OpenHCD USB Host Controller
  - Standard OpenHCD USB Host Controller
  - USB Mass Storage Device
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
+ 
  - Realtek RTL8139/810x Family Fast Ethernet NIC (driver 5.719.325.2009)
+ ϵͳ豸
  - ACPI Fan
  - ACPI Fixed Feature Button
  - ACPI Power Button
  - ACPI Thermal Zone
  - AMD Low Level Device Driver (driver 1.0.1.0)
  - Direct memory access controller
  - High Precision Event Timer (driver 7.0.0.1011)
  - ISAPNP Read Data Port
  - Logical Disk Manager
  - Microcode Update Device
  - Microsoft ACPI-Compliant System
  - Microsoft Composite Battery
  - Microsoft System Management BIOS Driver
  - Microsoft  High Definition Audio  UAA 
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Numeric data processor
  - NVIDIA nForce PCI System Management (driver 4.6.9.0)
  - PCI bus
  - PCI standard host CPU bridge
  - PCI standard host CPU bridge
  - PCI standard host CPU bridge
  - PCI standard host CPU bridge
  - PCI standard ISA bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard RAM Controller
  - PCI standard RAM Controller
  - Plug and Play Software Device Enumerator
  - Programmable interrupt controller
  - System board
  - System CMOS/real time clock
  - System speaker
  - System timer
  - Terminal Server Device Redirector
  - Terminal Server Keyboard Driver
  - Terminal Server Mouse Driver
  - Volume Manager
  - ̨ȫʾƵ
+ ʾ
  - NVIDIA G98-GL (driver 6.14.12.5931)

cpu registers:
eax = 0012f674
ebx = 00000000
ecx = 00000000
edx = 00000000
esi = 00e9b348
edi = 0012f8e4
eip = 004cfd49
esp = 0012f624
ebp = 0012f64c

stack dump:
0012f624  5c f6 12 00 ac 3a 40 00 - 4c f6 12 00 e4 f8 12 00  \....:@.L.......
0012f634  6c f8 12 00 f0 6d ec 00 - 00 00 00 00 00 00 00 00  l....m..........
0012f644  00 00 00 00 50 c0 e9 00 - 78 f6 12 00 d8 40 70 00  ....P...x....@p.
0012f654  74 f6 12 00 00 00 00 00 - 80 f6 12 00 ac 3a 40 00  t............:@.
0012f664  78 f6 12 00 f0 6d ec 00 - 00 00 00 00 00 00 00 00  x....m..........
0012f674  00 00 00 00 9c f6 12 00 - 63 5c 44 00 3c f8 12 00  ........c\D.<...
0012f684  1e 39 40 00 9c f6 12 00 - e4 f8 12 00 6c f8 12 00  .9@.........l...
0012f694  f0 6d ec 00 f0 6d ec 00 - c0 f6 12 00 c6 5a 44 00  .m...m.......ZD.
0012f6a4  f0 6d ec 00 74 37 40 00 - 01 f8 12 00 f0 6d ec 00  .m..t7@......m..
0012f6b4  d3 5a 44 00 3c 00 00 00 - e4 f8 12 00 0c f8 12 00  .ZD.<...........
0012f6c4  e7 33 40 00 99 95 44 00 - 38 3e 45 00 e4 f8 12 00  .3@...D.8>E.....
0012f6d4  6c f8 12 00 f0 6d ec 00 - a7 66 45 00 e4 f8 12 00  l....m...fE.....
0012f6e4  6c f8 12 00 f0 6d ec 00 - 01 00 00 00 00 00 00 00  l....m..........
0012f6f4  2d 0c fb 00 cd ab ba dc - 00 00 00 00 44 f7 12 00  -...........D...
0012f704  2d 0c fb 00 70 f7 12 00 - 16 88 d1 77 00 d0 fd 7f  -...p......w....
0012f714  70 f7 12 00 5a 88 d1 77 - 30 f7 12 00 2a 88 d1 77  p...Z..w0...*..w
0012f724  80 00 00 00 20 2e b4 00 - 34 2e b4 00 14 00 00 00  ........4.......
0012f734  01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00  ................
0012f744  00 00 00 00 f0 6d ec 00 - 00 00 00 00 00 00 00 00  .....m..........
0012f754  00 00 00 00 24 f7 12 00 - 00 00 00 00 48 f8 12 00  ....$.......H...

disassembling:
004cfd14     public IniFiles32.TIniFile32.ReadString:  ; function entry point
004cfd14 930   push    ebp
004cfd15       mov     ebp, esp
004cfd17       push    0
004cfd19       push    0
004cfd1b       push    0
004cfd1d       push    0
004cfd1f       push    ebx
004cfd20       push    esi
004cfd21       push    edi
004cfd22       mov     [ebp-4], ecx
004cfd25       mov     esi, edx
004cfd27       mov     ebx, eax
004cfd29       xor     eax, eax
004cfd2b       push    ebp
004cfd2c       push    $4cfe27                ; System.@HandleFinally
004cfd31       push    dword ptr fs:[eax]
004cfd34       mov     fs:[eax], esp
004cfd37 935   mov     eax, ebx
004cfd39       call    +$118e ($4d0ecc)       ; IniFiles32.TIniFile32.Reload
004cfd3e 936   mov     eax, [ebp+8]
004cfd41       mov     edx, [ebp+$c]
004cfd44       call    -$cbbd5 ($404174)      ; System.@LStrLAsg
004cfd49 937 > mov     eax, [ebx+$2c]
004cfd4c       mov     edx, [eax]
004cfd4e       call    dword ptr [edx+$14]
004cfd51       test    eax, eax
004cfd53       jle     loc_4cfe0c
004cfd59 939   mov     edx, esi
004cfd5b       mov     eax, ebx
004cfd5d       call    -$f56 ($4cee0c)        ; IniFiles32.TIniFile32.GetSectionIndex
004cfd62       mov     esi, eax
004cfd64 940   cmp     esi, -1
004cfd67       jz      loc_4cfe0c
004cfd6d 942   inc     esi
004cfd6e       jmp     loc_4cfde1
004cfd70 945   lea     ecx, [ebp-$c]
004cfd73       mov     edx, esi
004cfd75       mov     eax, [ebx+$2c]
004cfd78       mov     edi, [eax]
004cfd7a       call    dword ptr [edi+$c]
004cfd7d       mov     edx, [ebp-$c]
004cfd80       lea     ecx, [ebp-$10]
004cfd83       mov     eax, ebx
[...]

date/time         : 2012-06-14, 11:33:08, 890ms
computer name     : ZHENGYISONG
user name         : Administrator <admin>
registered owner  : Sky123.Org / Sky123.Org
operating system  : Windows XP Service Pack 3 (5.1.2600) build 2600
system language   : Chinese
system up time    : 3 hours 37 minutes
program up time   : 1 hour 4 minutes
processors        : 2x Pentium(R) Dual-Core CPU E5400 @ 2.70GHz
physical memory   : 709/2038 MB (free/total)
free disk space   : (C:) 20.77 GB (O:) 6.45 GB
display mode      : 1440x900, 32 bit
process id        : $16ac
allocated memory  : 21.19 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $0000635f, $c9910974, $6fabbe9f
exception number  : 1
exception class   : EAccessViolation
exception message : Access violation at address 0000635F. ȡ of address 0000635F.

main thread ($b00):
0000635f +0000 ???
0041c4ae +005e FlashFXP.exe Classes             TComponent.Notification
00452287 +000f FlashFXP.exe Controls            TControl.Notification
00445cd4 +0010 FlashFXP.exe Forms     2777   +1 TCustomForm.Notification
0041c3bb +000f FlashFXP.exe Classes             TComponent.RemoveComponent
0041c250 +005c FlashFXP.exe Classes             TComponent.Destroy
00452039 +0095 FlashFXP.exe Controls            TControl.Destroy
00454ef3 +00bb FlashFXP.exe Controls            TWinControl.Destroy
00444f10 +0028 FlashFXP.exe Forms     2259   +3 TScrollingWinControl.Destroy
00445b7f +00b7 FlashFXP.exe Forms     2734  +11 TCustomForm.Destroy
004033e4 +0008 FlashFXP.exe System              TObject.Free
00449594 +0000 FlashFXP.exe Forms     4619   +0 TCustomForm.CMRelease
00453e35 +0111 FlashFXP.exe Controls            TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls            TWinControl.WndProc
00446bcd +0571 FlashFXP.exe Forms     3235 +139 TCustomForm.WndProc
00509afb +003f FlashFXP.exe ThemeMgr            TWindowProcList.DispatchMessage
0050a448 +00dc FlashFXP.exe ThemeMgr            TThemeManager.FormWindowProc
0050b939 +0009 FlashFXP.exe ThemeMgr            TThemeManager.PreFormWindowProc
0045632c +002c FlashFXP.exe Controls            TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms     1529   +8 StdWndProc
77d196c2 +000a user32.dll                       DispatchMessageA
0044ca9f +008b FlashFXP.exe Forms     7117  +34 TApplication.ProcessMessage
0044cabe +000a FlashFXP.exe Forms     7148   +1 TApplication.ProcessMessages
0073c683 +023b FlashFXP.exe FrmMain1 10811  +43 TFrmMain.FormCloseQuery
00449759 +0055 FlashFXP.exe Forms     4688   +8 TCustomForm.CloseQuery
00449681 +0021 FlashFXP.exe Forms     4660   +4 TCustomForm.Close
00448b98 +0000 FlashFXP.exe Forms     4297   +0 TCustomForm.WMClose
00453e35 +0111 FlashFXP.exe Controls            TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls            TWinControl.WndProc
7719310d +0037 comctl32.dll                     HIMAGELIST_QueryInterface
771954e2 +007a comctl32.dll                     ImageList_Draw
00453e35 +0111 FlashFXP.exe Controls            TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls            TWinControl.WndProc
00446bcd +0571 FlashFXP.exe Forms     3235 +139 TCustomForm.WndProc
00509afb +003f FlashFXP.exe ThemeMgr            TWindowProcList.DispatchMessage
0050a448 +00dc FlashFXP.exe ThemeMgr            TThemeManager.FormWindowProc
0050b939 +0009 FlashFXP.exe ThemeMgr            TThemeManager.PreFormWindowProc
0045632c +002c FlashFXP.exe Controls            TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms     1529   +8 StdWndProc
7c92e470 +0010 ntdll.dll                        KiUserCallbackDispatcher
77d2f156 +2fd8 user32.dll                       DefWindowProcA
77d2a993 +0016 user32.dll                       CallWindowProcA
004567a7 +00e7 FlashFXP.exe Controls            TWinControl.DefaultHandler
00447e5a +005a FlashFXP.exe Forms     3853   +7 TCustomForm.DefaultHandler
00457dfb +009f FlashFXP.exe Controls            TWinControl.WMSysCommand
00448c77 +0053 FlashFXP.exe Forms     4328   +7 TCustomForm.WMSysCommand
0077dc79 +00ed FlashFXP.exe FrmMain1 32669   +0 TFrmMain.WMSyscommand
00453e35 +0111 FlashFXP.exe Controls            TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls            TWinControl.WndProc
00446bcd +0571 FlashFXP.exe Forms     3235 +139 TCustomForm.WndProc
00509afb +003f FlashFXP.exe ThemeMgr            TWindowProcList.DispatchMessage
0045632c +002c FlashFXP.exe Controls            TWinControl.MainWndProc
00509afb +003f FlashFXP.exe ThemeMgr            TWindowProcList.DispatchMessage
0050a448 +00dc FlashFXP.exe ThemeMgr            TThemeManager.FormWindowProc
0050b939 +0009 FlashFXP.exe ThemeMgr            TThemeManager.PreFormWindowProc
0045632c +002c FlashFXP.exe Controls            TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms     1529   +8 StdWndProc
77d292de +0044 user32.dll                       SendMessageW
77d2f156 +2fd8 user32.dll                       DefWindowProcA
77d2a993 +0016 user32.dll                       CallWindowProcA
004567a7 +00e7 FlashFXP.exe Controls            TWinControl.DefaultHandler
00447e5a +005a FlashFXP.exe Forms     3853   +7 TCustomForm.DefaultHandler
004540d1 +0015 FlashFXP.exe Controls            TControl.WMNCLButtonDown
00448944 +007c FlashFXP.exe Forms     4189  +12 TCustomForm.WMNCLButtonDown
00453e35 +0111 FlashFXP.exe Controls            TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls            TWinControl.WndProc
00446bcd +0571 FlashFXP.exe Forms     3235 +139 TCustomForm.WndProc
00509afb +003f FlashFXP.exe ThemeMgr            TWindowProcList.DispatchMessage
0050a448 +00dc FlashFXP.exe ThemeMgr            TThemeManager.FormWindowProc
0050b939 +0009 FlashFXP.exe ThemeMgr            TThemeManager.PreFormWindowProc
0045632c +002c FlashFXP.exe Controls            TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms     1529   +8 StdWndProc
77d196c2 +000a user32.dll                       DispatchMessageA
0044ca9f +008b FlashFXP.exe Forms     7117  +34 TApplication.ProcessMessage
0044cad6 +000a FlashFXP.exe Forms     7155   +1 TApplication.HandleMessage
0044cd8b +00bf FlashFXP.exe Forms     7259  +26 TApplication.Run
007964ed +1c69 FlashFXP.exe FlashFXP   920 +630 initialization

thread $f20:
7c92df48 +00a ntdll.dll                              NtWaitForMultipleObjects
7c80958a +000 kernel32.dll                           WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll                           WaitForMultipleObjects
00640bd3 +07b FlashFXP.exe UPTShellControls 4370 +13 TChangeHandlerThread.Execute
0041bfc1 +22d FlashFXP.exe Classes                   HexToBin
00404080 +028 FlashFXP.exe System                    ThreadWrapper

thread $1210:
7c92df48 +00a ntdll.dll                  NtWaitForMultipleObjects
7c80958a +000 kernel32.dll               WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll               WaitForMultipleObjects
00662068 +10c FlashFXP.exe SaveToFileThd TSaveFileWorker.Execute
0041bfc1 +22d FlashFXP.exe Classes       HexToBin
00404080 +028 FlashFXP.exe System        ThreadWrapper

thread $238:
7c92d218 +a ntdll.dll  NtDelayExecution

thread $ad4:
7c92df48 +a ntdll.dll  NtWaitForMultipleObjects

thread $1694: <priority:1>
7c92da48 +a ntdll.dll  NtRemoveIoCompletion

modules:
00400000 FlashFXP.exe           4.0.0.1534       O:\ù\flashftp
01020000 Normaliz.dll           6.0.5441.0       C:\WINDOWS\system32
027a0000 KZipShell.dll          1.0.0.1          C:\Program Files\ѹ
02e30000 libeay32.dll           1.0.0.3          O:\ù\flashftp
02f80000 ssleay32.dll           1.0.0.3          O:\ù\flashftp
039c0000 ieframe.dll            8.0.6001.18702   C:\WINDOWS\system32
044d0000 rarext.dll             4.1.0.0          C:\Program Files\WinRAR
04520000 MenuEx.dll             3.0.0.3037       C:\Program Files\360\360sd
04580000 shell360ext.dll        7.5.0.1060       C:\Program Files\360\360Safe\Utils
045d0000 360Common.dll          7.3.0.1055       C:\Program Files\360\360Safe
04630000 WoptiEncryptModule.dll 1.6.10.816       D:\ù߰\Żʦ
04700000 ShellMenu.dll          5.12.523.3121    C:\Program Files\Baofeng\StormPlayer
07160000 audiodev.dll           5.2.5721.5262    C:\WINDOWS\system32
10000000 360UDiskGuard.dll      2.0.0.1019       C:\Program Files\360\360Safe\safemon
10930000 PortableDeviceApi.dll  5.2.5721.5262    C:\WINDOWS\system32
11c70000 WMASF.DLL              11.0.5721.5262   C:\WINDOWS\system32
15110000 WMVCore.DLL            11.0.5721.5275   C:\WINDOWS\system32
16500000 wpdshext.dll           5.2.5721.5262    C:\WINDOWS\system32
1a400000 urlmon.dll             8.0.6001.18702   C:\WINDOWS\system32
1f840000 odbcint.dll            3.525.1117.0     C:\WINDOWS\system32
24fe0000 net_monitor2.0.2.6.dll 2.0.2.6          C:\Program Files\Common Files\Thunder Network\NetMon
3a110000 MSOXEV.DLL             12.0.4518.1014   C:\Program Files\Common Files\Microsoft Shared\OFFICE12
4ae90000 gdiplus.dll            5.2.6002.22791   C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22791_x-ww_c8dff154
5adc0000 uxtheme.dll            6.0.2900.5512    C:\WINDOWS\system32
5dca0000 iertutil.dll           8.0.6001.18702   C:\WINDOWS\system32
5efe0000 olepro32.dll           5.1.2600.5512    C:\WINDOWS\system32
5fdd0000 NETAPI32.dll           5.1.2600.5694    C:\WINDOWS\system32
60fd0000 hnetcfg.dll            5.1.2600.5512    C:\WINDOWS\system32
61be0000 MFC42LOC.DLL           6.0.8665.0       C:\WINDOWS\system32
62c20000 LPK.DLL                5.1.2600.5512    C:\WINDOWS\system32
63000000 WININET.dll            8.0.6001.18702   C:\WINDOWS\system32
67340000 safemon.dll            8.1.1.1020       C:\Program Files\360\360Safe\safemon
68000000 rsaenh.dll             5.1.2600.5507    C:\WINDOWS\system32
68100000 dssenh.dll             5.1.2600.5507    C:\WINDOWS\system32
6bd10000 msohevi.dll            12.0.4518.1014   C:\Program Files\Microsoft Office\Office12
719c0000 mswsock.dll            5.1.2600.5625    C:\WINDOWS\system32
71a00000 wshtcpip.dll           5.1.2600.5512    C:\WINDOWS\System32
71a10000 WS2HELP.dll            5.1.2600.5512    C:\WINDOWS\system32
71a20000 WS2_32.dll             5.1.2600.5512    C:\WINDOWS\system32
71a40000 wsock32.dll            5.1.2600.5512    C:\WINDOWS\system32
71a90000 MPR.dll                5.1.2600.5512    C:\WINDOWS\system32
71b70000 SAMLIB.dll             5.1.2600.5512    C:\WINDOWS\System32
71b90000 ntlanman.dll           5.1.2600.5512    C:\WINDOWS\System32
71c00000 NETRAP.dll             5.1.2600.5512    C:\WINDOWS\System32
71c10000 NETUI1.dll             5.1.2600.5512    C:\WINDOWS\System32
71c50000 NETUI0.dll             5.1.2600.5512    C:\WINDOWS\System32
727a0000 MFC42u.DLL             6.2.8081.0       C:\WINDOWS\system32
72f70000 winspool.drv           5.1.2600.5512    C:\WINDOWS\system32
73540000 ODBC32.dll             3.525.3012.0     C:\WINDOWS\system32
73640000 msctfime.ime           5.1.2600.5768    C:\WINDOWS\system32
73ce0000 shgina.dll             6.0.2900.5512    C:\WINDOWS\system32
73fa0000 USP10.dll              1.420.2600.5969  C:\WINDOWS\system32
74680000 MSCTF.dll              5.1.2600.5512    C:\WINDOWS\system32
75430000 CRYPTUI.dll            5.131.2600.5512  C:\WINDOWS\system32
758d0000 MSGINA.dll             5.1.2600.5512    C:\WINDOWS\system32
759d0000 USERENV.dll            5.1.2600.5512    C:\WINDOWS\system32
75ed0000 drprov.dll             5.1.2600.5512    C:\WINDOWS\System32
75ee0000 davclnt.dll            5.1.2600.5512    C:\WINDOWS\System32
75ef0000 browseui.dll           6.0.2900.6182    C:\WINDOWS\system32
76060000 SETUPAPI.dll           5.1.2600.5512    C:\WINDOWS\system32
762d0000 WINSTA.dll             5.1.2600.5512    C:\WINDOWS\system32
762f0000 MSIMG32.dll            5.1.2600.5512    C:\WINDOWS\system32
76300000 IMM32.DLL              5.1.2600.5512    C:\WINDOWS\system32
76320000 comdlg32.dll           6.0.2900.5512    C:\WINDOWS\system32
76570000 CSCDLL.dll             5.1.2600.5512    C:\WINDOWS\System32
76590000 cscui.dll              5.1.2600.5512    C:\WINDOWS\System32
765e0000 crypt32.dll            5.131.2600.6237  C:\WINDOWS\system32
76950000 LINKINFO.dll           5.1.2600.5512    C:\WINDOWS\system32
76960000 ntshrui.dll            5.1.2600.5512    C:\WINDOWS\system32
76990000 ole32.dll              5.1.2600.6168    C:\WINDOWS\system32
76af0000 ATL.DLL                3.5.2284.2       C:\WINDOWS\system32
76b10000 winmm.dll              5.1.2600.6160    C:\WINDOWS\system32
76bc0000 PSAPI.DLL              5.1.2600.5512    C:\WINDOWS\system32
76c00000 WINTRUST.dll           5.131.2600.5922  C:\WINDOWS\system32
76c60000 IMAGEHLP.dll           5.1.2600.6198    C:\WINDOWS\system32
76d30000 iphlpapi.dll           5.1.2600.5512    C:\WINDOWS\system32
76d70000 appHelp.dll            5.1.2600.5512    C:\WINDOWS\system32
76db0000 MSASN1.dll             5.1.2600.5875    C:\WINDOWS\system32
76f30000 WLDAP32.dll            5.1.2600.5512    C:\WINDOWS\system32
76fa0000 CLBCATQ.DLL            2001.12.4414.700 C:\WINDOWS\system32
77020000 COMRes.dll             2001.12.4414.700 C:\WINDOWS\system32
770f0000 oleaut32.dll           5.1.2600.6058    C:\WINDOWS\system32
77180000 comctl32.dll           6.0.2900.6028    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
77bd0000 version.dll            5.1.2600.5512    C:\WINDOWS\system32
77be0000 msvcrt.dll             7.0.2600.5512    C:\WINDOWS\system32
77d10000 user32.dll             5.1.2600.5512    C:\WINDOWS\system32
77da0000 advapi32.dll           5.1.2600.5755    C:\WINDOWS\system32
77e50000 RPCRT4.dll             5.1.2600.6022    C:\WINDOWS\system32
77ef0000 GDI32.dll              5.1.2600.5698    C:\WINDOWS\system32
77f40000 SHLWAPI.dll            6.0.2900.5912    C:\WINDOWS\system32
77fc0000 Secur32.dll            5.1.2600.5834    C:\WINDOWS\system32
78130000 MSVCR80.dll            8.0.50727.4053   C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989
7c360000 MSVCR71.dll            7.10.6030.0      C:\WINDOWS\system32
7c3c0000 MSVCP71.dll            7.10.6030.0      C:\WINDOWS\system32
7c800000 kernel32.dll           5.1.2600.5781    C:\WINDOWS\system32
7c920000 ntdll.dll              5.1.2600.6055    C:\WINDOWS\system32
7d590000 shell32.dll            6.0.2900.6072    C:\WINDOWS\system32
7e550000 shdocvw.dll            6.0.2900.6182    C:\WINDOWS\system32

processes:
0000 Idle                  0    0
0004 System                0    0    normal
0294 smss.exe              0    0    normal C:\WINDOWS\system32
02c8 csrss.exe             0    0
02e0 winlogon.exe          46   14   high   C:\WINDOWS\system32
030c services.exe          4    2    normal C:\WINDOWS\system32
0318 lsass.exe             4    2    normal C:\WINDOWS\system32
03b4 svchost.exe           4    1    normal C:\WINDOWS\system32
03f8 svchost.exe           0    0
0420 svchost.exe           11   26   normal C:\WINDOWS\System32
044c svchost.exe           0    0
0470 svchost.exe           0    0
047c zhudongfangyu.exe     4    5    normal C:\Program Files\360\360Safe\deepscan
0564 HZ_CommSrv.exe        4    1    normal C:\WINDOWS\system32
058c inetinfo.exe          4    7    normal C:\WINDOWS\system32\inetsrv
0598 sqlservr.exe          4    1    normal C:\PROGRA~1\MICROS~4\MSSQL\binn
0684 Explorer.EXE          540  339  normal C:\WINDOWS
06c0 mysqld-nt.exe         4    3    normal C:\mysql\bin
0764 WDKeyMonitorCCB.exe   11   8    normal C:\WINDOWS\system32\WatchData\Watchdata CCB OCL CSP v3.2
0798 360Tray.exe           236  79   normal C:\Program Files\360\360Safe\safemon
07b8 ctfmon.exe            28   12   normal C:\WINDOWS\system32
07c0 360sd.exe             336  182  normal C:\Program Files\360\360sd
07d0 sqlmangr.exe          153  93   normal C:\Program Files\Microsoft SQL Server\80\Tools\Binn
0608 360EntClient.exe      14   46   normal C:\Program Files\360\360Safe
0854 SoftManagerLite.exe   237  67   normal C:\Program Files\360\360Safe\SoftMgr
0894 360rp.exe             4    5    normal C:\Program Files\360\360sd
0e50 TXPlatform.exe        8    6    normal C:\Program Files\Tencent\QQ\Bin
0e74 QQ.exe                1153 164  normal C:\Program Files\Tencent\QQ\Bin
069c QQ.exe                1063 125  normal C:\Program Files\Tencent\QQ\Bin
00e4 GreenBrowser.exe      1277 523  normal C:\Program Files\GreenBrowser
0dc8 dllhost.exe           0    0
0a1c dllhost.exe           4    3    normal C:\WINDOWS\system32
0de0 msdtc.exe             0    0
0bf0 360rps.exe            4    3    normal C:\Program Files\360\360sd
0e0c QQExternal.exe        105  37   normal C:\Program Files\Tencent\QQ\Bin
0e98 WINWORD.EXE           347  106  normal C:\Program Files\Microsoft Office\Office12
0e1c Dreamweaver.exe       1495 1598 normal C:\Program Files\Adobe\Adobe Dreamweaver CS5
0758 CS5ServiceManager.exe 8    5    normal C:\Program Files\Common Files\Adobe\CS5ServiceManager
17d0 QQ.exe                827  115  normal C:\Program Files\Tencent\QQ\Bin
167c conime.exe            18   12   normal C:\WINDOWS\system32
17f4 QzoneMusic.exe        11   19   normal C:\Program Files\Tencent\QQMusic
16ac FlashFXP.exe          302  213  normal O:\ù\flashftp
1664 notepad.exe           35   21   normal C:\WINDOWS\system32
11bc SogouCloud.exe        8    1    normal C:\Program Files\SogouInput\6.2.0.7270

hardware:
+ DVD/CD-ROM 
  - PHILIPS SPD2216T
+ IDE ATA/ATAPI 
  - Intel(R) ICH7 Family Ultra ATA Storage Controllers - 27DF (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family Serial ATA Storage Controller - 27C0 (driver 9.1.1.1016)
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
+ 
  - Pentium(R) Dual-Core  CPU      E5400  @ 2.70GHz
  - Pentium(R) Dual-Core  CPU      E5400  @ 2.70GHz
+ 
  - Kingston DT 101 G2 USB Device
  - ST3250318AS
+ ˿ (COM  LPT)
  - ECP ӡ˿ (LPT1)
  - ͨѶ˿ (COM1)
+ 
  - 弴ü
  - 弴ü
+ 
  - ACPI Multiprocessor PC
+ 
  - QuickOn Button (driver 1.2.1.420)
+ ƵϷ
  - VIA High Definition Audio (driver 6.0.1.8700)
  - ͳƵ׽豸
  - ͳƵ
  - ý豸
  - Ƶ
  - Ƶ
+ ָ豸
  - Microsoft PS/2 Mouse
+ ͨô߿
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C9 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CA (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CB (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB2 Enhanced Host Controller - 27CC (driver 9.1.1.1016)
  - USB Mass Storage Device
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
+ 
  - Atheros L2 Fast Ethernet 10/100 Base-T Controller (driver 2.5.7.16)
+ ϵͳ豸
  - ACPI Fixed Feature Button
  - ACPI Power Button
  - ACPI Thermal Zone
  - Direct memory access controller
  - High Precision Event Timer (driver 7.0.0.1011)
  - Intel(R) 82801 PCI Bridge - 244E (driver 7.0.0.1011)
  - Intel(R) 82802 Firmware Hub Device
  - Intel(R) G33/G31/P35/P31 Express Chipset Processor to I/O Controller - 29C0 (driver 8.6.1.1001)
  - Intel(R) ICH7 Family LPC Interface Controller - 27B8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family PCI Express Root Port - 27D0 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family SMBus Controller - 27DA (driver 9.1.1.1016)
  - ISAPNP Read Data Port
  - Logical Disk Manager
  - Microcode Update Device
  - Microsoft ACPI-Compliant System
  - Microsoft Composite Battery
  - Microsoft System Management BIOS Driver
  - Microsoft  High Definition Audio  UAA 
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Numeric data processor
  - PCI bus
  - Plug and Play Software Device Enumerator
  - Printer Port Logical Interface
  - Programmable interrupt controller
  - System board
  - System board
  - System CMOS/real time clock
  - System speaker
  - System timer
  - Terminal Server Device Redirector
  - Terminal Server Keyboard Driver
  - Terminal Server Mouse Driver
  - Volume Manager
  - ̨ȫʾƵ
+ ʾ
  - Intel(R) G33/G31 Express Chipset Family (driver 6.14.10.5218)

cpu registers:
eax = 00eb67d0
ebx = 00ea9780
ecx = 00000001
edx = 00e96300
esi = 0000000e
edi = 00000002
eip = 0000635f
esp = 0012ecc8
ebp = 5dd2d35b

stack dump:
0012ecc8  b1 c4 41 00 00 63 e9 00 - 01 00 00 00 e0 da 70 00  ..A..c........p.
0012ecd8  00 63 e9 00 80 97 ea 00 - 01 00 00 00 8c 22 45 00  .c..........."E.
0012ece8  80 97 ea 00 00 63 e9 00 - 01 00 00 00 d9 5c 44 00  .....c.......\D.
0012ecf8  e0 da 70 00 c2 01 00 00 - 12 00 00 00 60 0d f2 00  ..p.........`...
0012ed08  b1 c4 41 00 00 63 e9 00 - 01 00 00 00 c4 ed 12 00  ..A..c..........
0012ed18  00 63 e9 00 60 0d f2 00 - 01 b3 f4 00 8c 22 45 00  .c..`........"E.
0012ed28  60 0d f2 00 00 63 e9 00 - 01 b3 f4 00 d9 5c 44 00  `....c.......\D.
0012ed38  c4 ed 12 00 e4 24 72 00 - 60 0d f2 00 00 63 e9 00  .....$r.`....c..
0012ed48  be c3 41 00 a0 ef 12 00 - 00 63 e9 00 00 63 e9 00  ..A......c...c..
0012ed58  55 c2 41 00 00 16 be 02 - c4 ed 12 00 a0 ef 12 00  U.A.............
0012ed68  00 63 e9 00 00 63 e9 00 - 3e 20 45 00 00 9f c0 02  .c...c..>.E.....
0012ed78  01 00 00 00 5d 37 40 00 - f7 43 42 00 60 7d f6 00  ....]7@..CB.`}..
0012ed88  60 7d f6 00 00 63 e9 00 - f8 4e 45 00 00 2a f3 00  `}...c...NE..*..
0012ed98  00 63 e9 00 00 9a f1 00 - 15 4f 44 00 a0 ef 12 00  .c.......OD.....
0012eda8  00 63 e9 00 84 5b 44 00 - 70 ef 12 00 ac 3a 40 00  .c...[D.p....:@.
0012edb8  c4 ed 12 00 3c 00 00 01 - 00 63 e9 00 10 ef 12 00  ....<....c......
0012edc8  e7 33 40 00 99 95 44 00 - 38 3e 45 00 a0 ef 12 00  .3@...D.8>E.....
0012edd8  a0 ef 12 00 00 63 e9 00 - a7 66 45 00 a0 ef 12 00  .....c...fE.....
0012ede8  a0 ef 12 00 20 df f9 00 - e2 a1 1b 00 60 04 ff 73  ............`..s
0012edf8  01 00 00 00 08 39 10 03 - f6 04 1e 00 08 30 10 03  .....9.......0..

disassembling:
00445cc4      public Forms.TCustomForm.Notification:  ; function entry point
00445cc4 2776   push    ebx
00445cc5        push    esi
00445cc6        push    edi
00445cc7        push    ebp
00445cc8        mov     ebx, ecx
00445cca        mov     esi, edx
00445ccc        mov     edi, eax
00445cce 2777   mov     ecx, ebx
00445cd0        mov     edx, esi
00445cd2        mov     eax, edi
00445cd4      > call    +$c59f ($452278)       ; Controls.TControl.Notification
00445cd9 2778   mov     eax, ebx
00445cdb        sub     al, 1
00445cdd        jb      loc_445ce6
00445cdf        jz      loc_445d51
00445ce1        jmp     loc_445d99
00445ce6 2781   mov     eax, esi
00445ce8        mov     edx, [$463dd8]
00445cee        call    -$4279f ($403554)      ; System.@IsClass
00445cf3        test    al, al
00445cf5        jz      loc_445d21
00445cf7 2783   cmp     dword ptr [edi+$2bc], 0
00445cfe        jnz     loc_445d12
00445d00        mov     dl, 1
00445d02        mov     eax, [$41233c]
00445d07        call    -$42960 ($4033ac)      ; System.TObject.Create
00445d0c        mov     [edi+$2bc], eax
00445d12 2784   mov     edx, esi
00445d14        mov     eax, [edi+$2bc]
00445d1a        call    -$31c93 ($41408c)      ; Classes.TList.Add
00445d1f        jmp     loc_445d99
[...]

date/time         : 2013-05-16, 16:25:46, 667ms
computer name     : ZHENGYISONG
user name         : Administrator <admin>
registered owner  : Sky123.Org / Sky123.Org
operating system  : Windows XP Service Pack 3 (5.1.2600) build 2600
system language   : Chinese
system up time    : 8 hours 5 minutes
program up time   : 1 minute 58 seconds
processors        : 2x Pentium(R) Dual-Core CPU E5400 @ 2.70GHz
physical memory   : 1046/2038 MB (free/total)
free disk space   : (C:) 13.46 GB (M:) 20.93 GB
display mode      : 1440x900, 32 bit
process id        : $4fc
allocated memory  : 29.49 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $1c382623, $54ce218a, $8cd16631
count             : 2
exception number  : 1
exception class   : EAccessViolation
exception message : Access violation at address 7C9301B3 in module 'ntdll.dll'. д of address 77F49B5A.

main thread ($a9c):
7c9301b3 +00ef ntdll.dll                                RtlAllocateHeap
7c809a79 +004c kernel32.dll                             LocalAlloc
77f4a018 +000f SHLWAPI.dll                              #544
006480fd +00e9 FlashFXP.exe UPTShellControls  8352  +23 TPTCustomShellList.ProcessMenuForAllSelected
007660d5 +0085 FlashFXP.exe FrmMain1         25198   +4 TFrmMain.Explorer1Click
00461047 +008f FlashFXP.exe Menus                       TMenuItem.Click
004621bf +0013 FlashFXP.exe Menus                       TMenu.DispatchCommand
0046314b +00bf FlashFXP.exe Menus                       TPopupList.WndProc
0046305d +001d FlashFXP.exe Menus                       TPopupList.MainWndProc
0041d0de +00a2 FlashFXP.exe Classes                     TStreamAdapter.Clone
77d196c2 +000a user32.dll                               DispatchMessageA
0044ca9f +008b FlashFXP.exe Forms             7117  +34 TApplication.ProcessMessage
0044cad6 +000a FlashFXP.exe Forms             7155   +1 TApplication.HandleMessage
0044cd8b +00bf FlashFXP.exe Forms             7259  +26 TApplication.Run
007964ed +1c69 FlashFXP.exe FlashFXP           920 +630 initialization

thread $f90:
7c92df48 +a ntdll.dll  NtWaitForMultipleObjects

thread $10b4:
7c92df48 +00a ntdll.dll                              NtWaitForMultipleObjects
7c80958a +000 kernel32.dll                           WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll                           WaitForMultipleObjects
00640bd3 +07b FlashFXP.exe UPTShellControls 4370 +13 TChangeHandlerThread.Execute
0041bfc1 +22d FlashFXP.exe Classes                   HexToBin
00404080 +028 FlashFXP.exe System                    ThreadWrapper

thread $7e0: <priority:1>
7c92da48 +a ntdll.dll  NtRemoveIoCompletion

thread $cd0:
7c92df48 +00a ntdll.dll                  NtWaitForMultipleObjects
7c80958a +000 kernel32.dll               WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll               WaitForMultipleObjects
00662068 +10c FlashFXP.exe SaveToFileThd TSaveFileWorker.Execute
0041bfc1 +22d FlashFXP.exe Classes       HexToBin
00404080 +028 FlashFXP.exe System        ThreadWrapper

thread $e30:
7c92daa8 +a ntdll.dll  NtReplyWaitReceivePortEx

thread $1190:
7c92d218 +0a ntdll.dll     NtDelayExecution
7c8023eb +4b kernel32.dll  SleepEx
7c802450 +0a kernel32.dll  Sleep
7c930432 +25 ntdll.dll     RtlAcquirePebLock

thread $688:
7c92daa8 +a ntdll.dll  NtReplyWaitReceivePortEx

thread $9c8:
7c92d218 +a ntdll.dll  NtDelayExecution

modules:
00400000 FlashFXP.exe           4.0.0.1534       M:\ù߰\flashfxp
00fd0000 Normaliz.dll           6.0.5441.0       C:\WINDOWS\system32
01570000 360CloudShellExt.dll   1.0.0.1007       C:\Program Files\360\360YunPan\360cloud
03270000 360UDiskGuard.dll      2.0.0.1039       C:\Program Files\360\360Safe\safemon
03910000 libeay32.dll           1.0.0.3          M:\ù߰\flashfxp
03a60000 ssleay32.dll           1.0.0.3          M:\ù߰\flashfxp
04290000 xpsp2res.dll           5.1.2600.5512    C:\WINDOWS\system32
07160000 audiodev.dll           5.2.5721.5262    C:\WINDOWS\system32
10000000 HKDll.dll                               D:\ù߰\PSTrayFactory
10930000 portabledeviceapi.dll  5.2.5721.5262    C:\WINDOWS\system32
11c70000 WMASF.DLL              11.0.5721.5262   C:\WINDOWS\system32
15110000 WMVCore.DLL            11.0.5721.5275   C:\WINDOWS\system32
16500000 wpdshext.dll           5.2.5721.5262    C:\WINDOWS\system32
1f840000 odbcint.dll            3.525.1117.0     C:\WINDOWS\system32
25300000 net_monitor2.0.2.9.dll 2.0.2.9          C:\Program Files\Common Files\Thunder Network\NetMon
3e410000 WININET.dll            8.0.6001.23486   C:\WINDOWS\system32
3eab0000 iertutil.dll           8.0.6001.23486   C:\WINDOWS\system32
3eca0000 ieframe.dll            8.0.6001.23486   C:\WINDOWS\system32
43ce0000 urlmon.dll             8.0.6001.23486   C:\WINDOWS\system32
4ae90000 gdiplus.dll            5.2.6002.22791   C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22791_x-ww_c8dff154
5a540000 wiashext.dll           5.1.2600.5512    C:\WINDOWS\system32
5adc0000 UxTheme.dll            6.0.2900.5512    C:\WINDOWS\system32
5efe0000 olepro32.dll           5.1.2600.5512    C:\WINDOWS\system32
5fdd0000 NETAPI32.dll           5.1.2600.6260    C:\WINDOWS\system32
60fd0000 hnetcfg.dll            5.1.2600.5512    C:\WINDOWS\system32
62c20000 LPK.DLL                5.1.2600.5512    C:\WINDOWS\system32
67340000 safemon.dll            8.2.2.1342       C:\Program Files\360\360Safe\safemon
68000000 rsaenh.dll             5.1.2600.5507    C:\WINDOWS\system32
68100000 dssenh.dll             5.1.2600.5507    C:\WINDOWS\system32
719c0000 mswsock.dll            5.1.2600.5625    C:\WINDOWS\System32
71a00000 wshtcpip.dll           5.1.2600.5512    C:\WINDOWS\System32
71a10000 WS2HELP.dll            5.1.2600.5512    C:\WINDOWS\system32
71a20000 WS2_32.dll             5.1.2600.5512    C:\WINDOWS\system32
71a40000 wsock32.dll            5.1.2600.5512    C:\WINDOWS\system32
71a90000 MPR.dll                5.1.2600.5512    C:\WINDOWS\system32
71b70000 SAMLIB.dll             5.1.2600.5512    C:\WINDOWS\System32
71b90000 ntlanman.dll           5.1.2600.5512    C:\WINDOWS\System32
71c00000 NETRAP.dll             5.1.2600.5512    C:\WINDOWS\System32
71c10000 NETUI1.dll             5.1.2600.5512    C:\WINDOWS\System32
71c50000 NETUI0.dll             5.1.2600.5512    C:\WINDOWS\System32
72f70000 winspool.drv           5.1.2600.5512    C:\WINDOWS\system32
73540000 ODBC32.dll             3.525.3012.0     C:\WINDOWS\system32
73640000 msctfime.ime           5.1.2600.5768    C:\WINDOWS\system32
73b10000 sti.dll                5.1.2600.5512    C:\WINDOWS\system32
73ce0000 shgina.dll             6.0.2900.5512    C:\WINDOWS\system32
73fa0000 USP10.dll              1.420.2600.5969  C:\WINDOWS\system32
74680000 MSCTF.dll              5.1.2600.5512    C:\WINDOWS\system32
74a40000 CFGMGR32.dll           5.1.2600.5512    C:\WINDOWS\system32
75430000 CRYPTUI.dll            5.131.2600.5512  C:\WINDOWS\system32
758d0000 MSGINA.dll             5.1.2600.5512    C:\WINDOWS\system32
759d0000 USERENV.dll            5.1.2600.5512    C:\WINDOWS\system32
75ed0000 drprov.dll             5.1.2600.5512    C:\WINDOWS\System32
75ee0000 davclnt.dll            5.1.2600.5512    C:\WINDOWS\System32
75ef0000 browseui.dll           6.0.2900.6182    C:\WINDOWS\system32
76060000 SETUPAPI.dll           5.1.2600.5512    C:\WINDOWS\system32
762d0000 WINSTA.dll             5.1.2600.5512    C:\WINDOWS\system32
76300000 IMM32.DLL              5.1.2600.5512    C:\WINDOWS\system32
76320000 comdlg32.dll           6.0.2900.5512    C:\WINDOWS\system32
76570000 CSCDLL.dll             5.1.2600.5512    C:\WINDOWS\System32
76590000 cscui.dll              5.1.2600.5512    C:\WINDOWS\System32
765e0000 crypt32.dll            5.131.2600.6237  C:\WINDOWS\system32
76950000 LINKINFO.dll           5.1.2600.5512    C:\WINDOWS\system32
76960000 ntshrui.dll            5.1.2600.5512    C:\WINDOWS\system32
76990000 ole32.dll              5.1.2600.6168    C:\WINDOWS\system32
76af0000 ATL.DLL                3.5.2284.2       C:\WINDOWS\system32
76b10000 winmm.dll              5.1.2600.6160    C:\WINDOWS\system32
76bc0000 PSAPI.DLL              5.1.2600.5512    C:\WINDOWS\system32
76c00000 WINTRUST.dll           5.131.2600.5922  C:\WINDOWS\system32
76c60000 IMAGEHLP.dll           5.1.2600.6198    C:\WINDOWS\system32
76d30000 iphlpapi.dll           5.1.2600.5512    C:\WINDOWS\system32
76d70000 appHelp.dll            5.1.2600.5512    C:\WINDOWS\system32
76db0000 MSASN1.dll             5.1.2600.5875    C:\WINDOWS\system32
76ef0000 DNSAPI.dll             5.1.2600.6089    C:\WINDOWS\system32
76f30000 WLDAP32.dll            5.1.2600.5512    C:\WINDOWS\system32
76f90000 rasadhlp.dll           5.1.2600.5512    C:\WINDOWS\system32
76fa0000 CLBCATQ.DLL            2001.12.4414.700 C:\WINDOWS\system32
77020000 COMRes.dll             2001.12.4414.700 C:\WINDOWS\system32
770f0000 oleaut32.dll           5.1.2600.6341    C:\WINDOWS\system32
77180000 comctl32.dll           6.0.2900.6028    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
77bd0000 version.dll            5.1.2600.5512    C:\WINDOWS\system32
77be0000 msvcrt.dll             7.0.2600.5512    C:\WINDOWS\system32
77d10000 user32.dll             5.1.2600.5512    C:\WINDOWS\system32
77da0000 advapi32.dll           5.1.2600.5755    C:\WINDOWS\system32
77e50000 RPCRT4.dll             5.1.2600.6022    C:\WINDOWS\system32
77ef0000 GDI32.dll              5.1.2600.5698    C:\WINDOWS\system32
77f40000 SHLWAPI.dll            6.0.2900.5912    C:\WINDOWS\system32
77fc0000 Secur32.dll            5.1.2600.5834    C:\WINDOWS\system32
7c360000 MSVCR71.dll            7.10.6030.0      C:\WINDOWS\system32
7c3c0000 MSVCP71.dll            7.10.6030.0      C:\WINDOWS\system32
7c800000 kernel32.dll           5.1.2600.6293    C:\WINDOWS\system32
7c920000 ntdll.dll              5.1.2600.6055    C:\WINDOWS\system32
7d590000 shell32.dll            6.0.2900.6242    C:\WINDOWS\system32
7e550000 shdocvw.dll            6.0.2900.6182    C:\WINDOWS\system32

processes:
0000 Idle                         0    0
0004 System                       0    0   normal
01a0 smss.exe                     0    0   normal C:\WINDOWS\system32
01e4 csrss.exe                    67   60  normal C:\WINDOWS\system32
01fc winlogon.exe                 44   14  high   C:\WINDOWS\system32
0228 services.exe                 4    2   normal C:\WINDOWS\system32
0234 lsass.exe                    6    3   normal C:\WINDOWS\system32
02d4 svchost.exe                  4    1   normal C:\WINDOWS\system32
0304 svchost.exe                  4    2   normal C:\WINDOWS\system32
0358 svchost.exe                  11   24  normal C:\WINDOWS\System32
0384 svchost.exe                  4    1   normal C:\WINDOWS\system32
0398 svchost.exe                  4    1   normal C:\WINDOWS\system32
03c8 zhudongfangyu.exe            4    5   normal C:\Program Files\360\360Safe\deepscan
04e8 aspnet_state.exe             4    2   normal C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727
0504 HZ_CommSrv.exe               4    1   normal C:\WINDOWS\system32
0518 inetinfo.exe                 4    7   normal C:\WINDOWS\system32\inetsrv
0530 MsDtsSrvr.exe                4    1   normal C:\Program Files\Microsoft SQL Server\90\DTS\Binn
0578 msmdsrv.exe                  4    2   normal C:\Program Files\Microsoft SQL Server\MSSQL.1\OLAP\bin
0588 mysqld-nt.exe                4    3   normal C:\mysql\bin
0614 ReportingServicesService.exe 4    2   normal C:\Program Files\Microsoft SQL Server\MSSQL.2\Reporting Services\ReportServer\bin
0644 sqlbrowser.exe               4    1   normal C:\Program Files\Microsoft SQL Server\90\Shared
0678 WDKeyMonitorCCB.exe          7    8   normal C:\WINDOWS\system32\WatchData\Watchdata CCB OCL CSP v3.2
03d4 PSTrayFactory.exe            166  150 normal D:\ù߰\PSTrayFactory
072c 360Tray.exe                  347  95  normal C:\Program Files\360\360Safe\safemon
0754 360sd.exe                    28   19  normal C:\Program Files\360\360sd
076c ctfmon.exe                   117  60  normal C:\WINDOWS\system32
0904 360rp.exe                    4    5   normal C:\Program Files\360\360sd
0748 SoftManagerLite.exe          282  99  normal C:\Program Files\360\360Safe\SoftMgr
0ff4 QQProtect.exe                7    14  normal C:\Program Files\Tencent\QQ\QQProtect\Bin
0e1c QQ.exe                       1570 209 normal C:\Program Files\Tencent\QQ\bin
08e4 TXPlatform.exe               5    5   normal C:\Program Files\Tencent\QQ\bin
01b4 QQ.exe                       787  123 normal C:\Program Files\Tencent\QQ\bin
097c QQ.exe                       952  144 normal C:\Program Files\Tencent\QQ\bin
10d8 SGImeGuard.exe               5    4   normal C:\Program Files\SogouInput\Components\AddressSearch\1.0.0.1169
11c4 dllhost.exe                  5    49  normal C:\WINDOWS\system32
066c dllhost.exe                  4    3   normal C:\WINDOWS\system32
0e00 svchost.exe                  4    2   normal C:\WINDOWS\system32
0d5c WINWORD.EXE                  280  107 normal C:\Program Files\Microsoft Office\Office12
0ebc 360rps.exe                   4    3   normal C:\Program Files\360\360sd
0f08 conime.exe                   15   12  normal C:\WINDOWS\system32
1184 KwService.exe                14   22  normal C:\Program Files\kuwo\KWMUSIC\bin
1450 SogouCloud.exe               4    1   normal C:\Program Files\SogouInput\6.2.0.7270
13a4 explorer.exe                 316  277 normal C:\WINDOWS
168c mstsc.exe                    126  105 normal C:\WINDOWS\system32
1388 iexplore.exe                 268  101 normal C:\Program Files\Internet Explorer
0ff8 iexplore.exe                 280  185 normal C:\Program Files\Internet Explorer
04fc FlashFXP.exe                 216  169 normal M:\ù߰\flashfxp
0ee4 Dreamweaver.exe              305  449 normal C:\Program Files\Macromedia\Dreamweaver 8

hardware:
+ DVD/CD-ROM 
  - PHILIPS SPD2216T
+ IDE ATA/ATAPI 
  - Intel(R) ICH7 Family Ultra ATA Storage Controllers - 27DF (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family Serial ATA Storage Controller - 27C0 (driver 9.1.1.1016)
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
+ 
  - Pentium(R) Dual-Core  CPU      E5400  @ 2.70GHz
  - Pentium(R) Dual-Core  CPU      E5400  @ 2.70GHz
+ 
  - ST3250318AS
  - 
+ ˿ (COM  LPT)
  - ECP ӡ˿ (LPT1)
  - ͨѶ˿ (COM1)
+ 
  - 弴ü
  - 弴ü
+ 
  - ACPI Multiprocessor PC
+ 
  - QuickOn Button (driver 1.2.1.420)
+ ƵϷ
  - VIA High Definition Audio (driver 6.0.1.8700)
  - ͳƵ׽豸
  - ͳƵ
  - ý豸
  - Ƶ
  - Ƶ
+ ָ豸
  - Microsoft PS/2 Mouse
+ ͨô߿
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C9 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CA (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CB (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB2 Enhanced Host Controller - 27CC (driver 9.1.1.1016)
  - USB Mass Storage Device
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
+ 
  - Atheros L2 Fast Ethernet 10/100 Base-T Controller (driver 2.5.7.16)
+ ϵͳ豸
  - ACPI Fixed Feature Button
  - ACPI Power Button
  - ACPI Thermal Zone
  - Direct memory access controller
  - High Precision Event Timer (driver 7.0.0.1011)
  - Intel(R) 82801 PCI Bridge - 244E (driver 7.0.0.1011)
  - Intel(R) 82802 Firmware Hub Device
  - Intel(R) G33/G31/P35/P31 Express Chipset Processor to I/O Controller - 29C0 (driver 8.6.1.1001)
  - Intel(R) ICH7 Family LPC Interface Controller - 27B8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family PCI Express Root Port - 27D0 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family SMBus Controller - 27DA (driver 9.1.1.1016)
  - ISAPNP Read Data Port
  - Logical Disk Manager
  - Microcode Update Device
  - Microsoft ACPI-Compliant System
  - Microsoft Composite Battery
  - Microsoft System Management BIOS Driver
  - Microsoft  High Definition Audio  UAA 
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Numeric data processor
  - PCI bus
  - Plug and Play Software Device Enumerator
  - Printer Port Logical Interface
  - Programmable interrupt controller
  - System board
  - System board
  - System CMOS/real time clock
  - System speaker
  - System timer
  - Terminal Server Device Redirector
  - Terminal Server Keyboard Driver
  - Terminal Server Mouse Driver
  - Volume Manager
  - ̨ȫʾƵ
+ ʾ
  - Intel(R) G33/G31 Express Chipset Family (driver 6.14.10.5218)

cpu registers:
eax = 77f49b08
ebx = 00150000
ecx = 00000010
edx = 20c40001
esi = 77f49b5c
edi = 77f49b54
eip = 7c9301b3
esp = 0012f2f8
ebp = 0012f518

stack dump:
0012f2f8  00 00 00 00 78 b6 c0 03 - 0e 00 07 80 00 00 00 00  ....x...........
0012f308  45 00 53 00 5c 00 4a 00 - 53 00 46 00 69 00 6c 00  E.S.\.J.S.F.i.l.
0012f318  65 00 5c 00 43 00 75 00 - 72 00 56 00 65 00 72 00  e.\.C.u.r.V.e.r.
0012f328  00 00 01 00 24 00 00 00 - 8c f2 12 00 2c f1 12 00  ....$.......,...
0012f338  b0 f5 12 00 20 e9 92 7c - a0 94 bf 03 98 a4 f4 77  .......|.......w
0012f348  00 00 00 00 ae df da 77 - 00 00 15 00 20 01 00 00  .......w........
0012f358  a0 a0 1a 00 e8 f5 12 00 - 6a 00 00 00 98 f3 12 00  ........j.......
0012f368  00 00 15 00 22 02 93 7c - 10 00 00 00 88 09 15 00  ...."..|........
0012f378  00 00 15 00 98 34 22 00 - 70 f3 12 00 00 00 15 00  .....4".p.......
0012f388  b4 f5 12 00 20 e9 92 7c - 28 02 93 7c ff ff ff ff  .......|(..|....
0012f398  22 02 93 7c 9b 01 93 7c - db 01 93 7c a0 b5 00 00  "..|...|...|....
0012f3a8  f0 f4 12 00 c9 43 f4 77 - f0 f4 12 00 e0 43 f4 77  .....C.w.....C.w
0012f3b8  ff ff 00 00 70 f5 12 00 - 80 00 00 00 02 00 00 00  ....p...........
0012f3c8  98 04 00 00 b7 a1 f4 77 - ed 43 f4 77 60 51 59 7d  .......w.C.w`QY}
0012f3d8  80 00 00 00 00 00 00 00 - 70 f5 12 00 00 00 00 00  ........p.......
0012f3e8  14 f6 12 00 20 e9 92 7c - 28 02 93 7c ff ff ff ff  .......|(..|....
0012f3f8  a0 0f 00 00 86 10 93 7c - db 01 93 7c 2c 7b 1d 00  .......|...|,{..
0012f408  08 00 00 00 f0 f6 12 00 - c4 f5 12 00 7f de da 77  ...............w
0012f418  28 f4 12 00 68 f6 12 00 - 54 f6 12 00 8c de da 77  (...h...T......w
0012f428  0d 00 00 00 45 00 88 00 - 00 00 0c 00 9e 00 00 00  ....E...........

disassembling:
[...]
006480c3        jnz     loc_6480cf
006480c5 8349   call    -$2444f6 ($403bd4)     ; System.@TryFinallyExit
006480ca        jmp     loc_6482d3
006480cf 8352   lea     eax, [ebp-$18]
006480d2        push    eax
006480d3        push    0
006480d5        push    $648304
006480da        mov     eax, [ebp-$10]
006480dd        mov     eax, [eax+4]
006480e0        push    eax
006480e1        mov     eax, [ebp-$10]
006480e4        mov     eax, [eax+8]
006480e7        push    eax
006480e8        mov     eax, [ebp-4]
006480eb        call    -$8e50 ($63f2a0)       ; UPTShellControls.GetValidParentHWND
006480f0        push    eax
006480f1        mov     eax, [ebp-4]
006480f4        mov     eax, [eax+$414]
006480fa        push    eax
006480fb        mov     eax, [eax]
006480fd      > call    dword ptr [eax+$28]
00648100        mov     ebx, eax
00648102 8353   mov     eax, ebx
00648104        call    -$237185 ($410f84)     ; ActiveX.Failed
00648109        test    al, al
0064810b        jz      loc_648117
0064810d        call    -$24453e ($403bd4)     ; System.@TryFinallyExit
00648112        jmp     loc_6482d3
00648117 8354   call    -$2402b8 ($407e64)     ; Windows.CreatePopupMenu
0064811c        mov     [ebp-$14], eax
0064811f 8355   cmp     dword ptr [ebp-$14], 0
00648123        jnz     loc_64812f
00648125        call    -$244556 ($403bd4)     ; System.@TryFinallyExit
0064812a        jmp     loc_6482d3
0064812f 8357   mov     eax, [ebp-4]
00648132        call    -$151dbb ($4f637c)     ; ComCtrls.TCustomListView.GetFocused
00648137        mov     edx, eax
00648139        mov     eax, [ebp-4]
0064813c        call    +$28c3 ($64aa04)       ; UPTShellControls.TPTCustomShellList.GetDataFromItem
00648141        mov     ebx, eax
00648143 8358   test    ebx, ebx
[...]

date/time         : 2013-05-16, 16:44:01, 479ms
computer name     : ZHENGYISONG
user name         : Administrator <admin>
registered owner  : Sky123.Org / Sky123.Org
operating system  : Windows XP Service Pack 3 (5.1.2600) build 2600
system language   : Chinese
system up time    : 8 hours 23 minutes
program up time   : 18 minutes
processors        : 2x Pentium(R) Dual-Core CPU E5400 @ 2.70GHz
physical memory   : 1131/2038 MB (free/total)
free disk space   : (C:) 13.47 GB (M:) 20.93 GB
display mode      : 1440x900, 32 bit
process id        : $1514
allocated memory  : 30.72 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $00000000, $10fec694, $3e4d33c2
exception number  : 1
exception class   : EAccessViolation
exception message : Access violation at address 00000000. ȡ of address 00000000.

main thread ($f84):
00000000 +0000 ???
77f440ce +0048 SHLWAPI.dll                              #219
769ad028 +0010 ole32.dll                                CoTaskMemAlloc
77f46c8d +001a SHLWAPI.dll                              SHStrDupW
77f440ce +0048 SHLWAPI.dll                              #219
00509afb +003f FlashFXP.exe ThemeMgr                    TWindowProcList.DispatchMessage
0045632c +002c FlashFXP.exe Controls                    TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms             1529   +8 StdWndProc
7c92e470 +0010 ntdll.dll                                KiUserCallbackDispatcher
006480fd +00e9 FlashFXP.exe UPTShellControls  8352  +23 TPTCustomShellList.ProcessMenuForAllSelected
007660d5 +0085 FlashFXP.exe FrmMain1         25198   +4 TFrmMain.Explorer1Click
00461047 +008f FlashFXP.exe Menus                       TMenuItem.Click
004621bf +0013 FlashFXP.exe Menus                       TMenu.DispatchCommand
0046314b +00bf FlashFXP.exe Menus                       TPopupList.WndProc
0046305d +001d FlashFXP.exe Menus                       TPopupList.MainWndProc
77d196c2 +000a user32.dll                               DispatchMessageA
0044ca9f +008b FlashFXP.exe Forms             7117  +34 TApplication.ProcessMessage
0044cad6 +000a FlashFXP.exe Forms             7155   +1 TApplication.HandleMessage
0044cd8b +00bf FlashFXP.exe Forms             7259  +26 TApplication.Run
007964ed +1c69 FlashFXP.exe FlashFXP           920 +630 initialization

thread $7cc:
7c92df48 +00a ntdll.dll                              NtWaitForMultipleObjects
7c80958a +000 kernel32.dll                           WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll                           WaitForMultipleObjects
00640bd3 +07b FlashFXP.exe UPTShellControls 4370 +13 TChangeHandlerThread.Execute
0041bfc1 +22d FlashFXP.exe Classes                   HexToBin
00404080 +028 FlashFXP.exe System                    ThreadWrapper

thread $17b8: <priority:1>
7c92da48 +a ntdll.dll  NtRemoveIoCompletion

thread $c58:
7c92df48 +00a ntdll.dll                  NtWaitForMultipleObjects
7c80958a +000 kernel32.dll               WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll               WaitForMultipleObjects
00662068 +10c FlashFXP.exe SaveToFileThd TSaveFileWorker.Execute
0041bfc1 +22d FlashFXP.exe Classes       HexToBin
00404080 +028 FlashFXP.exe System        ThreadWrapper

thread $15c0:
7c92daa8 +a ntdll.dll  NtReplyWaitReceivePortEx

thread $1554:
7c92d218 +a ntdll.dll  NtDelayExecution

thread $16a4:
7c92daa8 +a ntdll.dll  NtReplyWaitReceivePortEx

modules:
00400000 FlashFXP.exe           4.0.0.1534       M:\ù߰\flashfxp
00fd0000 Normaliz.dll           6.0.5441.0       C:\WINDOWS\system32
01570000 360CloudShellExt.dll   1.0.0.1007       C:\Program Files\360\360YunPan\360cloud
03270000 360UDiskGuard.dll      2.0.0.1039       C:\Program Files\360\360Safe\safemon
03910000 libeay32.dll           1.0.0.3          M:\ù߰\flashfxp
03a60000 ssleay32.dll           1.0.0.3          M:\ù߰\flashfxp
04230000 xpsp2res.dll           5.1.2600.5512    C:\WINDOWS\system32
04c90000 UnlockerCOM.dll                         C:\Program Files\Unlocker
04cb0000 rarext.dll             4.20.0.0         C:\Program Files\WinRAR
04d10000 MenuEx.dll             4.0.0.3105       C:\Program Files\360\360sd
04d80000 shell360ext.dll        7.5.0.1200       C:\Program Files\360\360Safe\Utils
04e70000 QvodBand.dll           3.0.0.0          C:\Program Files\QvodPlayer
04eb0000 AliIMExt.dll           1.0.0.1          C:\Program Files\AliWangWang\7.21.01C
04f00000 WoptiEncryptModule.dll 1.6.10.816       D:\ù߰\Żʦ
050d0000 ClickUpExt.dll         2.3.0.1          C:\Program Files\DBank\ClickUp
05110000 shell360dt.dll         2.5.0.1030       C:\Program Files\360\360Safe\SoftMgr\WallPaper
05160000 360CloudBar.dll        1.0.0.1045       C:\Program Files\360\360YunPan\360cloud
07160000 audiodev.dll           5.2.5721.5262    C:\WINDOWS\system32
10000000 HKDll.dll                               D:\ù߰\PSTrayFactory
10930000 portabledeviceapi.dll  5.2.5721.5262    C:\WINDOWS\system32
11c70000 WMASF.DLL              11.0.5721.5262   C:\WINDOWS\system32
15110000 WMVCore.DLL            11.0.5721.5275   C:\WINDOWS\system32
16500000 wpdshext.dll           5.2.5721.5262    C:\WINDOWS\system32
1f840000 odbcint.dll            3.525.1117.0     C:\WINDOWS\system32
25300000 net_monitor2.0.2.9.dll 2.0.2.9          C:\Program Files\Common Files\Thunder Network\NetMon
3e410000 WININET.dll            8.0.6001.23486   C:\WINDOWS\system32
3eab0000 iertutil.dll           8.0.6001.23486   C:\WINDOWS\system32
3eca0000 ieframe.dll            8.0.6001.23486   C:\WINDOWS\system32
43ce0000 urlmon.dll             8.0.6001.23486   C:\WINDOWS\system32
4ae90000 gdiplus.dll            5.2.6002.22791   C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22791_x-ww_c8dff154
5a540000 wiashext.dll           5.1.2600.5512    C:\WINDOWS\system32
5adc0000 UxTheme.dll            6.0.2900.5512    C:\WINDOWS\system32
5efe0000 olepro32.dll           5.1.2600.5512    C:\WINDOWS\system32
5fdd0000 NETAPI32.dll           5.1.2600.6260    C:\WINDOWS\system32
60fd0000 hnetcfg.dll            5.1.2600.5512    C:\WINDOWS\system32
62c20000 LPK.DLL                5.1.2600.5512    C:\WINDOWS\system32
67340000 safemon.dll            8.2.2.1342       C:\Program Files\360\360Safe\safemon
68000000 rsaenh.dll             5.1.2600.5507    C:\WINDOWS\system32
68100000 dssenh.dll             5.1.2600.5507    C:\WINDOWS\system32
719c0000 mswsock.dll            5.1.2600.5625    C:\WINDOWS\System32
71a00000 wshtcpip.dll           5.1.2600.5512    C:\WINDOWS\System32
71a10000 WS2HELP.dll            5.1.2600.5512    C:\WINDOWS\system32
71a20000 WS2_32.dll             5.1.2600.5512    C:\WINDOWS\system32
71a40000 wsock32.dll            5.1.2600.5512    C:\WINDOWS\system32
71a90000 MPR.dll                5.1.2600.5512    C:\WINDOWS\system32
71b70000 SAMLIB.dll             5.1.2600.5512    C:\WINDOWS\System32
71b90000 ntlanman.dll           5.1.2600.5512    C:\WINDOWS\System32
71c00000 NETRAP.dll             5.1.2600.5512    C:\WINDOWS\System32
71c10000 NETUI1.dll             5.1.2600.5512    C:\WINDOWS\System32
71c50000 NETUI0.dll             5.1.2600.5512    C:\WINDOWS\System32
72f70000 winspool.drv           5.1.2600.5512    C:\WINDOWS\system32
73540000 ODBC32.dll             3.525.3012.0     C:\WINDOWS\system32
73640000 msctfime.ime           5.1.2600.5768    C:\WINDOWS\system32
73b10000 sti.dll                5.1.2600.5512    C:\WINDOWS\system32
73ce0000 shgina.dll             6.0.2900.5512    C:\WINDOWS\system32
73fa0000 USP10.dll              1.420.2600.5969  C:\WINDOWS\system32
74680000 MSCTF.dll              5.1.2600.5512    C:\WINDOWS\system32
74a40000 CFGMGR32.dll           5.1.2600.5512    C:\WINDOWS\system32
75430000 CRYPTUI.dll            5.131.2600.5512  C:\WINDOWS\system32
758d0000 MSGINA.dll             5.1.2600.5512    C:\WINDOWS\system32
759d0000 USERENV.dll            5.1.2600.5512    C:\WINDOWS\system32
75ed0000 drprov.dll             5.1.2600.5512    C:\WINDOWS\System32
75ee0000 davclnt.dll            5.1.2600.5512    C:\WINDOWS\System32
75ef0000 browseui.dll           6.0.2900.6182    C:\WINDOWS\system32
76060000 SETUPAPI.dll           5.1.2600.5512    C:\WINDOWS\system32
762d0000 WINSTA.dll             5.1.2600.5512    C:\WINDOWS\system32
762f0000 MSIMG32.dll            5.1.2600.5512    C:\WINDOWS\system32
76300000 IMM32.DLL              5.1.2600.5512    C:\WINDOWS\system32
76320000 comdlg32.dll           6.0.2900.5512    C:\WINDOWS\system32
76570000 CSCDLL.dll             5.1.2600.5512    C:\WINDOWS\System32
76590000 cscui.dll              5.1.2600.5512    C:\WINDOWS\System32
765e0000 crypt32.dll            5.131.2600.6237  C:\WINDOWS\system32
76950000 LINKINFO.dll           5.1.2600.5512    C:\WINDOWS\system32
76960000 ntshrui.dll            5.1.2600.5512    C:\WINDOWS\system32
76990000 ole32.dll              5.1.2600.6168    C:\WINDOWS\system32
76af0000 ATL.DLL                3.5.2284.2       C:\WINDOWS\system32
76b10000 winmm.dll              5.1.2600.6160    C:\WINDOWS\system32
76bc0000 PSAPI.DLL              5.1.2600.5512    C:\WINDOWS\system32
76c00000 WINTRUST.dll           5.131.2600.5922  C:\WINDOWS\system32
76c60000 IMAGEHLP.dll           5.1.2600.6198    C:\WINDOWS\system32
76d30000 iphlpapi.dll           5.1.2600.5512    C:\WINDOWS\system32
76d70000 appHelp.dll            5.1.2600.5512    C:\WINDOWS\system32
76db0000 MSASN1.dll             5.1.2600.5875    C:\WINDOWS\system32
76ef0000 DNSAPI.dll             5.1.2600.6089    C:\WINDOWS\system32
76f30000 WLDAP32.dll            5.1.2600.5512    C:\WINDOWS\system32
76f90000 rasadhlp.dll           5.1.2600.5512    C:\WINDOWS\system32
76fa0000 CLBCATQ.DLL            2001.12.4414.700 C:\WINDOWS\system32
77020000 COMRes.dll             2001.12.4414.700 C:\WINDOWS\system32
770f0000 oleaut32.dll           5.1.2600.6341    C:\WINDOWS\system32
77180000 comctl32.dll           6.0.2900.6028    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
77bd0000 version.dll            5.1.2600.5512    C:\WINDOWS\system32
77be0000 msvcrt.dll             7.0.2600.5512    C:\WINDOWS\system32
77d10000 user32.dll             5.1.2600.5512    C:\WINDOWS\system32
77da0000 advapi32.dll           5.1.2600.5755    C:\WINDOWS\system32
77e50000 RPCRT4.dll             5.1.2600.6022    C:\WINDOWS\system32
77ef0000 GDI32.dll              5.1.2600.5698    C:\WINDOWS\system32
77f40000 SHLWAPI.dll            6.0.2900.5912    C:\WINDOWS\system32
77fc0000 Secur32.dll            5.1.2600.5834    C:\WINDOWS\system32
78050000 MSVCP100.dll           10.0.40219.1     C:\WINDOWS\system32
78aa0000 MSVCR100.dll           10.0.40219.1     C:\WINDOWS\system32
7c360000 MSVCR71.dll            7.10.6030.0      C:\WINDOWS\system32
7c3c0000 MSVCP71.dll            7.10.6030.0      C:\WINDOWS\system32
7c800000 kernel32.dll           5.1.2600.6293    C:\WINDOWS\system32
7c920000 ntdll.dll              5.1.2600.6055    C:\WINDOWS\system32
7d590000 shell32.dll            6.0.2900.6242    C:\WINDOWS\system32
7e550000 shdocvw.dll            6.0.2900.6182    C:\WINDOWS\system32
7e940000 wshext.dll             5.7.0.18066      C:\WINDOWS\system32

processes:
0000 Idle                         0    0
0004 System                       0    0   normal
01a0 smss.exe                     0    0   normal C:\WINDOWS\system32
01e4 csrss.exe                    67   60  normal C:\WINDOWS\system32
01fc winlogon.exe                 44   14  high   C:\WINDOWS\system32
0228 services.exe                 4    2   normal C:\WINDOWS\system32
0234 lsass.exe                    6    3   normal C:\WINDOWS\system32
02d4 svchost.exe                  4    1   normal C:\WINDOWS\system32
0304 svchost.exe                  4    2   normal C:\WINDOWS\system32
0358 svchost.exe                  11   25  normal C:\WINDOWS\System32
0384 svchost.exe                  4    1   normal C:\WINDOWS\system32
0398 svchost.exe                  4    1   normal C:\WINDOWS\system32
03c8 zhudongfangyu.exe            4    5   normal C:\Program Files\360\360Safe\deepscan
04e8 aspnet_state.exe             4    2   normal C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727
0504 HZ_CommSrv.exe               4    1   normal C:\WINDOWS\system32
0518 inetinfo.exe                 4    7   normal C:\WINDOWS\system32\inetsrv
0530 MsDtsSrvr.exe                4    1   normal C:\Program Files\Microsoft SQL Server\90\DTS\Binn
0578 msmdsrv.exe                  4    2   normal C:\Program Files\Microsoft SQL Server\MSSQL.1\OLAP\bin
0588 mysqld-nt.exe                4    3   normal C:\mysql\bin
0614 ReportingServicesService.exe 4    2   normal C:\Program Files\Microsoft SQL Server\MSSQL.2\Reporting Services\ReportServer\bin
0644 sqlbrowser.exe               4    1   normal C:\Program Files\Microsoft SQL Server\90\Shared
0678 WDKeyMonitorCCB.exe          7    8   normal C:\WINDOWS\system32\WatchData\Watchdata CCB OCL CSP v3.2
03d4 PSTrayFactory.exe            168  153 normal D:\ù߰\PSTrayFactory
072c 360Tray.exe                  379  106 normal C:\Program Files\360\360Safe\safemon
0754 360sd.exe                    28   19  normal C:\Program Files\360\360sd
076c ctfmon.exe                   139  71  normal C:\WINDOWS\system32
0904 360rp.exe                    4    6   normal C:\Program Files\360\360sd
0748 SoftManagerLite.exe          282  102 normal C:\Program Files\360\360Safe\SoftMgr
0ff4 QQProtect.exe                7    14  normal C:\Program Files\Tencent\QQ\QQProtect\Bin
0e1c QQ.exe                       1570 209 normal C:\Program Files\Tencent\QQ\bin
08e4 TXPlatform.exe               5    5   normal C:\Program Files\Tencent\QQ\bin
01b4 QQ.exe                       809  127 normal C:\Program Files\Tencent\QQ\bin
097c QQ.exe                       952  144 normal C:\Program Files\Tencent\QQ\bin
11c4 dllhost.exe                  5    49  normal C:\WINDOWS\system32
066c dllhost.exe                  4    3   normal C:\WINDOWS\system32
0d5c WINWORD.EXE                  280  107 normal C:\Program Files\Microsoft Office\Office12
0ebc 360rps.exe                   4    3   normal C:\Program Files\360\360sd
13a4 explorer.exe                 424  383 normal C:\WINDOWS
168c mstsc.exe                    126  105 normal C:\WINDOWS\system32
1388 iexplore.exe                 268  100 normal C:\Program Files\Internet Explorer
0ff8 iexplore.exe                 266  154 normal C:\Program Files\Internet Explorer
0ee4 Dreamweaver.exe              392  794 normal C:\Program Files\Macromedia\Dreamweaver 8
0bcc GreenBrowser.exe             544  278 normal C:\Program Files\GreenBrowser
1514 FlashFXP.exe                 249  196 normal M:\ù߰\flashfxp
1564 SogouCloud.exe               4    1   normal C:\Program Files\SogouInput\6.2.0.7270

hardware:
+ DVD/CD-ROM 
  - PHILIPS SPD2216T
+ IDE ATA/ATAPI 
  - Intel(R) ICH7 Family Ultra ATA Storage Controllers - 27DF (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family Serial ATA Storage Controller - 27C0 (driver 9.1.1.1016)
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
+ 
  - Pentium(R) Dual-Core  CPU      E5400  @ 2.70GHz
  - Pentium(R) Dual-Core  CPU      E5400  @ 2.70GHz
+ 
  - ST3250318AS
  - 
+ ˿ (COM  LPT)
  - ECP ӡ˿ (LPT1)
  - ͨѶ˿ (COM1)
+ 
  - 弴ü
  - 弴ü
+ 
  - ACPI Multiprocessor PC
+ 
  - QuickOn Button (driver 1.2.1.420)
+ ƵϷ
  - VIA High Definition Audio (driver 6.0.1.8700)
  - ͳƵ׽豸
  - ͳƵ
  - ý豸
  - Ƶ
  - Ƶ
+ ָ豸
  - Microsoft PS/2 Mouse
+ ͨô߿
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C9 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CA (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CB (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB2 Enhanced Host Controller - 27CC (driver 9.1.1.1016)
  - USB Mass Storage Device
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
+ 
  - Atheros L2 Fast Ethernet 10/100 Base-T Controller (driver 2.5.7.16)
+ ϵͳ豸
  - ACPI Fixed Feature Button
  - ACPI Power Button
  - ACPI Thermal Zone
  - Direct memory access controller
  - High Precision Event Timer (driver 7.0.0.1011)
  - Intel(R) 82801 PCI Bridge - 244E (driver 7.0.0.1011)
  - Intel(R) 82802 Firmware Hub Device
  - Intel(R) G33/G31/P35/P31 Express Chipset Processor to I/O Controller - 29C0 (driver 8.6.1.1001)
  - Intel(R) ICH7 Family LPC Interface Controller - 27B8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family PCI Express Root Port - 27D0 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family SMBus Controller - 27DA (driver 9.1.1.1016)
  - ISAPNP Read Data Port
  - Logical Disk Manager
  - Microcode Update Device
  - Microsoft ACPI-Compliant System
  - Microsoft Composite Battery
  - Microsoft System Management BIOS Driver
  - Microsoft  High Definition Audio  UAA 
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Numeric data processor
  - PCI bus
  - Plug and Play Software Device Enumerator
  - Printer Port Logical Interface
  - Programmable interrupt controller
  - System board
  - System board
  - System CMOS/real time clock
  - System speaker
  - System timer
  - Terminal Server Device Redirector
  - Terminal Server Keyboard Driver
  - Terminal Server Mouse Driver
  - Volume Manager
  - ̨ȫʾƵ
+ ʾ
  - Intel(R) G33/G31 Express Chipset Family (driver 6.14.10.5218)

cpu registers:
eax = 80004001
ebx = 00244d70
ecx = 7d5c6494
edx = 00000000
esi = 77f4af28
edi = 77f4ad08
eip = 00000000
esp = 0012f4fc
ebp = 0012f520

stack dump:
0012f4fc  20 f5 12 00 00 00 00 00 - ec f6 12 00 02 00 07 81  ................
0012f50c  8c 49 1e 00 00 e2 bb 03 - ec f6 12 00 b0 ea 59 7d  .I............Y}
0012f51c  57 00 07 80 53 00 68 00 - 65 00 6c 00 6c 00 45 00  W...S.h.e.l.l.E.
0012f52c  78 00 5c 00 44 00 61 00 - 74 00 61 00 48 00 61 00  x.\.D.a.t.a.H.a.
0012f53c  6e 00 64 00 6c 00 65 00 - 72 00 00 00 94 49 1e 00  n.d.l.e.r....I..
0012f54c  00 51 24 00 00 00 00 00 - 6c f5 12 00 00 00 15 00  .Q$.....l.......
0012f55c  00 51 24 00 00 bd 15 00 - 78 f5 12 00 d8 d1 da 77  .Q$.....x......w
0012f56c  00 bd 15 00 f2 03 01 00 - 20 61 e1 77 d4 f4 12 00  .........a.w....
0012f57c  95 d2 da 77 fc fc 12 00 - 20 e9 92 7c 60 00 93 7c  ...w.......|`..|
0012f58c  ff ff ff ff 5d 00 93 7c - d4 cf 9a 76 00 00 15 00  ....]..|...v....
0012f59c  00 00 00 00 90 8d 24 00 - b4 f5 12 00 c0 f5 12 00  ......$.........
0012f5ac  d1 40 f4 77 88 49 1e 00 - e4 f5 12 00 00 00 00 00  .@.w.I..........
0012f5bc  20 e2 bb 03 d8 f5 12 00 - 5b 9d f4 77 88 49 1e 00  ........[..w.I..
0012f5cc  60 9d f4 77 44 51 5c 7d - 40 ea c3 03 f4 f5 12 00  `..wDQ\}@.......
0012f5dc  f0 a2 00 00 10 f6 12 00 - f2 a9 f4 77 08 ad f4 77  ...........w...w
0012f5ec  40 ae f4 77 05 00 00 00 - 00 51 24 00 02 00 07 81  @..w.....Q$.....
0012f5fc  b0 ea 59 7d ec f6 12 00 - 02 00 07 81 8c 49 1e 00  ..Y}.........I..
0012f60c  00 e2 bb 03 30 f6 12 00 - ff ac f4 77 08 ad f4 77  ....0......w...w
0012f61c  00 51 24 00 f0 a2 00 00 - 50 f6 12 00 21 af f4 77  .Q$.....P...!..w
0012f62c  08 ad f4 77 28 af f4 77 - 02 00 00 00 70 4d 24 00  ...w(..w....pM$.

disassembling:
00443c88      public Forms.StdWndProc:         ; function entry point
00443c88 1521   push    ebp
00443c89        mov     ebp, esp
00443c8b 1522   xor     eax, eax
00443c8d 1523   push    eax
00443c8e 1524   push    dword ptr [ebp+$14]
00443c91 1525   push    dword ptr [ebp+$10]
00443c94 1526   push    dword ptr [ebp+$c]
00443c97 1527   mov     edx, esp
00443c99 1528   mov     eax, [ecx+4]
00443c9c 1529 > call    dword ptr [ecx]
00443c9e 1530   add     esp, $c
00443ca1 1531   pop     eax
00443ca2 1532   pop     ebp
00443ca3        ret     $10

date/time         : 2013-09-24, 10:38:02, 484ms
computer name     : ZHENGYISONG
user name         : Administrator <admin>
registered owner  : Sky123.Org / Sky123.Org
operating system  : Windows XP Service Pack 3 (5.1.2600) build 2600
system language   : Chinese
system up time    : 2 hours 24 minutes
program up time   : 29 minutes 55 seconds
processors        : 2x Pentium(R) Dual-Core CPU E5400 @ 2.70GHz
physical memory   : 1243/2038 MB (free/total)
free disk space   : (C:) 10.83 GB (L:) 14.32 GB
display mode      : 1440x900, 32 bit
process id        : $1720
allocated memory  : 30.12 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $d1b23712, $cc7f4923, $f97c2ea9
exception number  : 1
exception class   : EAccessViolation
exception message : Access violation at address 0064BFC9 in module 'FlashFXP.exe'. ȡ of address 00000000.

main thread ($11fc):
0064bfc9 +002d FlashFXP.exe UPTShellControls 10935   +2 TPTCustomShellList.WMGetIShellBrowser
00453e35 +0111 FlashFXP.exe Controls                    TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls                    TWinControl.WndProc
004f5c5e +0072 FlashFXP.exe ComCtrls                    TCustomListView.WndProc
00509afb +003f FlashFXP.exe ThemeMgr                    TWindowProcList.DispatchMessage
0050a7e1 +004d FlashFXP.exe ThemeMgr                    TThemeManager.ListviewWindowProc
0050b959 +0009 FlashFXP.exe ThemeMgr                    TThemeManager.PreListviewWindowProc
0045632c +002c FlashFXP.exe Controls                    TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms             1529   +8 StdWndProc
7c92e470 +0010 ntdll.dll                                KiUserCallbackDispatcher
77d2b104 +0014 user32.dll                               EnumChildWindows
0064819d +0189 FlashFXP.exe UPTShellControls  8368  +39 TPTCustomShellList.ProcessMenuForAllSelected
007660d5 +0085 FlashFXP.exe FrmMain1         25198   +4 TFrmMain.Explorer1Click
00461047 +008f FlashFXP.exe Menus                       TMenuItem.Click
004621bf +0013 FlashFXP.exe Menus                       TMenu.DispatchCommand
0046314b +00bf FlashFXP.exe Menus                       TPopupList.WndProc
0046305d +001d FlashFXP.exe Menus                       TPopupList.MainWndProc
77d196c2 +000a user32.dll                               DispatchMessageA
0044ca9f +008b FlashFXP.exe Forms             7117  +34 TApplication.ProcessMessage
0044cad6 +000a FlashFXP.exe Forms             7155   +1 TApplication.HandleMessage
0044cd8b +00bf FlashFXP.exe Forms             7259  +26 TApplication.Run
007964ed +1c69 FlashFXP.exe FlashFXP           920 +630 initialization

thread $11ac:
7c92df48 +00a ntdll.dll                              NtWaitForMultipleObjects
7c80958a +000 kernel32.dll                           WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll                           WaitForMultipleObjects
00640bd3 +07b FlashFXP.exe UPTShellControls 4370 +13 TChangeHandlerThread.Execute
0041bfc1 +22d FlashFXP.exe Classes                   HexToBin
00404080 +028 FlashFXP.exe System                    ThreadWrapper

thread $10ec:
7c92df48 +00a ntdll.dll                  NtWaitForMultipleObjects
7c80958a +000 kernel32.dll               WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll               WaitForMultipleObjects
00662068 +10c FlashFXP.exe SaveToFileThd TSaveFileWorker.Execute
0041bfc1 +22d FlashFXP.exe Classes       HexToBin
00404080 +028 FlashFXP.exe System        ThreadWrapper

thread $1394:
7c92daa8 +a ntdll.dll  NtReplyWaitReceivePortEx

thread $1754: <priority:1>
7c92da48 +a ntdll.dll  NtRemoveIoCompletion

thread $160c:
7c92df48 +a ntdll.dll     NtWaitForMultipleObjects
7c80958a +0 kernel32.dll  WaitForMultipleObjectsEx

thread $162c:
7c92daa8 +a ntdll.dll  NtReplyWaitReceivePortEx

thread $ff4:
7c92d218 +0a ntdll.dll     NtDelayExecution
7c8023eb +4b kernel32.dll  SleepEx
7c802450 +0a kernel32.dll  Sleep

thread $464:
7c92df48 +0a ntdll.dll     NtWaitForMultipleObjects
7c80958a +00 kernel32.dll  WaitForMultipleObjectsEx
77d195f3 +00 user32.dll    MsgWaitForMultipleObjectsEx
77d196a3 +1a user32.dll    MsgWaitForMultipleObjects

modules:
00400000 FlashFXP.exe             4.0.0.1534       L:\ù߰\flashfxp
00fd0000 Normaliz.dll             6.0.5441.0       C:\WINDOWS\system32
01570000 360CloudShellExt.dll     1.0.0.1007       C:\Program Files\360\360YunPan\360cloud
03460000 Shell.dll                1.0.0.1          C:\Program Files\115\115com
035b0000 360UDiskGuard.dll        2.0.0.1039       C:\Program Files\360\360Safe\safemon
03c30000 libeay32.dll             1.0.0.3          L:\ù߰\flashfxp
03d80000 ssleay32.dll             1.0.0.3          L:\ù߰\flashfxp
04110000 ikutm.dll                4.0.1.7040       C:\Program Files\YouKu\YoukuClient
04170000 ikutmco.dll              4.0.1.7040       C:\Program Files\YouKu\YoukuClient
04260000 UnlockerCOM.dll                           C:\Program Files\Unlocker
04280000 rarext.dll               4.20.0.0         C:\Program Files\WinRAR
046d0000 xpsp2res.dll             5.1.2600.5512    C:\WINDOWS\system32
04d20000 WDContextMenuHandler.dll 1.6.0.3          C:\Program Files\Western Digital\WD SmartWare
04f10000 WDCollections.dll        1.6.0.2          C:\Program Files\Western Digital\WD SmartWare
05d30000 SoftMgrExt.dll           1.0.0.1101       C:\Program Files\360\360Safe\softmgr
05d90000 MenuEx.dll               4.0.0.3105       C:\Program Files\360\360sd
05e00000 shell360ext.dll          7.5.0.1205       C:\Program Files\360\360Safe\Utils
05ef0000 ShellEx_103.dll          1.0.0.3          C:\Program Files\FreeTime\FormatFactory
05f20000 MSVCP110.dll             11.0.51106.1     C:\Program Files\FreeTime\FormatFactory
05fb0000 MSVCR110.dll             11.0.51106.1     C:\Program Files\FreeTime\FormatFactory
06090000 WoptiEncryptModule.dll   1.6.10.816       D:\ù߰\Żʦ
06260000 shell360dt.dll           2.5.0.1035       C:\Program Files\360\360Safe\SoftMgr\WallPaper
062b0000 360CloudBar.dll          1.0.0.1045       C:\Program Files\360\360YunPan\360cloud
063b0000 CTXROT~1.DLL                              C:\PROGRA~1\EXSOFT~1\PHOTOI~1\OCX
07160000 audiodev.dll             5.2.5721.5262    C:\WINDOWS\system32
10000000 HKDll.dll                                 D:\ù߰\PSTrayFactory
10930000 portabledeviceapi.dll    5.2.5721.5262    C:\WINDOWS\system32
11c70000 WMASF.DLL                11.0.5721.5262   C:\WINDOWS\system32
15110000 WMVCore.DLL              11.0.5721.5275   C:\WINDOWS\system32
16500000 wpdshext.dll             5.2.5721.5262    C:\WINDOWS\system32
1f840000 odbcint.dll              3.525.1117.0     C:\WINDOWS\system32
3e410000 WININET.dll              8.0.6001.23520   C:\WINDOWS\system32
3eab0000 iertutil.dll             8.0.6001.23520   C:\WINDOWS\system32
3eca0000 ieframe.dll              8.0.6001.23520   C:\WINDOWS\system32
43ce0000 urlmon.dll               8.0.6001.23520   C:\WINDOWS\system32
4ae90000 gdiplus.dll              5.2.6002.23084   C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.23084_x-ww_f3f35550
5a540000 wiashext.dll             5.1.2600.5512    C:\WINDOWS\system32
5adc0000 UxTheme.dll              6.0.2900.5512    C:\WINDOWS\system32
5cbc0000 shimgvw.dll              6.0.2900.6072    C:\WINDOWS\system32
5dd50000 msxml3.dll               8.100.1053.0     C:\WINDOWS\system32
5efe0000 olepro32.dll             5.1.2600.5512    C:\WINDOWS\system32
5fdd0000 NETAPI32.dll             5.1.2600.6260    C:\WINDOWS\system32
60fd0000 hnetcfg.dll              5.1.2600.5512    C:\WINDOWS\system32
61880000 OLEACC.dll               7.0.2600.6153    C:\WINDOWS\system32
62c20000 LPK.DLL                  5.1.2600.5512    C:\WINDOWS\system32
68000000 rsaenh.dll               5.1.2600.5507    C:\WINDOWS\system32
68100000 dssenh.dll               5.1.2600.5507    C:\WINDOWS\system32
6bd10000 msohevi.dll              12.0.4518.1014   C:\Program Files\Microsoft Office\Office12
70200000 safemon.dll              8.2.2.1630       C:\Program Files\360\360Safe\safemon
719c0000 mswsock.dll              5.1.2600.5625    C:\WINDOWS\system32
71a00000 wshtcpip.dll             5.1.2600.5512    C:\WINDOWS\System32
71a10000 WS2HELP.dll              5.1.2600.5512    C:\WINDOWS\system32
71a20000 WS2_32.dll               5.1.2600.5512    C:\WINDOWS\system32
71a40000 wsock32.dll              5.1.2600.5512    C:\WINDOWS\system32
71a90000 MPR.dll                  5.1.2600.5512    C:\WINDOWS\system32
71b70000 SAMLIB.dll               5.1.2600.5512    C:\WINDOWS\System32
71b90000 ntlanman.dll             5.1.2600.5512    C:\WINDOWS\System32
71c00000 NETRAP.dll               5.1.2600.5512    C:\WINDOWS\System32
71c10000 NETUI1.dll               5.1.2600.5512    C:\WINDOWS\System32
71c50000 NETUI0.dll               5.1.2600.5512    C:\WINDOWS\System32
72f70000 winspool.drv             5.1.2600.5512    C:\WINDOWS\system32
73540000 ODBC32.dll               3.525.3012.0     C:\WINDOWS\system32
73640000 msctfime.ime             5.1.2600.5768    C:\WINDOWS\system32
73ac0000 avifil32.dll             5.1.2600.5908    C:\WINDOWS\system32
73b10000 sti.dll                  5.1.2600.5512    C:\WINDOWS\system32
73b40000 MSVFW32.dll              5.1.2600.5512    C:\WINDOWS\system32
73ce0000 shgina.dll               6.0.2900.5512    C:\WINDOWS\system32
73fa0000 USP10.dll                1.420.2600.6421  C:\WINDOWS\system32
74680000 MSCTF.dll                5.1.2600.5512    C:\WINDOWS\system32
74a40000 CFGMGR32.dll             5.1.2600.5512    C:\WINDOWS\system32
75430000 CRYPTUI.dll              5.131.2600.5512  C:\WINDOWS\system32
758d0000 MSGINA.dll               5.1.2600.5512    C:\WINDOWS\system32
759d0000 USERENV.dll              5.1.2600.5512    C:\WINDOWS\system32
75e00000 SXS.DLL                  5.1.2600.5699    C:\WINDOWS\system32
75ed0000 drprov.dll               5.1.2600.5512    C:\WINDOWS\System32
75ee0000 davclnt.dll              5.1.2600.5512    C:\WINDOWS\System32
75ef0000 browseui.dll             6.0.2900.6182    C:\WINDOWS\system32
76060000 SETUPAPI.dll             5.1.2600.5512    C:\WINDOWS\system32
762d0000 WINSTA.dll               5.1.2600.5512    C:\WINDOWS\system32
762f0000 MSIMG32.dll              5.1.2600.5512    C:\WINDOWS\system32
76300000 IMM32.DLL                5.1.2600.5512    C:\WINDOWS\system32
76320000 comdlg32.dll             6.0.2900.5512    C:\WINDOWS\system32
76570000 CSCDLL.dll               5.1.2600.5512    C:\WINDOWS\System32
76590000 cscui.dll                5.1.2600.5512    C:\WINDOWS\System32
765e0000 crypt32.dll              5.131.2600.6237  C:\WINDOWS\system32
76950000 LINKINFO.dll             5.1.2600.5512    C:\WINDOWS\system32
76960000 ntshrui.dll              5.1.2600.5512    C:\WINDOWS\system32
76990000 ole32.dll                5.1.2600.6435    C:\WINDOWS\system32
76af0000 ATL.DLL                  3.5.2284.2       C:\WINDOWS\system32
76b10000 winmm.dll                5.1.2600.6160    C:\WINDOWS\system32
76bc0000 PSAPI.DLL                5.1.2600.5512    C:\WINDOWS\system32
76c00000 WINTRUST.dll             5.131.2600.5922  C:\WINDOWS\system32
76c60000 IMAGEHLP.dll             5.1.2600.6198    C:\WINDOWS\system32
76d70000 appHelp.dll              5.1.2600.5512    C:\WINDOWS\system32
76db0000 MSASN1.dll               5.1.2600.5875    C:\WINDOWS\system32
76f30000 WLDAP32.dll              5.1.2600.5512    C:\WINDOWS\system32
76fa0000 CLBCATQ.DLL              2001.12.4414.700 C:\WINDOWS\system32
77020000 COMRes.dll               2001.12.4414.700 C:\WINDOWS\system32
770f0000 oleaut32.dll             5.1.2600.6341    C:\WINDOWS\system32
77180000 comctl32.dll             6.0.2900.6028    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
77bb0000 MSACM32.dll              5.1.2600.5512    C:\WINDOWS\system32
77bd0000 version.dll              5.1.2600.5512    C:\WINDOWS\system32
77be0000 msvcrt.dll               7.0.2600.5512    C:\WINDOWS\system32
77d10000 user32.dll               5.1.2600.5512    C:\WINDOWS\system32
77da0000 advapi32.dll             5.1.2600.5755    C:\WINDOWS\system32
77e50000 RPCRT4.dll               5.1.2600.6399    C:\WINDOWS\system32
77ef0000 GDI32.dll                5.1.2600.5698    C:\WINDOWS\system32
77f40000 SHLWAPI.dll              6.0.2900.5912    C:\WINDOWS\system32
77fc0000 Secur32.dll              5.1.2600.5834    C:\WINDOWS\system32
78130000 MSVCR80.dll              8.0.50727.4053   C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989
78aa0000 MSVCR100.dll             10.0.40219.1     C:\WINDOWS\system32
7c800000 kernel32.dll             5.1.2600.6293    C:\WINDOWS\system32
7c920000 ntdll.dll                5.1.2600.6055    C:\WINDOWS\system32
7c9c0000 msi.dll                  3.1.4001.5512    C:\WINDOWS\system32
7d590000 shell32.dll              6.0.2900.6242    C:\WINDOWS\system32
7e550000 shdocvw.dll              6.0.2900.6182    C:\WINDOWS\system32

processes:
0000 Idle               0    0
0004 System             0    0   normal
01a0 smss.exe           0    0   normal C:\WINDOWS\system32
01d4 csrss.exe          0    0
01ec winlogon.exe       44   14  high   C:\WINDOWS\system32
0218 services.exe       4    2   normal C:\WINDOWS\system32
0224 lsass.exe          4    1   normal C:\WINDOWS\system32
02cc svchost.exe        4    1   normal C:\WINDOWS\system32
02f8 svchost.exe        0    0
033c svchost.exe        11   26  normal C:\WINDOWS\System32
0380 svchost.exe        0    0
03a4 svchost.exe        0    0
03b0 zhudongfangyu.exe  4    5   normal C:\Program Files\360\360Safe\deepscan
05d0 PSTrayFactory.exe  162  147 normal D:\ù߰\PSTrayFactory
0604 360Tray.exe        396  99  normal C:\Program Files\360\360Safe\safemon
0614 360sd.exe          19   14  normal C:\Program Files\360\360sd
0624 ctfmon.exe         17   12  normal C:\WINDOWS\system32
073c SoftMgrLite.exe    269  144 normal C:\Program Files\360\360Safe\SoftMgr\SML
00d4 BFAssistantSvc.exe 4    5   normal C:\Program Files\Baofeng\PhoneAssistant
011c inetinfo.exe       4    7   normal C:\WINDOWS\system32\inetsrv
01c8 WDDriveService.exe 4    6   normal C:\Program Files\Western Digital\WD Drive Manager
02c8 WDRulesEngine.exe  4    5   idle   C:\Program Files\Western Digital\WD SmartWare
043c WDBackupEngine.exe 4    7   idle   C:\Program Files\Western Digital\WD SmartWare
0924 360rp.exe          4    7   normal C:\Program Files\360\360sd
0804 QQProtect.exe      7    16  normal C:\Program Files\Tencent\QQ\QQProtect\Bin
0aec QQ.exe             1004 155 normal C:\Program Files\Tencent\QQ\bin
0b94 TXPlatform.exe     4    6   normal C:\Program Files\Tencent\QQ\bin
0dbc QQ.exe             640  111 normal C:\Program Files\Tencent\QQ\bin
0d64 QQ.exe             543  102 normal C:\Program Files\Tencent\QQ\bin
12a0 svchost.exe        4    2   normal C:\WINDOWS\system32
158c explorer.exe       746  631 normal C:\WINDOWS
152c 360rps.exe         4    3   normal C:\Program Files\360\360sd
1700 QQExternal.exe     17   22  normal C:\Program Files\Tencent\QQ\bin
0294 SzFastInstall.exe  123  25  normal C:\Program Files\SogouInput\6.7.0.0499
1560 GreenBrowser.exe   406  254 normal C:\Program Files\GreenBrowser
1720 FlashFXP.exe       337  217 normal L:\ù߰\flashfxp
1088 mstsc.exe          124  109 normal C:\WINDOWS\system32

hardware:
+ DVD/CD-ROM 
  - PHILIPS SPD2216T
+ IDE ATA/ATAPI 
  - Intel(R) ICH7 Family Ultra ATA Storage Controllers - 27DF (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family Serial ATA Storage Controller - 27C0 (driver 9.1.1.1016)
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
+ WD Drive Management devices
  - WD SES Device (driver 1.0.9.0)
+ 
  - Pentium(R) Dual-Core  CPU      E5400  @ 2.70GHz
  - Pentium(R) Dual-Core  CPU      E5400  @ 2.70GHz
+ 
  -  vivo V2 BBK USB Device
  - Generic External USB Device
  - ST3250318AS
  - WD My Passport 0748 USB Device
  - 
+ ˿ (COM  LPT)
  - ECP ӡ˿ (LPT1)
  - ͨѶ˿ (COM1)
+ 
  - 弴ü
  - 弴ü
+ 
  - ACPI Multiprocessor PC
+ 
  - QuickOn Button (driver 1.2.1.420)
+ ƵϷ
  - VIA High Definition Audio (driver 6.0.1.8700)
  - ͳƵ׽豸
  - ͳƵ
  - ý豸
  - Ƶ
  - Ƶ
+ ָ豸
  - Microsoft PS/2 Mouse
+ ͨô߿
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C9 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CA (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CB (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB2 Enhanced Host Controller - 27CC (driver 9.1.1.1016)
  - USB Mass Storage Device
  - USB Mass Storage Device
  - USB Mass Storage Device
  - USB Mass Storage Device
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
+ 
  - Atheros L2 Fast Ethernet 10/100 Base-T Controller (driver 2.5.7.16)
+ ϵͳ豸
  - ACPI Fixed Feature Button
  - ACPI Power Button
  - ACPI Thermal Zone
  - Direct memory access controller
  - High Precision Event Timer (driver 7.0.0.1011)
  - Intel(R) 82801 PCI Bridge - 244E (driver 7.0.0.1011)
  - Intel(R) 82802 Firmware Hub Device
  - Intel(R) G33/G31/P35/P31 Express Chipset Processor to I/O Controller - 29C0 (driver 8.6.1.1001)
  - Intel(R) ICH7 Family LPC Interface Controller - 27B8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family PCI Express Root Port - 27D0 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family SMBus Controller - 27DA (driver 9.1.1.1016)
  - ISAPNP Read Data Port
  - Logical Disk Manager
  - Microcode Update Device
  - Microsoft ACPI-Compliant System
  - Microsoft Composite Battery
  - Microsoft System Management BIOS Driver
  - Microsoft  High Definition Audio  UAA 
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Numeric data processor
  - PCI bus
  - Plug and Play Software Device Enumerator
  - Printer Port Logical Interface
  - Programmable interrupt controller
  - System board
  - System board
  - System CMOS/real time clock
  - System speaker
  - System timer
  - Terminal Server Device Redirector
  - Terminal Server Keyboard Driver
  - Terminal Server Mouse Driver
  - Volume Manager
  - ̨ȫʾƵ
+ ʾ
  - Intel(R) G33/G31 Express Chipset Family (driver 6.14.10.5218)

cpu registers:
eax = 00000000
ebx = 0012f840
ecx = 00000000
edx = 0012f840
esi = 0012f840
edi = 00000407
eip = 0064bfc9
esp = 0012f664
ebp = 0012f684

stack dump:
0012f664  00 00 00 00 9c 11 7a 00 - 4c f8 12 00 10 f8 12 00  ......z.L.......
0012f674  ac 3a 40 00 84 f6 12 00 - 40 ca e8 00 00 00 00 00  .:@.....@.......
0012f684  c8 f7 12 00 38 3e 45 00 - 07 04 00 00 40 f8 12 00  ....8>E.....@...
0012f694  40 ca e8 00 a7 66 45 00 - 07 04 00 00 40 f8 12 00  @....fE.....@...
0012f6a4  40 ca e8 00 bc 67 45 00 - c4 f6 12 00 b8 f8 12 00  @....gE.........
0012f6b4  40 f8 12 00 20 5b ee 00 - 40 f8 12 00 20 5b ee 00  @....[..@....[..
0012f6c4  08 f8 12 00 38 3e 45 00 - b8 f8 12 00 40 f8 12 00  ....8>E.....@...
0012f6d4  20 5b ee 00 a7 66 45 00 - b8 f8 12 00 da 0d fb 00  .[...fE.........
0012f6e4  20 5b ee 00 b4 f8 12 00 - b4 f8 12 00 30 11 f1 00  .[..........0...
0012f6f4  a7 66 45 00 b4 f8 12 00 - 0e 33 1c 77 10 dd f9 00  .fE......3.w....
0012f704  32 38 93 7c 74 fa 12 00 - 00 00 00 00 d0 11 f5 03  28.|t...........
0012f714  18 00 00 00 40 00 00 00 - 48 f7 12 00 34 87 d1 77  ....@...H...4..w
0012f724  32 06 4d 00 07 04 00 00 - 00 00 00 00 00 00 00 00  2.M.............
0012f734  0e 33 1c 77 cd ab ba dc - 00 00 00 00 84 f7 12 00  .3.w............
0012f744  0e 33 1c 77 b0 f7 12 00 - 16 88 d1 77 00 e0 fd 7f  .3.w.......w....
0012f754  b0 f7 12 00 5a 88 d1 77 - 70 f7 12 00 2a 88 d1 77  ....Z..wp...*..w
0012f764  07 04 00 00 0e 33 1c 77 - 40 f8 12 00 14 00 00 00  .....3.w@.......
0012f774  01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00  ................
0012f784  00 00 00 00 b0 f9 12 00 - 00 00 00 00 00 00 00 00  ................
0012f794  10 f8 12 00 80 42 41 00 - 88 42 41 00 00 00 00 00  .....BA..BA.....

disassembling:
0064bf9c       public UPTShellControls.TPTCustomShellList.WMGetIShellBrowser:  ; function entry point
0064bf9c 10933   push    ebp
0064bf9d         mov     ebp, esp
0064bf9f         push    0
0064bfa1         push    ebx
0064bfa2         mov     ebx, edx
0064bfa4         xor     eax, eax
0064bfa6         push    ebp
0064bfa7         push    $64bfe3                ; System.@HandleFinally
0064bfac         push    dword ptr fs:[eax]
0064bfaf         mov     fs:[eax], esp
0064bfb2 10934   lea     eax, [ebp-4]
0064bfb5         push    eax
0064bfb6         call    -$27 ($64bf94)         ; UPTShellControls._SHGetInstanceExplorer
0064bfbb 10935   lea     eax, [ebx+$c]
0064bfbe         push    eax
0064bfbf         mov     eax, [$7b4948]
0064bfc4         push    eax
0064bfc5         mov     eax, [ebp-4]
0064bfc8         push    eax
0064bfc9       > mov     eax, [eax]
0064bfcb         call    dword ptr [eax]
0064bfcd         xor     eax, eax
0064bfcf         pop     edx
0064bfd0         pop     ecx
0064bfd1         pop     ecx
0064bfd2         mov     fs:[eax], edx
0064bfd5         push    $64bfea
0064bfda         lea     eax, [ebp-4]
0064bfdd         call    -$245a9e ($406544)     ; System.@IntfClear
0064bfe2         ret
0064bfe3         jmp     -$24856c ($403a7c)     ; System.@HandleFinally
0064bfe8         jmp     loc_64bfda
0064bfea 10936   pop     ebx
0064bfeb         pop     ecx
0064bfec         pop     ebp
0064bfed         ret

date/time         : 2015-07-09, 01:05:40, 765ms
computer name     : 4IL60FQEY41AA6Q
user name         : Administrator <admin>
registered owner  : ΢û / ΢й
operating system  : Windows XP Service Pack 3 (5.1.2600) build 2600
system language   : Chinese
system up time    : 1 hour 47 minutes
program up time   : 1 hour 24 minutes
processors        : 2x AMD Athlon(tm) 64 X2 Dual Core Processor 5000+
physical memory   : 2290/3070 MB (free/total)
free disk space   : (C:) 17.30 GB (L:) 24.96 GB
display mode      : 1440x900, 32 bit
process id        : $16c4
allocated memory  : 76.11 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $eb093fce, $80e81af5, $04b12db1
exception number  : 1
exception class   : EAccessViolation
exception message : Access violation at address 004CFD49 in module 'FlashFXP.exe'. ȡ of address 0000002C.

main thread ($16c8):
004cfd49 +0035 FlashFXP.exe IniFiles32    937   +7 TIniFile32.ReadString
004d0da6 +0032 FlashFXP.exe IniFiles32   1310   +2 TIniFile32.ValueExists
006e0b7d +0069 FlashFXP.exe SiteManager  3280   +4 TFrmSite.TreeSiteBeforeItemPaint
005072c7 +05f7 FlashFXP.exe TreeNT                 TCustomTreeNT.CNNotify
00453e35 +0111 FlashFXP.exe Controls               TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls               TWinControl.WndProc
00507799 +004d FlashFXP.exe TreeNT                 TCustomTreeNT.WndProc
00453c64 +0024 FlashFXP.exe Controls               TControl.Perform
00456823 +0023 FlashFXP.exe Controls               TWinControl.DefaultHandler
00456d81 +000d FlashFXP.exe Controls               TWinControl.WMNotify
00453e35 +0111 FlashFXP.exe Controls               TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls               TWinControl.WndProc
00507799 +004d FlashFXP.exe TreeNT                 TCustomTreeNT.WndProc
00453c64 +0024 FlashFXP.exe Controls               TControl.Perform
00453e35 +0111 FlashFXP.exe Controls               TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls               TWinControl.WndProc
0045632c +002c FlashFXP.exe Controls               TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms        1529   +8 StdWndProc
77d292de +0044 user32.dll                          SendMessageW
77d2a993 +0016 user32.dll                          CallWindowProcA
004567a7 +00e7 FlashFXP.exe Controls               TWinControl.DefaultHandler
00453e35 +0111 FlashFXP.exe Controls               TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls               TWinControl.WndProc
00507799 +004d FlashFXP.exe TreeNT                 TCustomTreeNT.WndProc
0045632c +002c FlashFXP.exe Controls               TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms        1529   +8 StdWndProc
77d2f406 +0044 user32.dll                          SendMessageA
0042c5d7 +000f FlashFXP.exe Commctrl               TreeView_SetItem
00502e9e +0032 FlashFXP.exe TreeNT                 TTreeNTNode.SetText
005045f8 +0020 FlashFXP.exe TreeNT                 TTreeNTNode.Assign
005040f9 +0141 FlashFXP.exe TreeNT                 TTreeNTNode.InternalMove
005042a9 +0159 FlashFXP.exe TreeNT                 TTreeNTNode.MoveTo
006dabfc +0298 FlashFXP.exe SiteManager  1623  +40 TFrmSite.LoadSites
006da7fd +28d9 FlashFXP.exe SiteManager  1572 +428 TFrmSite.FormCreate
00445be9 +0031 FlashFXP.exe Forms        2744   +3 TCustomForm.DoCreate
0044592d +0009 FlashFXP.exe Forms        2680   +0 TCustomForm.AfterConstruction
00403763 +0003 FlashFXP.exe System                 @AfterConstruction
0044590d +0171 FlashFXP.exe Forms        2674  +16 TCustomForm.Create
00727b96 +005a FlashFXP.exe FrmMain1     2830   +8 TFrmMain.CreateWindowShow
00739c2f +0093 FlashFXP.exe FrmMain1     9912  +20 TFrmMain.SM1Click
00461047 +008f FlashFXP.exe Menus                  TMenuItem.Click
004621bf +0013 FlashFXP.exe Menus                  TMenu.DispatchCommand
004489cb +001f FlashFXP.exe Forms        4206   +2 TCustomForm.WMCommand
00453e35 +0111 FlashFXP.exe Controls               TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls               TWinControl.WndProc
00446bcd +0571 FlashFXP.exe Forms        3235 +139 TCustomForm.WndProc
00509afb +003f FlashFXP.exe ThemeMgr               TWindowProcList.DispatchMessage
0050a448 +00dc FlashFXP.exe ThemeMgr               TThemeManager.FormWindowProc
0050b939 +0009 FlashFXP.exe ThemeMgr               TThemeManager.PreFormWindowProc
0045632c +002c FlashFXP.exe Controls               TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms        1529   +8 StdWndProc
77d196c2 +000a user32.dll                          DispatchMessageA
0044ca9f +008b FlashFXP.exe Forms        7117  +34 TApplication.ProcessMessage
0044cabe +000a FlashFXP.exe Forms        7148   +1 TApplication.ProcessMessages
00769e5f +09a3 FlashFXP.exe FrmMain1    26599 +222 TFrmMain.FormDestroy
00445c5d +0031 FlashFXP.exe Forms        2755   +3 TCustomForm.DoDestroy
00445ac1 +005d FlashFXP.exe Forms        2719   +7 TCustomForm.BeforeDestruction
00403771 +0009 FlashFXP.exe System                 @BeforeDestruction
00445ace +0006 FlashFXP.exe Forms        2723   +0 TCustomForm.Destroy
004033e4 +0008 FlashFXP.exe System                 TObject.Free
0041c349 +0019 FlashFXP.exe Classes                TComponent.Remove
0041c40a +001e FlashFXP.exe Classes                TComponent.DestroyComponents
004436ab +002f FlashFXP.exe Forms        1261   +3 DoneApplication
0040a9b6 +0026 FlashFXP.exe SysUtils               DoExitProc
00403f50 +0028 FlashFXP.exe System                 @Halt0
00796548 +1cc4 FlashFXP.exe FlashFXP      939 +649 initialization

thread $15d4:
7c92df48 +00a ntdll.dll                              NtWaitForMultipleObjects
7c80958a +000 kernel32.dll                           WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll                           WaitForMultipleObjects
00640bd3 +07b FlashFXP.exe UPTShellControls 4370 +13 TChangeHandlerThread.Execute
0041bfc1 +22d FlashFXP.exe Classes                   HexToBin
00404080 +028 FlashFXP.exe System                    ThreadWrapper

thread $d1c:
7c92df48 +00a ntdll.dll                              NtWaitForMultipleObjects
7c80958a +000 kernel32.dll                           WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll                           WaitForMultipleObjects
00640bd3 +07b FlashFXP.exe UPTShellControls 4370 +13 TChangeHandlerThread.Execute
0041bfc1 +22d FlashFXP.exe Classes                   HexToBin
00404080 +028 FlashFXP.exe System                    ThreadWrapper

modules:
00400000 FlashFXP.exe      4.0.0.1534       L:\ù\flashftp
01530000 Tpdata.dll        1.0.1.3000       C:\Documents and Settings\All Users\Application Data\Tpdata
027f0000 Normaliz.dll      6.0.5441.0       C:\WINDOWS\system32
02f30000 libeay32.dll      1.0.0.3          L:\ù\flashftp
03080000 ssleay32.dll      1.0.0.3          L:\ù\flashftp
03540000 PALMINPUTIME.IME  1.9.0.840        C:\WINDOWS\system32
10000000 360UDiskGuard.dll 2.0.0.1101       C:\Program Files\360\360Safe\safemon
3e410000 WININET.dll       8.0.6001.23580   C:\WINDOWS\system32
3eab0000 iertutil.dll      8.0.6001.23580   C:\WINDOWS\system32
43ce0000 urlmon.dll        8.0.6001.23580   C:\WINDOWS\system32
5adc0000 uxtheme.dll       6.0.2900.5512    C:\WINDOWS\system32
5efe0000 olepro32.dll      5.1.2600.5512    C:\WINDOWS\system32
5fdd0000 NETAPI32.dll      5.1.2600.6260    C:\WINDOWS\system32
60fd0000 hnetcfg.dll       5.1.2600.5512    C:\WINDOWS\system32
62c20000 LPK.DLL           5.1.2600.5512    C:\WINDOWS\system32
68000000 rsaenh.dll        5.1.2600.5507    C:\WINDOWS\system32
68100000 dssenh.dll        5.1.2600.5507    C:\WINDOWS\system32
68d60000 DBGHELP.DLL       5.1.2600.5512    C:\WINDOWS\system32
719c0000 mswsock.dll       5.1.2600.5625    C:\WINDOWS\System32
71a00000 wshtcpip.dll      5.1.2600.5512    C:\WINDOWS\System32
71a10000 WS2HELP.dll       5.1.2600.5512    C:\WINDOWS\system32
71a20000 WS2_32.dll        5.1.2600.5512    C:\WINDOWS\system32
71a40000 wsock32.dll       5.1.2600.5512    C:\WINDOWS\system32
71b70000 SAMLIB.dll        5.1.2600.5512    C:\WINDOWS\system32
72240000 SensApi.dll       5.1.2600.5512    C:\WINDOWS\system32
72f70000 winspool.drv      5.1.2600.5512    C:\WINDOWS\system32
73640000 msctfime.ime      5.1.2600.5768    C:\WINDOWS\system32
73fa0000 USP10.dll         1.420.2600.6421  C:\WINDOWS\system32
74680000 MSCTF.dll         5.1.2600.5512    C:\WINDOWS\system32
75430000 CRYPTUI.dll       5.131.2600.5512  C:\WINDOWS\system32
759d0000 USERENV.dll       5.1.2600.5512    C:\WINDOWS\system32
75ef0000 browseui.dll      6.0.2900.6104    C:\WINDOWS\system32
76060000 SETUPAPI.dll      5.1.2600.5512    C:\WINDOWS\system32
76300000 IMM32.DLL         5.1.2600.5512    C:\WINDOWS\system32
76320000 comdlg32.dll      6.0.2900.5512    C:\WINDOWS\system32
765e0000 crypt32.dll       5.131.2600.6459  C:\WINDOWS\system32
76960000 ntshrui.dll       5.1.2600.5512    C:\WINDOWS\system32
76990000 ole32.dll         5.1.2600.6435    C:\WINDOWS\system32
76af0000 ATL.DLL           3.5.2284.2       C:\WINDOWS\system32
76b10000 winmm.dll         5.1.2600.6160    C:\WINDOWS\system32
76bc0000 psapi.dll         5.1.2600.5512    C:\WINDOWS\system32
76c00000 WINTRUST.dll      5.131.2600.6198  C:\WINDOWS\system32
76c60000 IMAGEHLP.dll      5.1.2600.6479    C:\WINDOWS\system32
76cb0000 NTMARTA.DLL       5.1.2600.5512    C:\WINDOWS\system32
76d30000 IPHLPAPI.DLL      5.1.2600.5512    C:\WINDOWS\system32
76d70000 appHelp.dll       5.1.2600.5512    C:\WINDOWS\system32
76db0000 MSASN1.dll        5.1.2600.5875    C:\WINDOWS\system32
76ef0000 DNSAPI.dll        5.1.2600.6089    C:\WINDOWS\system32
76f30000 WLDAP32.dll       5.1.2600.5512    C:\WINDOWS\system32
76f80000 winrnr.dll        5.1.2600.5512    C:\WINDOWS\System32
76f90000 rasadhlp.dll      5.1.2600.5512    C:\WINDOWS\system32
76fa0000 CLBCATQ.DLL       2001.12.4414.700 C:\WINDOWS\system32
77020000 COMRes.dll        2001.12.4414.700 C:\WINDOWS\system32
770f0000 oleaut32.dll      5.1.2600.6341    C:\WINDOWS\system32
77180000 comctl32.dll      6.0.2900.6028    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
77bd0000 version.dll       5.1.2600.5512    C:\WINDOWS\system32
77be0000 msvcrt.dll        7.0.2600.5512    C:\WINDOWS\system32
77d10000 user32.dll        5.1.2600.5512    C:\WINDOWS\system32
77da0000 advapi32.dll      5.1.2600.5755    C:\WINDOWS\system32
77e50000 RPCRT4.dll        5.1.2600.6477    C:\WINDOWS\system32
77ef0000 GDI32.dll         5.1.2600.6460    C:\WINDOWS\system32
77f40000 SHLWAPI.dll       6.0.2900.5912    C:\WINDOWS\system32
77fc0000 Secur32.dll       5.1.2600.5834    C:\WINDOWS\system32
7c800000 kernel32.dll      5.1.2600.6293    C:\WINDOWS\system32
7c920000 ntdll.dll         5.1.2600.6055    C:\WINDOWS\system32
7d590000 shell32.dll       6.0.2900.6242    C:\WINDOWS\system32
7e550000 shdocvw.dll       6.0.2900.6104    C:\WINDOWS\system32

processes:
0000 Idle                 0   0
0004 System               0   0   normal
0298 smss.exe             0   0   normal       C:\WINDOWS\system32
02d8 CSRSS.EXE            0   0
02f8 winlogon.exe         45  14  high         C:\WINDOWS\system32
0324 services.exe         4   2   normal       C:\WINDOWS\system32
0330 lsass.exe            4   1   normal       C:\WINDOWS\system32
03e0 svchost.exe          4   1   normal       C:\WINDOWS\system32
0440 SVCHOST.EXE          0   0
04a0 svchost.exe          10  29  normal       C:\WINDOWS\System32
0530 SVCHOST.EXE          0   0
05ac SVCHOST.EXE          0   0
05c8 zhudongfangyu.exe    4   5   normal       C:\Program Files\360\360Safe\deepscan
0658 spoolsv.exe          4   4   normal       C:\WINDOWS\system32
0758 inetinfo.exe         4   7   normal       C:\WINDOWS\system32\inetsrv
0790 QQProtect.exe        4   23  normal       C:\Program Files\Common Files\Tencent\QQProtect\Bin
0688 Explorer.EXE         499 397 normal       C:\WINDOWS
06d0 ctfmon.exe           141 43  normal       C:\WINDOWS\system32
0718 360Tray.exe          267 91  normal       C:\Program Files\360\360Safe\safemon
0114 360sd.exe            511 237 normal       C:\Program Files\360\360sd
03fc PalmInputGuard.exe   8   4   normal       C:\Program Files\PalmInput\Extensions\Guard\1.5.0.12
0564 SoftMgrLite.exe      26  30  normal       C:\Program Files\360\360Safe\SoftMgr\SML
0bec 360rp.exe            7   3   normal       C:\Program Files\360\360sd
0fe4 svchost.exe          4   1   normal       C:\WINDOWS\System32
0fd4 360se.exe            518 167 normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
080c 360se.exe            10  1   normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
0984 rundll32.exe         27  16  normal       C:\WINDOWS\system32
08f0 QQ.exe               102 157 normal       D:\ù\Ѷ\QQ\Bin
09b0 TXPlatform.exe       8   4   normal       D:\ù\Ѷ\QQ\Bin
0a54 PalmInputService.exe 16  9   normal       C:\Program Files\PalmInput\1.9.0.840
053c QQ.exe               156 179 normal       D:\ù\Ѷ\QQ\Bin
16c4 FlashFXP.exe         294 371 normal       L:\ù\flashftp
1714 360safe.exe          59  34  normal       C:\Program Files\360\360Safe
0548 360se.exe            147 1   normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
10cc 360se.exe            23  22  normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
0924 360se.exe            19  1   below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
125c mstsc.exe            154 120 normal       C:\WINDOWS\system32
0cfc 360se.exe            119 71  below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
0878 cmd.exe              4   1   normal       C:\WINDOWS\system32
13d0 conime.exe           17  13  normal       C:\WINDOWS\system32
1138 360se.exe            123 68  normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
158c 360se.exe            83  1   below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
0e94 mstsc.exe            125 98  normal       C:\WINDOWS\system32
15e0 QQExternal.exe       16  22  normal       D:\ù\Ѷ\QQ\Bin
0558 360se.exe            97  52  below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application

hardware:
+ DVD/CD-ROM 
  - PIONEER DVD-RW  DVR-219L
+ IDE ATA/ATAPI 
  - ׼˫ͨ PCI IDE 
  - ׼˫ͨ PCI IDE 
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
+ 
  - AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ (driver 1.3.2.0)
  - AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ (driver 1.3.2.0)
+ 
  - ST3250310AS
  - WD Elements 1042 USB Device
  - WD Elements 1078 USB Device
+ ˿ (COM  LPT)
  - ͨѶ˿ (COM1)
+ 
  - 弴ü
+ 
  - ACPI Multiprocessor PC
+ 
  - ׼ 101/102  Microsoft Ȼ PS/2 
+ ƵϷ
  - NVIDIA High Definition Audio (driver 1.2.22.1)
  - NVIDIA High Definition Audio (driver 1.2.22.1)
  - NVIDIA High Definition Audio (driver 1.2.22.1)
  - NVIDIA High Definition Audio (driver 1.2.22.1)
  - Realtek High Definition Audio (driver 5.10.0.6449)
  - ͳƵ׽豸
  - ͳƵ
  - ý豸
  - Ƶ
  - Ƶ
+ ָ豸
  - PS/2 Compatible Mouse
+ ͨô߿
  - Standard Enhanced PCI to USB Host Controller
  - Standard Enhanced PCI to USB Host Controller
  - Standard OpenHCD USB Host Controller
  - Standard OpenHCD USB Host Controller
  - USB Mass Storage Device
  - USB Mass Storage Device
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
+ 
  - Realtek RTL8139/810x Family Fast Ethernet NIC (driver 5.719.325.2009)
+ ϵͳ豸
  - ACPI Fan
  - ACPI Fixed Feature Button
  - ACPI Power Button
  - ACPI Thermal Zone
  - AMD Low Level Device Driver (driver 1.0.1.0)
  - Direct memory access controller
  - High precision event timer
  - ISAPNP Read Data Port
  - Logical Disk Manager
  - Microcode Update Device
  - Microsoft ACPI-Compliant System
  - Microsoft System Management BIOS Driver
  - Microsoft  High Definition Audio  UAA 
  - Microsoft  High Definition Audio  UAA 
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Numeric data processor
  - NVIDIA nForce PCI System Management (driver 4.6.9.0)
  - PCI bus
  - PCI standard host CPU bridge
  - PCI standard host CPU bridge
  - PCI standard host CPU bridge
  - PCI standard host CPU bridge
  - PCI standard ISA bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard RAM Controller
  - PCI standard RAM Controller
  - Plug and Play Software Device Enumerator
  - Programmable interrupt controller
  - System board
  - System CMOS/real time clock
  - System speaker
  - System timer
  - Terminal Server Device Redirector
  - Terminal Server Keyboard Driver
  - Terminal Server Mouse Driver
  - Volume Manager
  - ̨ȫʾƵ
+ ʾ
  - NVIDIA GeForce GT 220 (driver 6.14.12.6658)

cpu registers:
eax = 0012ec58
ebx = 00000000
ecx = 00000000
edx = 00000000
esi = 006e0bc0
edi = 02bbd438
eip = 004cfd49
esp = 0012ec08
ebp = 0012ec30

stack dump:
0012ec08  40 ec 12 00 ac 3a 40 00 - 30 ec 12 00 38 d4 bb 02  @....:@.0...8...
0012ec18  c0 0b 6e 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ..n.............
0012ec28  00 00 00 00 38 d4 bb 02 - 5c ec 12 00 ab 0d 4d 00  ....8...\.....M.
0012ec38  58 ec 12 00 ec 0d 4d 00 - 64 ec 12 00 ac 3a 40 00  X.....M.d....:@.
0012ec48  5c ec 12 00 90 ec 12 00 - f0 93 c4 02 a0 1a b2 02  \...............
0012ec58  00 00 00 00 90 ec 12 00 - 82 0b 6e 00 a4 ec 12 00  ..........n.....
0012ec68  ac 3a 40 00 90 ec 12 00 - a0 1a b2 02 f0 82 f1 00  .:@.............
0012ec78  f0 82 f1 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0012ec88  00 00 00 00 00 00 00 00 - f0 ec 12 00 cd 72 50 00  .............rP.
0012ec98  e3 ec 12 00 00 00 12 00 - 0c f2 12 00 c8 ef 12 00  ................
0012eca8  ac 3a 40 00 f0 ec 12 00 - f0 82 f1 00 4c ee 12 00  .:@.........L...
0012ecb8  f0 82 f1 00 f0 82 f1 00 - 00 00 00 00 00 00 00 00  ................
0012ecc8  00 00 00 00 f8 f1 12 00 - f8 f1 12 00 0c 11 00 00  ................
0012ecd8  66 09 03 00 66 09 03 00 - 1d 00 00 00 00 00 00 00  f...f...........
0012ece8  18 36 00 00 4c ee 12 00 - 34 ee 12 00 38 3e 45 00  .6..L...4...8>E.
0012ecf8  f0 82 f1 00 4c ee 12 00 - f0 82 f1 00 a7 66 45 00  ....L........fE.
0012ed08  f0 82 f1 00 4c ee 12 00 - f0 82 f1 00 f0 82 f1 00  ....L...........
0012ed18  28 ed 12 00 00 00 00 00 - 70 c2 f9 00 ee 52 50 00  (.......p....RP.
0012ed28  04 00 00 00 48 ab 1f 00 - 00 00 00 00 3e ee 12 00  ....H.......>...
0012ed38  00 00 00 00 00 00 02 00 - 00 fc fd 7f fc f0 12 00  ................

disassembling:
004cfd14     public IniFiles32.TIniFile32.ReadString:  ; function entry point
004cfd14 930   push    ebp
004cfd15       mov     ebp, esp
004cfd17       push    0
004cfd19       push    0
004cfd1b       push    0
004cfd1d       push    0
004cfd1f       push    ebx
004cfd20       push    esi
004cfd21       push    edi
004cfd22       mov     [ebp-4], ecx
004cfd25       mov     esi, edx
004cfd27       mov     ebx, eax
004cfd29       xor     eax, eax
004cfd2b       push    ebp
004cfd2c       push    $4cfe27                ; System.@HandleFinally
004cfd31       push    dword ptr fs:[eax]
004cfd34       mov     fs:[eax], esp
004cfd37 935   mov     eax, ebx
004cfd39       call    +$118e ($4d0ecc)       ; IniFiles32.TIniFile32.Reload
004cfd3e 936   mov     eax, [ebp+8]
004cfd41       mov     edx, [ebp+$c]
004cfd44       call    -$cbbd5 ($404174)      ; System.@LStrLAsg
004cfd49 937 > mov     eax, [ebx+$2c]
004cfd4c       mov     edx, [eax]
004cfd4e       call    dword ptr [edx+$14]
004cfd51       test    eax, eax
004cfd53       jle     loc_4cfe0c
004cfd59 939   mov     edx, esi
004cfd5b       mov     eax, ebx
004cfd5d       call    -$f56 ($4cee0c)        ; IniFiles32.TIniFile32.GetSectionIndex
004cfd62       mov     esi, eax
004cfd64 940   cmp     esi, -1
004cfd67       jz      loc_4cfe0c
004cfd6d 942   inc     esi
004cfd6e       jmp     loc_4cfde1
004cfd70 945   lea     ecx, [ebp-$c]
004cfd73       mov     edx, esi
004cfd75       mov     eax, [ebx+$2c]
004cfd78       mov     edi, [eax]
004cfd7a       call    dword ptr [edi+$c]
004cfd7d       mov     edx, [ebp-$c]
004cfd80       lea     ecx, [ebp-$10]
004cfd83       mov     eax, ebx
[...]

date/time         : 2015-08-12, 17:42:46, 156ms
computer name     : MFFJBFG1BBOASEZ
user name         : Administrator <admin>
registered owner  : ΢û / ΢й
operating system  : Windows XP Service Pack 3 (5.1.2600) build 2600
system language   : Chinese
system up time    : 9 hours 17 minutes
program up time   : 1 hour 10 minutes
processors        : 2x Pentium(R) Dual-Core CPU E5300 @ 2.60GHz
physical memory   : 1891/3327 MB (free/total)
free disk space   : (C:) 26.93 GB (K:) 24.27 GB
display mode      : 1440x900, 32 bit
process id        : $2050
allocated memory  : 90.86 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $eb093fce, $55103b8b, $4d60fff5
exception number  : 1
exception class   : EAccessViolation
exception message : Access violation at address 004CFD49 in module 'FlashFXP.exe'. ȡ of address 0000002C.

main thread ($2570):
004cfd49 +0035 FlashFXP.exe IniFiles32   937   +7 TIniFile32.ReadString
004cfe66 +002e FlashFXP.exe IniFiles32   962   +1 TIniFile32.ReadInteger
007426c0 +00ac FlashFXP.exe FrmMain1   12840  +10 TFrmMain.BuildMenuList
007627b5 +01d9 FlashFXP.exe FrmMain1   23920  +40 TFrmMain.PopSitePopup
004636fd +000d FlashFXP.exe Menus                 TPopupMenu.DoPopup
004637da +0032 FlashFXP.exe Menus                 TPopupMenu.Popup
004fc0f6 +0246 FlashFXP.exe ComCtrls              TToolBar.CheckMenuDropdown
004f8b8d +0039 FlashFXP.exe ComCtrls              TToolButton.CheckMenuDropdown
004fb522 +0036 FlashFXP.exe ComCtrls              TToolBar.CNNotify
00453e35 +0111 FlashFXP.exe Controls              TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls              TWinControl.WndProc
004fb881 +0231 FlashFXP.exe ComCtrls              TToolBar.WndProc
0045632c +002c FlashFXP.exe Controls              TWinControl.MainWndProc
00509afb +003f FlashFXP.exe ThemeMgr              TWindowProcList.DispatchMessage
0050b8f4 +01b8 FlashFXP.exe ThemeMgr              TThemeManager.WinControlWindowProc
0050b9c9 +0009 FlashFXP.exe ThemeMgr              TThemeManager.PreWinControlWindowProc
00453c64 +0024 FlashFXP.exe Controls              TControl.Perform
00453e35 +0111 FlashFXP.exe Controls              TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls              TWinControl.WndProc
004fb881 +0231 FlashFXP.exe ComCtrls              TToolBar.WndProc
00509afb +003f FlashFXP.exe ThemeMgr              TWindowProcList.DispatchMessage
0050b8f4 +01b8 FlashFXP.exe ThemeMgr              TThemeManager.WinControlWindowProc
0050b9c9 +0009 FlashFXP.exe ThemeMgr              TThemeManager.PreWinControlWindowProc
0045632c +002c FlashFXP.exe Controls              TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms       1529   +8 StdWndProc
77d2f406 +0044 user32.dll                         SendMessageA
00509afb +003f FlashFXP.exe ThemeMgr              TWindowProcList.DispatchMessage
0050b8f4 +01b8 FlashFXP.exe ThemeMgr              TThemeManager.WinControlWindowProc
0050b9c9 +0009 FlashFXP.exe ThemeMgr              TThemeManager.PreWinControlWindowProc
0045632c +002c FlashFXP.exe Controls              TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms       1529   +8 StdWndProc
77d196c2 +000a user32.dll                         DispatchMessageA
0044ca9f +008b FlashFXP.exe Forms       7117  +34 TApplication.ProcessMessage
0044cabe +000a FlashFXP.exe Forms       7148   +1 TApplication.ProcessMessages
00769dbe +0902 FlashFXP.exe FrmMain1   26583 +206 TFrmMain.FormDestroy
00445c5d +0031 FlashFXP.exe Forms       2755   +3 TCustomForm.DoDestroy
00445ac1 +005d FlashFXP.exe Forms       2719   +7 TCustomForm.BeforeDestruction
00403771 +0009 FlashFXP.exe System                @BeforeDestruction
00445ace +0006 FlashFXP.exe Forms       2723   +0 TCustomForm.Destroy
004033e4 +0008 FlashFXP.exe System                TObject.Free
0041c349 +0019 FlashFXP.exe Classes               TComponent.Remove
0041c40a +001e FlashFXP.exe Classes               TComponent.DestroyComponents
004436ab +002f FlashFXP.exe Forms       1261   +3 DoneApplication
0040a9b6 +0026 FlashFXP.exe SysUtils              DoExitProc
00403f50 +0028 FlashFXP.exe System                @Halt0
00796548 +1cc4 FlashFXP.exe FlashFXP     939 +649 initialization

thread $256c:
7c92df48 +00a ntdll.dll                              NtWaitForMultipleObjects
7c80958a +000 kernel32.dll                           WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll                           WaitForMultipleObjects
00640bd3 +07b FlashFXP.exe UPTShellControls 4370 +13 TChangeHandlerThread.Execute
0041bfc1 +22d FlashFXP.exe Classes                   HexToBin
00404080 +028 FlashFXP.exe System                    ThreadWrapper

thread $2338:
7c92df58 +0a ntdll.dll     NtWaitForSingleObject
7c8025d5 +85 kernel32.dll  WaitForSingleObjectEx
7c80253d +0d kernel32.dll  WaitForSingleObject

thread $d8c:
7c92df48 +00a ntdll.dll                  NtWaitForMultipleObjects
7c80958a +000 kernel32.dll               WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll               WaitForMultipleObjects
00662068 +10c FlashFXP.exe SaveToFileThd TSaveFileWorker.Execute
0041bfc1 +22d FlashFXP.exe Classes       HexToBin
00404080 +028 FlashFXP.exe System        ThreadWrapper

thread $1f00:
7c92d218 +a ntdll.dll  NtDelayExecution

modules:
00400000 FlashFXP.exe          4.0.0.1534       K:\ù\flashftp
03320000 Normaliz.dll          6.0.5441.0       C:\WINDOWS\system32
03a00000 TaobaoProtectSE.dll   2.4.2.5          C:\Documents and Settings\Administrator\Application Data\TaobaoProtect
03aa0000 libeay32.dll          1.0.0.3          K:\ù\flashftp
03bf0000 ssleay32.dll          1.0.0.3          K:\ù\flashftp
04340000 GOOGLEPINYIN2.IME     2.7.25.128       C:\WINDOWS\system32
08fe0000 Audiodev.dll          5.2.5721.5262    C:\WINDOWS\system32
10000000 360UDiskGuard.dll     2.0.0.1101       C:\Program Files\360\360Safe\safemon
10930000 PortableDeviceApi.dll 5.2.5721.5262    C:\WINDOWS\system32
11c70000 WMASF.DLL             11.0.5721.5262   C:\WINDOWS\system32
15110000 WMVCore.DLL           11.0.5721.5275   C:\WINDOWS\system32
16500000 wpdshext.dll          5.2.5721.5262    C:\WINDOWS\system32
1f840000 odbcint.dll           3.525.1117.0     C:\WINDOWS\system32
3e410000 WININET.dll           8.0.6001.23580   C:\WINDOWS\system32
3eab0000 iertutil.dll          8.0.6001.23580   C:\WINDOWS\system32
3eca0000 ieframe.dll           8.0.6001.23580   C:\WINDOWS\system32
43ce0000 urlmon.dll            8.0.6001.23580   C:\WINDOWS\system32
4ae90000 gdiplus.dll           5.2.6002.23084   C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.23084_x-ww_f3f35550
5adc0000 uxtheme.dll           6.0.2900.5512    C:\WINDOWS\system32
5dd50000 msxml3.dll            8.100.1054.0     C:\WINDOWS\system32
5efe0000 olepro32.dll          5.1.2600.5512    C:\WINDOWS\system32
5fdd0000 NETAPI32.dll          5.1.2600.6260    C:\WINDOWS\system32
60fd0000 hnetcfg.dll           5.1.2600.5512    C:\WINDOWS\system32
62c20000 LPK.DLL               5.1.2600.5512    C:\WINDOWS\system32
68000000 rsaenh.dll            5.1.2600.5507    C:\WINDOWS\system32
68100000 dssenh.dll            5.1.2600.5507    C:\WINDOWS\system32
68d60000 dbghelp.dll           5.1.2600.5512    C:\WINDOWS\system32
6bd10000 msohevi.dll           12.0.4518.1014   C:\Program Files\Microsoft Office\Office12
719c0000 mswsock.dll           5.1.2600.5625    C:\WINDOWS\System32
71a00000 wshtcpip.dll          5.1.2600.5512    C:\WINDOWS\System32
71a10000 WS2HELP.dll           5.1.2600.5512    C:\WINDOWS\system32
71a20000 WS2_32.dll            5.1.2600.5512    C:\WINDOWS\system32
71a40000 wsock32.dll           5.1.2600.5512    C:\WINDOWS\system32
71a90000 MPR.dll               5.1.2600.5512    C:\WINDOWS\system32
71b70000 SAMLIB.dll            5.1.2600.5512    C:\WINDOWS\System32
71b90000 ntlanman.dll          5.1.2600.5512    C:\WINDOWS\System32
71c00000 NETRAP.dll            5.1.2600.5512    C:\WINDOWS\System32
71c10000 NETUI1.dll            5.1.2600.5512    C:\WINDOWS\System32
71c50000 NETUI0.dll            5.1.2600.5512    C:\WINDOWS\System32
72f70000 winspool.drv          5.1.2600.5512    C:\WINDOWS\system32
73540000 ODBC32.dll            3.525.3012.0     C:\WINDOWS\system32
73640000 msctfime.ime          5.1.2600.5768    C:\WINDOWS\system32
73ce0000 shgina.dll            6.0.2900.5512    C:\WINDOWS\system32
73fa0000 USP10.dll             1.420.2600.6421  C:\WINDOWS\system32
74680000 MSCTF.dll             5.1.2600.5512    C:\WINDOWS\system32
75430000 CRYPTUI.dll           5.131.2600.5512  C:\WINDOWS\system32
758d0000 MSGINA.dll            5.1.2600.5512    C:\WINDOWS\system32
759d0000 USERENV.dll           5.1.2600.5512    C:\WINDOWS\system32
75ed0000 drprov.dll            5.1.2600.5512    C:\WINDOWS\System32
75ee0000 davclnt.dll           5.1.2600.5512    C:\WINDOWS\System32
75ef0000 browseui.dll          6.0.2900.6254    C:\WINDOWS\system32
76060000 SETUPAPI.dll          5.1.2600.5512    C:\WINDOWS\system32
762d0000 WINSTA.dll            5.1.2600.5512    C:\WINDOWS\system32
762f0000 MSIMG32.dll           5.1.2600.5512    C:\WINDOWS\system32
76300000 IMM32.DLL             5.1.2600.5512    C:\WINDOWS\system32
76320000 comdlg32.dll          6.0.2900.5512    C:\WINDOWS\system32
76570000 CSCDLL.dll            5.1.2600.5512    C:\WINDOWS\System32
76590000 cscui.dll             5.1.2600.5512    C:\WINDOWS\System32
765e0000 crypt32.dll           5.131.2600.6459  C:\WINDOWS\system32
76950000 LINKINFO.dll          5.1.2600.5512    C:\WINDOWS\system32
76960000 ntshrui.dll           5.1.2600.5512    C:\WINDOWS\system32
76990000 ole32.dll             5.1.2600.6435    C:\WINDOWS\system32
76af0000 ATL.DLL               3.5.2284.2       C:\WINDOWS\system32
76b10000 winmm.dll             5.1.2600.6160    C:\WINDOWS\system32
76b80000 sfc.dll               5.1.2600.5512    C:\WINDOWS\system32
76bc0000 psapi.dll             5.1.2600.5512    C:\WINDOWS\system32
76c00000 WINTRUST.dll          5.131.2600.6198  C:\WINDOWS\system32
76c30000 sfc_os.dll            5.1.2600.5512    C:\WINDOWS\system32
76c60000 IMAGEHLP.dll          5.1.2600.6479    C:\WINDOWS\system32
76d30000 iphlpapi.dll          5.1.2600.5512    C:\WINDOWS\system32
76d70000 appHelp.dll           5.1.2600.5512    C:\WINDOWS\system32
76db0000 MSASN1.dll            5.1.2600.5875    C:\WINDOWS\system32
76ef0000 DNSAPI.dll            5.1.2600.6089    C:\WINDOWS\system32
76f30000 WLDAP32.dll           5.1.2600.5512    C:\WINDOWS\system32
76f80000 winrnr.dll            5.1.2600.5512    C:\WINDOWS\System32
76f90000 rasadhlp.dll          5.1.2600.5512    C:\WINDOWS\system32
76fa0000 CLBCATQ.DLL           2001.12.4414.700 C:\WINDOWS\system32
77020000 COMRes.dll            2001.12.4414.700 C:\WINDOWS\system32
770f0000 oleaut32.dll          5.1.2600.6341    C:\WINDOWS\system32
77180000 comctl32.dll          6.0.2900.6028    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
77bd0000 version.dll           5.1.2600.5512    C:\WINDOWS\system32
77be0000 msvcrt.dll            7.0.2600.5512    C:\WINDOWS\system32
77d10000 user32.dll            5.1.2600.5512    C:\WINDOWS\system32
77da0000 advapi32.dll          5.1.2600.5755    C:\WINDOWS\system32
77e50000 RPCRT4.dll            5.1.2600.6477    C:\WINDOWS\system32
77ef0000 GDI32.dll             5.1.2600.6460    C:\WINDOWS\system32
77f40000 SHLWAPI.dll           6.0.2900.5912    C:\WINDOWS\system32
77fc0000 Secur32.dll           5.1.2600.5834    C:\WINDOWS\system32
78130000 MSVCR80.dll           8.0.50727.6195   C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86
7c800000 kernel32.dll          5.1.2600.5781    C:\WINDOWS\system32
7c920000 ntdll.dll             5.1.2600.6055    C:\WINDOWS\system32
7d590000 shell32.dll           6.0.2900.6242    C:\WINDOWS\system32
7e550000 shdocvw.dll           6.0.2900.6254    C:\WINDOWS\system32

processes:
0000 Idle                 0   0
0004 System               0   0   normal
01dc smss.exe             0   0   normal       C:\WINDOWS\system32
0244 csrss.exe            0   0
0264 winlogon.exe         45  14  high         C:\WINDOWS\system32
0290 services.exe         4   2   normal       C:\WINDOWS\system32
029c lsass.exe            4   3   normal       C:\WINDOWS\system32
0348 svchost.exe          4   1   normal       C:\WINDOWS\system32
0374 svchost.exe          0   0
039c svchost.exe          10  32  normal       C:\WINDOWS\System32
03c4 svchost.exe          4   1   normal       C:\WINDOWS\system32
0484 svchost.exe          0   0
0490 svchost.exe          4   2   normal       C:\WINDOWS\System32
04b8 svchost.exe          0   0
04cc zhudongfangyu.exe    4   5   normal       C:\Program Files\360\360Safe\deepscan
04f4 svchost.exe          4   1   normal       C:\WINDOWS\System32
0628 DhMachineSvc.exe     4   4   normal       C:\Program Files\Microsoft Device Health
063c DhPluginMgr.exe      4   5   normal       C:\Program Files\Microsoft Device Health\PluginManager
065c inetinfo.exe         4   7   normal       C:\WINDOWS\system32\inetsrv
0670 sqlservr.exe         4   1   normal       C:\Program Files\Microsoft SQL Server\MSSQL\Binn
06e4 mysqld.exe           4   2   normal       C:\mysql\bin
06fc pcas.exe             4   3   normal       C:\Program Files\alipay\aliedit\5.3.0.3807
03e8 svchost.exe          4   3   normal       C:\WINDOWS\System32
0438 secbizsrv.exe        4   14  normal       C:\Program Files\alipay\aliedit\5.3.0.3807
0458 TBSecSvc.exe         4   6   normal       C:\Documents and Settings\Administrator\Application Data\TaobaoProtect
0860 wmiprvse.exe         0   0
0928 Explorer.EXE         429 235 normal       C:\WINDOWS
0978 360Tray.exe          240 77  normal       C:\Program Files\360\360Safe\safemon
0980 ctfmon.exe           28  12  normal       C:\WINDOWS\system32
0990 360sd.exe            469 214 normal       C:\Program Files\360\360sd
09c4 PalmInputGuard.exe   8   4   normal       C:\Program Files\PalmInput\Extensions\Guard\1.5.0.12
0ae4 TaobaoProtect.exe    14  16  normal       C:\Documents and Settings\Administrator\Application Data\TaobaoProtect
0b74 alg.exe              0   0
0bac unsecapp.exe         0   0
0c60 aliwssv.exe          4   1   normal       C:\Program Files\alipay\aliedit\5.3.0.3807
0a90 360rp.exe            7   3   normal       C:\Program Files\360\360sd
0a64 QQ.exe               342 216 normal       D:\ù\Ѷ\Bin
0ef0 TXPlatform.exe       8   6   normal       D:\ù\Ѷ\Bin
0420 QQ.exe               156 158 normal       D:\ù\Ѷ\Bin
0880 QQ.exe               402 201 normal       D:\ù\Ѷ\Bin
1124 WifiService.exe      16  6   normal       C:\Program Files\Wifisrv
13dc Alipaybsm.exe        18  84  normal       C:\Documents and Settings\All Users\Application Data\alipay
0d84 360se.exe            716 203 normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
1804 360se.exe            8   1   normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
0d90 mstsc.exe            140 117 normal       C:\WINDOWS\system32
1a38 360rps.exe           4   3   normal       C:\Program Files\360\360sd
0170 conime.exe           17  12  normal       C:\WINDOWS\system32
1a4c PalmInputService.exe 13  6   normal       C:\Program Files\PalmInput\1.9.0.840
1998 360se.exe            8   1   below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
1dec 360se.exe            167 73  normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
1474 mstsc.exe            119 96  normal       C:\WINDOWS\system32
19b8 mstsc.exe            126 100 normal       C:\WINDOWS\system32
2088 360se.exe            163 66  below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
2268 svchost.exe          4   2   normal       C:\WINDOWS\system32
2050 FlashFXP.exe         267 194 normal       K:\ù\flashftp
1354 QQExternal.exe       69  37  normal       D:\ù\Ѷ\Bin
2860 QQExternal.exe       81  21  normal       D:\ù\Ѷ\Bin
125c 360se.exe            241 69  below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
1f1c 360se.exe            45  1   below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
2b08 360se.exe            16  11  normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
28e8 QQExternal.exe       19  21  normal       D:\ù\Ѷ\Bin

hardware:
+ IDE ATA/ATAPI 
  - Intel(R) N10/ICH7 Family Serial ATA Storage Controller - 27C0 (driver 9.1.1.1016)
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
+ 
  - Pentium(R) Dual-Core  CPU      E5300  @ 2.60GHz
  - Pentium(R) Dual-Core  CPU      E5300  @ 2.60GHz
+ 
  - ST500DM002-1BD142
  - WD Elements 1078 USB Device
+ 
  - 弴ü
+ 
  - ACPI Multiprocessor PC
+ 
  - ׼ 101/102  Microsoft Ȼ PS/2 
+ ƵϷ
  - Realtek High Definition Audio (driver 5.10.0.6449)
  - ͳƵ׽豸
  - ͳƵ
  - ý豸
  - Ƶ
  - Ƶ
+ ָ豸
  - Microsoft PS/2 Mouse
+ ͨô߿
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C9 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CA (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CB (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB2 Enhanced Host Controller - 27CC (driver 9.1.1.1016)
  - USB Mass Storage Device
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
+ 
  - Realtek PCIe FE Family Controller (driver 5.788.613.2011)
  - Realtek RTL8188EU Wireless LAN 802.11n USB 2.0 Network Adapter (driver 1024.9.1219.2013)
+ ϵͳ豸
  - ACPI Fixed Feature Button
  - ACPI Power Button
  - ACPI Thermal Zone
  - Direct memory access controller
  - Intel(R) 4 Series Chipset PCI Express Root Port - 2E31 (driver 9.1.0.1012)
  - Intel(R) 4 Series Chipset Processor to I/O Controller - 2E30 (driver 9.1.0.1012)
  - Intel(R) 82801BA/CA PCI Bridge - 244E (driver 3.30.1002.0)
  - Intel(R) 82802 Firmware Hub Device
  - Intel(R) ICH7 Family LPC Interface Controller - 27B8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family PCI Express Root Port - 27D0 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family PCI Express Root Port - 27D2 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family SMBus Controller - 27DA (driver 9.1.1.1016)
  - ISAPNP Read Data Port
  - Logical Disk Manager
  - Microcode Update Device
  - Microsoft ACPI-Compliant System
  - Microsoft Composite Battery
  - Microsoft System Management BIOS Driver
  - Microsoft  High Definition Audio  UAA 
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Numeric data processor
  - PCI bus
  - Plug and Play Software Device Enumerator
  - Programmable interrupt controller
  - System board
  - System board
  - System CMOS/real time clock
  - System speaker
  - System timer
  - Terminal Server Device Redirector
  - Terminal Server Keyboard Driver
  - Terminal Server Mouse Driver
  - Volume Manager
  - ̨ȫʾƵ
+ ʾ
  - NVIDIA GeForce 9500 GT (driver 6.14.12.6658)

cpu registers:
eax = 0012f668
ebx = 00000000
ecx = 00000000
edx = 00000000
esi = 00742cc4
edi = 00742cc4
eip = 004cfd49
esp = 0012f614
ebp = 0012f63c

stack dump:
0012f614  4c f6 12 00 ac 3a 40 00 - 3c f6 12 00 c4 2c 74 00  L....:@.<....,t.
0012f624  00 00 00 00 e8 ba f5 00 - 00 00 00 00 00 00 00 00  ................
0012f634  00 00 00 00 b4 2c 74 00 - 70 f6 12 00 6b fe 4c 00  .....,t.p...k.L.
0012f644  68 f6 12 00 00 00 00 00 - 80 f6 12 00 ac 3a 40 00  h............:@.
0012f654  70 f6 12 00 4c 00 00 00 - d6 02 00 00 e8 ba f5 00  p...L...........
0012f664  00 00 00 00 00 00 00 00 - b4 2c 74 00 d4 f6 12 00  .........,t.....
0012f674  c5 26 74 00 00 00 00 00 - 00 00 00 00 dc f6 12 00  .&t.............
0012f684  ac 3a 40 00 d4 f6 12 00 - 4c 00 00 00 d6 02 00 00  .:@.....L.......
0012f694  e8 ba f5 00 00 00 00 00 - 00 00 00 00 4c 00 00 00  ............L...
0012f6a4  c0 f6 12 00 4c 00 00 00 - 40 f1 7b 03 00 00 00 00  ....L...@.{.....
0012f6b4  2a 11 46 00 06 00 00 00 - 01 00 00 00 2e 0f 4d 00  *.F...........M.
0012f6c4  4c 00 00 00 d6 02 00 00 - e8 ba f5 00 90 a9 e9 00  L...............
0012f6d4  0c f7 12 00 ba 27 76 00 - 38 f7 12 00 ac 3a 40 00  .....'v.8....:@.
0012f6e4  0c f7 12 00 4c 00 00 00 - d6 02 00 00 e8 ba f5 00  ....L...........
0012f6f4  00 00 00 00 00 00 00 00 - 7c 27 45 00 00 00 00 00  ........|'E.....
0012f704  58 f7 12 00 90 a9 e9 00 - 74 f7 12 00 00 37 46 00  X.......t....7F.
0012f714  e8 ba f5 00 dd 37 46 00 - d6 02 00 00 4c 00 00 00  .....7F.....L...
0012f724  74 f7 12 00 e8 ba f5 00 - 50 e2 e8 00 d8 df 45 00  t.......P.....E.
0012f734  f9 c0 4f 00 44 f7 12 00 - ac 3a 40 00 74 f7 12 00  ..O.D....:@.t...
0012f744  34 fb 12 00 ac 3a 40 00 - 74 f7 12 00 50 e2 e8 00  4....:@.t...P...

disassembling:
004cfd14     public IniFiles32.TIniFile32.ReadString:  ; function entry point
004cfd14 930   push    ebp
004cfd15       mov     ebp, esp
004cfd17       push    0
004cfd19       push    0
004cfd1b       push    0
004cfd1d       push    0
004cfd1f       push    ebx
004cfd20       push    esi
004cfd21       push    edi
004cfd22       mov     [ebp-4], ecx
004cfd25       mov     esi, edx
004cfd27       mov     ebx, eax
004cfd29       xor     eax, eax
004cfd2b       push    ebp
004cfd2c       push    $4cfe27                ; System.@HandleFinally
004cfd31       push    dword ptr fs:[eax]
004cfd34       mov     fs:[eax], esp
004cfd37 935   mov     eax, ebx
004cfd39       call    +$118e ($4d0ecc)       ; IniFiles32.TIniFile32.Reload
004cfd3e 936   mov     eax, [ebp+8]
004cfd41       mov     edx, [ebp+$c]
004cfd44       call    -$cbbd5 ($404174)      ; System.@LStrLAsg
004cfd49 937 > mov     eax, [ebx+$2c]
004cfd4c       mov     edx, [eax]
004cfd4e       call    dword ptr [edx+$14]
004cfd51       test    eax, eax
004cfd53       jle     loc_4cfe0c
004cfd59 939   mov     edx, esi
004cfd5b       mov     eax, ebx
004cfd5d       call    -$f56 ($4cee0c)        ; IniFiles32.TIniFile32.GetSectionIndex
004cfd62       mov     esi, eax
004cfd64 940   cmp     esi, -1
004cfd67       jz      loc_4cfe0c
004cfd6d 942   inc     esi
004cfd6e       jmp     loc_4cfde1
004cfd70 945   lea     ecx, [ebp-$c]
004cfd73       mov     edx, esi
004cfd75       mov     eax, [ebx+$2c]
004cfd78       mov     edi, [eax]
004cfd7a       call    dword ptr [edi+$c]
004cfd7d       mov     edx, [ebp-$c]
004cfd80       lea     ecx, [ebp-$10]
004cfd83       mov     eax, ebx
[...]

date/time         : 2015-09-15, 12:01:22, 937ms
computer name     : MFFJBFG1BBOASEZ
user name         : Administrator <admin>
registered owner  : ΢û / ΢й
operating system  : Windows XP Service Pack 3 (5.1.2600) build 2600
system language   : Chinese
system up time    : 3 hours 40 minutes
program up time   : 2 hours
processors        : 2x Pentium(R) Dual-Core CPU E5300 @ 2.60GHz
physical memory   : 1762/3327 MB (free/total)
free disk space   : (C:) 26.90 GB (K:) 23.16 GB
display mode      : 1440x900, 32 bit
process id        : $14de0
allocated memory  : 23.00 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $ac4418ac, $f82d8525, $ed9bd532
exception number  : 1
exception class   : EOutOfMemory
exception message : Out of memory.

main thread ($14de4):
004041ad +000d FlashFXP.exe System                @NewAnsiString
004041cf +000b FlashFXP.exe System                @LStrFromPCharLen
004045b3 +0023 FlashFXP.exe System                @LStrCopy
0074465f +00eb FlashFXP.exe FrmMain1   13532  +17 LoadStatusText
00744a97 +02fb FlashFXP.exe FrmMain1   13602  +54 TFrmMain.CreateEditor
007786c0 +0038 FlashFXP.exe FrmMain1   31646   +1 TFrmMain.ConsoleDblClick
00453fe9 +0015 FlashFXP.exe Controls              TControl.DblClick
0045410c +0034 FlashFXP.exe Controls              TControl.WMLButtonDblClk
004db750 +004c FlashFXP.exe cxGraphics  2534   +7 TCustomConsole.WMLButtonDblClk
00453e35 +0111 FlashFXP.exe Controls              TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls              TWinControl.WndProc
00509afb +003f FlashFXP.exe ThemeMgr              TWindowProcList.DispatchMessage
0050b8f4 +01b8 FlashFXP.exe ThemeMgr              TThemeManager.WinControlWindowProc
0050b9c9 +0009 FlashFXP.exe ThemeMgr              TThemeManager.PreWinControlWindowProc
0045632c +002c FlashFXP.exe Controls              TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms       1529   +8 StdWndProc
77d196c2 +000a user32.dll                         DispatchMessageA
0044ca9f +008b FlashFXP.exe Forms       7117  +34 TApplication.ProcessMessage
0044cad6 +000a FlashFXP.exe Forms       7155   +1 TApplication.HandleMessage
0044cd8b +00bf FlashFXP.exe Forms       7259  +26 TApplication.Run
007964ed +1c69 FlashFXP.exe FlashFXP     920 +630 initialization

thread $14e44:
7c92df48 +00a ntdll.dll                              NtWaitForMultipleObjects
7c80958a +000 kernel32.dll                           WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll                           WaitForMultipleObjects
00640bd3 +07b FlashFXP.exe UPTShellControls 4370 +13 TChangeHandlerThread.Execute
0041bfc1 +22d FlashFXP.exe Classes                   HexToBin
00404080 +028 FlashFXP.exe System                    ThreadWrapper

thread $13b4:
7c92df48 +00a ntdll.dll                  NtWaitForMultipleObjects
7c80958a +000 kernel32.dll               WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll               WaitForMultipleObjects
00662068 +10c FlashFXP.exe SaveToFileThd TSaveFileWorker.Execute
0041bfc1 +22d FlashFXP.exe Classes       HexToBin
00404080 +028 FlashFXP.exe System        ThreadWrapper

thread $1461c: <priority:1>
7c92da48 +a ntdll.dll  NtRemoveIoCompletion

modules:
00400000 FlashFXP.exe          4.0.0.1534       K:\ù\flashftp
02c00000 Normaliz.dll          6.0.5441.0       C:\WINDOWS\system32
032e0000 TaobaoProtectSE.dll   2.4.2.5          C:\Documents and Settings\Administrator\Application Data\TaobaoProtect
03380000 libeay32.dll          1.0.0.3          K:\ù\flashftp
034d0000 ssleay32.dll          1.0.0.3          K:\ù\flashftp
03d00000 rarext.dll            5.21.0.0         C:\Program Files\WinRAR
03f60000 SoftMgrExt.dll        1.1.0.1025       C:\Program Files\360\360Safe\SoftMgr
040a0000 360Base.dll           1.0.0.1070       C:\Program Files\360\360Safe
04190000 MenuEx.dll            5.0.0.5076       C:\Program Files\360\360sd
04220000 shell360ext.dll       7.5.0.1275       C:\Program Files\360\360Safe\Utils
04310000 360WangPanShell.dll   1.0.0.1030       C:\Program Files\360\360WangPan
04470000 360base.dll           1.0.0.1041       C:\Program Files\360\360WangPan
07160000 Audiodev.dll          5.2.5721.5262    C:\WINDOWS\system32
10000000 360UDiskGuard.dll     2.0.0.1101       C:\Program Files\360\360Safe\safemon
10930000 PortableDeviceApi.dll 5.2.5721.5262    C:\WINDOWS\system32
11c70000 WMASF.DLL             11.0.5721.5262   C:\WINDOWS\system32
15110000 WMVCore.DLL           11.0.5721.5275   C:\WINDOWS\system32
16500000 wpdshext.dll          5.2.5721.5262    C:\WINDOWS\system32
1f840000 odbcint.dll           3.525.1117.0     C:\WINDOWS\system32
3e410000 WININET.dll           8.0.6001.23580   C:\WINDOWS\system32
3eab0000 iertutil.dll          8.0.6001.23580   C:\WINDOWS\system32
43ce0000 urlmon.dll            8.0.6001.23580   C:\WINDOWS\system32
4ae90000 gdiplus.dll           5.2.6002.23084   C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.23084_x-ww_f3f35550
5adc0000 uxtheme.dll           6.0.2900.5512    C:\WINDOWS\system32
5efe0000 olepro32.dll          5.1.2600.5512    C:\WINDOWS\system32
5fdd0000 NETAPI32.dll          5.1.2600.6260    C:\WINDOWS\system32
60fd0000 hnetcfg.dll           5.1.2600.5512    C:\WINDOWS\system32
62c20000 LPK.DLL               5.1.2600.5512    C:\WINDOWS\system32
68000000 rsaenh.dll            5.1.2600.5507    C:\WINDOWS\system32
68100000 dssenh.dll            5.1.2600.5507    C:\WINDOWS\system32
6bd10000 msohevi.dll           12.0.4518.1014   C:\Program Files\Microsoft Office\Office12
719c0000 mswsock.dll           5.1.2600.5625    C:\WINDOWS\system32
71a00000 wshtcpip.dll          5.1.2600.5512    C:\WINDOWS\System32
71a10000 WS2HELP.dll           5.1.2600.5512    C:\WINDOWS\system32
71a20000 WS2_32.dll            5.1.2600.5512    C:\WINDOWS\system32
71a40000 wsock32.dll           5.1.2600.5512    C:\WINDOWS\system32
71a90000 MPR.dll               5.1.2600.5512    C:\WINDOWS\system32
71b70000 SAMLIB.dll            5.1.2600.5512    C:\WINDOWS\System32
71b90000 ntlanman.dll          5.1.2600.5512    C:\WINDOWS\System32
71c00000 NETRAP.dll            5.1.2600.5512    C:\WINDOWS\System32
71c10000 NETUI1.dll            5.1.2600.5512    C:\WINDOWS\System32
71c50000 NETUI0.dll            5.1.2600.5512    C:\WINDOWS\System32
72f70000 winspool.drv          5.1.2600.5512    C:\WINDOWS\system32
73250000 RICHED32.DLL          5.1.2600.0       C:\WINDOWS\system32
73540000 ODBC32.dll            3.525.3012.0     C:\WINDOWS\system32
73640000 msctfime.ime          5.1.2600.5768    C:\WINDOWS\system32
73ce0000 shgina.dll            6.0.2900.5512    C:\WINDOWS\system32
73fa0000 USP10.dll             1.420.2600.6421  C:\WINDOWS\system32
74680000 MSCTF.dll             5.1.2600.5512    C:\WINDOWS\system32
74d90000 RICHED20.dll          5.30.23.1230     C:\WINDOWS\system32
75430000 CRYPTUI.dll           5.131.2600.5512  C:\WINDOWS\system32
758d0000 MSGINA.dll            5.1.2600.5512    C:\WINDOWS\system32
759d0000 USERENV.dll           5.1.2600.5512    C:\WINDOWS\system32
75ed0000 drprov.dll            5.1.2600.5512    C:\WINDOWS\System32
75ee0000 davclnt.dll           5.1.2600.5512    C:\WINDOWS\System32
75ef0000 browseui.dll          6.0.2900.6254    C:\WINDOWS\system32
76060000 SETUPAPI.dll          5.1.2600.5512    C:\WINDOWS\system32
762d0000 WINSTA.dll            5.1.2600.5512    C:\WINDOWS\system32
762f0000 MSIMG32.dll           5.1.2600.5512    C:\WINDOWS\system32
76300000 IMM32.DLL             5.1.2600.5512    C:\WINDOWS\system32
76320000 comdlg32.dll          6.0.2900.5512    C:\WINDOWS\system32
76570000 CSCDLL.dll            5.1.2600.5512    C:\WINDOWS\System32
76590000 cscui.dll             5.1.2600.5512    C:\WINDOWS\System32
765e0000 crypt32.dll           5.131.2600.6459  C:\WINDOWS\system32
76950000 LINKINFO.dll          5.1.2600.5512    C:\WINDOWS\system32
76960000 ntshrui.dll           5.1.2600.5512    C:\WINDOWS\system32
76990000 ole32.dll             5.1.2600.6435    C:\WINDOWS\system32
76af0000 ATL.DLL               3.5.2284.2       C:\WINDOWS\system32
76b10000 winmm.dll             5.1.2600.6160    C:\WINDOWS\system32
76b80000 sfc.dll               5.1.2600.5512    C:\WINDOWS\system32
76bc0000 psapi.dll             5.1.2600.5512    C:\WINDOWS\system32
76c00000 WINTRUST.dll          5.131.2600.6198  C:\WINDOWS\system32
76c30000 sfc_os.dll            5.1.2600.5512    C:\WINDOWS\system32
76c60000 IMAGEHLP.dll          5.1.2600.6479    C:\WINDOWS\system32
76d30000 iphlpapi.dll          5.1.2600.5512    C:\WINDOWS\system32
76d70000 appHelp.dll           5.1.2600.5512    C:\WINDOWS\system32
76db0000 MSASN1.dll            5.1.2600.5875    C:\WINDOWS\system32
76ef0000 DNSAPI.dll            5.1.2600.6089    C:\WINDOWS\system32
76f30000 WLDAP32.dll           5.1.2600.5512    C:\WINDOWS\system32
76f80000 winrnr.dll            5.1.2600.5512    C:\WINDOWS\System32
76f90000 rasadhlp.dll          5.1.2600.5512    C:\WINDOWS\system32
76fa0000 CLBCATQ.DLL           2001.12.4414.700 C:\WINDOWS\system32
77020000 COMRes.dll            2001.12.4414.700 C:\WINDOWS\system32
770f0000 oleaut32.dll          5.1.2600.6341    C:\WINDOWS\system32
77180000 comctl32.dll          6.0.2900.6028    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
77bd0000 version.dll           5.1.2600.5512    C:\WINDOWS\system32
77be0000 msvcrt.dll            7.0.2600.5512    C:\WINDOWS\system32
77d10000 user32.dll            5.1.2600.5512    C:\WINDOWS\system32
77da0000 advapi32.dll          5.1.2600.5755    C:\WINDOWS\system32
77e50000 RPCRT4.dll            5.1.2600.6477    C:\WINDOWS\system32
77ef0000 GDI32.dll             5.1.2600.6460    C:\WINDOWS\system32
77f40000 SHLWAPI.dll           6.0.2900.5912    C:\WINDOWS\system32
77fc0000 Secur32.dll           5.1.2600.5834    C:\WINDOWS\system32
78130000 MSVCR80.dll           8.0.50727.6195   C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86
7c800000 kernel32.dll          5.1.2600.5781    C:\WINDOWS\system32
7c920000 ntdll.dll             5.1.2600.6055    C:\WINDOWS\system32
7d590000 shell32.dll           6.0.2900.6242    C:\WINDOWS\system32
7e550000 shdocvw.dll           6.0.2900.6254    C:\WINDOWS\system32

processes:
00000 Idle              0   0
00004 System            0   0   normal
001c4 smss.exe          0   0   normal       C:\WINDOWS\system32
00234 csrss.exe         0   0
00254 winlogon.exe      45  14  high         C:\WINDOWS\system32
00280 services.exe      4   2   normal       C:\WINDOWS\system32
0028c lsass.exe         4   1   normal       C:\WINDOWS\system32
00338 svchost.exe       4   1   normal       C:\WINDOWS\system32
00364 svchost.exe       0   0
0038c svchost.exe       10  26  normal       C:\WINDOWS\System32
003b4 svchost.exe       4   1   normal       C:\WINDOWS\system32
0046c svchost.exe       0   0
00484 svchost.exe       4   2   normal       C:\WINDOWS\System32
004ac svchost.exe       0   0
004c0 zhudongfangyu.exe 4   6   normal       C:\Program Files\360\360Safe\deepscan
004e4 svchost.exe       4   1   normal       C:\WINDOWS\System32
00600 WPService.exe     8   3   normal       C:\Program Files\CMBCHINA\WebProtect
0062c DhMachineSvc.exe  4   4   normal       C:\Program Files\Microsoft Device Health
0063c DhPluginMgr.exe   4   6   normal       C:\Program Files\Microsoft Device Health\PluginManager
0065c inetinfo.exe      4   7   normal       C:\WINDOWS\system32\inetsrv
00670 sqlservr.exe      4   1   normal       C:\Program Files\Microsoft SQL Server\MSSQL\Binn
006d4 mysqld.exe        4   2   normal       C:\mysql\bin
006e8 pcas.exe          4   3   normal       C:\Program Files\alipay\aliedit\5.3.0.3807
00320 alg.exe           0   0
00a34 Explorer.EXE      419 363 normal       C:\WINDOWS
00a98 360Tray.exe       259 87  normal       C:\Program Files\360\360Safe\safemon
00aa0 ctfmon.exe        164 69  normal       C:\WINDOWS\system32
00ab4 360sd.exe         469 214 normal       C:\Program Files\360\360sd
009b0 360se.exe         791 248 normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
00b78 360se.exe         8   1   normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
00aa8 TaobaoProtect.exe 17  18  normal       C:\Documents and Settings\Administrator\Application Data\TaobaoProtect
0134c QQ.exe            268 162 normal       D:\ù\Ѷ\Bin
0147c TXPlatform.exe    8   5   normal       D:\ù\Ѷ\Bin
00e90 QQ.exe            111 119 normal       D:\ù\Ѷ\Bin
015b4 QQ.exe            243 158 normal       D:\ù\Ѷ\Bin
08a34 360se.exe         209 1   normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
08b54 dllhost.exe       0   0
08b94 dllhost.exe       4   3   normal       C:\WINDOWS\system32
08ea4 dreamweaver.exe   559 821 normal       C:\Program Files\Macromedia\Dreamweaver 8
09d98 360rp.exe         7   3   normal       C:\Program Files\360\360sd
14de0 FlashFXP.exe      268 207 normal       K:\ù\flashftp
01c0c svchost.exe       4   2   normal       C:\WINDOWS\system32
05c3c conime.exe        15  9   normal       C:\WINDOWS\system32
06abc 360se.exe         228 1   normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
0db80 360se.exe         157 1   below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
0dc60 360se.exe         42  76  normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
0e02c 360se.exe         199 69  below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
117d0 360se.exe         38  1   below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
15650 360se.exe         537 1   below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
17e28 360se.exe         292 1   below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
183c4 360se.exe         8   1   below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
18614 360se.exe         196 1   normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application

hardware:
+ IDE ATA/ATAPI 
  - Intel(R) N10/ICH7 Family Serial ATA Storage Controller - 27C0 (driver 9.1.1.1016)
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
+ 
  - Pentium(R) Dual-Core  CPU      E5300  @ 2.60GHz
  - Pentium(R) Dual-Core  CPU      E5300  @ 2.60GHz
+ 
  - ST500DM002-1BD142
  - WD Elements 1078 USB Device
+ 
  - 弴ü
+ 
  - ACPI Multiprocessor PC
+ 
  - ׼ 101/102  Microsoft Ȼ PS/2 
+ ƵϷ
  - Realtek High Definition Audio (driver 5.10.0.6449)
  - ͳƵ׽豸
  - ͳƵ
  - ý豸
  - Ƶ
  - Ƶ
+ ָ豸
  - Microsoft PS/2 Mouse
+ ͨô߿
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C9 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CA (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CB (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB2 Enhanced Host Controller - 27CC (driver 9.1.1.1016)
  - USB Mass Storage Device
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
+ 
  - Realtek PCIe FE Family Controller (driver 5.788.613.2011)
  - Realtek RTL8188EU Wireless LAN 802.11n USB 2.0 Network Adapter (driver 1024.9.1219.2013)
+ ϵͳ豸
  - ACPI Fixed Feature Button
  - ACPI Power Button
  - ACPI Thermal Zone
  - Direct memory access controller
  - Intel(R) 4 Series Chipset PCI Express Root Port - 2E31 (driver 9.1.0.1012)
  - Intel(R) 4 Series Chipset Processor to I/O Controller - 2E30 (driver 9.1.0.1012)
  - Intel(R) 82801BA/CA PCI Bridge - 244E (driver 3.30.1002.0)
  - Intel(R) 82802 Firmware Hub Device
  - Intel(R) ICH7 Family LPC Interface Controller - 27B8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family PCI Express Root Port - 27D0 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family PCI Express Root Port - 27D2 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family SMBus Controller - 27DA (driver 9.1.1.1016)
  - ISAPNP Read Data Port
  - Logical Disk Manager
  - Microcode Update Device
  - Microsoft ACPI-Compliant System
  - Microsoft Composite Battery
  - Microsoft System Management BIOS Driver
  - Microsoft  High Definition Audio  UAA 
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Numeric data processor
  - PCI bus
  - Plug and Play Software Device Enumerator
  - Programmable interrupt controller
  - System board
  - System board
  - System CMOS/real time clock
  - System speaker
  - System timer
  - Terminal Server Device Redirector
  - Terminal Server Keyboard Driver
  - Terminal Server Mouse Driver
  - Volume Manager
  - ̨ȫʾƵ
+ ʾ
  - NVIDIA GeForce 9500 GT (driver 6.14.12.6658)

cpu registers:
eax = 00f8c038
ebx = 004041ad
ecx = 0040eda8
edx = 004041ad
esi = 0303c048
edi = 5dd2d35b
eip = 004041ad
esp = 0012faf0
ebp = 0012fb8c

stack dump:
0012faf0  ad 41 40 00 de fa ed 0e - 01 00 00 00 07 00 00 00  .A@.............
0012fb00  04 fb 12 00 ad 41 40 00 - 38 c0 f8 00 ad 41 40 00  .....A@.8....A@.
0012fb10  48 c0 03 03 5b d3 d2 5d - 8c fb 12 00 20 fb 12 00  H...[..]........
0012fb20  80 fb 12 00 f8 2a 40 00 - 5b d3 d2 5d d4 41 40 00  .....*@.[..].A@.
0012fb30  00 00 00 00 00 00 00 00 - 5b d3 d2 5d b8 45 40 00  ........[..].E@.
0012fb40  d0 97 00 03 64 46 74 00 - 80 fb 12 00 58 fb 12 00  ....dFt.....X...
0012fb50  ac 3a 40 00 8c fb 12 00 - 98 fb 12 00 ac 3a 40 00  .:@..........:@.
0012fb60  8c fb 12 00 e0 fd 12 00 - 00 00 00 00 00 00 00 00  ................
0012fb70  00 00 00 00 01 00 00 00 - 83 00 00 00 50 83 f9 00  ............P...
0012fb80  00 00 00 00 0d 01 00 00 - 5b d3 d2 5d c0 fb 12 00  ........[..]....
0012fb90  9c 4a 74 00 c0 fb 12 00 - e0 fb 12 00 ac 3a 40 00  .Jt..........:@.
0012fba0  c0 fb 12 00 e0 fd 12 00 - 40 ca 09 03 d0 2d f0 00  ........@....-..
0012fbb0  00 00 00 00 00 00 00 00 - 00 00 00 00 d0 2d f0 00  .............-..
0012fbc0  f8 fb 12 00 c5 86 77 00 - 40 ca 09 03 00 00 00 00  ......w.@.......
0012fbd0  01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0012fbe0  b0 fd 12 00 ac 3a 40 00 - f8 fb 12 00 40 ca 09 03  .....:@.....@...
0012fbf0  40 ca 09 03 00 00 00 00 - 2c fc 12 00 ef 3f 45 00  @.......,....?E.
0012fc00  d4 3f 45 00 11 41 45 00 - e0 fd 12 00 e0 fd 12 00  .?E..AE.........
0012fc10  40 ca 09 03 55 b7 4d 00 - e0 fd 12 00 e0 fd 12 00  @...U.M.........
0012fc20  40 ca 09 03 e0 fd 12 00 - 40 ca 09 03 70 fd 12 00  @.......@...p...

disassembling:
[...]
00744623         cmp     esi, eax
00744625         jnz     loc_744633
00744627 13528   mov     eax, [ebx]
00744629         call    -$3402a6 ($404388)     ; System.@LStrLen
0074462e         mov     [ebp-4], eax
00744631         jmp     loc_74464b
00744633 13530   lea     eax, [esi+esi*2]
00744636         mov     edx, [ebx+$13]
00744639         movsx   edx, word ptr [edx+eax*4+$14]
0074463e         mov     ecx, [ebx+$13]
00744641         movsx   eax, word ptr [ecx+eax*4+8]
00744646         sub     edx, eax
00744648         mov     [ebp-4], edx
0074464b 13532   lea     eax, [ebp-$c]
0074464e         push    eax
0074464f         lea     edi, [esi+esi*2]
00744652         mov     eax, [ebx+$13]
00744655         movsx   edx, word ptr [eax+edi*4+8]
0074465a         mov     eax, [ebx]
0074465c         mov     ecx, [ebp-4]
0074465f       > call    -$3400d4 ($404590)     ; System.@LStrCopy
00744664 13533   mov     eax, [ebx+$13]
00744667         call    -$33e88c ($405de0)     ; System.@DynArrayHigh
0074466c         cmp     esi, eax
0074466e         jnz     loc_74467d
00744670 13534   lea     eax, [ebp-$c]
00744673         mov     edx, $744798
00744678         call    -$3402ed ($404390)     ; System.@LStrCat
0074467d 13536   mov     eax, [ebp+8]
00744680         mov     eax, [eax+8]
00744683         mov     eax, [eax+$58]
00744686         call    -$320703 ($423f88)     ; Graphics.TFont.GetSize
0074468b         push    eax
0074468c         mov     eax, [ebx+$13]
0074468f         mov     al, [eax+edi*4+$a]
00744693         push    eax
00744694         mov     eax, [ebx+$13]
00744697         mov     eax, [eax+edi*4]
0074469a         push    eax
0074469b         mov     eax, [ebx+$13]
0074469e         call    -$33e8c3 ($405de0)     ; System.@DynArrayHigh
[...]

date/time         : 2015-11-16, 00:46:06, 718ms
computer name     : AYBHIMXNYAK4SZI
user name         : Administrator <admin>
registered owner  : Sky123.Org / Sky123.Org
operating system  : Windows XP Service Pack 3 (5.1.2600) build 2600
system language   : Chinese
system up time    : 5 hours 19 minutes
program up time   : 1 hour 24 minutes
processors        : 2x AMD Athlon(tm) 64 X2 Dual Core Processor 5000+
physical memory   : 2653/3070 MB (free/total)
free disk space   : (C:) 20.04 GB (L:) 47.35 GB
display mode      : 1440x900, 32 bit
process id        : $cdc
allocated memory  : 16.02 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $5c64617b, $00a91c90, $d97ccf84
exception number  : 1
exception class   : EAccessViolation
exception message : Access violation at address 004231A7 in module 'FlashFXP.exe'. ȡ of address 6F6C632E.

main thread ($10a4):
004231a7 +0063 FlashFXP.exe Graphics            initialization
00423b23 +0013 FlashFXP.exe Graphics            TFont.Destroy
004033e4 +0008 FlashFXP.exe System              TObject.Free
00452024 +0080 FlashFXP.exe Controls            TControl.Destroy
0040375a +0002 FlashFXP.exe System              @ClassDestroy
004243f2 +001e FlashFXP.exe Graphics            TBrush.Destroy
00454ec3 +008b FlashFXP.exe Controls            TWinControl.Destroy
0045a695 +001d FlashFXP.exe Controls            TCustomControl.Destroy
00454ec3 +008b FlashFXP.exe Controls            TWinControl.Destroy
00444f10 +0028 FlashFXP.exe Forms     2259   +3 TScrollingWinControl.Destroy
00445b7f +00b7 FlashFXP.exe Forms     2734  +11 TCustomForm.Destroy
004033e4 +0008 FlashFXP.exe System              TObject.Free
007749f4 +0118 FlashFXP.exe FrmMain1 30122  +26 TFrmMain.FormClose
0044626f +0017 FlashFXP.exe Forms     2933   +1 TCustomForm.DoClose
004496b5 +0055 FlashFXP.exe Forms     4668  +12 TCustomForm.Close
00448b98 +0000 FlashFXP.exe Forms     4297   +0 TCustomForm.WMClose
00453e35 +0111 FlashFXP.exe Controls            TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls            TWinControl.WndProc
00446bcd +0571 FlashFXP.exe Forms     3235 +139 TCustomForm.WndProc
00509afb +003f FlashFXP.exe ThemeMgr            TWindowProcList.DispatchMessage
0050a448 +00dc FlashFXP.exe ThemeMgr            TThemeManager.FormWindowProc
0050b939 +0009 FlashFXP.exe ThemeMgr            TThemeManager.PreFormWindowProc
0045632c +002c FlashFXP.exe Controls            TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms     1529   +8 StdWndProc
7c92e470 +0010 ntdll.dll                        KiUserCallbackDispatcher
77d2f156 +2fd8 user32.dll                       DefWindowProcA
77d2a993 +0016 user32.dll                       CallWindowProcA
004567a7 +00e7 FlashFXP.exe Controls            TWinControl.DefaultHandler
00447e5a +005a FlashFXP.exe Forms     3853   +7 TCustomForm.DefaultHandler
00457dfb +009f FlashFXP.exe Controls            TWinControl.WMSysCommand
00448c77 +0053 FlashFXP.exe Forms     4328   +7 TCustomForm.WMSysCommand
0077dc79 +00ed FlashFXP.exe FrmMain1 32669   +0 TFrmMain.WMSyscommand
00453e35 +0111 FlashFXP.exe Controls            TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls            TWinControl.WndProc
00446bcd +0571 FlashFXP.exe Forms     3235 +139 TCustomForm.WndProc
00509afb +003f FlashFXP.exe ThemeMgr            TWindowProcList.DispatchMessage
0045632c +002c FlashFXP.exe Controls            TWinControl.MainWndProc
00509afb +003f FlashFXP.exe ThemeMgr            TWindowProcList.DispatchMessage
0050a448 +00dc FlashFXP.exe ThemeMgr            TThemeManager.FormWindowProc
0050b939 +0009 FlashFXP.exe ThemeMgr            TThemeManager.PreFormWindowProc
0045632c +002c FlashFXP.exe Controls            TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms     1529   +8 StdWndProc
77d292de +0044 user32.dll                       SendMessageW
77d2f156 +2fd8 user32.dll                       DefWindowProcA
77d2a993 +0016 user32.dll                       CallWindowProcA
004567a7 +00e7 FlashFXP.exe Controls            TWinControl.DefaultHandler
00447e5a +005a FlashFXP.exe Forms     3853   +7 TCustomForm.DefaultHandler
004540d1 +0015 FlashFXP.exe Controls            TControl.WMNCLButtonDown
00448944 +007c FlashFXP.exe Forms     4189  +12 TCustomForm.WMNCLButtonDown
00453e35 +0111 FlashFXP.exe Controls            TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls            TWinControl.WndProc
00446bcd +0571 FlashFXP.exe Forms     3235 +139 TCustomForm.WndProc
00509afb +003f FlashFXP.exe ThemeMgr            TWindowProcList.DispatchMessage
0050a448 +00dc FlashFXP.exe ThemeMgr            TThemeManager.FormWindowProc
0050b939 +0009 FlashFXP.exe ThemeMgr            TThemeManager.PreFormWindowProc
0045632c +002c FlashFXP.exe Controls            TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms     1529   +8 StdWndProc
77d196c2 +000a user32.dll                       DispatchMessageA
0044ca9f +008b FlashFXP.exe Forms     7117  +34 TApplication.ProcessMessage
0044cad6 +000a FlashFXP.exe Forms     7155   +1 TApplication.HandleMessage
0044cd8b +00bf FlashFXP.exe Forms     7259  +26 TApplication.Run
007964ed +1c69 FlashFXP.exe FlashFXP   920 +630 initialization

thread $1344:
7c92df48 +00a ntdll.dll                              NtWaitForMultipleObjects
7c80958a +000 kernel32.dll                           WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll                           WaitForMultipleObjects
00640bd3 +07b FlashFXP.exe UPTShellControls 4370 +13 TChangeHandlerThread.Execute
0041bfc1 +22d FlashFXP.exe Classes                   HexToBin
00404080 +028 FlashFXP.exe System                    ThreadWrapper

thread $4a4:
7c92df48 +00a ntdll.dll                  NtWaitForMultipleObjects
7c80958a +000 kernel32.dll               WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll               WaitForMultipleObjects
00662068 +10c FlashFXP.exe SaveToFileThd TSaveFileWorker.Execute
0041bfc1 +22d FlashFXP.exe Classes       HexToBin
00404080 +028 FlashFXP.exe System        ThreadWrapper

modules:
00400000 FlashFXP.exe           4.0.0.1534       L:\ù߰\flashftp
02990000 Normaliz.dll           6.0.5441.0       C:\WINDOWS\system32
03160000 libeay32.dll           1.0.0.3          L:\ù߰\flashftp
032b0000 ssleay32.dll           1.0.0.3          L:\ù߰\flashftp
10000000 360UDiskGuard.dll      2.0.0.1101       C:\Program Files\360\360Safe\safemon
20db0000 iFlyIMEQuickLaunch.dll                  C:\Program Files\iFly Info Tek\iFlyIME\2.1.1395
3e410000 WININET.dll            8.0.6001.23580   C:\WINDOWS\system32
3eab0000 iertutil.dll           8.0.6001.23580   C:\WINDOWS\system32
43ce0000 urlmon.dll             8.0.6001.23580   C:\WINDOWS\system32
5adc0000 uxtheme.dll            6.0.2900.5512    C:\WINDOWS\system32
5efe0000 olepro32.dll           5.1.2600.5512    C:\WINDOWS\system32
5fdd0000 NETAPI32.dll           5.1.2600.6260    C:\WINDOWS\system32
60fd0000 hnetcfg.dll            5.1.2600.5512    C:\WINDOWS\system32
62c20000 LPK.DLL                5.1.2600.5512    C:\WINDOWS\system32
68000000 rsaenh.dll             5.1.2600.5507    C:\WINDOWS\system32
68100000 dssenh.dll             5.1.2600.5507    C:\WINDOWS\system32
719c0000 mswsock.dll            5.1.2600.5625    C:\WINDOWS\system32
71a00000 wshtcpip.dll           5.1.2600.5512    C:\WINDOWS\System32
71a10000 WS2HELP.dll            5.1.2600.5512    C:\WINDOWS\system32
71a20000 WS2_32.dll             5.1.2600.5512    C:\WINDOWS\system32
71a40000 wsock32.dll            5.1.2600.5512    C:\WINDOWS\system32
72f70000 winspool.drv           5.1.2600.5512    C:\WINDOWS\system32
73640000 msctfime.ime           5.1.2600.5768    C:\WINDOWS\system32
73fa0000 USP10.dll              1.420.2600.6421  C:\WINDOWS\system32
74680000 MSCTF.dll              5.1.2600.5512    C:\WINDOWS\system32
75430000 CRYPTUI.dll            5.131.2600.5512  C:\WINDOWS\system32
759d0000 USERENV.dll            5.1.2600.5512    C:\WINDOWS\system32
75ef0000 browseui.dll           6.0.2900.6254    C:\WINDOWS\system32
76060000 SETUPAPI.dll           5.1.2600.5512    C:\WINDOWS\system32
76300000 IMM32.DLL              5.1.2600.5512    C:\WINDOWS\system32
76320000 comdlg32.dll           6.0.2900.5512    C:\WINDOWS\system32
76570000 CSCDLL.dll             5.1.2600.5512    C:\WINDOWS\System32
76590000 cscui.dll              5.1.2600.5512    C:\WINDOWS\System32
765e0000 crypt32.dll            5.131.2600.6459  C:\WINDOWS\system32
76960000 ntshrui.dll            5.1.2600.5512    C:\WINDOWS\system32
76990000 ole32.dll              5.1.2600.6435    C:\WINDOWS\system32
76af0000 ATL.DLL                3.5.2284.2       C:\WINDOWS\system32
76b10000 winmm.dll              5.1.2600.6160    C:\WINDOWS\system32
76bc0000 psapi.dll              5.1.2600.5512    C:\WINDOWS\system32
76c00000 WINTRUST.dll           5.131.2600.6198  C:\WINDOWS\system32
76c60000 IMAGEHLP.dll           5.1.2600.6479    C:\WINDOWS\system32
76d30000 iphlpapi.dll           5.1.2600.5512    C:\WINDOWS\system32
76d70000 appHelp.dll            5.1.2600.5512    C:\WINDOWS\system32
76db0000 MSASN1.dll             5.1.2600.5875    C:\WINDOWS\system32
76ef0000 DNSAPI.dll             5.1.2600.6089    C:\WINDOWS\system32
76f30000 WLDAP32.dll            5.1.2600.5512    C:\WINDOWS\system32
76f90000 rasadhlp.dll           5.1.2600.5512    C:\WINDOWS\system32
76fa0000 CLBCATQ.DLL            2001.12.4414.700 C:\WINDOWS\system32
77020000 COMRes.dll             2001.12.4414.700 C:\WINDOWS\system32
770f0000 oleaut32.dll           5.1.2600.6341    C:\WINDOWS\system32
77180000 comctl32.dll           6.0.2900.6028    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
77bd0000 version.dll            5.1.2600.5512    C:\WINDOWS\system32
77be0000 msvcrt.dll             7.0.2600.5512    C:\WINDOWS\system32
77d10000 user32.dll             5.1.2600.5512    C:\WINDOWS\system32
77da0000 advapi32.dll           5.1.2600.5755    C:\WINDOWS\system32
77e50000 RPCRT4.dll             5.1.2600.6477    C:\WINDOWS\system32
77ef0000 GDI32.dll              5.1.2600.6460    C:\WINDOWS\system32
77f40000 SHLWAPI.dll            6.0.2900.5912    C:\WINDOWS\system32
77fc0000 Secur32.dll            5.1.2600.5834    C:\WINDOWS\system32
78050000 MSVCP100.dll           10.0.40219.325   C:\WINDOWS\system32
78aa0000 MSVCR100.dll           10.0.40219.325   C:\WINDOWS\system32
7c800000 kernel32.dll           5.1.2600.5781    C:\WINDOWS\system32
7c920000 ntdll.dll              5.1.2600.6055    C:\WINDOWS\system32
7d590000 shell32.dll            6.0.2900.6242    C:\WINDOWS\system32
7e550000 shdocvw.dll            6.0.2900.6254    C:\WINDOWS\system32

processes:
000 Idle              0   0
004 System            0   0   normal
2a0 smss.exe          0   0   normal C:\WINDOWS\system32
2e0 csrss.exe         0   0
300 winlogon.exe      38  14  high   C:\WINDOWS\system32
32c services.exe      4   2   normal C:\WINDOWS\system32
338 lsass.exe         4   1   normal C:\WINDOWS\system32
3fc nvsvc32.exe       8   5   normal C:\WINDOWS\system32
430 svchost.exe       4   1   normal C:\WINDOWS\system32
474 svchost.exe       0   0
4d4 svchost.exe       10  34  normal C:\WINDOWS\System32
594 svchost.exe       0   0
5e8 svchost.exe       0   0
638 zhudongfangyu.exe 4   4   normal C:\Program Files\360\360Safe\deepscan
678 Explorer.EXE      323 234 normal C:\WINDOWS
734 ctfmon.exe        30  14  normal C:\WINDOWS\system32
258 360Tray.exe       246 83  normal C:\Program Files\360\360Safe\safemon
5d4 QQProtect.exe     4   17  normal C:\Program Files\Common Files\Tencent\QQProtect\Bin
9dc alg.exe           0   0
da8 svchost.exe       4   1   normal C:\WINDOWS\System32
fe4 WINWORD.EXE       267 72  normal C:\Program Files\Microsoft Office\Office12
cdc FlashFXP.exe      248 178 normal L:\ù߰\flashftp

hardware:
+ DVD/CD-ROM 
  - PIONEER DVD-RW  DVR-219L
+ IDE ATA/ATAPI 
  - ׼˫ͨ PCI IDE 
  - ׼˫ͨ PCI IDE 
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
+ 
  - AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ (driver 1.3.2.0)
  - AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ (driver 1.3.2.0)
+ 
  - Kingston DT 101 G2 USB Device
  - ST3250310AS
  - WD Elements 1078 USB Device
+ ˿ (COM  LPT)
  - ͨѶ˿ (COM1)
+ 
  - 弴ü
+ 
  - ACPI Multiprocessor PC
+ 
  - ׼ 101/102  Microsoft Ȼ PS/2 
+ ƵϷ
  - NVIDIA High Definition Audio (driver 1.3.26.4)
  - NVIDIA High Definition Audio (driver 1.3.26.4)
  - NVIDIA High Definition Audio (driver 1.3.26.4)
  - NVIDIA High Definition Audio (driver 1.3.26.4)
  - Realtek High Definition Audio (driver 5.10.0.6777)
  - ͳƵ׽豸
  - ͳƵ
  - ý豸
  - Ƶ
  - Ƶ
+ ָ豸
  - PS/2 Compatible Mouse
+ ͨô߿
  - Standard Enhanced PCI to USB Host Controller
  - Standard Enhanced PCI to USB Host Controller
  - Standard OpenHCD USB Host Controller
  - Standard OpenHCD USB Host Controller
  - USB Mass Storage Device
  - USB Mass Storage Device
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
+ 
  - Realtek RTL8139/810x Family Fast Ethernet NIC (driver 5.719.325.2009)
+ ϵͳ豸
  - ACPI Fan
  - ACPI Fixed Feature Button
  - ACPI Power Button
  - ACPI Thermal Zone
  - AMD Low Level Device Driver (driver 1.0.1.0)
  - Direct memory access controller
  - High precision event timer
  - ISAPNP Read Data Port
  - Logical Disk Manager
  - Microcode Update Device
  - Microsoft ACPI-Compliant System
  - Microsoft Composite Battery
  - Microsoft System Management BIOS Driver
  - Microsoft  High Definition Audio  UAA 
  - Microsoft  High Definition Audio  UAA 
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Numeric data processor
  - NVIDIA nForce PCI System Management (driver 4.7.9.0)
  - PCI bus
  - PCI standard host CPU bridge
  - PCI standard host CPU bridge
  - PCI standard host CPU bridge
  - PCI standard host CPU bridge
  - PCI standard ISA bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - PCI standard RAM Controller
  - PCI standard RAM Controller
  - Plug and Play Software Device Enumerator
  - Programmable interrupt controller
  - System board
  - System CMOS/real time clock
  - System speaker
  - System timer
  - Terminal Server Device Redirector
  - Terminal Server Keyboard Driver
  - Terminal Server Mouse Driver
  - Volume Manager
  - ̨ȫʾƵ
+ ʾ
  - NVIDIA GeForce GT 220 (driver 6.14.12.7061)

cpu registers:
eax = 6f6c632e
ebx = 02d89901
ecx = 00000000
edx = 6f6c632e
esi = 02d97a50
edi = 007bdbb4
eip = 004231a7
esp = 0012ef50
ebp = 0012ef6c

stack dump:
0012ef50  ec ef 12 00 ac 3a 40 00 - 6c ef 12 00 d0 11 db 02  .....:@.l.......
0012ef60  a6 33 40 01 d0 11 db 02 - 38 8f fa 00 00 f0 12 00  .3@.....8.......
0012ef70  28 3b 42 00 f0 6e f6 00 - f0 6e f6 00 e7 33 40 00  (;B..n...n...3@.
0012ef80  29 20 45 00 00 07 d0 02 - 01 00 00 00 5d 37 40 00  ).E.........]7@.
0012ef90  f7 43 42 00 f0 6e f6 00 - f0 6e f6 00 f0 6e f6 00  .CB..n...n...n..
0012efa0  f8 4e 45 00 01 76 43 00 - f0 6e f6 00 e0 74 ea 00  .NE..vC..n...t..
0012efb0  c6 4e 45 00 00 d4 f5 00 - e0 74 ea 00 01 00 00 00  .NE......t......
0012efc0  9a a6 45 00 e0 74 ea 00 - 90 8c f2 00 c6 4e 45 00  ..E..t.......NE.
0012efd0  00 bb f3 00 90 8c f2 00 - 00 99 d8 02 15 4f 44 00  .............OD.
0012efe0  ac 8a 7b 00 01 00 00 00 - 84 5b 44 00 0c f0 12 00  ..{......[D.....
0012eff0  ac 3a 40 00 00 f0 12 00 - 44 f1 12 01 90 8c f2 00  .:@.....D.......
0012f000  44 f1 12 00 e7 33 40 00 - f9 49 77 00 04 f3 12 00  D....3@..Iw.....
0012f010  ac 3a 40 00 44 f1 12 00 - 34 f3 12 00 00 8c f0 00  .:@.D...4.......
0012f020  00 8c f0 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0012f030  fc ef 12 00 88 f0 12 00 - 8f 04 d4 77 30 88 d1 77  ...........w0..w
0012f040  ff ff ff ff 2a 88 d1 77 - a0 8e d2 77 00 00 00 00  ....*..w...w....
0012f050  d5 0f 00 01 a2 01 33 00 - 0a 00 00 00 ff ff ff ff  ......3.........
0012f060  00 00 00 00 1c 30 b1 00 - ab 8e d2 77 34 f3 12 00  .....0.....w4...
0012f070  00 8c f0 00 00 8c f0 00 - 00 8c f0 00 00 00 00 00  ................
0012f080  6c f0 12 00 70 f0 12 00 - 10 f1 12 00 8f 04 d4 77  l...p..........w

disassembling:
00444ee8      public Forms.TScrollingWinControl.Destroy:  ; function entry point
00444ee8 2256   push    ebx
00444ee9        push    esi
00444eea        call    -$41787 ($403768)      ; System.@BeforeDestruction
00444eef        mov     ebx, edx
00444ef1        mov     esi, eax
00444ef3 2257   mov     eax, [esi+$1ec]
00444ef9        call    -$41b22 ($4033dc)      ; System.TObject.Free
00444efe 2258   mov     eax, [esi+$1f0]
00444f04        call    -$41b2d ($4033dc)      ; System.TObject.Free
00444f09 2259   mov     edx, ebx
00444f0b        and     dl, -4
00444f0e        mov     eax, esi
00444f10      > call    +$ff23 ($454e38)       ; Controls.TWinControl.Destroy
00444f15        test    bl, bl
00444f17        jle     loc_444f20
00444f19        mov     eax, esi
00444f1b        call    -$417c8 ($403758)      ; System.@ClassDestroy
00444f20 2260   pop     esi
00444f21        pop     ebx
00444f22        ret

date/time         : 2016-01-08, 18:58:36, 218ms
computer name     : MFFJBFG1BBOASEZ
user name         : Administrator <admin>
registered owner  : ΢û / ΢й
operating system  : Windows XP Service Pack 3 (5.1.2600) build 2600
system language   : Chinese
system up time    : 5 hours 15 minutes
program up time   : 3 hours 27 minutes
processors        : 2x Pentium(R) Dual-Core CPU E5300 @ 2.60GHz
physical memory   : 1726/3327 MB (free/total)
free disk space   : (C:) 24.10 GB (K:) 8.39 GB
display mode      : 1440x900, 32 bit
process id        : $784
allocated memory  : 81.26 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $eb093fce, $79d4e878, $cb32b37c
exception number  : 1
exception class   : EAccessViolation
exception message : Access violation at address 004CFD49 in module 'FlashFXP.exe'. ȡ of address 0000002C.

main thread ($1288):
004cfd49 +0035 FlashFXP.exe IniFiles32    937   +7 TIniFile32.ReadString
004d0da6 +0032 FlashFXP.exe IniFiles32   1310   +2 TIniFile32.ValueExists
006e0b7d +0069 FlashFXP.exe SiteManager  3280   +4 TFrmSite.TreeSiteBeforeItemPaint
005072c7 +05f7 FlashFXP.exe TreeNT                 TCustomTreeNT.CNNotify
00453e35 +0111 FlashFXP.exe Controls               TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls               TWinControl.WndProc
00507799 +004d FlashFXP.exe TreeNT                 TCustomTreeNT.WndProc
00453c64 +0024 FlashFXP.exe Controls               TControl.Perform
00456823 +0023 FlashFXP.exe Controls               TWinControl.DefaultHandler
00456d81 +000d FlashFXP.exe Controls               TWinControl.WMNotify
00453e35 +0111 FlashFXP.exe Controls               TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls               TWinControl.WndProc
00507799 +004d FlashFXP.exe TreeNT                 TCustomTreeNT.WndProc
00453c64 +0024 FlashFXP.exe Controls               TControl.Perform
00453e35 +0111 FlashFXP.exe Controls               TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls               TWinControl.WndProc
0045632c +002c FlashFXP.exe Controls               TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms        1529   +8 StdWndProc
77d292de +0044 user32.dll                          SendMessageW
77d2a993 +0016 user32.dll                          CallWindowProcA
004567a7 +00e7 FlashFXP.exe Controls               TWinControl.DefaultHandler
00453e35 +0111 FlashFXP.exe Controls               TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls               TWinControl.WndProc
00507799 +004d FlashFXP.exe TreeNT                 TCustomTreeNT.WndProc
0045632c +002c FlashFXP.exe Controls               TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms        1529   +8 StdWndProc
77d2f406 +0044 user32.dll                          SendMessageA
0042c5d7 +000f FlashFXP.exe Commctrl               TreeView_SetItem
00502e9e +0032 FlashFXP.exe TreeNT                 TTreeNTNode.SetText
005045f8 +0020 FlashFXP.exe TreeNT                 TTreeNTNode.Assign
005040f9 +0141 FlashFXP.exe TreeNT                 TTreeNTNode.InternalMove
005042a9 +0159 FlashFXP.exe TreeNT                 TTreeNTNode.MoveTo
006dabfc +0298 FlashFXP.exe SiteManager  1623  +40 TFrmSite.LoadSites
006da7fd +28d9 FlashFXP.exe SiteManager  1572 +428 TFrmSite.FormCreate
00445be9 +0031 FlashFXP.exe Forms        2744   +3 TCustomForm.DoCreate
0044592d +0009 FlashFXP.exe Forms        2680   +0 TCustomForm.AfterConstruction
00403763 +0003 FlashFXP.exe System                 @AfterConstruction
0044590d +0171 FlashFXP.exe Forms        2674  +16 TCustomForm.Create
00727b96 +005a FlashFXP.exe FrmMain1     2830   +8 TFrmMain.CreateWindowShow
00739c2f +0093 FlashFXP.exe FrmMain1     9912  +20 TFrmMain.SM1Click
00461047 +008f FlashFXP.exe Menus                  TMenuItem.Click
004621bf +0013 FlashFXP.exe Menus                  TMenu.DispatchCommand
004489cb +001f FlashFXP.exe Forms        4206   +2 TCustomForm.WMCommand
00453e35 +0111 FlashFXP.exe Controls               TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls               TWinControl.WndProc
00446bcd +0571 FlashFXP.exe Forms        3235 +139 TCustomForm.WndProc
00509afb +003f FlashFXP.exe ThemeMgr               TWindowProcList.DispatchMessage
0050a448 +00dc FlashFXP.exe ThemeMgr               TThemeManager.FormWindowProc
0050b939 +0009 FlashFXP.exe ThemeMgr               TThemeManager.PreFormWindowProc
0045632c +002c FlashFXP.exe Controls               TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms        1529   +8 StdWndProc
77d196c2 +000a user32.dll                          DispatchMessageA
0044ca9f +008b FlashFXP.exe Forms        7117  +34 TApplication.ProcessMessage
0044cabe +000a FlashFXP.exe Forms        7148   +1 TApplication.ProcessMessages
00769dbe +0902 FlashFXP.exe FrmMain1    26583 +206 TFrmMain.FormDestroy
00445c5d +0031 FlashFXP.exe Forms        2755   +3 TCustomForm.DoDestroy
00445ac1 +005d FlashFXP.exe Forms        2719   +7 TCustomForm.BeforeDestruction
00403771 +0009 FlashFXP.exe System                 @BeforeDestruction
00445ace +0006 FlashFXP.exe Forms        2723   +0 TCustomForm.Destroy
004033e4 +0008 FlashFXP.exe System                 TObject.Free
0041c349 +0019 FlashFXP.exe Classes                TComponent.Remove
0041c40a +001e FlashFXP.exe Classes                TComponent.DestroyComponents
004436ab +002f FlashFXP.exe Forms        1261   +3 DoneApplication
0040a9b6 +0026 FlashFXP.exe SysUtils               DoExitProc
00403f50 +0028 FlashFXP.exe System                 @Halt0
00796548 +1cc4 FlashFXP.exe FlashFXP      939 +649 initialization

thread $400:
7c92df48 +00a ntdll.dll                              NtWaitForMultipleObjects
7c80958a +000 kernel32.dll                           WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll                           WaitForMultipleObjects
00640bd3 +07b FlashFXP.exe UPTShellControls 4370 +13 TChangeHandlerThread.Execute
0041bfc1 +22d FlashFXP.exe Classes                   HexToBin
00404080 +028 FlashFXP.exe System                    ThreadWrapper

thread $32c:
7c92df48 +00a ntdll.dll                  NtWaitForMultipleObjects
7c80958a +000 kernel32.dll               WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll               WaitForMultipleObjects
00662068 +10c FlashFXP.exe SaveToFileThd TSaveFileWorker.Execute
0041bfc1 +22d FlashFXP.exe Classes       HexToBin
00404080 +028 FlashFXP.exe System        ThreadWrapper

thread $1bac:
7c92daa8 +a ntdll.dll  NtReplyWaitReceivePortEx

thread $1a34:
7c92df58 +0a ntdll.dll     NtWaitForSingleObject
7c8025d5 +85 kernel32.dll  WaitForSingleObjectEx
7c80253d +0d kernel32.dll  WaitForSingleObject

thread $1a08:
7c92d218 +a ntdll.dll  NtDelayExecution

modules:
00400000 FlashFXP.exe          4.0.0.1534       K:\ù߰\flashftp
02a80000 Normaliz.dll          6.0.5441.0       C:\WINDOWS\system32
031e0000 libeay32.dll          1.0.0.3          K:\ù߰\flashftp
03330000 ssleay32.dll          1.0.0.3          K:\ù߰\flashftp
03c90000 xpsp2res.dll          5.1.2600.5512    C:\WINDOWS\system32
044e0000 GOOGLEPINYIN2.IME     2.7.25.128       C:\WINDOWS\system32
07160000 Audiodev.dll          5.2.5721.5262    C:\WINDOWS\system32
10000000 360UDiskGuard.dll     2.0.0.1101       C:\Program Files\360\360Safe\safemon
10930000 PortableDeviceApi.dll 5.2.5721.5262    C:\WINDOWS\system32
11c70000 WMASF.DLL             11.0.5721.5262   C:\WINDOWS\system32
15110000 WMVCore.DLL           11.0.5721.5275   C:\WINDOWS\system32
16500000 wpdshext.dll          5.2.5721.5262    C:\WINDOWS\system32
1f840000 odbcint.dll           3.525.1117.0     C:\WINDOWS\system32
3e410000 WININET.dll           8.0.6001.23580   C:\WINDOWS\system32
3eab0000 iertutil.dll          8.0.6001.23580   C:\WINDOWS\system32
3eca0000 ieframe.dll           8.0.6001.23580   C:\WINDOWS\system32
43ce0000 urlmon.dll            8.0.6001.23580   C:\WINDOWS\system32
4ae90000 gdiplus.dll           5.2.6002.23084   C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.23084_x-ww_f3f35550
5a540000 wiashext.dll          5.1.2600.5512    C:\WINDOWS\system32
5adc0000 uxtheme.dll           6.0.2900.5512    C:\WINDOWS\system32
5dd50000 msxml3.dll            8.100.1054.0     C:\WINDOWS\system32
5efe0000 olepro32.dll          5.1.2600.5512    C:\WINDOWS\system32
5fdd0000 NETAPI32.dll          5.1.2600.6260    C:\WINDOWS\system32
60fd0000 hnetcfg.dll           5.1.2600.5512    C:\WINDOWS\system32
62c20000 LPK.DLL               5.1.2600.5512    C:\WINDOWS\system32
68000000 rsaenh.dll            5.1.2600.5507    C:\WINDOWS\system32
68100000 dssenh.dll            5.1.2600.5507    C:\WINDOWS\system32
68d60000 dbghelp.dll           5.1.2600.5512    C:\WINDOWS\system32
6bd10000 msohevi.dll           12.0.4518.1014   C:\Program Files\Microsoft Office\Office12
719c0000 mswsock.dll           5.1.2600.5625    C:\WINDOWS\System32
71a00000 wshtcpip.dll          5.1.2600.5512    C:\WINDOWS\System32
71a10000 WS2HELP.dll           5.1.2600.5512    C:\WINDOWS\system32
71a20000 WS2_32.dll            5.1.2600.5512    C:\WINDOWS\system32
71a40000 wsock32.dll           5.1.2600.5512    C:\WINDOWS\system32
71a90000 MPR.dll               5.1.2600.5512    C:\WINDOWS\system32
71b70000 SAMLIB.dll            5.1.2600.5512    C:\WINDOWS\System32
71b90000 ntlanman.dll          5.1.2600.5512    C:\WINDOWS\System32
71c00000 NETRAP.dll            5.1.2600.5512    C:\WINDOWS\System32
71c10000 NETUI1.dll            5.1.2600.5512    C:\WINDOWS\System32
71c50000 NETUI0.dll            5.1.2600.5512    C:\WINDOWS\System32
72f70000 winspool.drv          5.1.2600.5512    C:\WINDOWS\system32
73540000 ODBC32.dll            3.525.3012.0     C:\WINDOWS\system32
73640000 msctfime.ime          5.1.2600.5768    C:\WINDOWS\system32
73b10000 sti.dll               5.1.2600.5512    C:\WINDOWS\system32
73ce0000 shgina.dll            6.0.2900.5512    C:\WINDOWS\system32
73fa0000 USP10.dll             1.420.2600.6421  C:\WINDOWS\system32
74680000 MSCTF.dll             5.1.2600.5512    C:\WINDOWS\system32
74a40000 CFGMGR32.dll          5.1.2600.5512    C:\WINDOWS\system32
75430000 CRYPTUI.dll           5.131.2600.5512  C:\WINDOWS\system32
758d0000 MSGINA.dll            5.1.2600.5512    C:\WINDOWS\system32
759d0000 USERENV.dll           5.1.2600.5512    C:\WINDOWS\system32
75ed0000 drprov.dll            5.1.2600.5512    C:\WINDOWS\System32
75ee0000 davclnt.dll           5.1.2600.5512    C:\WINDOWS\System32
75ef0000 browseui.dll          6.0.2900.6254    C:\WINDOWS\system32
76060000 SETUPAPI.dll          5.1.2600.5512    C:\WINDOWS\system32
762d0000 WINSTA.dll            5.1.2600.5512    C:\WINDOWS\system32
762f0000 MSIMG32.dll           5.1.2600.5512    C:\WINDOWS\system32
76300000 IMM32.DLL             5.1.2600.5512    C:\WINDOWS\system32
76320000 comdlg32.dll          6.0.2900.5512    C:\WINDOWS\system32
76570000 CSCDLL.dll            5.1.2600.5512    C:\WINDOWS\System32
76590000 cscui.dll             5.1.2600.5512    C:\WINDOWS\System32
765e0000 crypt32.dll           5.131.2600.6459  C:\WINDOWS\system32
76950000 LINKINFO.dll          5.1.2600.5512    C:\WINDOWS\system32
76960000 ntshrui.dll           5.1.2600.5512    C:\WINDOWS\system32
76990000 ole32.dll             5.1.2600.6435    C:\WINDOWS\system32
76af0000 ATL.DLL               3.5.2284.2       C:\WINDOWS\system32
76b10000 winmm.dll             5.1.2600.6160    C:\WINDOWS\system32
76bc0000 psapi.dll             5.1.2600.5512    C:\WINDOWS\system32
76c00000 WINTRUST.dll          5.131.2600.6198  C:\WINDOWS\system32
76c60000 IMAGEHLP.dll          5.1.2600.6479    C:\WINDOWS\system32
76d30000 iphlpapi.dll          5.1.2600.5512    C:\WINDOWS\system32
76d70000 appHelp.dll           5.1.2600.5512    C:\WINDOWS\system32
76db0000 MSASN1.dll            5.1.2600.5875    C:\WINDOWS\system32
76ef0000 DNSAPI.dll            5.1.2600.6089    C:\WINDOWS\system32
76f30000 WLDAP32.dll           5.1.2600.5512    C:\WINDOWS\system32
76f80000 winrnr.dll            5.1.2600.5512    C:\WINDOWS\System32
76f90000 rasadhlp.dll          5.1.2600.5512    C:\WINDOWS\system32
76fa0000 CLBCATQ.DLL           2001.12.4414.700 C:\WINDOWS\system32
77020000 COMRes.dll            2001.12.4414.700 C:\WINDOWS\system32
770f0000 oleaut32.dll          5.1.2600.6341    C:\WINDOWS\system32
77180000 comctl32.dll          6.0.2900.6028    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
77bd0000 version.dll           5.1.2600.5512    C:\WINDOWS\system32
77be0000 msvcrt.dll            7.0.2600.5512    C:\WINDOWS\system32
77d10000 user32.dll            5.1.2600.5512    C:\WINDOWS\system32
77da0000 advapi32.dll          5.1.2600.5755    C:\WINDOWS\system32
77e50000 RPCRT4.dll            5.1.2600.6477    C:\WINDOWS\system32
77ef0000 GDI32.dll             5.1.2600.6460    C:\WINDOWS\system32
77f40000 SHLWAPI.dll           6.0.2900.5912    C:\WINDOWS\system32
77fc0000 Secur32.dll           5.1.2600.5834    C:\WINDOWS\system32
78130000 MSVCR80.dll           8.0.50727.6195   C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86
7c800000 kernel32.dll          5.1.2600.5781    C:\WINDOWS\system32
7c920000 ntdll.dll             5.1.2600.6055    C:\WINDOWS\system32
7d590000 shell32.dll           6.0.2900.6242    C:\WINDOWS\system32
7e550000 shdocvw.dll           6.0.2900.6254    C:\WINDOWS\system32

processes:
0000 Idle                   0   0
0004 System                 0   0   normal
01c0 smss.exe               0   0   normal       C:\WINDOWS\system32
01f0 csrss.exe              0   0
0210 winlogon.exe           45  14  high         C:\WINDOWS\system32
0248 services.exe           4   2   normal       C:\WINDOWS\system32
0254 lsass.exe              6   4   normal       C:\WINDOWS\system32
0304 svchost.exe            4   2   normal       C:\WINDOWS\system32
0330 svchost.exe            0   0
0374 svchost.exe            10  30  normal       C:\WINDOWS\System32
039c svchost.exe            4   1   normal       C:\WINDOWS\system32
0444 svchost.exe            0   0
0450 svchost.exe            4   2   normal       C:\WINDOWS\System32
04a8 svchost.exe            0   0
04c0 zhudongfangyu.exe      4   2   normal       C:\Program Files\360\360Safe\deepscan
04e8 svchost.exe            4   2   normal       C:\WINDOWS\System32
05ec WPService.exe          8   3   normal       C:\Program Files\CMBCHINA\WebProtect
0608 DhMachineSvc.exe       4   3   normal       C:\Program Files\Microsoft Device Health
0624 DhPluginMgr.exe        4   5   normal       C:\Program Files\Microsoft Device Health\PluginManager
065c inetinfo.exe           4   7   normal       C:\WINDOWS\system32\inetsrv
0674 sqlservr.exe           4   1   normal       C:\Program Files\Microsoft SQL Server\MSSQL\Binn
06e0 mysqld.exe             4   2   normal       C:\mysql\bin
0718 pcas.exe               4   3   normal       C:\Program Files\alipay\aliedit\5.3.0.3807
0148 secbizsrv.exe          4   6   normal       C:\Program Files\alipay\aliedit\5.3.0.3807
0160 svchost.exe            4   2   normal       C:\WINDOWS\system32
0178 TeamViewer_Service.exe 4   4   normal       C:\Program Files\TeamViewer
0908 alg.exe                0   0
0ac0 Explorer.EXE           297 229 normal       C:\WINDOWS
0b18 360Tray.exe            265 82  normal       C:\Program Files\360\360Safe\safemon
0b20 ctfmon.exe             101 46  normal       C:\WINDOWS\system32
0b30 360sd.exe              469 214 normal       C:\Program Files\360\360sd
0b84 PalmInputGuard.exe     8   4   normal       C:\Program Files\PalmInput\Extensions\Guard\1.5.0.12
0c20 aliwssv.exe            4   1   normal       C:\Program Files\alipay\aliedit\5.3.0.3807
0d94 RunDll32.exe           17  11  normal       C:\WINDOWS\system32
0ff0 360rp.exe              7   3   normal       C:\Program Files\360\360sd
01e8 QQ.exe                 224 182 normal       D:\ù\Ѷ\Bin
06d0 TXPlatform.exe         8   6   normal       D:\ù\Ѷ\Bin
0b38 QQ.exe                 146 154 normal       D:\ù\Ѷ\Bin
07e0 QQ.exe                 145 157 normal       D:\ù\Ѷ\Bin
0e1c AndroidServer.exe      13  18  normal       C:\Documents and Settings\Administrator\Application Data\Tencent\AndroidServer\1.0.0.509
1690 360se.exe              764 174 normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
167c 360se.exe              10  1   normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
0f70 360se.exe              11  11  normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
149c BaiduYunGuanjia.exe    122 99  normal       C:\Program Files\baidu\BaiduYunGuanjia
119c conime.exe             15  9   normal       C:\WINDOWS\system32
1714 360se.exe              616 2   normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
0e18 dllhost.exe            0   0
1464 dllhost.exe            4   3   normal       C:\WINDOWS\system32
1778 360se.exe              18  79  normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
1138 360MobileMgr.exe       684 205 normal       C:\Program Files\360\360Safe\mobilemgr
0db4 360MobileLink.exe      157 26  normal       C:\Program Files\360\360Safe\mobilemgr
0784 FlashFXP.exe           315 374 normal       K:\ù߰\flashftp
04b8 360se.exe              28  1   below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
06c0 mstsc.exe              186 111 normal       C:\WINDOWS\system32
08f0 360se.exe              256 2   below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
1cf8 PalmInputService.exe   8   4   normal       C:\Program Files\PalmInput\1.9.0.840
1e70 360se.exe              691 2   below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
12d0 360se.exe              135 73  below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application

hardware:
+ Android Phone
  - Android Composite ADB Interface (driver 4.0.0.0)
+ IDE ATA/ATAPI 
  - Intel(R) N10/ICH7 Family Serial ATA Storage Controller - 27C0 (driver 9.1.1.1016)
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
+ 
  - Pentium(R) Dual-Core  CPU      E5300  @ 2.60GHz
  - Pentium(R) Dual-Core  CPU      E5300  @ 2.60GHz
+ 
  - ST500DM002-1BD142
  - WD Elements 1078 USB Device
+ 
  - 弴ü
+ 
  - ACPI Multiprocessor PC
+ 
  - ׼ 101/102  Microsoft Ȼ PS/2 
+ ƵϷ
  - Realtek High Definition Audio (driver 5.10.0.6449)
  - ͳƵ׽豸
  - ͳƵ
  - ý豸
  - Ƶ
  - Ƶ
+ ָ豸
  - Microsoft PS/2 Mouse
+ ͨô߿
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C9 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CA (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CB (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB2 Enhanced Host Controller - 27CC (driver 9.1.1.1016)
  - USB Mass Storage Device
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
+ 
  - Realtek PCIe FE Family Controller (driver 5.788.613.2011)
+ ϵͳ豸
  - ACPI Fixed Feature Button
  - ACPI Power Button
  - ACPI Thermal Zone
  - Direct memory access controller
  - Intel(R) 4 Series Chipset PCI Express Root Port - 2E31 (driver 9.1.0.1012)
  - Intel(R) 4 Series Chipset Processor to I/O Controller - 2E30 (driver 9.1.0.1012)
  - Intel(R) 82801BA/CA PCI Bridge - 244E (driver 3.30.1002.0)
  - Intel(R) 82802 Firmware Hub Device
  - Intel(R) ICH7 Family LPC Interface Controller - 27B8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family PCI Express Root Port - 27D0 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family PCI Express Root Port - 27D2 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family SMBus Controller - 27DA (driver 9.1.1.1016)
  - ISAPNP Read Data Port
  - Logical Disk Manager
  - Microcode Update Device
  - Microsoft ACPI-Compliant System
  - Microsoft Composite Battery
  - Microsoft System Management BIOS Driver
  - Microsoft  High Definition Audio  UAA 
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Numeric data processor
  - PCI bus
  - Plug and Play Software Device Enumerator
  - Programmable interrupt controller
  - System board
  - System board
  - System CMOS/real time clock
  - System speaker
  - System timer
  - Terminal Server Device Redirector
  - Terminal Server Keyboard Driver
  - Terminal Server Mouse Driver
  - Volume Manager
  - ̨ȫʾƵ
+ ʾ
  - NVIDIA GeForce 9500 GT (driver 6.14.12.6658)

cpu registers:
eax = 0012ec58
ebx = 00000000
ecx = 00000000
edx = 00000000
esi = 006e0bc0
edi = 02e898a8
eip = 004cfd49
esp = 0012ec08
ebp = 0012ec30

stack dump:
0012ec08  40 ec 12 00 ac 3a 40 00 - 30 ec 12 00 a8 98 e8 02  @....:@.0.......
0012ec18  c0 0b 6e 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ..n.............
0012ec28  00 00 00 00 a8 98 e8 02 - 5c ec 12 00 ab 0d 4d 00  ........\.....M.
0012ec38  58 ec 12 00 ec 0d 4d 00 - 64 ec 12 00 ac 3a 40 00  X.....M.d....:@.
0012ec48  5c ec 12 00 90 ec 12 00 - b0 8f f2 02 a0 bd f3 00  \...............
0012ec58  00 00 00 00 90 ec 12 00 - 82 0b 6e 00 a4 ec 12 00  ..........n.....
0012ec68  ac 3a 40 00 90 ec 12 00 - a0 bd f3 00 90 8c f2 00  .:@.............
0012ec78  90 8c f2 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0012ec88  00 00 00 00 00 00 00 00 - f0 ec 12 00 cd 72 50 00  .............rP.
0012ec98  e3 ec 12 00 00 00 12 00 - 0c f2 12 00 c8 ef 12 00  ................
0012eca8  ac 3a 40 00 f0 ec 12 00 - 90 8c f2 00 4c ee 12 00  .:@.........L...
0012ecb8  90 8c f2 00 90 8c f2 00 - 00 00 00 00 00 00 00 00  ................
0012ecc8  00 00 00 00 f8 f1 12 00 - f8 f1 12 00 0c 11 00 00  ................
0012ecd8  fe 05 0f 00 fe 05 0f 00 - 1d 00 00 00 00 00 00 00  ................
0012ece8  18 36 00 00 4c ee 12 00 - 34 ee 12 00 38 3e 45 00  .6..L...4...8>E.
0012ecf8  90 8c f2 00 4c ee 12 00 - 90 8c f2 00 a7 66 45 00  ....L........fE.
0012ed08  90 8c f2 00 4c ee 12 00 - 90 8c f2 00 90 8c f2 00  ....L...........
0012ed18  28 ed 12 00 00 00 00 00 - 50 b5 f9 00 ee 52 50 00  (.......P....RP.
0012ed28  04 00 00 00 30 09 1a 00 - 00 00 00 00 3e ee 12 00  ....0.......>...
0012ed38  00 00 00 00 00 00 02 00 - 00 fc fd 7f fc f0 12 00  ................

disassembling:
004cfd14     public IniFiles32.TIniFile32.ReadString:  ; function entry point
004cfd14 930   push    ebp
004cfd15       mov     ebp, esp
004cfd17       push    0
004cfd19       push    0
004cfd1b       push    0
004cfd1d       push    0
004cfd1f       push    ebx
004cfd20       push    esi
004cfd21       push    edi
004cfd22       mov     [ebp-4], ecx
004cfd25       mov     esi, edx
004cfd27       mov     ebx, eax
004cfd29       xor     eax, eax
004cfd2b       push    ebp
004cfd2c       push    $4cfe27                ; System.@HandleFinally
004cfd31       push    dword ptr fs:[eax]
004cfd34       mov     fs:[eax], esp
004cfd37 935   mov     eax, ebx
004cfd39       call    +$118e ($4d0ecc)       ; IniFiles32.TIniFile32.Reload
004cfd3e 936   mov     eax, [ebp+8]
004cfd41       mov     edx, [ebp+$c]
004cfd44       call    -$cbbd5 ($404174)      ; System.@LStrLAsg
004cfd49 937 > mov     eax, [ebx+$2c]
004cfd4c       mov     edx, [eax]
004cfd4e       call    dword ptr [edx+$14]
004cfd51       test    eax, eax
004cfd53       jle     loc_4cfe0c
004cfd59 939   mov     edx, esi
004cfd5b       mov     eax, ebx
004cfd5d       call    -$f56 ($4cee0c)        ; IniFiles32.TIniFile32.GetSectionIndex
004cfd62       mov     esi, eax
004cfd64 940   cmp     esi, -1
004cfd67       jz      loc_4cfe0c
004cfd6d 942   inc     esi
004cfd6e       jmp     loc_4cfde1
004cfd70 945   lea     ecx, [ebp-$c]
004cfd73       mov     edx, esi
004cfd75       mov     eax, [ebx+$2c]
004cfd78       mov     edi, [eax]
004cfd7a       call    dword ptr [edi+$c]
004cfd7d       mov     edx, [ebp-$c]
004cfd80       lea     ecx, [ebp-$10]
004cfd83       mov     eax, ebx
[...]

date/time         : 2016-01-30, 15:43:51, 93ms
computer name     : MFFJBFG1BBOASEZ
user name         : Administrator <admin>
registered owner  : ΢û / ΢й
operating system  : Windows XP Service Pack 3 (5.1.2600) build 2600
system language   : Chinese
system up time    : 1 hour 31 minutes
program up time   : 1 hour 25 minutes
processors        : 2x Pentium(R) Dual-Core CPU E5300 @ 2.60GHz
physical memory   : 2246/3327 MB (free/total)
free disk space   : (C:) 24.52 GB (K:) 7.72 GB
display mode      : 1440x900, 32 bit
process id        : $4a8
allocated memory  : 22.74 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $964a04ba, $f25e119b, $0eeb3f9c
exception number  : 1
exception class   : EAccessViolation
exception message : Access violation at address 00408E0F in module 'FlashFXP.exe'. ȡ of address 0A0D7D64.

main thread ($8e8):
00408e0f +0037 FlashFXP.exe FastMM4             FastGetMem
004029f8 +0004 FlashFXP.exe System              @GetMem
00403374 +0004 FlashFXP.exe System              TObject.NewInstance
0040370f +0007 FlashFXP.exe System              @ClassCreate
0045ec4d +000d FlashFXP.exe Menus               TMenuItem.Create
00742aea +04d6 FlashFXP.exe FrmMain1 12944 +114 TFrmMain.BuildMenuList
007627b5 +01d9 FlashFXP.exe FrmMain1 23920  +40 TFrmMain.PopSitePopup
004636fd +000d FlashFXP.exe Menus               TPopupMenu.DoPopup
004637da +0032 FlashFXP.exe Menus               TPopupMenu.Popup
004fc0f6 +0246 FlashFXP.exe ComCtrls            TToolBar.CheckMenuDropdown
004f8b8d +0039 FlashFXP.exe ComCtrls            TToolButton.CheckMenuDropdown
004fb522 +0036 FlashFXP.exe ComCtrls            TToolBar.CNNotify
00453e35 +0111 FlashFXP.exe Controls            TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls            TWinControl.WndProc
004fb881 +0231 FlashFXP.exe ComCtrls            TToolBar.WndProc
0045632c +002c FlashFXP.exe Controls            TWinControl.MainWndProc
00509afb +003f FlashFXP.exe ThemeMgr            TWindowProcList.DispatchMessage
0050b8f4 +01b8 FlashFXP.exe ThemeMgr            TThemeManager.WinControlWindowProc
0050b9c9 +0009 FlashFXP.exe ThemeMgr            TThemeManager.PreWinControlWindowProc
00453c64 +0024 FlashFXP.exe Controls            TControl.Perform
00453e35 +0111 FlashFXP.exe Controls            TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls            TWinControl.WndProc
004fb881 +0231 FlashFXP.exe ComCtrls            TToolBar.WndProc
00509afb +003f FlashFXP.exe ThemeMgr            TWindowProcList.DispatchMessage
0050b8f4 +01b8 FlashFXP.exe ThemeMgr            TThemeManager.WinControlWindowProc
0050b9c9 +0009 FlashFXP.exe ThemeMgr            TThemeManager.PreWinControlWindowProc
0045632c +002c FlashFXP.exe Controls            TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms     1529   +8 StdWndProc
77d2f406 +0044 user32.dll                       SendMessageA
00509afb +003f FlashFXP.exe ThemeMgr            TWindowProcList.DispatchMessage
0050b8f4 +01b8 FlashFXP.exe ThemeMgr            TThemeManager.WinControlWindowProc
0050b9c9 +0009 FlashFXP.exe ThemeMgr            TThemeManager.PreWinControlWindowProc
0045632c +002c FlashFXP.exe Controls            TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms     1529   +8 StdWndProc
77d196c2 +000a user32.dll                       DispatchMessageA
0044ca9f +008b FlashFXP.exe Forms     7117  +34 TApplication.ProcessMessage
0044cad6 +000a FlashFXP.exe Forms     7155   +1 TApplication.HandleMessage
0044cd8b +00bf FlashFXP.exe Forms     7259  +26 TApplication.Run
007964ed +1c69 FlashFXP.exe FlashFXP   920 +630 initialization

thread $70:
7c92df48 +00a ntdll.dll                              NtWaitForMultipleObjects
7c80958a +000 kernel32.dll                           WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll                           WaitForMultipleObjects
00640bd3 +07b FlashFXP.exe UPTShellControls 4370 +13 TChangeHandlerThread.Execute
0041bfc1 +22d FlashFXP.exe Classes                   HexToBin
00404080 +028 FlashFXP.exe System                    ThreadWrapper

thread $1538:
7c92df48 +00a ntdll.dll                  NtWaitForMultipleObjects
7c80958a +000 kernel32.dll               WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll               WaitForMultipleObjects
00662068 +10c FlashFXP.exe SaveToFileThd TSaveFileWorker.Execute
0041bfc1 +22d FlashFXP.exe Classes       HexToBin
00404080 +028 FlashFXP.exe System        ThreadWrapper

thread $139c: <priority:1>
7c92da48 +a ntdll.dll  NtRemoveIoCompletion

thread $16f0:
7c92daa8 +a ntdll.dll  NtReplyWaitReceivePortEx

modules:
00400000 FlashFXP.exe          4.0.0.1534       K:\ù߰\flashftp
02c60000 Normaliz.dll          6.0.5441.0       C:\WINDOWS\system32
033c0000 libeay32.dll          1.0.0.3          K:\ù߰\flashftp
03510000 ssleay32.dll          1.0.0.3          K:\ù߰\flashftp
03ae0000 rarext.dll            5.30.0.0         C:\Program Files\WinRAR
03c50000 SoftMgrExt.dll        1.1.0.1035       C:\Program Files\360\360Safe\SoftMgr
03d90000 360Base.dll           1.0.0.1101       C:\Program Files\360\360Safe
03ea0000 MenuEx.dll            5.0.0.5076       C:\Program Files\360\360sd
03f30000 shell360ext.dll       7.5.0.1301       C:\Program Files\360\360Safe\Utils
04020000 360WangPanShell.dll   1.0.0.1030       C:\Program Files\360\360WangPan
04180000 360base.dll           1.0.0.1041       C:\Program Files\360\360WangPan
04ac0000 xpsp2res.dll          5.1.2600.5512    C:\WINDOWS\system32
07160000 Audiodev.dll          5.2.5721.5262    C:\WINDOWS\system32
10000000 360UDiskGuard.dll     2.0.0.1101       C:\Program Files\360\360Safe\safemon
10930000 PortableDeviceApi.dll 5.2.5721.5262    C:\WINDOWS\system32
11c70000 WMASF.DLL             11.0.5721.5262   C:\WINDOWS\system32
15110000 WMVCore.DLL           11.0.5721.5275   C:\WINDOWS\system32
16500000 wpdshext.dll          5.2.5721.5262    C:\WINDOWS\system32
1f840000 odbcint.dll           3.525.1117.0     C:\WINDOWS\system32
3e410000 WININET.dll           8.0.6001.23580   C:\WINDOWS\system32
3eab0000 iertutil.dll          8.0.6001.23580   C:\WINDOWS\system32
3eca0000 ieframe.dll           8.0.6001.23580   C:\WINDOWS\system32
43ce0000 urlmon.dll            8.0.6001.23580   C:\WINDOWS\system32
4ae90000 gdiplus.dll           5.2.6002.23084   C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.23084_x-ww_f3f35550
5a540000 wiashext.dll          5.1.2600.5512    C:\WINDOWS\system32
5adc0000 uxtheme.dll           6.0.2900.5512    C:\WINDOWS\system32
5efe0000 olepro32.dll          5.1.2600.5512    C:\WINDOWS\system32
5fdd0000 NETAPI32.dll          5.1.2600.6260    C:\WINDOWS\system32
60fd0000 hnetcfg.dll           5.1.2600.5512    C:\WINDOWS\system32
62c20000 LPK.DLL               5.1.2600.5512    C:\WINDOWS\system32
68000000 rsaenh.dll            5.1.2600.5507    C:\WINDOWS\system32
68100000 dssenh.dll            5.1.2600.5507    C:\WINDOWS\system32
6bd10000 msohevi.dll           12.0.4518.1014   C:\Program Files\Microsoft Office\Office12
719c0000 mswsock.dll           5.1.2600.5625    C:\WINDOWS\System32
71a00000 wshtcpip.dll          5.1.2600.5512    C:\WINDOWS\System32
71a10000 WS2HELP.dll           5.1.2600.5512    C:\WINDOWS\system32
71a20000 WS2_32.dll            5.1.2600.5512    C:\WINDOWS\system32
71a40000 wsock32.dll           5.1.2600.5512    C:\WINDOWS\system32
71a90000 MPR.dll               5.1.2600.5512    C:\WINDOWS\system32
71b70000 SAMLIB.dll            5.1.2600.5512    C:\WINDOWS\System32
71b90000 ntlanman.dll          5.1.2600.5512    C:\WINDOWS\System32
71c00000 NETRAP.dll            5.1.2600.5512    C:\WINDOWS\System32
71c10000 NETUI1.dll            5.1.2600.5512    C:\WINDOWS\System32
71c50000 NETUI0.dll            5.1.2600.5512    C:\WINDOWS\System32
72f70000 winspool.drv          5.1.2600.5512    C:\WINDOWS\system32
73540000 ODBC32.dll            3.525.3012.0     C:\WINDOWS\system32
73640000 msctfime.ime          5.1.2600.5768    C:\WINDOWS\system32
73b10000 sti.dll               5.1.2600.5512    C:\WINDOWS\system32
73ce0000 shgina.dll            6.0.2900.5512    C:\WINDOWS\system32
73fa0000 USP10.dll             1.420.2600.6421  C:\WINDOWS\system32
74680000 MSCTF.dll             5.1.2600.5512    C:\WINDOWS\system32
74a40000 CFGMGR32.dll          5.1.2600.5512    C:\WINDOWS\system32
75430000 CRYPTUI.dll           5.131.2600.5512  C:\WINDOWS\system32
758d0000 MSGINA.dll            5.1.2600.5512    C:\WINDOWS\system32
759d0000 USERENV.dll           5.1.2600.5512    C:\WINDOWS\system32
75ed0000 drprov.dll            5.1.2600.5512    C:\WINDOWS\System32
75ee0000 davclnt.dll           5.1.2600.5512    C:\WINDOWS\System32
75ef0000 browseui.dll          6.0.2900.6254    C:\WINDOWS\system32
76060000 SETUPAPI.dll          5.1.2600.5512    C:\WINDOWS\system32
762d0000 WINSTA.dll            5.1.2600.5512    C:\WINDOWS\system32
762f0000 MSIMG32.dll           5.1.2600.5512    C:\WINDOWS\system32
76300000 IMM32.DLL             5.1.2600.5512    C:\WINDOWS\system32
76320000 comdlg32.dll          6.0.2900.5512    C:\WINDOWS\system32
76570000 CSCDLL.dll            5.1.2600.5512    C:\WINDOWS\System32
76590000 cscui.dll             5.1.2600.5512    C:\WINDOWS\System32
765e0000 crypt32.dll           5.131.2600.6459  C:\WINDOWS\system32
76960000 ntshrui.dll           5.1.2600.5512    C:\WINDOWS\system32
76990000 ole32.dll             5.1.2600.6435    C:\WINDOWS\system32
76af0000 ATL.DLL               3.5.2284.2       C:\WINDOWS\system32
76b10000 winmm.dll             5.1.2600.6160    C:\WINDOWS\system32
76bc0000 psapi.dll             5.1.2600.5512    C:\WINDOWS\system32
76c00000 WINTRUST.dll          5.131.2600.6198  C:\WINDOWS\system32
76c60000 IMAGEHLP.dll          5.1.2600.6479    C:\WINDOWS\system32
76d30000 iphlpapi.dll          5.1.2600.5512    C:\WINDOWS\system32
76d70000 appHelp.dll           5.1.2600.5512    C:\WINDOWS\system32
76db0000 MSASN1.dll            5.1.2600.5875    C:\WINDOWS\system32
76ef0000 DNSAPI.dll            5.1.2600.6089    C:\WINDOWS\system32
76f30000 WLDAP32.dll           5.1.2600.5512    C:\WINDOWS\system32
76f80000 winrnr.dll            5.1.2600.5512    C:\WINDOWS\System32
76f90000 rasadhlp.dll          5.1.2600.5512    C:\WINDOWS\system32
76fa0000 CLBCATQ.DLL           2001.12.4414.700 C:\WINDOWS\system32
77020000 COMRes.dll            2001.12.4414.700 C:\WINDOWS\system32
770f0000 oleaut32.dll          5.1.2600.6341    C:\WINDOWS\system32
77180000 comctl32.dll          6.0.2900.6028    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
77bd0000 version.dll           5.1.2600.5512    C:\WINDOWS\system32
77be0000 msvcrt.dll            7.0.2600.5512    C:\WINDOWS\system32
77d10000 user32.dll            5.1.2600.5512    C:\WINDOWS\system32
77da0000 advapi32.dll          5.1.2600.5755    C:\WINDOWS\system32
77e50000 RPCRT4.dll            5.1.2600.6477    C:\WINDOWS\system32
77ef0000 GDI32.dll             5.1.2600.6460    C:\WINDOWS\system32
77f40000 SHLWAPI.dll           6.0.2900.5912    C:\WINDOWS\system32
77fc0000 Secur32.dll           5.1.2600.5834    C:\WINDOWS\system32
78130000 MSVCR80.dll           8.0.50727.6195   C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86
7c800000 kernel32.dll          5.1.2600.5781    C:\WINDOWS\system32
7c920000 ntdll.dll             5.1.2600.6055    C:\WINDOWS\system32
7d590000 shell32.dll           6.0.2900.6242    C:\WINDOWS\system32
7e550000 shdocvw.dll           6.0.2900.6254    C:\WINDOWS\system32

processes:
0000 Idle              0   0
0004 System            0   0    normal
01c8 smss.exe          0   0    normal       C:\WINDOWS\system32
0200 csrss.exe         0   0
0220 winlogon.exe      45  14   high         C:\WINDOWS\system32
024c services.exe      4   2    normal       C:\WINDOWS\system32
0258 lsass.exe         4   2    normal       C:\WINDOWS\system32
0314 svchost.exe       4   1    normal       C:\WINDOWS\system32
0340 svchost.exe       0   0
0384 svchost.exe       10  31   normal       C:\WINDOWS\System32
03b0 svchost.exe       4   1    normal       C:\WINDOWS\system32
045c svchost.exe       0   0
0484 svchost.exe       4   2    normal       C:\WINDOWS\System32
04b0 svchost.exe       0   0
04c4 zhudongfangyu.exe 4   2    normal       C:\Program Files\360\360Safe\deepscan
04f0 svchost.exe       4   1    normal       C:\WINDOWS\System32
0600 DhMachineSvc.exe  4   3    normal       C:\Program Files\Microsoft Device Health
062c DhPluginMgr.exe   4   5    normal       C:\Program Files\Microsoft Device Health\PluginManager
0654 inetinfo.exe      4   7    normal       C:\WINDOWS\system32\inetsrv
066c sqlservr.exe      4   1    normal       C:\Program Files\Microsoft SQL Server\MSSQL\Binn
0748 pcas.exe          4   3    normal       C:\Program Files\alipay\aliedit\5.3.0.3807
0728 alg.exe           0   0
0958 Explorer.EXE      331 216  normal       C:\WINDOWS
0998 360Tray.exe       282 91   normal       C:\Program Files\360\360Safe\safemon
09a0 ctfmon.exe        129 54   normal       C:\WINDOWS\system32
09b4 360sd.exe         469 214  normal       C:\Program Files\360\360sd
0148 360rp.exe         7   3    normal       C:\Program Files\360\360sd
0880 360se.exe         676 212  normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
09b0 wdswfsafe.exe     4   4    normal       C:\Program Files\360\360Safe\safemon
0f9c 360se.exe         9   1    normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
0b38 360se.exe         11  10   normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
0c90 QQ.exe            276 186  normal       D:\ù\Ѷ\Bin
0d0c TXPlatform.exe    8   5    normal       D:\ù\Ѷ\Bin
0ed0 QQ.exe            136 147  normal       D:\ù\Ѷ\Bin
0ae4 QQ.exe            93  126  normal       D:\ù\Ѷ\Bin
0c30 360se.exe         160 1    normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
0e14 360se.exe         18  59   normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
04a8 FlashFXP.exe      270 203  normal       K:\ù߰\flashftp
1688 dllhost.exe       0   0
0c0c dllhost.exe       4   3    normal       C:\WINDOWS\system32
035c Dreamweaver.exe   654 1344 normal       C:\Program Files\Macromedia\Dreamweaver 8
0f5c svchost.exe       4   2    normal       C:\WINDOWS\system32
00c8 POWERPNT.EXE      159 98   normal       C:\Program Files\Microsoft Office\Office12
1048 conime.exe        15  9    normal       C:\WINDOWS\system32
15f4 WPService.exe     8   3    normal       C:\Program Files\CMBCHINA\WebProtect
061c 360se.exe         152 1    below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
1400 360se.exe         117 1    below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application

hardware:
+ IDE ATA/ATAPI 
  - Intel(R) N10/ICH7 Family Serial ATA Storage Controller - 27C0 (driver 9.1.1.1016)
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
+ 
  - Pentium(R) Dual-Core  CPU      E5300  @ 2.60GHz
  - Pentium(R) Dual-Core  CPU      E5300  @ 2.60GHz
+ 
  - ST500DM002-1BD142
  - WD Elements 1078 USB Device
+ 
  - 弴ü
+ 
  - ACPI Multiprocessor PC
+ 
  - ׼ 101/102  Microsoft Ȼ PS/2 
+ ƵϷ
  - Realtek High Definition Audio (driver 5.10.0.6449)
  - ͳƵ׽豸
  - ͳƵ
  - ý豸
  - Ƶ
  - Ƶ
+ ָ豸
  - Microsoft PS/2 Mouse
+ ͨô߿
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C9 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CA (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CB (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB2 Enhanced Host Controller - 27CC (driver 9.1.1.1016)
  - USB Mass Storage Device
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
+ 
  - Realtek PCIe FE Family Controller (driver 5.788.613.2011)
+ ϵͳ豸
  - ACPI Fixed Feature Button
  - ACPI Power Button
  - ACPI Thermal Zone
  - Direct memory access controller
  - Intel(R) 4 Series Chipset PCI Express Root Port - 2E31 (driver 9.1.0.1012)
  - Intel(R) 4 Series Chipset Processor to I/O Controller - 2E30 (driver 9.1.0.1012)
  - Intel(R) 82801BA/CA PCI Bridge - 244E (driver 3.30.1002.0)
  - Intel(R) 82802 Firmware Hub Device
  - Intel(R) ICH7 Family LPC Interface Controller - 27B8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family PCI Express Root Port - 27D0 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family PCI Express Root Port - 27D2 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family SMBus Controller - 27DA (driver 9.1.1.1016)
  - ISAPNP Read Data Port
  - Logical Disk Manager
  - Microcode Update Device
  - Microsoft ACPI-Compliant System
  - Microsoft Composite Battery
  - Microsoft System Management BIOS Driver
  - Microsoft  High Definition Audio  UAA 
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Numeric data processor
  - PCI bus
  - Plug and Play Software Device Enumerator
  - Programmable interrupt controller
  - System board
  - System board
  - System CMOS/real time clock
  - System speaker
  - System timer
  - Terminal Server Device Redirector
  - Terminal Server Keyboard Driver
  - Terminal Server Mouse Driver
  - Volume Manager
  - ̨ȫʾƵ
+ ʾ
  - NVIDIA GeForce 9500 GT (driver 6.14.12.6658)

cpu registers:
eax = 0a0d7d68
ebx = 00797398
ecx = fffffff8
edx = 03031920
esi = 00f83aa8
edi = 00412a2c
eip = 00408e0f
esp = 0012f6b8
ebp = 0012f6f8

stack dump:
0012f6b8  2b 00 00 00 fe 29 40 00 - 79 33 40 00 e8 d7 45 00  +....)@.y3@...E.
0012f6c8  12 37 40 00 2b 00 00 00 - a0 05 e8 00 01 35 f8 00  .7@.+........5..
0012f6d8  52 ec 45 00 2c 2a 41 00 - a8 3a f8 00 2b 00 00 00  R.E.,*A..:..+...
0012f6e8  02 00 00 00 a8 3a f8 00 - 2b 00 00 00 a0 05 e8 00  .....:..+.......
0012f6f8  54 f7 12 00 ef 2a 74 00 - 5c f7 12 00 ac 3a 40 00  T....*t.\....:@.
0012f708  54 f7 12 00 4c 00 00 00 - d5 02 00 00 e8 ba f5 00  T...L...........
0012f718  00 00 00 00 00 00 00 00 - 01 00 00 00 00 00 00 00  ................
0012f728  2b 01 00 00 2a 11 46 01 - 00 00 00 00 03 00 00 00  +...*.F.........
0012f738  06 00 00 00 06 00 00 00 - 19 00 00 00 00 00 00 00  ................
0012f748  a0 25 03 03 30 22 03 03 - a0 05 e8 00 8c f7 12 00  .%..0"..........
0012f758  ba 27 76 00 b8 f7 12 00 - ac 3a 40 00 8c f7 12 00  .'v......:@.....
0012f768  4c 00 00 00 d5 02 00 00 - e8 ba f5 00 00 00 00 00  L...............
0012f778  00 00 00 00 7c 27 45 00 - 00 00 00 00 d8 f7 12 00  ....|'E.........
0012f788  a0 05 e8 00 f4 f7 12 00 - 00 37 46 00 e8 ba f5 00  .........7F.....
0012f798  dd 37 46 00 d5 02 00 00 - 4c 00 00 00 f4 f7 12 00  .7F.....L.......
0012f7a8  e8 ba f5 00 60 3e e7 00 - d8 df 45 00 f9 c0 4f 00  ....`>....E...O.
0012f7b8  c4 f7 12 00 ac 3a 40 00 - f4 f7 12 00 b4 fb 12 00  .....:@.........
0012f7c8  ac 3a 40 00 f4 f7 12 00 - 60 3e e7 00 b0 be 4f 00  .:@.....`>....O.
0012f7d8  00 00 00 00 1e 00 00 00 - d5 02 00 00 4c 00 00 00  ............L...
0012f7e8  e8 ba 00 00 60 3e e7 00 - 60 56 e9 00 54 f9 12 00  ....`>..`V..T...

disassembling:
[...]
00742aa4 12931   cmp     dword ptr [ebp-$20], 0
00742aa8         jnz     loc_742ac3
00742aaa 12933   inc     dword ptr [ebp-$18]
00742aad 12934   mov     eax, [ebp-4]
00742ab0         mov     eax, [eax+$328]
00742ab6         mov     eax, [eax+$28]
00742ab9         mov     edx, [ebp-8]
00742abc         call    -$2e1a5d ($461064)     ; Menus.TMenuItem.Add
00742ac1         jmp     loc_742ace
00742ac3 12937   mov     edx, [ebp-8]
00742ac6         mov     eax, [ebp-$c]
00742ac9         call    -$2e1a6a ($461064)     ; Menus.TMenuItem.Add
00742ace 12939   mov     eax, [ebp-8]
00742ad1         mov     [ebp-$c], eax
00742ad4 12942   inc     dword ptr [ebp-$20]
00742ad7 12889   dec     dword ptr [ebp-$30]
00742ada         jnz     loc_7428cc
00742ae0 12944   mov     ecx, [ebp-4]
00742ae3         mov     dl, 1
00742ae5         mov     eax, [$45d79c]
00742aea       > call    -$2e3eaf ($45ec40)     ; Menus.TMenuItem.Create
00742aef         mov     [ebp-8], eax
00742af2 12946   cmp     dword ptr [ebp-$14], 0
00742af6         jz      loc_742b1e
00742af8         mov     eax, [ebp-$c]
00742afb         call    -$2e1df4 ($460d0c)     ; Menus.TMenuItem.GetCount
00742b00         cdq
00742b01         idiv    dword ptr [ebp-$14]
00742b04         test    edx, edx
00742b06         jnz     loc_742b1e
00742b08         mov     eax, [ebp-$c]
00742b0b         call    -$2e1e04 ($460d0c)     ; Menus.TMenuItem.GetCount
00742b10         test    eax, eax
00742b12         jz      loc_742b1e
00742b14 12947   mov     dl, 2
00742b16         mov     eax, [ebp-8]
00742b19         call    -$2e1fba ($460b64)     ; Menus.TMenuItem.SetBreak
00742b1e 12949   lea     ecx, [ebp-$3c]
00742b21         mov     edx, ebx
00742b23         mov     eax, esi
00742b25         mov     edi, [eax]
[...]

date/time         : 2016-04-29, 16:41:41, 421ms
computer name     : MFFJBFG1BBOASEZ
user name         : Administrator <admin>
registered owner  : ΢û / ΢й
operating system  : Windows XP Service Pack 3 (5.1.2600) build 2600
system language   : Chinese
system up time    : 3 hours 12 minutes
program up time   : 1 hour 55 minutes
processors        : 2x Pentium(R) Dual-Core CPU E5300 @ 2.60GHz
physical memory   : 1916/3327 MB (free/total)
free disk space   : (C:) 23.15 GB (K:) 68.29 GB
display mode      : 1440x900, 32 bit
process id        : $1918
allocated memory  : 22.66 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $eb093fce, $ac2cc906, $538105ea
count             : 4
exception number  : 1
exception class   : EAccessViolation
exception message : Access violation at address 004CFD49 in module 'FlashFXP.exe'. ȡ of address 0000002C.

main thread ($191c):
004cfd49 +0035 FlashFXP.exe IniFiles32   937   +7 TIniFile32.ReadString
004cfe66 +002e FlashFXP.exe IniFiles32   962   +1 TIniFile32.ReadInteger
007426c0 +00ac FlashFXP.exe FrmMain1   12840  +10 TFrmMain.BuildMenuList
007627b5 +01d9 FlashFXP.exe FrmMain1   23920  +40 TFrmMain.PopSitePopup
004636fd +000d FlashFXP.exe Menus                 TPopupMenu.DoPopup
004637da +0032 FlashFXP.exe Menus                 TPopupMenu.Popup
004fc0f6 +0246 FlashFXP.exe ComCtrls              TToolBar.CheckMenuDropdown
004f8b8d +0039 FlashFXP.exe ComCtrls              TToolButton.CheckMenuDropdown
004fb522 +0036 FlashFXP.exe ComCtrls              TToolBar.CNNotify
00453e35 +0111 FlashFXP.exe Controls              TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls              TWinControl.WndProc
004fb881 +0231 FlashFXP.exe ComCtrls              TToolBar.WndProc
0045632c +002c FlashFXP.exe Controls              TWinControl.MainWndProc
00509afb +003f FlashFXP.exe ThemeMgr              TWindowProcList.DispatchMessage
0050b8f4 +01b8 FlashFXP.exe ThemeMgr              TThemeManager.WinControlWindowProc
0050b9c9 +0009 FlashFXP.exe ThemeMgr              TThemeManager.PreWinControlWindowProc
00453c64 +0024 FlashFXP.exe Controls              TControl.Perform
00453e35 +0111 FlashFXP.exe Controls              TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls              TWinControl.WndProc
004fb881 +0231 FlashFXP.exe ComCtrls              TToolBar.WndProc
00509afb +003f FlashFXP.exe ThemeMgr              TWindowProcList.DispatchMessage
0050b8f4 +01b8 FlashFXP.exe ThemeMgr              TThemeManager.WinControlWindowProc
0050b9c9 +0009 FlashFXP.exe ThemeMgr              TThemeManager.PreWinControlWindowProc
0045632c +002c FlashFXP.exe Controls              TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms       1529   +8 StdWndProc
77d2f406 +0044 user32.dll                         SendMessageA
00509afb +003f FlashFXP.exe ThemeMgr              TWindowProcList.DispatchMessage
0050b8f4 +01b8 FlashFXP.exe ThemeMgr              TThemeManager.WinControlWindowProc
0050b9c9 +0009 FlashFXP.exe ThemeMgr              TThemeManager.PreWinControlWindowProc
0045632c +002c FlashFXP.exe Controls              TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms       1529   +8 StdWndProc
77d196c2 +000a user32.dll                         DispatchMessageA
0044ca9f +008b FlashFXP.exe Forms       7117  +34 TApplication.ProcessMessage
0044cabe +000a FlashFXP.exe Forms       7148   +1 TApplication.ProcessMessages
00769e5f +09a3 FlashFXP.exe FrmMain1   26599 +222 TFrmMain.FormDestroy
00445c5d +0031 FlashFXP.exe Forms       2755   +3 TCustomForm.DoDestroy
00445ac1 +005d FlashFXP.exe Forms       2719   +7 TCustomForm.BeforeDestruction
00403771 +0009 FlashFXP.exe System                @BeforeDestruction
00445ace +0006 FlashFXP.exe Forms       2723   +0 TCustomForm.Destroy
004033e4 +0008 FlashFXP.exe System                TObject.Free
0041c349 +0019 FlashFXP.exe Classes               TComponent.Remove
0041c40a +001e FlashFXP.exe Classes               TComponent.DestroyComponents
004436ab +002f FlashFXP.exe Forms       1261   +3 DoneApplication
0040a9b6 +0026 FlashFXP.exe SysUtils              DoExitProc
00403f50 +0028 FlashFXP.exe System                @Halt0
00796548 +1cc4 FlashFXP.exe FlashFXP     939 +649 initialization

thread $1930:
7c92df48 +00a ntdll.dll                              NtWaitForMultipleObjects
7c80958a +000 kernel32.dll                           WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll                           WaitForMultipleObjects
00640bd3 +07b FlashFXP.exe UPTShellControls 4370 +13 TChangeHandlerThread.Execute
0041bfc1 +22d FlashFXP.exe Classes                   HexToBin
00404080 +028 FlashFXP.exe System                    ThreadWrapper

thread $1af4:
7c92daa8 +a ntdll.dll  NtReplyWaitReceivePortEx

modules:
00400000 FlashFXP.exe          4.0.0.1534       K:\ù߰\flashftp
01590000 Normaliz.dll          6.0.5441.0       C:\WINDOWS\system32
03340000 ssleay32.dll          1.0.0.3          K:\ù߰\flashftp
03540000 libeay32.dll          1.0.0.3          K:\ù߰\flashftp
03d10000 rarext.dll            5.30.0.0         C:\Program Files\WinRAR
03e80000 SoftMgrExt.dll        1.1.0.1035       C:\Program Files\360\360Safe\SoftMgr
03fc0000 360Base.dll           1.0.0.1120       C:\Program Files\360\360Safe
040d0000 MenuEx.dll            5.0.0.5076       C:\Program Files\360\360sd
04150000 shell360ext.dll       7.5.0.1311       C:\Program Files\360\360Safe\Utils
04240000 qingshellext.dll      10.1.0.5603      C:\Documents and Settings\Administrator\Local Settings\Application Data\Kingsoft\WPS Office\10.1.0.5603\office6
04290000 MediaLibraryIcon.dll  5.57.202.0       C:\Program Files\Baofeng\StormPlayer
04370000 crt.dll               5.57.202.0       C:\Program Files\Baofeng\StormPlayer
043c0000 360WangPanShell.dll   1.0.0.1030       C:\Program Files\360\360WangPan
04520000 360base.dll           1.0.0.1041       C:\Program Files\360\360WangPan
04930000 xpsp2res.dll          5.1.2600.5512    C:\WINDOWS\system32
07160000 Audiodev.dll          5.2.5721.5262    C:\WINDOWS\system32
10000000 360UDiskGuard.dll     2.0.0.1111       C:\Program Files\360\360Safe\safemon
10930000 PortableDeviceApi.dll 5.2.5721.5262    C:\WINDOWS\system32
11c70000 WMASF.DLL             11.0.5721.5262   C:\WINDOWS\system32
15110000 WMVCore.DLL           11.0.5721.5275   C:\WINDOWS\system32
16500000 wpdshext.dll          5.2.5721.5262    C:\WINDOWS\system32
1f840000 odbcint.dll           3.525.1117.0     C:\WINDOWS\system32
3e410000 WININET.dll           8.0.6001.23580   C:\WINDOWS\system32
3eab0000 iertutil.dll          8.0.6001.23580   C:\WINDOWS\system32
3eca0000 ieframe.dll           8.0.6001.23580   C:\WINDOWS\system32
43ce0000 urlmon.dll            8.0.6001.23580   C:\WINDOWS\system32
4ae90000 gdiplus.dll           5.2.6002.23084   C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.23084_x-ww_f3f35550
5a540000 wiashext.dll          5.1.2600.5512    C:\WINDOWS\system32
5adc0000 uxtheme.dll           6.0.2900.5512    C:\WINDOWS\system32
5efe0000 olepro32.dll          5.1.2600.5512    C:\WINDOWS\system32
5fdd0000 NETAPI32.dll          5.1.2600.6260    C:\WINDOWS\system32
60fd0000 hnetcfg.dll           5.1.2600.5512    C:\WINDOWS\system32
62c20000 LPK.DLL               5.1.2600.5512    C:\WINDOWS\system32
68000000 rsaenh.dll            5.1.2600.5507    C:\WINDOWS\system32
68100000 dssenh.dll            5.1.2600.5507    C:\WINDOWS\system32
6bd10000 msohevi.dll           12.0.4518.1014   C:\Program Files\Microsoft Office\Office12
719c0000 mswsock.dll           5.1.2600.5625    C:\WINDOWS\System32
71a00000 wshtcpip.dll          5.1.2600.5512    C:\WINDOWS\System32
71a10000 WS2HELP.dll           5.1.2600.5512    C:\WINDOWS\system32
71a20000 WS2_32.dll            5.1.2600.5512    C:\WINDOWS\system32
71a40000 wsock32.dll           5.1.2600.5512    C:\WINDOWS\system32
71a90000 MPR.dll               5.1.2600.5512    C:\WINDOWS\system32
71b70000 SAMLIB.dll            5.1.2600.5512    C:\WINDOWS\System32
71b90000 ntlanman.dll          5.1.2600.5512    C:\WINDOWS\System32
71c00000 NETRAP.dll            5.1.2600.5512    C:\WINDOWS\System32
71c10000 NETUI1.dll            5.1.2600.5512    C:\WINDOWS\System32
71c50000 NETUI0.dll            5.1.2600.5512    C:\WINDOWS\System32
72240000 SensApi.dll           5.1.2600.5512    C:\WINDOWS\system32
72f70000 winspool.drv          5.1.2600.5512    C:\WINDOWS\system32
73540000 ODBC32.dll            3.525.3012.0     C:\WINDOWS\system32
73640000 msctfime.ime          5.1.2600.5768    C:\WINDOWS\system32
73b10000 sti.dll               5.1.2600.5512    C:\WINDOWS\system32
73ce0000 shgina.dll            6.0.2900.5512    C:\WINDOWS\system32
73fa0000 USP10.dll             1.420.2600.6421  C:\WINDOWS\system32
74680000 MSCTF.dll             5.1.2600.5512    C:\WINDOWS\system32
74a40000 CFGMGR32.dll          5.1.2600.5512    C:\WINDOWS\system32
75430000 CRYPTUI.dll           5.131.2600.5512  C:\WINDOWS\system32
758d0000 MSGINA.dll            5.1.2600.5512    C:\WINDOWS\system32
759d0000 USERENV.dll           5.1.2600.5512    C:\WINDOWS\system32
75ed0000 drprov.dll            5.1.2600.5512    C:\WINDOWS\System32
75ee0000 davclnt.dll           5.1.2600.5512    C:\WINDOWS\System32
75ef0000 browseui.dll          6.0.2900.6254    C:\WINDOWS\system32
76060000 SETUPAPI.dll          5.1.2600.5512    C:\WINDOWS\system32
762d0000 WINSTA.dll            5.1.2600.5512    C:\WINDOWS\system32
762f0000 MSIMG32.dll           5.1.2600.5512    C:\WINDOWS\system32
76300000 IMM32.DLL             5.1.2600.5512    C:\WINDOWS\system32
76320000 comdlg32.dll          6.0.2900.5512    C:\WINDOWS\system32
76570000 CSCDLL.dll            5.1.2600.5512    C:\WINDOWS\System32
76590000 cscui.dll             5.1.2600.5512    C:\WINDOWS\System32
765e0000 crypt32.dll           5.131.2600.6459  C:\WINDOWS\system32
76950000 LINKINFO.dll          5.1.2600.5512    C:\WINDOWS\system32
76960000 ntshrui.dll           5.1.2600.5512    C:\WINDOWS\system32
76990000 ole32.dll             5.1.2600.6435    C:\WINDOWS\system32
76af0000 ATL.DLL               3.5.2284.2       C:\WINDOWS\system32
76b10000 winmm.dll             5.1.2600.6160    C:\WINDOWS\system32
76bc0000 psapi.dll             5.1.2600.5512    C:\WINDOWS\system32
76c00000 WINTRUST.dll          5.131.2600.6198  C:\WINDOWS\system32
76c60000 IMAGEHLP.dll          5.1.2600.6479    C:\WINDOWS\system32
76d30000 iphlpapi.dll          5.1.2600.5512    C:\WINDOWS\system32
76d70000 appHelp.dll           5.1.2600.5512    C:\WINDOWS\system32
76db0000 MSASN1.dll            5.1.2600.5875    C:\WINDOWS\system32
76ef0000 DNSAPI.dll            5.1.2600.6089    C:\WINDOWS\system32
76f30000 WLDAP32.dll           5.1.2600.5512    C:\WINDOWS\system32
76f80000 winrnr.dll            5.1.2600.5512    C:\WINDOWS\System32
76f90000 rasadhlp.dll          5.1.2600.5512    C:\WINDOWS\system32
76fa0000 CLBCATQ.DLL           2001.12.4414.700 C:\WINDOWS\system32
77020000 COMRes.dll            2001.12.4414.700 C:\WINDOWS\system32
770f0000 oleaut32.dll          5.1.2600.6341    C:\WINDOWS\system32
77180000 comctl32.dll          6.0.2900.6028    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
77bd0000 version.dll           5.1.2600.5512    C:\WINDOWS\system32
77be0000 msvcrt.dll            7.0.2600.5512    C:\WINDOWS\system32
77d10000 user32.dll            5.1.2600.5512    C:\WINDOWS\system32
77da0000 advapi32.dll          5.1.2600.5755    C:\WINDOWS\system32
77e50000 RPCRT4.dll            5.1.2600.6477    C:\WINDOWS\system32
77ef0000 GDI32.dll             5.1.2600.6460    C:\WINDOWS\system32
77f40000 SHLWAPI.dll           6.0.2900.5912    C:\WINDOWS\system32
77fc0000 Secur32.dll           5.1.2600.5834    C:\WINDOWS\system32
78050000 MSVCP100.dll          10.0.40219.325   C:\Program Files\Baofeng\StormPlayer
78130000 MSVCR80.dll           8.0.50727.6195   C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86
78aa0000 MSVCR100.dll          10.0.40219.325   C:\Program Files\Baofeng\StormPlayer
7c800000 kernel32.dll          5.1.2600.5781    C:\WINDOWS\system32
7c920000 ntdll.dll             5.1.2600.6055    C:\WINDOWS\system32
7d590000 shell32.dll           6.0.2900.6242    C:\WINDOWS\system32
7e550000 shdocvw.dll           6.0.2900.6254    C:\WINDOWS\system32

processes:
0000 Idle               0    0
0004 System             0    0   normal
01c4 smss.exe           0    0   normal       C:\WINDOWS\system32
01f8 csrss.exe          0    0
0218 winlogon.exe       45   14  high         C:\WINDOWS\system32
0254 services.exe       4    2   normal       C:\WINDOWS\system32
0260 lsass.exe          4    1   normal       C:\WINDOWS\system32
030c svchost.exe        4    1   normal       C:\WINDOWS\system32
0338 svchost.exe        0    0
037c svchost.exe        10   36  normal       C:\WINDOWS\System32
03a4 svchost.exe        4    1   normal       C:\WINDOWS\system32
0458 svchost.exe        0    0
0468 svchost.exe        4    3   normal       C:\WINDOWS\System32
04ac svchost.exe        0    0
04bc zhudongfangyu.exe  4    2   normal       C:\Program Files\360\360Safe\deepscan
04ec svchost.exe        4    1   normal       C:\WINDOWS\System32
063c sqlservr.exe       4    1   normal       C:\Program Files\Microsoft SQL Server\MSSQL\Binn
064c mysqld.exe         4    2   normal       C:\mysql\bin
0698 pcas.exe           4    3   normal       C:\Program Files\alipay\aliedit\5.3.0.3807
07b0 secbizsrv.exe      4    7   normal       C:\Program Files\alipay\aliedit\5.3.0.3807
07dc WySafeMonitor.exe  4    2   normal       C:\Program Files\WangYin\wyedit\104.15.302.155
0818 alg.exe            0    0
085c Explorer.EXE       248  194 normal       C:\WINDOWS
08a4 aliwssv.exe        4    1   normal       C:\Program Files\alipay\aliedit\5.3.0.3807
0908 360Tray.exe        242  78  normal       C:\Program Files\360\360Safe\safemon
0910 ctfmon.exe         121  57  normal       C:\WINDOWS\system32
0920 360sd.exe          469  214 normal       C:\Program Files\360\360sd
0970 PalmInputGuard.exe 8    4   normal       C:\Program Files\PalmInput\Extensions\Guard\1.5.0.12
0c08 svchost.exe        4    1   normal       C:\WINDOWS\System32
0d00 360rp.exe          7    3   normal       C:\Program Files\360\360sd
0f1c 360se.exe          1416 234 normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
0f98 wdswfsafe.exe      4    4   normal       C:\Program Files\360\360Safe\safemon
01ec 360se.exe          37   1   normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
076c 360se.exe          11   10  normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
0264 QQ.exe             146  139 normal       D:\ù\Ѷ\Bin
0e4c TXPlatform.exe     8    5   normal       D:\ù\Ѷ\Bin
09c0 QQ.exe             105  151 normal       D:\ù\Ѷ\Bin
0ca8 QQ.exe             239  174 normal       D:\ù\Ѷ\Bin
1024 conime.exe         17   12  normal       C:\WINDOWS\system32
1384 mstsc.exe          139  108 normal       C:\WINDOWS\system32
0508 mstsc.exe          47   46  normal       C:\WINDOWS\system32
14f4 svchost.exe        4    2   normal       C:\WINDOWS\system32
135c dllhost.exe        4    3   normal       C:\WINDOWS\system32
061c msdtc.exe          0    0
1680 360se.exe          20   155 normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
1918 FlashFXP.exe       249  185 normal       K:\ù߰\flashftp
197c 360se.exe          223  1   normal       C:\Documents and Settings\Administrator\Application Data\360se6\Application
1b14 inetinfo.exe       4    7   normal       C:\WINDOWS\system32\inetsrv
1ae4 alicnotify.exe     14   8   normal       C:\Documents and Settings\Administrator\Application Data\alipay\cf
1be8 360se.exe          537  1   below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
19c4 wpscloudsvr.exe    18   46  normal       C:\Documents and Settings\Administrator\Local Settings\Application Data\Kingsoft\WPS Office\10.1.0.5603\office6
19d0 wmiprvse.exe       0    0
1394 QQExternal.exe     74   26  normal       D:\ù\Ѷ\Bin
1558 dllhost.exe        0    0
103c 360se.exe          77   1   below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
1d74 360se.exe          121  1   below normal C:\Documents and Settings\Administrator\Application Data\360se6\Application

hardware:
+ IDE ATA/ATAPI 
  - Intel(R) N10/ICH7 Family Serial ATA Storage Controller - 27C0 (driver 9.1.1.1016)
  - Ҫ IDE ͨ
  - Ҫ IDE ͨ
+ 
  - Pentium(R) Dual-Core  CPU      E5300  @ 2.60GHz
  - Pentium(R) Dual-Core  CPU      E5300  @ 2.60GHz
+ 
  - ST500DM002-1BD142
  - WD Elements 1078 USB Device
+ 
  - 弴ü
+ 
  - ACPI Multiprocessor PC
+ 
  - ׼ 101/102  Microsoft Ȼ PS/2 
+ ƵϷ
  - Realtek High Definition Audio (driver 5.10.0.6449)
  - ͳƵ׽豸
  - ͳƵ
  - ý豸
  - Ƶ
  - Ƶ
+ ָ豸
  - Microsoft PS/2 Mouse
+ ͨô߿
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C9 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CA (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CB (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family USB2 Enhanced Host Controller - 27CC (driver 9.1.1.1016)
  - USB Mass Storage Device
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
+ 
  - Realtek PCIe FE Family Controller (driver 5.788.613.2011)
+ ϵͳ豸
  - ACPI Fixed Feature Button
  - ACPI Power Button
  - ACPI Thermal Zone
  - Direct memory access controller
  - Intel(R) 4 Series Chipset PCI Express Root Port - 2E31 (driver 9.1.0.1012)
  - Intel(R) 4 Series Chipset Processor to I/O Controller - 2E30 (driver 9.1.0.1012)
  - Intel(R) 82801BA/CA PCI Bridge - 244E (driver 3.30.1002.0)
  - Intel(R) 82802 Firmware Hub Device
  - Intel(R) ICH7 Family LPC Interface Controller - 27B8 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family PCI Express Root Port - 27D0 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family PCI Express Root Port - 27D2 (driver 9.1.1.1016)
  - Intel(R) N10/ICH7 Family SMBus Controller - 27DA (driver 9.1.1.1016)
  - ISAPNP Read Data Port
  - Logical Disk Manager
  - Microcode Update Device
  - Microsoft ACPI-Compliant System
  - Microsoft Composite Battery
  - Microsoft System Management BIOS Driver
  - Microsoft  High Definition Audio  UAA 
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Numeric data processor
  - PCI bus
  - Plug and Play Software Device Enumerator
  - Programmable interrupt controller
  - System board
  - System board
  - System CMOS/real time clock
  - System speaker
  - System timer
  - Terminal Server Device Redirector
  - Terminal Server Keyboard Driver
  - Terminal Server Mouse Driver
  - Volume Manager
  - ̨ȫʾƵ
+ ʾ
  - NVIDIA GeForce 9500 GT (driver 6.14.12.6658)

cpu registers:
eax = 0012f668
ebx = 00000000
ecx = 00000000
edx = 00000000
esi = 00742cc4
edi = 00742cc4
eip = 004cfd49
esp = 0012f614
ebp = 0012f63c

stack dump:
0012f614  4c f6 12 00 ac 3a 40 00 - 3c f6 12 00 c4 2c 74 00  L....:@.<....,t.
0012f624  00 00 00 00 50 bb f5 00 - 00 00 00 00 00 00 00 00  ....P...........
0012f634  00 00 00 00 b4 2c 74 00 - 70 f6 12 00 6b fe 4c 00  .....,t.p...k.L.
0012f644  68 f6 12 00 00 00 00 00 - 80 f6 12 00 ac 3a 40 00  h............:@.
0012f654  70 f6 12 00 94 00 00 00 - bc 03 00 00 50 bb f5 00  p...........P...
0012f664  00 00 00 00 00 00 00 00 - b4 2c 74 00 d4 f6 12 00  .........,t.....
0012f674  c5 26 74 00 00 00 00 00 - 00 00 00 00 dc f6 12 00  .&t.............
0012f684  ac 3a 40 00 d4 f6 12 00 - 94 00 00 00 bc 03 00 00  .:@.............
0012f694  50 bb f5 00 00 00 00 00 - 00 00 00 00 94 00 00 00  P...............
0012f6a4  c0 f6 12 00 94 00 00 00 - 30 d7 eb 02 00 00 00 00  ........0.......
0012f6b4  2a 11 46 00 06 00 00 00 - 01 00 00 00 2e 0f 4d 00  *.F...........M.
0012f6c4  94 00 00 00 bc 03 00 00 - 50 bb f5 00 c0 df ef 02  ........P.......
0012f6d4  0c f7 12 00 ba 27 76 00 - 38 f7 12 00 ac 3a 40 00  .....'v.8....:@.
0012f6e4  0c f7 12 00 94 00 00 00 - bc 03 00 00 50 bb f5 00  ............P...
0012f6f4  00 00 00 00 00 00 00 00 - 7c 27 45 00 00 00 00 00  ........|'E.....
0012f704  58 f7 12 00 c0 df ef 02 - 74 f7 12 00 00 37 46 00  X.......t....7F.
0012f714  50 bb f5 00 dd 37 46 00 - bc 03 00 00 94 00 00 00  P....7F.........
0012f724  74 f7 12 00 50 bb f5 00 - 90 d1 e3 02 d8 df 45 00  t...P.........E.
0012f734  f9 c0 4f 00 44 f7 12 00 - ac 3a 40 00 74 f7 12 00  ..O.D....:@.t...
0012f744  34 fb 12 00 ac 3a 40 00 - 74 f7 12 00 90 d1 e3 02  4....:@.t.......

disassembling:
004cfd14     public IniFiles32.TIniFile32.ReadString:  ; function entry point
004cfd14 930   push    ebp
004cfd15       mov     ebp, esp
004cfd17       push    0
004cfd19       push    0
004cfd1b       push    0
004cfd1d       push    0
004cfd1f       push    ebx
004cfd20       push    esi
004cfd21       push    edi
004cfd22       mov     [ebp-4], ecx
004cfd25       mov     esi, edx
004cfd27       mov     ebx, eax
004cfd29       xor     eax, eax
004cfd2b       push    ebp
004cfd2c       push    $4cfe27                ; System.@HandleFinally
004cfd31       push    dword ptr fs:[eax]
004cfd34       mov     fs:[eax], esp
004cfd37 935   mov     eax, ebx
004cfd39       call    +$118e ($4d0ecc)       ; IniFiles32.TIniFile32.Reload
004cfd3e 936   mov     eax, [ebp+8]
004cfd41       mov     edx, [ebp+$c]
004cfd44       call    -$cbbd5 ($404174)      ; System.@LStrLAsg
004cfd49 937 > mov     eax, [ebx+$2c]
004cfd4c       mov     edx, [eax]
004cfd4e       call    dword ptr [edx+$14]
004cfd51       test    eax, eax
004cfd53       jle     loc_4cfe0c
004cfd59 939   mov     edx, esi
004cfd5b       mov     eax, ebx
004cfd5d       call    -$f56 ($4cee0c)        ; IniFiles32.TIniFile32.GetSectionIndex
004cfd62       mov     esi, eax
004cfd64 940   cmp     esi, -1
004cfd67       jz      loc_4cfe0c
004cfd6d 942   inc     esi
004cfd6e       jmp     loc_4cfde1
004cfd70 945   lea     ecx, [ebp-$c]
004cfd73       mov     edx, esi
004cfd75       mov     eax, [ebx+$2c]
004cfd78       mov     edi, [eax]
004cfd7a       call    dword ptr [edi+$c]
004cfd7d       mov     edx, [ebp-$c]
004cfd80       lea     ecx, [ebp-$10]
004cfd83       mov     eax, ebx
[...]

date/time         : 2017-11-04, 16:54:31, 562ms
computer name     : USER-20171006RY
user name         : Administrator <admin>
registered owner  : Sky123.Org / Sky123.Org
operating system  : Windows XP Service Pack 3 (5.1.2600) build 2600
system language   : Chinese
system up time    : 6 hours 50 minutes
program up time   : 4 hours 7 minutes
processors        : 12x Intel(R) Xeon(R) CPU L5640 @ 2.27GHz
physical memory   : 1342/3383 MB (free/total)
free disk space   : (C:) 38.62 GB (K:) 26.87 GB
display mode      : 1920x1080, 32 bit
process id        : $f8
allocated memory  : 20.83 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $8cb7f9be, $93af1276, $1faa9912
exception number  : 1
exception class   : EExternalException
exception message : External exception C0000006.

main thread ($98c):
00511cd8 +0000 FlashFXP.exe ComObj                      OleCheck
00514bf5 +0049 FlashFXP.exe UPTShellUtils     1994   +6 PtFlushDriveInfoCache
0064b72f +002b FlashFXP.exe UPTShellControls 10542   +5 TPTCustomShellList.TimerElapsed
00632843 +000f FlashFXP.exe TimerEx                     TTimerEx.Timer
00632670 +0040 FlashFXP.exe TimerEx                     TTimerEx.AppWinProcEx
0044be41 +0051 FlashFXP.exe Forms             6675   +4 TApplication.WndProc
00443c9c +0014 FlashFXP.exe Forms             1529   +8 StdWndProc
77d196c2 +000a user32.dll                               DispatchMessageA
0044ca9f +008b FlashFXP.exe Forms             7117  +34 TApplication.ProcessMessage
0044cad6 +000a FlashFXP.exe Forms             7155   +1 TApplication.HandleMessage
0044cd8b +00bf FlashFXP.exe Forms             7259  +26 TApplication.Run
007964ed +1c69 FlashFXP.exe FlashFXP           920 +630 initialization

thread $698:
7c92df48 +00a ntdll.dll                              NtWaitForMultipleObjects
7c80958a +000 kernel32.dll                           WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll                           WaitForMultipleObjects
00640bd3 +07b FlashFXP.exe UPTShellControls 4370 +13 TChangeHandlerThread.Execute
0041bfc1 +22d FlashFXP.exe Classes                   HexToBin
00404080 +028 FlashFXP.exe System                    ThreadWrapper

thread $ecc:
7c92df48 +00a ntdll.dll                  NtWaitForMultipleObjects
7c80958a +000 kernel32.dll               WaitForMultipleObjectsEx
7c80a110 +013 kernel32.dll               WaitForMultipleObjects
00662068 +10c FlashFXP.exe SaveToFileThd TSaveFileWorker.Execute
0041bfc1 +22d FlashFXP.exe Classes       HexToBin
00404080 +028 FlashFXP.exe System        ThreadWrapper

thread $fc4:
7c92d218 +a ntdll.dll  NtDelayExecution

modules:
00400000 FlashFXP.exe                     4.0.0.1534       K:\ù\flashftp
02c50000 Normaliz.dll                     6.0.5441.0       C:\WINDOWS\system32
032e0000 browserhook.dll                  4.0.1.1          C:\Program Files\IQIYI Video\LStyle\6.1.55.5138\Accelerator
03350000 api-ms-win-core-synch-l1-2-0.dll 10.0.10137.0     C:\WINDOWS\system32
033f0000 ssleay32.dll                     1.0.0.3          K:\ù\flashftp
03470000 libeay32.dll                     1.0.0.3          K:\ù\flashftp
07160000 audiodev.dll                     5.2.5721.5262    C:\WINDOWS\system32
10000000 360UDiskGuard.dll                2.0.0.1241       C:\Program Files\360\360Safe\safemon
10930000 PortableDeviceApi.dll            5.2.5721.5262    C:\WINDOWS\system32
11c70000 WMASF.DLL                        11.0.5721.5262   C:\WINDOWS\system32
15110000 WMVCore.DLL                      11.0.5721.5275   C:\WINDOWS\system32
16500000 wpdshext.dll                     5.2.5721.5262    C:\WINDOWS\system32
1f840000 odbcint.dll                      3.525.1117.0     C:\WINDOWS\system32
3e410000 WININET.dll                      8.0.6001.23942   C:\WINDOWS\system32
3eab0000 iertutil.dll                     8.0.6001.23942   C:\WINDOWS\system32
3eca0000 ieframe.dll                      8.0.6001.23942   C:\WINDOWS\system32
43ce0000 urlmon.dll                       8.0.6001.23942   C:\WINDOWS\system32
4ae90000 gdiplus.dll                      5.2.6002.24064   C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.24064_x-ww_22782591
5adc0000 uxtheme.dll                      6.0.2900.5512    C:\WINDOWS\system32
5efe0000 olepro32.dll                     5.1.2600.5512    C:\WINDOWS\system32
5fdd0000 NETAPI32.dll                     5.1.2600.6260    C:\WINDOWS\system32
60fd0000 hnetcfg.dll                      5.1.2600.5512    C:\WINDOWS\system32
62c20000 LPK.DLL                          5.1.2600.5512    C:\WINDOWS\system32
68000000 rsaenh.dll                       5.1.2600.5507    C:\WINDOWS\system32
68100000 dssenh.dll                       5.1.2600.5507    C:\WINDOWS\system32
6bd10000 msohevi.dll                      12.0.4518.1014   C:\Program Files\Microsoft Office\Office12
719c0000 mswsock.dll                      5.1.2600.5625    C:\WINDOWS\system32
71a00000 wshtcpip.dll                     5.1.2600.5512    C:\WINDOWS\System32
71a10000 WS2HELP.dll                      5.1.2600.5512    C:\WINDOWS\system32
71a20000 WS2_32.dll                       5.1.2600.5512    C:\WINDOWS\system32
71a40000 wsock32.dll                      5.1.2600.5512    C:\WINDOWS\system32
71a90000 MPR.dll                          5.1.2600.5512    C:\WINDOWS\system32
71b70000 SAMLIB.dll                       5.1.2600.5512    C:\WINDOWS\system32
71b90000 ntlanman.dll                     5.1.2600.5512    C:\WINDOWS\System32
71c00000 NETRAP.dll                       5.1.2600.5512    C:\WINDOWS\System32
71c10000 NETUI1.dll                       5.1.2600.5512    C:\WINDOWS\System32
71c50000 NETUI0.dll                       5.1.2600.5512    C:\WINDOWS\System32
72f70000 winspool.drv                     5.1.2600.5512    C:\WINDOWS\system32
73540000 ODBC32.dll                       3.525.3012.0     C:\WINDOWS\system32
73640000 msctfime.ime                     5.1.2600.5768    C:\WINDOWS\system32
73ce0000 shgina.dll                       6.0.2900.5512    C:\WINDOWS\system32
73fa0000 USP10.dll                        1.420.2600.7209  C:\WINDOWS\system32
74680000 MSCTF.dll                        5.1.2600.5512    C:\WINDOWS\system32
75430000 CRYPTUI.dll                      5.131.2600.5512  C:\WINDOWS\system32
758d0000 MSGINA.dll                       5.1.2600.5512    C:\WINDOWS\system32
759d0000 USERENV.dll                      5.1.2600.5512    C:\WINDOWS\system32
75ed0000 drprov.dll                       5.1.2600.5512    C:\WINDOWS\System32
75ee0000 davclnt.dll                      5.1.2600.5512    C:\WINDOWS\System32
75ef0000 browseui.dll                     6.0.2900.6347    C:\WINDOWS\system32
76060000 SETUPAPI.dll                     5.1.2600.5512    C:\WINDOWS\system32
762d0000 WINSTA.dll                       5.1.2600.5512    C:\WINDOWS\system32
76300000 IMM32.DLL                        5.1.2600.5512    C:\WINDOWS\system32
76320000 comdlg32.dll                     6.0.2900.5512    C:\WINDOWS\system32
76570000 CSCDLL.dll                       5.1.2600.5512    C:\WINDOWS\System32
76590000 cscui.dll                        5.1.2600.5512    C:\WINDOWS\System32
765e0000 crypt32.dll                      5.131.2600.6459  C:\WINDOWS\system32
76960000 ntshrui.dll                      5.1.2600.5512    C:\WINDOWS\system32
76990000 ole32.dll                        5.1.2600.6435    C:\WINDOWS\system32
76af0000 ATL.DLL                          3.5.2284.2       C:\WINDOWS\system32
76b10000 winmm.dll                        5.1.2600.6160    C:\WINDOWS\system32
76bc0000 psapi.dll                        5.1.2600.5512    C:\WINDOWS\system32
76c00000 WINTRUST.dll                     5.131.2600.6285  C:\WINDOWS\system32
76c60000 IMAGEHLP.dll                     5.1.2600.6479    C:\WINDOWS\system32
76d30000 IPHLPAPI.DLL                     5.1.2600.5512    C:\WINDOWS\system32
76d70000 appHelp.dll                      5.1.2600.5512    C:\WINDOWS\system32
76db0000 MSASN1.dll                       5.1.2600.5875    C:\WINDOWS\system32
76f30000 WLDAP32.dll                      5.1.2600.5512    C:\WINDOWS\system32
76fa0000 CLBCATQ.DLL                      2001.12.4414.700 C:\WINDOWS\system32
77020000 COMRes.dll                       2001.12.4414.700 C:\WINDOWS\system32
770f0000 oleaut32.dll                     5.1.2600.6341    C:\WINDOWS\system32
77180000 comctl32.dll                     6.0.2900.6028    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202
77bd0000 version.dll                      5.1.2600.5512    C:\WINDOWS\system32
77be0000 msvcrt.dll                       7.0.2600.5512    C:\WINDOWS\system32
77d10000 user32.dll                       5.1.2600.5512    C:\WINDOWS\system32
77da0000 advapi32.dll                     5.1.2600.5755    C:\WINDOWS\system32
77e50000 RPCRT4.dll                       5.1.2600.6477    C:\WINDOWS\system32
77ef0000 GDI32.dll                        5.1.2600.7209    C:\WINDOWS\system32
77f40000 SHLWAPI.dll                      6.0.2900.5912    C:\WINDOWS\system32
77fc0000 Secur32.dll                      5.1.2600.5834    C:\WINDOWS\system32
78130000 MSVCR80.dll                      8.0.50727.6195   C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86
7c800000 kernel32.dll                     5.1.2600.6532    C:\WINDOWS\system32
7c920000 ntdll.dll                        5.1.2600.6055    C:\WINDOWS\system32
7d590000 shell32.dll                      6.0.2900.6242    C:\WINDOWS\system32
7e550000 shdocvw.dll                      6.0.2900.6347    C:\WINDOWS\system32

processes:
0000 Idle                  0    0
0004 System                0    0    normal
0338 smss.exe              0    0    normal C:\WINDOWS\system32
037c csrss.exe             0    0
03a4 winlogon.exe          46   14   high   C:\WINDOWS\system32
03d0 services.exe          4    2    normal C:\WINDOWS\system32
03dc lsass.exe             6    4    normal C:\WINDOWS\system32
0484 nvsvc32.exe           16   4    normal C:\WINDOWS\system32
04a0 svchost.exe           4    1    normal C:\WINDOWS\system32
04e4 svchost.exe           0    0
0544 svchost.exe           11   30   normal C:\WINDOWS\System32
05d4 svchost.exe           0    0
05fc svchost.exe           0    0
061c zhudongfangyu.exe     4    2    normal C:\Program Files\360\360Safe\deepscan
0794 spoolsv.exe           4    4    normal C:\WINDOWS\system32
07f8 inetinfo.exe          4    4    normal C:\WINDOWS\system32\inetsrv
0210 QQProtect.exe         4    27   normal C:\Program Files\Common Files\Tencent\QQProtect\Bin
07ec Explorer.EXE          522  365  normal C:\WINDOWS
0280 360Tray.exe           297  85   normal C:\Program Files\360\360Safe\safemon
02e8 ctfmon.exe            28   12   normal C:\WINDOWS\system32
030c 360sd.exe             496  234  normal C:\Program Files\360\360sd
02f8 YunDetectService.exe  11   5    normal C:\Program Files\baidu\BaiduNetdisk
074c QyKernel.exe          17   13   normal C:\Program Files\IQIYI Video\LStyle\6.1.55.5138
0d88 360rp.exe             7    3    normal C:\Program Files\360\360sd
0d9c SoftMgrLite.exe       23   37   normal C:\Program Files\360\360Safe\SoftMgr\SML
0e10 QyFragment.exe        28   41   normal C:\Program Files\IQIYI Video\LStyle\6.1.55.5138
08fc conime.exe            0    0    normal
1080 svchost.exe           4    1    normal C:\WINDOWS\System32
1230 AndroidService.exe    4    1    normal C:\Program Files\IQIYI Video\LStyle\6.1.55.5138\QYAppPlugin\mobileassistantplugin
1650 rundll32.exe          17   8    normal C:\WINDOWS\system32
16c8 conime.exe            15   11   normal C:\WINDOWS\system32
05b0 360se.exe             332  114  normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
0b60 wdswfsafe.exe         4    4    normal C:\Program Files\360\360Safe\safemon
1718 360se.exe             4    1    normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
08e8 phpStudy.exe          188  135  normal E:\phpStudy
14b8 httpd.exe             4    1    normal E:\phpStudy\Apache\bin
1538 mysqld.exe            4    2    normal E:\phpStudy\mysql\bin
0bf0 httpd.exe             11   12   normal E:\phpStudy\Apache\bin
0580 360se.exe             590  6    normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
0bb4 360MobileMgr.exe      419  108  normal C:\Program Files\360\360Safe\mobilemgr
05bc 360MobileLink.exe     163  75   normal C:\Program Files\360\360Safe\mobilemgr
1500 Dreamweaver.exe       1074 1059 normal C:\Program Files\Adobe\Adobe Dreamweaver CS6
09cc CS6ServiceManager.exe 8    5    normal C:\Program Files\Common Files\Adobe\CS6ServiceManager
1708 360se.exe             18   317  normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
11ec 360se.exe             604  5    normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
0438 360se.exe             118  5    normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
0300 360se.exe             108  5    normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
1724 360se.exe             478  5    normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
123c SogouCloud.exe        8    5    normal C:\Program Files\SogouInput\8.6.0.1634
00f8 FlashFXP.exe          233  174  normal K:\ù\flashftp
168c 360se.exe             416  5    normal C:\Documents and Settings\Administrator\Application Data\360se6\Application
1bc8 QQ.exe                75   181  normal H:\ù\Tencent\QQ\Bin
1984 TXPlatform.exe        8    5    normal H:\ù\Tencent\QQ\Bin
1eb4 WeChat.exe            155  53   normal H:\ù\WeChat
18ac AndroidServer.exe     13   20   normal C:\Documents and Settings\Administrator\Application Data\Tencent\AndroidServer\1.0.0.584
1f5c tadb.exe              4    1    normal C:\Documents and Settings\Administrator\Application Data\Tencent\AndroidServer\1.0.0.584

hardware:
+ DVD/CD-ROM 
  - PIONEER DVD-RW  DVR-219L
+ IDE ATA/ATAPI 
  - Intel(R) ICH10 Family 6 Port SATA AHCI Controller - 3A22 (driver 9.1.9.1005)
+ 
  - Intel(R) Xeon(R) CPU           L5640  @ 2.27GHz
  - Intel(R) Xeon(R) CPU           L5640  @ 2.27GHz
  - Intel(R) Xeon(R) CPU           L5640  @ 2.27GHz
  - Intel(R) Xeon(R) CPU           L5640  @ 2.27GHz
  - Intel(R) Xeon(R) CPU           L5640  @ 2.27GHz
  - Intel(R) Xeon(R) CPU           L5640  @ 2.27GHz
  - Intel(R) Xeon(R) CPU           L5640  @ 2.27GHz
  - Intel(R) Xeon(R) CPU           L5640  @ 2.27GHz
  - Intel(R) Xeon(R) CPU           L5640  @ 2.27GHz
  - Intel(R) Xeon(R) CPU           L5640  @ 2.27GHz
  - Intel(R) Xeon(R) CPU           L5640  @ 2.27GHz
  - Intel(R) Xeon(R) CPU           L5640  @ 2.27GHz
+ 
  - ST3500413AS
  - WD Elements 1042 USB Device
  - WDC WD3200AAKS-61L9A0
+ ˿ (COM  LPT)
  - ͨѶ˿ (COM1)
+ 
  - 弴ü
+ 
  - ACPI Multiprocessor PC
+ 
  - HID Keyboard Device
  - HID Keyboard Device
  - HID Keyboard Device
  - HID Keyboard Device
+ ѧ豸
  - HID-compliant device
  - HID-compliant device
  - USB ѧ豸
  - USB ѧ豸
  - USB ѧ豸
  -  HID ׼û豸
+ ƵϷ
  - NVIDIA High Definition Audio (driver 1.3.34.17)
  - NVIDIA High Definition Audio (driver 1.3.34.17)
  - NVIDIA High Definition Audio (driver 1.3.34.17)
  - NVIDIA High Definition Audio (driver 1.3.34.17)
  - Realtek High Definition Audio (driver 5.10.0.6873)
  - ͳƵ׽豸
  - ͳƵ
  - ý豸
  - Ƶ
  - Ƶ
+ ָ豸
  - HID-compliant mouse
+ ͨô߿
  - Intel(R) ICH10 Family USB Enhanced Host Controller - 3A3A (driver 9.1.9.1006)
  - Intel(R) ICH10 Family USB Enhanced Host Controller - 3A3C (driver 9.1.9.1006)
  - Intel(R) ICH10 Family USB Universal Host Controller - 3A34 (driver 9.1.9.1006)
  - Intel(R) ICH10 Family USB Universal Host Controller - 3A35 (driver 9.1.9.1006)
  - Intel(R) ICH10 Family USB Universal Host Controller - 3A36 (driver 9.1.9.1006)
  - Intel(R) ICH10 Family USB Universal Host Controller - 3A37 (driver 9.1.9.1006)
  - Intel(R) ICH10 Family USB Universal Host Controller - 3A38 (driver 9.1.9.1006)
  - Intel(R) ICH10 Family USB Universal Host Controller - 3A39 (driver 9.1.9.1006)
  - USB Composite Device
  - USB Mass Storage Device
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
+ 
  - Realtek PCIe GBE Family Controller (driver 5.824.107.2014)
+ ϵͳ豸
  - ACPI Fixed Feature Button
  - ACPI Power Button
  - Direct memory access controller
  - Intel(R) 5520/5500/X58 I/O Hub to ESI Port - 3406 (driver 9.1.9.1005)
  - Intel(R) 7500/5520/5500/X58 I/O Hub Control Status and RAS Registers - 3423 (driver 9.1.9.1005)
  - Intel(R) 7500/5520/5500/X58 I/O Hub GPIO and Scratch Pad Registers - 3422 (driver 9.1.9.1005)
  - Intel(R) 7500/5520/5500/X58 I/O Hub PCI Express Root Port 1 - 3408 (driver 9.1.9.1005)
  - Intel(R) 7500/5520/5500/X58 I/O Hub PCI Express Root Port 3 - 340A - 340a (driver 9.1.9.1005)
  - Intel(R) 7500/5520/5500/X58 I/O Hub PCI Express Root Port 7 - 340E - 340e (driver 9.1.9.1005)
  - Intel(R) 7500/5520/5500/X58 I/O Hub System Management Registers - 342E - 342e (driver 9.1.9.1005)
  - Intel(R) 7500/5520/5500/X58 I/O Hub Throttle Registers - 3438 (driver 9.1.9.1005)
  - Intel(R) 82801 PCI Bridge - 244E (driver 7.0.0.1011)
  - Intel(R) ICH10 Family PCI Express Root Port 1 - 3A40 (driver 9.1.9.1005)
  - Intel(R) ICH10 Family PCI Express Root Port 3 - 3A44 (driver 9.1.9.1005)
  - Intel(R) ICH10 Family SMBus Controller - 3A30 (driver 9.1.9.1005)
  - Intel(R) ICH10 LPC Interface Controller - 3A18 (driver 9.1.9.1005)
  - ISAPNP Read Data Port
  - Logical Disk Manager
  - Microcode Update Device
  - Microsoft ACPI-Compliant System
  - Microsoft Composite Battery
  - Microsoft System Management BIOS Driver
  - Microsoft  High Definition Audio  UAA 
  - Microsoft  High Definition Audio  UAA 
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Numeric data processor
  - PCI bus
  - Plug and Play Software Device Enumerator
  - Programmable interrupt controller
  - System board
  - System board
  - System CMOS/real time clock
  - System speaker
  - System timer
  - Terminal Server Device Redirector
  - Terminal Server Keyboard Driver
  - Terminal Server Mouse Driver
  - Volume Manager
  - ̨ȫʾƵ
+ ʾ
  - NVIDIA GeForce GTX 750 Ti (driver 6.14.13.3182)

cpu registers:
eax = 00000000
ebx = 00f94a90
ecx = 0012fd58
edx = 00000016
esi = 00000002
edi = 00f85120
eip = 00511cd8
esp = 0012fd38
ebp = 0012fd64

stack dump:
0012fd38  fa 4b 51 00 48 fd 12 00 - ac 3a 40 00 64 fd 12 00  .KQ.H....:@.d...
0012fd48  80 fd 12 00 ac 3a 40 00 - 64 fd 12 00 35 01 00 00  .....:@.d...5...
0012fd58  f0 63 6f 03 00 00 00 00 - 8a e1 d3 77 70 fd 12 00  .co........wp...
0012fd68  34 b7 64 00 70 59 11 03 - a0 fd 12 00 46 28 63 00  4.d.pY......F(c.
0012fd78  34 28 63 00 75 26 63 00 - a8 fd 12 00 1e 39 40 00  4(c.u&c......9@.
0012fd88  a0 fd 12 00 20 51 f8 00 - 02 00 00 00 0c 00 00 00  .....Q..........
0012fd98  0c 00 00 00 90 4a f9 00 - d8 fd 12 00 43 be 44 00  .....J......C.D.
0012fda8  74 fe 12 00 3d c6 44 00 - d8 fd 12 00 58 fe 12 00  t...=.D.....X...
0012fdb8  ef 0f 00 01 00 00 00 00 - 58 63 45 00 3a 47 c0 1c  ........XcE.:G..
0012fdc8  1c fe 12 00 50 fe 2f 03 - e0 fd 12 00 30 80 f6 00  ....P./.....0...
0012fdd8  f0 fd 12 00 9e 3c 44 00 - 13 01 00 00 4f 04 00 00  .....<D.....O...
0012fde8  00 00 00 00 00 00 00 00 - 1c fe 12 00 34 87 d1 77  ............4..w
0012fdf8  00 0d 05 00 13 01 00 00 - 4f 04 00 00 00 00 00 00  ........O.......
0012fe08  ef 0f 00 01 cd ab ba dc - 00 00 00 00 58 fe 12 00  ............X...
0012fe18  ef 0f 00 01 84 fe 12 00 - 16 88 d1 77 ef 0f 00 01  ...........w....
0012fe28  00 0d 05 00 13 01 00 00 - 4f 04 00 00 00 00 00 00  ........O.......
0012fe38  1c ff 12 00 14 ff 12 00 - 30 81 b8 00 14 00 00 00  ........0.......
0012fe48  01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00  ................
0012fe58  00 00 00 00 30 00 00 00 - 01 00 00 00 00 00 00 00  ....0...........
0012fe68  00 00 00 00 38 fe 12 00 - 00 0d 05 00 d4 fe 12 00  ....8...........

disassembling:
[...]
00514bb7        xor     eax, eax
00514bb9        push    ebp
00514bba        push    $514c5c                ; System.@HandleFinally
00514bbf        push    dword ptr fs:[eax]
00514bc2        mov     fs:[eax], esp
00514bc5 1989   cmp     dword ptr [$7bc32c], 0
00514bcc        jnz     loc_514c46
00514bce 1992   xor     eax, eax
00514bd0        mov     [ebp-$c], eax
00514bd3        lea     eax, [ebp-8]
00514bd6        call    -$10e697 ($406544)     ; System.@IntfClear
00514bdb 1993   xor     eax, eax
00514bdd        push    ebp
00514bde        push    $514c3f                ; System.@HandleFinally
00514be3        push    dword ptr fs:[eax]
00514be6        mov     fs:[eax], esp
00514be9 1994   lea     ecx, [ebp-$c]
00514bec        mov     dl, $11
00514bee        xor     eax, eax
00514bf0        call    -$10c9 ($513b2c)       ; UPTShellUtils.ShellGetSpecialFolderIdList
00514bf5      > call    -$2f22 ($511cd8)       ; ComObj.OleCheck
00514bfa 1995   lea     edx, [ebp-8]
00514bfd        mov     eax, [ebp-$c]
00514c00        call    -$143d ($5137c8)       ; UPTShellUtils.ShellGetFolderFromIdList
00514c05        call    -$2f32 ($511cd8)       ; ComObj.OleCheck
00514c0a 1996   mov     dword ptr [ebp-$10], $1000000
00514c11 1997   xor     eax, eax
00514c13        mov     [ebp-4], eax
00514c16 1998   lea     eax, [ebp-$10]
00514c19        push    eax
00514c1a        lea     eax, [ebp-4]
00514c1d        push    eax
00514c1e        push    0
00514c20        mov     eax, [ebp-8]
00514c23        push    eax
00514c24        mov     eax, [eax]
00514c26        call    dword ptr [eax+$24]
00514c29        xor     eax, eax
00514c2b        pop     edx
00514c2c        pop     ecx
00514c2d        pop     ecx
[...]

date/time         : 2020-07-09, 11:41:36, 947ms
computer name     : SC-202004221433
user name         : Administrator
registered owner  : 123
operating system  : Windows NT New x64 (6.2.9200) build 9200
system language   : Chinese (Simplified)
system up time    : 3 hours 13 minutes
program up time   : 1 minute 15 seconds
processors        : 8x Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz
physical memory   : 11670/16274 MB (free/total)
free disk space   : (C:) 43.19 GB (H:) 13.95 GB
display mode      : 1920x1080, 32 bit
process id        : $2cc8
allocated memory  : 41.92 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $392841d5, $c2e144a8, $8189405d
exception number  : 1
exception class   : EAccessViolation
exception message : Access violation at address 0073A8DB in module 'FlashFXP.exe'. ȡ of address 0F800047.

main thread ($3e44):
0073a8db +0047 FlashFXP.exe FrmMain1 10238   +5 TFrmMain.mnuRefreshClick
0041cb83 +000f FlashFXP.exe Classes             TBasicAction.Execute
0046459d +0031 FlashFXP.exe ActnList            TContainedAction.Execute
00464e52 +0012 FlashFXP.exe ActnList            TCustomAction.Execute
004648df +004b FlashFXP.exe ActnList            TCustomActionList.IsShortCut
00449ebc +003c FlashFXP.exe Forms     5034   +3 DispatchShortCut
00449f34 +0060 FlashFXP.exe Forms     5045   +3 TCustomForm.IsShortCut
0077b779 +0009 FlashFXP.exe FrmMain1 32669   +0 TFrmMain.IsShortCut
0045835e +0066 FlashFXP.exe Controls            TWinControl.IsMenuKey
0045839e +0012 FlashFXP.exe Controls            TWinControl.CNKeyDown
00453e35 +0111 FlashFXP.exe Controls            TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls            TWinControl.WndProc
0043e3bd +013d FlashFXP.exe StdCtrls            TCustomComboBox.WndProc
00509afb +003f FlashFXP.exe ThemeMgr            TWindowProcList.DispatchMessage
0050b7ba +007e FlashFXP.exe ThemeMgr            TThemeManager.WinControlWindowProc
0050b9c9 +0009 FlashFXP.exe ThemeMgr            TThemeManager.PreWinControlWindowProc
0045632c +002c FlashFXP.exe Controls            TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms     1529   +8 StdWndProc
76d012e4 +0044 user32.dll                       SendMessageA
0044c934 +0050 FlashFXP.exe Forms     7051  +11 TApplication.IsKeyMsg
0044ca82 +006e FlashFXP.exe Forms     7113  +30 TApplication.ProcessMessage
0044cad6 +000a FlashFXP.exe Forms     7155   +1 TApplication.HandleMessage
0044cd8b +00bf FlashFXP.exe Forms     7259  +26 TApplication.Run
007964ed +1c69 FlashFXP.exe FlashFXP   920 +630 initialization
7674f987 +0017 KERNEL32.DLL                     BaseThreadInitThunk

thread $3604:
7674f987 +17 KERNEL32.DLL  BaseThreadInitThunk

thread $39bc:
7674f987 +17 KERNEL32.DLL  BaseThreadInitThunk

thread $4224:
771a961d +fd KERNELBASE.dll  WaitForMultipleObjectsEx
7674f987 +17 KERNEL32.DLL    BaseThreadInitThunk

thread $2d28:
771a961d +0fd KERNELBASE.dll                           WaitForMultipleObjectsEx
771a9503 +013 KERNELBASE.dll                           WaitForMultipleObjects
00640bd3 +07b FlashFXP.exe   UPTShellControls 4370 +13 TChangeHandlerThread.Execute
0041bfc4 +230 FlashFXP.exe   Classes                   HexToBin
00404080 +028 FlashFXP.exe   System                    ThreadWrapper
7674f987 +017 KERNEL32.DLL                             BaseThreadInitThunk

thread $2f14:
7674f987 +17 KERNEL32.DLL  BaseThreadInitThunk

thread $432c:
7674f987 +17 KERNEL32.DLL  BaseThreadInitThunk

thread $32c8: <priority:1>
7674f987 +17 KERNEL32.DLL  BaseThreadInitThunk

thread $38e4:
7674f987 +17 KERNEL32.DLL  BaseThreadInitThunk

thread $3cc8:
7674f987 +17 KERNEL32.DLL  BaseThreadInitThunk

thread $247c:
7674f987 +17 KERNEL32.DLL  BaseThreadInitThunk

thread $2ff0:
76d18e77 +47 user32.dll    MsgWaitForMultipleObjectsEx
7674f987 +17 KERNEL32.DLL  BaseThreadInitThunk

thread $41d4:
771a961d +0fd KERNELBASE.dll               WaitForMultipleObjectsEx
771a9503 +013 KERNELBASE.dll               WaitForMultipleObjects
00662068 +10c FlashFXP.exe   SaveToFileThd TSaveFileWorker.Execute
0041bfc4 +230 FlashFXP.exe   Classes       HexToBin
00404080 +028 FlashFXP.exe   System        ThreadWrapper
7674f987 +017 KERNEL32.DLL                 BaseThreadInitThunk

modules:
00400000 FlashFXP.exe                  4.0.0.1534          H:\ù߰\flashftp
04c40000 ssleay32.dll                  1.0.0.3             H:\ù߰\flashftp
10000000 libeay32.dll                  1.0.0.3             H:\ù߰\flashftp
500b0000 msvcp110_win.dll              6.2.19041.1         C:\WINDOWS\SYSTEM32
50120000 policymanager.dll             6.2.19041.1         C:\WINDOWS\SYSTEM32
501a0000 thumbcache.dll                6.2.19041.1         C:\Windows\System32
62210000 dxgi.dll                      6.2.19041.1         C:\WINDOWS\system32
622e0000 dcomp.dll                     6.2.19041.264       C:\WINDOWS\system32
62450000 d3d11.dll                     6.2.19041.1         C:\WINDOWS\system32
62630000 dataexchange.dll              6.2.19041.264       C:\WINDOWS\system32
62b90000 tiptsf.dll                    6.2.19041.329       C:\Program Files (x86)\Common Files\microsoft shared\ink
67620000 dssenh.dll                    6.2.19041.1         C:\WINDOWS\system32
6b660000 sppc.dll                      6.2.19041.1         C:\Windows\System32
6b680000 Bcp47Langs.dll                6.2.19041.1         C:\Windows\System32
6b6d0000 SLC.dll                       6.2.19041.1         C:\Windows\System32
6b6f0000 appresolver.dll               6.2.19041.264       C:\Windows\System32
6b760000 Windows.StateRepositoryPS.dll 6.2.19041.329       C:\Windows\System32
6b8b0000 TextShaping.dll                                   C:\WINDOWS\SYSTEM32
6bff0000 twinapi.appcore.dll           6.2.19041.264       C:\WINDOWS\system32
6d260000 wintypes.dll                  6.2.19041.329       C:\WINDOWS\SYSTEM32
6d340000 CoreMessaging.dll             6.2.19041.264       C:\WINDOWS\System32
6d500000 CoreUIComponents.dll          6.2.19041.1         C:\WINDOWS\System32
6d780000 textinputframework.dll        6.2.19041.1         C:\WINDOWS\SYSTEM32
6e370000 wsock32.dll                   6.2.19041.1         C:\WINDOWS\SYSTEM32
6e490000 LINKINFO.dll                  6.2.19041.1         C:\WINDOWS\SYSTEM32
6f640000 WindowsCodecs.dll             6.2.19041.207       C:\WINDOWS\SYSTEM32
6fba0000 olepro32.dll                  6.2.19041.84        C:\WINDOWS\SYSTEM32
6feb0000 uxtheme.dll                   6.2.19041.1         C:\WINDOWS\system32
70b40000 winspool.drv                  6.2.19041.1         C:\WINDOWS\SYSTEM32
71130000 comctl32.dll                  6.10.19041.1        C:\WINDOWS\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1_none_fd031af45b0106f2
71340000 cscapi.dll                    6.2.19041.1         C:\WINDOWS\SYSTEM32
71350000 ntshrui.dll                   6.2.19041.1         C:\WINDOWS\SYSTEM32
713b0000 apphelp.dll                   6.2.19041.1         C:\WINDOWS\SYSTEM32
71c20000 winrnr.dll                    6.2.19041.1         C:\WINDOWS\System32
71c30000 SAMLIB.dll                    6.2.19041.1         C:\WINDOWS\SYSTEM32
71c50000 NLAapi.dll                    6.2.19041.1         C:\WINDOWS\system32
71c70000 wshbth.dll                    6.2.19041.1         C:\WINDOWS\system32
71c80000 pnrpnsp.dll                   6.2.19041.1         C:\WINDOWS\system32
71ca0000 napinsp.dll                   6.2.19041.1         C:\WINDOWS\system32
71cc0000 WINNSI.DLL                    6.2.19041.1         C:\WINDOWS\SYSTEM32
71cd0000 ondemandconnroutehelper.dll   6.2.19041.1         C:\WINDOWS\SYSTEM32
71cf0000 ntmarta.dll                   6.2.19041.1         C:\WINDOWS\SYSTEM32
71ee0000 fwpuclnt.dll                  6.2.19041.1         C:\WINDOWS\System32
71f40000 rasadhlp.dll                  6.2.19041.1         C:\Windows\System32
71fc0000 propsys.dll                   7.0.19041.1         C:\WINDOWS\system32
72a30000 mswsock.dll                   6.2.19041.1         C:\WINDOWS\system32
72b40000 profapi.dll                   6.2.19041.1         C:\WINDOWS\SYSTEM32
72cd0000 iertutil.dll                  11.0.19041.1        C:\WINDOWS\SYSTEM32
72f30000 wininet.dll                   11.0.19041.117      C:\WINDOWS\SYSTEM32
73b90000 MSASN1.dll                    6.2.19041.1         C:\WINDOWS\SYSTEM32
73ba0000 winhttp.dll                   6.2.19041.264       C:\WINDOWS\SYSTEM32
73c70000 srvcli.dll                    6.2.19041.1         C:\WINDOWS\SYSTEM32
741e0000 rsaenh.dll                    6.2.19041.1         C:\WINDOWS\system32
742a0000 DNSAPI.dll                    6.2.19041.1         C:\WINDOWS\SYSTEM32
74580000 windows.storage.dll           6.2.19041.329       C:\WINDOWS\SYSTEM32
74bc0000 CRYPTBASE.dll                 6.2.19041.1         C:\WINDOWS\SYSTEM32
74bd0000 CRYPTSP.dll                   6.2.19041.1         C:\WINDOWS\SYSTEM32
74c00000 Wldp.dll                      6.2.19041.1         C:\WINDOWS\SYSTEM32
74c30000 kernel.appcore.dll            6.2.19041.1         C:\WINDOWS\SYSTEM32
74c40000 samcli.dll                    6.2.19041.1         C:\WINDOWS\SYSTEM32
74c60000 netutils.dll                  6.2.19041.1         C:\WINDOWS\SYSTEM32
74d30000 SSPICLI.DLL                   6.2.19041.1         C:\WINDOWS\SYSTEM32
74d60000 Secur32.dll                   6.2.19041.1         C:\WINDOWS\SYSTEM32
74e00000 winmm.dll                     6.2.19041.1         C:\WINDOWS\SYSTEM32
75100000 IPHLPAPI.DLL                  6.2.19041.1         C:\WINDOWS\SYSTEM32
75240000 USERENV.dll                   6.2.19041.1         C:\Windows\System32
75270000 version.dll                   6.2.19041.1         C:\WINDOWS\SYSTEM32
75290000 IMM32.DLL                     6.2.19041.1         C:\WINDOWS\System32
752c0000 combase.dll                   6.2.19041.329       C:\WINDOWS\System32
75540000 msvcp_win.dll                 6.2.19041.1         C:\WINDOWS\System32
755d0000 MSCTF.dll                     6.2.19041.329       C:\WINDOWS\System32
756b0000 shell32.dll                   6.2.19041.329       C:\WINDOWS\System32
75dd0000 ucrtbase.dll                  6.2.19041.1         C:\WINDOWS\System32
75f20000 CFGMGR32.dll                  6.2.19041.1         C:\WINDOWS\System32
75f60000 sechost.dll                   6.2.19041.1         C:\WINDOWS\System32
76070000 crypt32.dll                   6.2.19041.21        C:\WINDOWS\System32
76170000 msvcrt.dll                    7.0.19041.1         C:\WINDOWS\System32
766d0000 bcryptPrimitives.dll          6.2.19041.264       C:\WINDOWS\System32
76730000 KERNEL32.DLL                  6.2.19041.292       C:\WINDOWS\System32
76820000 GDI32.dll                     6.2.19041.1         C:\WINDOWS\System32
768a0000 SHLWAPI.dll                   6.2.19041.1         C:\WINDOWS\System32
768f0000 comdlg32.dll                  6.2.19041.329       C:\WINDOWS\System32
769a0000 WS2_32.dll                    6.2.19041.1         C:\WINDOWS\System32
76a10000 ole32.dll                     6.2.19041.84        C:\WINDOWS\System32
76b60000 oleaut32.dll                  6.2.19041.329       C:\WINDOWS\System32
76c00000 advapi32.dll                  6.2.19041.1         C:\WINDOWS\System32
76ce0000 user32.dll                    6.2.19041.264       C:\WINDOWS\System32
76e80000 clbcatq.dll                   2001.12.10941.16384 C:\WINDOWS\System32
76f00000 shcore.dll                    6.2.19041.264       C:\WINDOWS\System32
76f90000 gdi32full.dll                 6.2.19041.329       C:\WINDOWS\System32
77070000 bcrypt.dll                    6.2.19041.1         C:\WINDOWS\System32
77090000 KERNELBASE.dll                6.2.19041.329       C:\WINDOWS\System32
772b0000 RPCRT4.dll                    6.2.19041.1         C:\WINDOWS\System32
77370000 NSI.dll                       6.2.19041.1         C:\WINDOWS\System32
77380000 win32u.dll                    6.2.19041.329       C:\WINDOWS\System32
773b0000 ntdll.dll                     6.2.19041.207       C:\WINDOWS\SYSTEM32
7af80000 explorerframe.dll             6.2.19041.329       C:\WINDOWS\system32

processes:
0000 Idle                        0 0   0
0004 System                      0 0   0
008c Registry                    0 0   0
01c0 smss.exe                    0 0   0
0318 csrss.exe                   0 0   0
03d4 wininit.exe                 0 0   0
03e4 csrss.exe                   1 0   0
02a8 services.exe                0 0   0
02d0 lsass.exe                   0 0   0
0374 winlogon.exe                1 0   0
0418 svchost.exe                 0 0   0
0430 svchost.exe                 0 0   0
0440 fontdrvhost.exe             1 0   0
0448 fontdrvhost.exe             0 0   0
04a0 svchost.exe                 0 0   0
04d0 svchost.exe                 0 0   0
0518 dwm.exe                     1 0   0
05d0 svchost.exe                 0 0   0
05f8 svchost.exe                 0 0   0
0600 svchost.exe                 0 0   0
066c svchost.exe                 0 0   0
0674 svchost.exe                 0 0   0
06a0 svchost.exe                 0 0   0
06a8 svchost.exe                 0 0   0
06b0 svchost.exe                 0 0   0
06b8 svchost.exe                 0 0   0
06c0 svchost.exe                 0 0   0
06cc svchost.exe                 0 0   0
06e0 svchost.exe                 0 0   0
073c svchost.exe                 0 0   0
0764 svchost.exe                 0 0   0
0770 svchost.exe                 0 0   0
05a8 svchost.exe                 0 0   0
0854 svchost.exe                 0 0   0
087c svchost.exe                 0 0   0
08cc igfxCUIService.exe          0 0   0
08e0 svchost.exe                 0 0   0
0948 svchost.exe                 0 0   0
09f4 svchost.exe                 0 0   0
0a1c svchost.exe                 0 0   0
0a6c svchost.exe                 0 0   0
0abc NVDisplay.Container.exe     0 0   0
0b1c svchost.exe                 0 0   0
0b24 svchost.exe                 0 0   0
0b54 svchost.exe                 0 0   0
0b5c svchost.exe                 0 0   0
0b6c Memory Compression          0 0   0
0bf4 svchost.exe                 0 0   0
09c4 NVDisplay.Container.exe     1 0   0
0c10 svchost.exe                 0 0   0
0c50 svchost.exe                 0 0   0
0d7c svchost.exe                 0 0   0
0dec svchost.exe                 0 0   0
0df4 svchost.exe                 0 0   0
0dfc 360rps.exe                  0 0   0
0e04 ZhuDongFangYu.exe           0 0   0
0e98 svchost.exe                 0 0   0
0ed0 svchost.exe                 0 0   0
0f1c spoolsv.exe                 0 0   0
0f84 svchost.exe                 0 0   0
0fb4 svchost.exe                 0 0   0
1018 IntelCpHDCPSvc.exe          0 0   0
1020 AlibabaProtect.exe          0 0   0
1028 svchost.exe                 0 0   0
1030 svchost.exe                 0 0   0
103c OneApp.IGCC.WinService.exe  0 0   0
104c FlashHelperService.exe      0 0   0
1058 svchost.exe                 0 0   0
1074 svchost.exe                 0 0   0
109c ngslotd.exe                 0 0   0
10ac nvcontainer.exe             0 0   0
10d0 pcas.exe                    0 0   0
10f4 QQProtect.exe               0 0   0
1108 RtkAudUService64.exe        0 0   0
1120 svchost.exe                 0 0   0
1130 RtkBtManServ.exe            0 0   0
115c svchost.exe                 0 0   0
1164 svchost.exe                 0 0   0
1174 svchost.exe                 0 0   0
1184 TeamViewer_Service.exe      0 0   0
11a8 svchost.exe                 0 0   0
11b0 svchost.exe                 0 0   0
11c8 wwbizsrv.exe                0 0   0
1224 IntelCpHeciSvc.exe          0 0   0
13dc svchost.exe                 0 0   0
15f0 rundll32.exe                1 0   0
18cc svchost.exe                 0 0   0
0b9c nvcontainer.exe             1 2   12  normal       C:\Program Files\NVIDIA Corporation\NvContainer
1cb4 sihost.exe                  1 0   8   normal       C:\Windows\System32
1cdc svchost.exe                 1 0   1   normal       C:\Windows\System32
1ce4 svchost.exe                 1 0   1   normal       C:\Windows\System32
1d14 svchost.exe                 1 0   4   normal       C:\Windows\System32
1da0 taskhostw.exe               1 8   6   normal       C:\Windows\System32
1e18 svchost.exe                 0 0   0
1e94 svchost.exe                 0 0   0
1edc NVIDIA Web Helper.exe       1 2   12  below normal C:\Program Files (x86)\NVIDIA Corporation\NvNode
1ef8 igfxEM.exe                  1 10  18  normal       C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_575293f865d051e0
1f04 svchost.exe                 0 0   0
1f38 svchost.exe                 0 0   0
1f60 ctfmon.exe                  1 0   0
1fa8 conhost.exe                 1 10  3   below normal C:\Windows\System32
1ca0 ChsIME.exe                  1 0   0
2038 svchost.exe                 1 0   5   normal       C:\Windows\System32
2148 360wpsrv.exe                1 0   0
2358 RuntimeBroker.exe           1 40  1   normal       C:\Windows\System32
23b4 SearchIndexer.exe           0 0   0
21bc RuntimeBroker.exe           1 36  5   normal       C:\Windows\System32
2544 RuntimeBroker.exe           1 0   1   normal       C:\Windows\System32
2740 explorer.exe                1 0   0
18f8 CNCBUK2WDAdmin.exe          1 0   0
151c D4Svr_CITIC.exe             1 0   0
068c explorer.exe                1 561 423 normal       C:\Windows
202c StartMenuExperienceHost.exe 1 0   13  normal       C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy
24b4 SearchApp.exe               1 12  49  normal       C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy
2024 TextInputHost.exe           1 0   50  normal       C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp
24ec 360tray.exe                 1 0   0
2620 svchost.exe                 0 0   0
1f0c 360Newsld.exe               1 78  7   normal       C:\Users\Administrator\AppData\Roaming\360Safe\SoftMgr
0934 SoftMgrLite.exe             1 0   0
2874 guardhp.exe                 1 0   0
28c0 svchost.exe                 1 0   1   normal       C:\Windows\System32
0690 SgrmBroker.exe              0 0   0
201c svchost.exe                 0 0   0
0524 svchost.exe                 0 0   0
27cc MobileDeviceSrv.exe         1 0   0
0f54 svchost.exe                 0 0   0
24f4 BirdPlayer.exe              1 0   0
2a88 svchost.exe                 0 0   0
1570 svchost.exe                 0 0   0
18b4 360rp.exe                   1 0   0
2350 360sd.exe                   1 0   0
0878 SogouCloud.exe              1 8   9   normal       D:\ù߰\sogoupinyin\9.7.0.3676
0a18 ApplicationFrameHost.exe    1 108 46  normal       C:\Windows\System32
2558 WeChat.exe                  1 358 99  normal       C:\Program Files (x86)\Tencent\WeChat
0f24 WeChat.exe                  1 268 89  normal       C:\Program Files (x86)\Tencent\WeChat
2a98 wechatweb.exe               1 1   1   normal       C:\Program Files (x86)\Tencent\WeChat
0cf4 wechatweb.exe               1 1   1   normal       C:\Program Files (x86)\Tencent\WeChat
0a14 WeChatApp.exe               1 17  48  normal       C:\Program Files (x86)\Tencent\WeChat
085c WeChatApp.exe               1 102 93  normal       C:\Program Files (x86)\Tencent\WeChat
1ab0 360se.exe                   1 484 183 normal       C:\Users\Administrator\AppData\Roaming\secoresdk\360se6\Application
120c 360se.exe                   1 6   6   normal       C:\Users\Administrator\AppData\Roaming\secoresdk\360se6\Application
2b5c 360se.exe                   1 0   1   normal       C:\Users\Administrator\AppData\Roaming\secoresdk\360se6\Application
2870 wdswfsafe.exe               1 0   3   normal       C:\Program Files (x86)\360\360Safe\safemon
1924 360se.exe                   1 0   2   normal       C:\Users\Administrator\AppData\Roaming\secoresdk\360se6\Application
2c64 360se.exe                   1 0   2   normal       C:\Users\Administrator\AppData\Roaming\secoresdk\360se6\Application
2d24 sesvc.exe                   1 0   3   normal       C:\Users\Administrator\AppData\Roaming\secoresdk\360se6\Application\components\sesvc
28c8 360se.exe                   1 0   1   normal       C:\Users\Administrator\AppData\Roaming\secoresdk\360se6\Application
2df0 sesvc.exe                   1 13  22  normal       C:\Users\Administrator\AppData\Roaming\secoresdk\360se6\Application\components\sesvc
0d6c Microsoft.Photos.exe        1 0   10  normal       C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2020.19111.24110.0_x64__8wekyb3d8bbwe
24bc RuntimeBroker.exe           1 36  12  normal       C:\Windows\System32
2cd8 BaofengPlatform.exe         1 12  46  normal       D:\ù߰\Baofeng\StormPlayer
2ecc BFDesktopTips.exe           1 3   9   normal       D:\ù߰\Baofeng\StormPlayer
3194 svchost.exe                 0 0   0
3360 phpStudy.exe                1 0   0
26f0 httpd.exe                   1 0   0
0be4 mysqld.exe                  1 0   0
3374 conhost.exe                 1 0   0
3598 httpd.exe                   1 0   0
3780 svchost.exe                 0 0   0
1d60 MicrosoftEdge.exe           1 11  55  normal       C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe
2478 browser_broker.exe          1 0   3   normal       C:\Windows\System32
3648 RuntimeBroker.exe           1 0   1   normal       C:\Windows\System32
33ec MicrosoftEdgeCP.exe         1 0   23  normal       C:\Windows\System32
2eb4 MicrosoftEdgeSH.exe         1 0   9   normal       C:\Windows\System32
0734 SystemSettings.exe          1 11  30  normal       C:\Windows\ImmersiveControlPanel
1db8 WmiPrvSE.exe                0 0   0
2a4c svchost.exe                 0 0   0
3814 QQ.exe                      1 227 184 normal       D:\ù߰\Tencent\QQ\Bin
399c TXPlatform.exe              1 0   2   normal       D:\ù߰\Tencent\QQ\Bin
3a28 QQ.exe                      1 178 164 normal       D:\ù߰\Tencent\QQ\Bin
3f8c wpscenter.exe               1 4   22  normal       D:\ù߰\Kingsoft\WPS Office\11.3.0.9228\office6
30d0 ShellExperienceHost.exe     1 6   30  normal       C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy
3d18 RuntimeBroker.exe           1 40  4   normal       C:\Windows\System32
4168 360se.exe                   1 161 80  normal       C:\Users\Administrator\AppData\Roaming\secoresdk\360se6\Application
3338 360se.exe                   1 0   2   normal       C:\Users\Administrator\AppData\Roaming\secoresdk\360se6\Application
348c svchost.exe                 0 0   0
3358 360se.exe                   1 0   2   normal       C:\Users\Administrator\AppData\Roaming\secoresdk\360se6\Application
43b8 mstsc.exe                   1 114 83  normal       C:\Windows\System32
3d28 svchost.exe                 0 0   0
3128 360se.exe                   1 0   2   normal       C:\Users\Administrator\AppData\Roaming\secoresdk\360se6\Application
365c WUDFHost.exe                0 0   0
3120 360UDiskPro.exe             1 0   0
2d98 SGTool.exe                  1 0   5   normal       D:\ù߰\sogoupinyin\9.7.0.3676
15f8 SearchProtocolHost.exe      0 0   0
3840 SearchFilterHost.exe        0 0   0
3a40 smartscreen.exe             1 0   4   normal       C:\Windows\System32
2cc8 FlashFXP.exe                1 237 192 normal       H:\ù߰\flashftp
2da0 svchost.exe                 0 0   0
08d4 360se.exe                   1 0   2   normal       C:\Users\Administrator\AppData\Roaming\secoresdk\360se6\Application

hardware:
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
  - Fax
  - Microsoft Print to PDF
  - Microsoft XPS Document Writer
  - OneNote for Windows 10
  - ӡ
+ {36fc9e60-c465-11cf-8056-444553540000}
  - Intel(R) USB 3.0 չ - 1.0 (Microsoft)
  - NVIDIA USB 3.10 չ - 1.10 (Microsoft)
  - NVIDIA USB Type-C Port Policy Controller (driver 1.38.831.832)
  - Realtek USB 2.0 Card Reader (driver 10.0.18362.31248)
  - USB Composite Device
  - USB 洢豸
  - USB (USB 3.0)
  - USB (USB 3.0)
+ {4d36e966-e325-11ce-bfc1-08002be10318}
  -  ACPI x64 ĵ
+ {4d36e967-e325-11ce-bfc1-08002be10318}
  - Kingston DataTraveler 2.0 USB Device
  - SKHynix_HFS256GD9TNG-L5B0B
  - TOSHIBA DT01ACA100                LENOVO
+ {4d36e968-e325-11ce-bfc1-08002be10318}
  - Intel(R) UHD Graphics 630 (driver 27.20.100.7988)
  - NVIDIA GeForce GTX 1660 Ti (driver 26.21.14.4141)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
  - ׼ SATA AHCI 
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
  - HID Keyboard Device
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
  - NVIDIA High Definition Audio (driver 1.3.38.21)
  - NVIDIA Virtual Audio Device (Wave Extensible) (WDM) (driver 4.13.0.0)
  - Realtek(R) Audio (driver 6.0.8923.1)
  - Ӣض(R) ʾƵ (driver 10.27.0.8)
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
  - ͨü弴ü
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
  - HID-compliant mouse
+ {4d36e972-e325-11ce-bfc1-08002be10318}
  - Bluetooth Device (Personal Area Network)
  - Intel(R) Ethernet Connection (2) I219-V (driver 12.18.9.11)
  - Realtek 8821CE Wireless LAN 802.11ac PCI-E NIC
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
  - Microsoft 洢ռ
  - ׼ NVM Express 
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
  - ACPI ۺ
  - ACPI Դť
  - ACPI ̶ܰť
  - ACPI Ѿ
  - ACPI ˯߰ť
  - High Definition Audio 
  - High Definition Audio 
  - Intel(R) 200 Series Chipset Family LPC Controller - A2CC (driver 10.1.1.38)
  - Intel(R) 200 Series Chipset Family PCI Express Root Port #21 - A2EB (driver 10.1.1.38)
  - Intel(R) 200 Series Chipset Family PCI Express Root Port #6 - A295 (driver 10.1.1.38)
  - Intel(R) 200 Series Chipset Family PMC - A2A1 (driver 10.1.1.38)
  - Intel(R) 200 Series Chipset Family SMBUS - A2A3 (driver 10.1.1.38)
  - Intel(R) 200 Series Chipset Family Thermal subsystem - A2B1 (driver 10.1.1.42)
  - Intel(R) Management Engine Interface  (driver 1914.12.0.1256)
  - Intel(R) Power Engine Plug-in
  - Microsoft ACPI-Compliant System
  - Microsoft Hyper-V ⻯ṹ
  - Microsoft System Management BIOS Driver
  - Microsoft Windows Management Interface for ACPI
  - Microsoft Windows Management Interface for ACPI
  - Microsoft 
  - Microsoft ʾ
  - Microsoft ö
  - NDIS ö
  - NVVHCI Enumerator (driver 3.3.2475.1519)
  - PCI Express ˿
  - PCI Express 
  - PCI ׼ CPU 
  - UMBus Root Bus Enumerator
  - ö
  - ߾¼ʱ
  - 弴豸ö
  - 豸
  - 
  - ɱжϿ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ֵݴ
  - ϵͳʱ
  - Զ豸ض
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
  - Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz
  - Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz
  - Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz
  - Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz
  - Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz
  - Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz
  - Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz
  - Intel(R) Core(TM) i7-9700 CPU @ 3.00GHz
+ {50dd5230-ba8a-11d1-bf5d-0000f805f530}
  - USB Token 32 Holder (driver 2.5.9.1105)
  - USB Token 32 Holder (driver 2.5.9.1105)
+ {5c4c3332-344d-483c-8739-259e934c9cc8}
  - Intel(R) Graphics Command Center (driver 27.20.100.7988)
  - Intel(R) Graphics Control Panel (driver 27.20.100.7988)
  - Realtek Audio Effects Component (driver 11.0.6000.717)
  - Realtek Audio Universal Service (driver 1.0.0.197)
  - Realtek Hardware Support Application (driver 11.0.6000.191)
+ {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
  - FT SCR2000A 0
  - FT SCR2000A 1
  - Microsoft Device Association Root Enumerator
  - Microsoft GS ϳ
  - Microsoft Passport Container Enumeration Bus
  - Microsoft Radio Device Enumeration Bus
  - Microsoft RRAS Root Enumerator
  - Smart Card Device Enumeration Bus
  - WLAN
  - 
+ {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
  - USB 豸
  - USB 豸
  - USB 豸
  -  HID ׼ϵͳ
  -  HID ׼û豸
+ {d94ee5d8-d189-4994-83d2-f68d7d41b0e6}
  - εƽ̨ģ 2.0
+ {db4f6ddd-9c0e-45e4-9597-78dbbad0f412}
  - ܿɸѡ
  - ܿɸѡ
+ {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
  - Bluetooth Device (RFCOMM Protocol TDI)
  - Microsoft  LE ö
  - Microsoft ö
  - Realtek Bluetooth Adapter (driver 1.7.1019.3005)
+ {eec5ad98-8080-425f-922a-dabf3de3f69a}
  - EFI
  - ëU

cpu registers:
eax = 0f800000
ebx = 027dc370
ecx = 00282000
edx = 00000000
esi = 007bddb8
edi = 027bf3e0
eip = 0073a8db
esp = 0019fa7c
ebp = 0019fa8c

stack dump:
0019fa7c  70 c3 7d 02 70 c3 7d 02 - 04 00 00 00 20 06 76 02  p.}.p.}.......v.
0019fa8c  74 00 00 00 86 cb 41 00 - f4 48 46 00 a2 45 46 00  t.....A..HF..EF.
0019fa9c  e0 f3 7b 02 0e 00 00 00 - 70 c3 7d 02 57 4e 46 00  ..{.....p.}.WNF.
0019faac  40 4e 46 00 e4 48 46 00 - d0 fa 19 00 00 00 00 00  @NF..HF.........
0019fabc  00 00 00 00 02 00 00 00 - c1 9e 44 00 68 40 79 02  ..........D.h@y.
0019facc  6c 26 46 00 f0 fa 19 00 - 39 9f 44 00 f0 fa 19 00  l&F.....9.D.....
0019fadc  20 06 76 02 70 b7 77 00 - 22 00 00 00 e4 fc 19 00  ..v.p.w.".......
0019faec  20 06 76 02 e4 fc 19 00 - 7e b7 77 00 63 83 45 00  ..v.....~.w.c.E.
0019fafc  60 22 70 02 01 1a 3a 6d - 64 fc 19 00 00 bd 00 00  `"p...:md.......
0019fb0c  e4 fc 19 00 60 22 70 02 - a3 83 45 00 00 bd 00 00  ....`"p...E.....
0019fb1c  e4 fc 19 00 60 22 70 02 - 38 3e 45 00 00 bd 00 00  ....`"p.8>E.....
0019fb2c  e4 fc 19 00 60 22 70 02 - a7 66 45 00 00 bd 00 00  ....`"p..fE.....
0019fb3c  e4 fc 19 00 60 22 70 02 - 60 ec 35 6d a0 5f bc 00  ....`"p.`.5m._..
0019fb4c  a2 ec 35 6d 83 57 a0 19 - c8 64 ab 04 b8 fc 19 00  ..5m.W...d......
0019fb5c  50 35 77 04 00 00 00 00 - e8 fb 19 00 7e f4 34 6d  P5w.........~.4m
0019fb6c  2a 00 00 00 50 35 77 04 - 50 35 77 04 0c fc 19 00  *...P5w.P5w.....
0019fb7c  69 e6 34 6d 00 00 00 00 - e0 a2 6f 02 1b e6 34 6d  i.4m......o...4m
0019fb8c  00 00 6f 02 00 00 00 00 - 3a da 37 6d e0 fb 19 00  ..o.....:.7m....
0019fb9c  ff 50 d1 76 f0 8d 2f 01 - 00 00 00 00 64 00 00 00  .P.v../.....d...
0019fbac  94 35 77 04 82 3f 35 6d - 00 00 00 00 0c fc 19 00  .5w..?5m........

disassembling:
[...]
0073a89a         push    ebx
0073a89b         push    esi
0073a89c         mov     [ebp-4], eax
0073a89f         mov     esi, $7bddb8
0073a8a4 10234   mov     al, [$7be234]
0073a8a9         mov     [ebp-5], al
0073a8ac 10236   mov     al, [ebp-5]
0073a8af         not     al
0073a8b1         dec     eax
0073a8b2         sub     al, 2
0073a8b4         jb      loc_73aa5d
0073a8ba 10238   xor     eax, eax
0073a8bc         mov     al, [ebp-5]
0073a8bf         imul    eax, eax, $117
0073a8c5         mov     eax, [esi+eax*2-$12b]
0073a8cc         test    eax, eax
0073a8ce         jz      loc_73a8fd
0073a8d0         xor     edx, edx
0073a8d2         mov     dl, [ebp-5]
0073a8d5         imul    edx, edx, $117
0073a8db       > cmp     byte ptr [eax+$47], 0
0073a8df         jz      loc_73a8fd
0073a8e1 10240   xor     edx, edx
0073a8e3         mov     dl, [ebp-5]
0073a8e6         imul    edx, edx, $117
0073a8ec         mov     edx, eax
0073a8ee         mov     cl, 1
0073a8f0         mov     eax, [ebp-4]
0073a8f3         call    +$2f8a0 ($76a198)      ; FrmMain1.TFrmMain.LocalRefresh
0073a8f8 10241   jmp     loc_73aa5d
0073a8fd 10244   xor     eax, eax
0073a8ff         mov     al, [ebp-5]
0073a902         imul    eax, eax, $117
0073a908         cmp     byte ptr [esi+eax*2-$7e], 0
0073a90d         jz      loc_73a971
0073a90f         mov     eax, [esi+eax*2-$11f]
0073a916         cmp     byte ptr [eax+$2d0], 0
0073a91d         jnz     loc_73a971
0073a91f 10246   xor     eax, eax
0073a921         mov     al, [ebp-5]
0073a924         imul    ebx, eax, $117
[...]

date/time         : 2020-12-26, 12:59:41, 923ms
computer name     : USER-20201004XA
user name         : Administrator <admin>
registered owner  : Windows û
operating system  : Windows 7 x64 Service Pack 1 (6.1.7601) build 7601
system language   : Chinese (Simplified)
system up time    : 31 minutes 45 seconds
program up time   : 14 minutes 25 seconds
processors        : 8x Intel(R) Xeon(R) CPU X5677 @ 3.47GHz
physical memory   : 5069/8183 MB (free/total)
free disk space   : (C:) 5.36 GB (O:) 48.91 GB
display mode      : 1920x1080, 32 bit
process id        : $20b8
allocated memory  : 104.46 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $3879e35e, $778a108b, $c81eec3e
exception number  : 1
exception class   : EAccessViolation
exception message : Access violation at address 0073A983 in module 'FlashFXP.exe'. ȡ of address 988002D0.

main thread ($d60):
0073a983 +00ef FlashFXP.exe FrmMain1 10252  +19 TFrmMain.mnuRefreshClick
0041cb83 +000f FlashFXP.exe Classes             TBasicAction.Execute
0046459d +0031 FlashFXP.exe ActnList            TContainedAction.Execute
00464e52 +0012 FlashFXP.exe ActnList            TCustomAction.Execute
004648df +004b FlashFXP.exe ActnList            TCustomActionList.IsShortCut
00449ebc +003c FlashFXP.exe Forms     5034   +3 DispatchShortCut
00449f34 +0060 FlashFXP.exe Forms     5045   +3 TCustomForm.IsShortCut
0077b779 +0009 FlashFXP.exe FrmMain1 32669   +0 TFrmMain.IsShortCut
0045835e +0066 FlashFXP.exe Controls            TWinControl.IsMenuKey
0045839e +0012 FlashFXP.exe Controls            TWinControl.CNKeyDown
00453e35 +0111 FlashFXP.exe Controls            TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls            TWinControl.WndProc
0043e3bd +013d FlashFXP.exe StdCtrls            TCustomComboBox.WndProc
00509afb +003f FlashFXP.exe ThemeMgr            TWindowProcList.DispatchMessage
0050b7ba +007e FlashFXP.exe ThemeMgr            TThemeManager.WinControlWindowProc
0050b9c9 +0009 FlashFXP.exe ThemeMgr            TThemeManager.PreWinControlWindowProc
0045632c +002c FlashFXP.exe Controls            TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms     1529   +8 StdWndProc
76047245 +0047 user32.dll                       SendMessageA
0044c934 +0050 FlashFXP.exe Forms     7051  +11 TApplication.IsKeyMsg
0044ca82 +006e FlashFXP.exe Forms     7113  +30 TApplication.ProcessMessage
0044cad6 +000a FlashFXP.exe Forms     7155   +1 TApplication.HandleMessage
0044cd8b +00bf FlashFXP.exe Forms     7259  +26 TApplication.Run
007964ed +1c69 FlashFXP.exe FlashFXP   920 +630 initialization
75c33368 +0010 kernel32.dll                     BaseThreadInitThunk

thread $1da4:
77021f4f +0b ntdll.dll     NtWaitForWorkViaWorkerFactory
75c33368 +10 kernel32.dll  BaseThreadInitThunk

thread $888:
77020166 +0e ntdll.dll     NtWaitForMultipleObjects
75c33368 +10 kernel32.dll  BaseThreadInitThunk

thread $2158:
77020166 +00e ntdll.dll                                NtWaitForMultipleObjects
75d51714 +0fa KERNELBASE.dll                           WaitForMultipleObjectsEx
75c319f7 +089 kernel32.dll                             WaitForMultipleObjectsEx
75c341d3 +013 kernel32.dll                             WaitForMultipleObjects
00640bd3 +07b FlashFXP.exe   UPTShellControls 4370 +13 TChangeHandlerThread.Execute
0041bfc4 +230 FlashFXP.exe   Classes                   HexToBin
00404080 +028 FlashFXP.exe   System                    ThreadWrapper
75c33368 +010 kernel32.dll                             BaseThreadInitThunk

thread $1efc:
7701f8da +0e ntdll.dll       NtWaitForSingleObject
75d515c8 +92 KERNELBASE.dll  WaitForSingleObjectEx
75c3118f +3e kernel32.dll    WaitForSingleObjectEx
75c33368 +10 kernel32.dll    BaseThreadInitThunk

thread $1a78:
77021f4f +0b ntdll.dll     NtWaitForWorkViaWorkerFactory
75c33368 +10 kernel32.dll  BaseThreadInitThunk

thread $1854:
7701f8da +0e ntdll.dll       NtWaitForSingleObject
75d515c8 +92 KERNELBASE.dll  WaitForSingleObjectEx
75c3118f +3e kernel32.dll    WaitForSingleObjectEx
75c31143 +0d kernel32.dll    WaitForSingleObject
75c33368 +10 kernel32.dll    BaseThreadInitThunk

thread $19fc: <priority:1>
7701f962 +0e ntdll.dll     NtRemoveIoCompletion
75c33368 +10 kernel32.dll  BaseThreadInitThunk

thread $c8c:
77020166 +00e ntdll.dll                    NtWaitForMultipleObjects
75d51714 +0fa KERNELBASE.dll               WaitForMultipleObjectsEx
75c319f7 +089 kernel32.dll                 WaitForMultipleObjectsEx
75c341d3 +013 kernel32.dll                 WaitForMultipleObjects
00662068 +10c FlashFXP.exe   SaveToFileThd TSaveFileWorker.Execute
0041bfc4 +230 FlashFXP.exe   Classes       HexToBin
00404080 +028 FlashFXP.exe   System        ThreadWrapper
75c33368 +010 kernel32.dll                 BaseThreadInitThunk

modules:
00400000 FlashFXP.exe                     4.0.0.1534         O:\ù߰\flashftp
05100000 ssleay32.dll                     1.0.0.3            O:\ù߰\flashftp
0f520000 GOOGLEPINYIN2.IME                2.7.25.128         C:\Windows\system32
10000000 libeay32.dll                     1.0.0.3            O:\ù߰\flashftp
55040000 explorerframe.dll                6.1.7601.23893     C:\Windows\system32
551b0000 msxml3.dll                       8.110.7601.23648   C:\Windows\System32
5fae0000 DUI70.dll                        6.1.7600.16385     C:\Windows\system32
63b70000 dssenh.dll                       6.1.7600.16385     C:\Windows\system32
63ba0000 tiptsf.dll                       6.1.7601.18984     C:\Program Files (x86)\Common Files\microsoft shared\ink
63c00000 DUser.dll                        6.1.7600.16385     C:\Windows\system32
644a0000 EhStorShell.dll                  6.1.7600.16385     C:\Windows\system32
6c5b0000 shdocvw.dll                      6.1.7601.23896     C:\Windows\System32
6ccb0000 dwmapi.dll                       6.1.7601.18917     C:\Windows\system32
6d010000 IconCodecService.dll             6.1.7600.16385     C:\Windows\system32
6d200000 uxtheme.dll                      6.1.7600.16385     C:\Windows\system32
6daf0000 MSIMG32.dll                      6.1.7600.16385     C:\Windows\system32
6db00000 wsock32.dll                      6.1.7600.16385     C:\Windows\system32
6dc90000 PROPSYS.dll                      7.0.7601.17514     C:\Windows\system32
6de50000 SAMLIB.dll                       6.1.7601.23677     C:\Windows\system32
6e6c0000 sensapi.dll                      6.1.7600.16385     C:\Windows\system32
6e6d0000 wship6.dll                       6.1.7600.16385     C:\Windows\System32
6e6e0000 rasadhlp.dll                     6.1.7600.16385     C:\Windows\system32
6e780000 winrnr.dll                       6.1.7600.16385     C:\Windows\System32
6e7c0000 pnrpnsp.dll                      6.1.7600.16385     C:\Windows\system32
6e7e0000 napinsp.dll                      6.1.7600.16385     C:\Windows\system32
6e7f0000 NLAapi.dll                       6.1.7601.18685     C:\Windows\system32
6f2d0000 iNetSafe.dll                     1.0.2.1740         C:\Program Files (x86)\360\360Safe719015\360Safe\safemon
6f350000 iFlyIMEQuickLaunch.dll                              C:\Program Files (x86)\Ѷ뷨\2.1.1708
6f380000 olepro32.dll                     6.1.7601.17514     C:\Windows\system32
6f570000 rasman.dll                       6.1.7600.16385     C:\Windows\system32
6f590000 RASAPI32.dll                     6.1.7600.16385     C:\Windows\system32
6fc90000 MSVCP100.dll                     10.0.40219.325     C:\Windows\system32
6fd00000 MSVCR100.dll                     10.0.40219.325     C:\Windows\system32
70050000 OLEACC.dll                       7.0.0.0            C:\Windows\system32
70090000 safemon.dll                      8.6.0.3460         C:\Program Files (x86)\360\360Safe719015\360Safe\safemon
708e0000 mswsock.dll                      6.1.7601.23451     C:\Windows\System32
70a50000 comctl32.dll                     6.10.7601.18837    C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
70cd0000 dnsapi.DLL                       6.1.7601.17570     C:\Windows\system32
70f30000 rsaenh.dll                       6.1.7600.16385     C:\Windows\system32
70f70000 bcrypt.dll                       6.1.7601.23915     C:\Windows\System32
710e0000 rtutils.dll                      6.1.7601.17514     C:\Windows\system32
710f0000 wshtcpip.dll                     6.1.7600.16385     C:\Windows\System32
71150000 safewrapper32.dll                2.0.0.1160         C:\Program Files (x86)\360\360Safe719015\360Safe\safemon
71170000 gdiplus.dll                      6.1.7601.23894     C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23894_none_5c0be957a009922e
715b0000 CRYPTSP.dll                      6.1.7601.23471     C:\Windows\system32
716a0000 samcli.dll                       6.1.7601.17514     C:\Windows\system32
716b0000 wkscli.dll                       6.1.7601.17514     C:\Windows\system32
716c0000 LINKINFO.dll                     6.1.7600.16385     C:\Windows\system32
717d0000 MPR.dll                          6.1.7600.16385     C:\Windows\system32
71cb0000 winspool.drv                     6.1.7601.17514     C:\Windows\system32
720f0000 ntshrui.dll                      6.1.7601.17755     C:\Windows\system32
72580000 slc.dll                          6.1.7600.16385     C:\Windows\system32
72590000 cscapi.dll                       6.1.7601.17514     C:\Windows\system32
728c0000 WindowsCodecs.dll                6.2.9200.21830     C:\Windows\system32
72a20000 srvcli.dll                       6.1.7601.17514     C:\Windows\system32
72a40000 netutils.dll                     6.1.7601.17514     C:\Windows\system32
72a50000 NETAPI32.dll                     6.1.7601.17887     C:\Windows\system32
72af0000 Secur32.dll                      6.1.7601.23915     C:\Windows\system32
73720000 winmm.dll                        6.1.7601.17514     C:\Windows\system32
73c70000 dbghelp.dll                      6.1.7601.17514     C:\Windows\system32
73d60000 apphelp.dll                      6.1.7601.19050     C:\Windows\system32
73db0000 fwpuclnt.dll                     6.1.7601.18283     C:\Windows\System32
73df0000 ntmarta.dll                      6.1.7600.16385     C:\Windows\system32
73fd0000 api-ms-win-core-synch-l1-2-0.DLL 10.0.10586.1171    C:\Windows\system32
73fe0000 profapi.dll                      6.1.7600.16385     C:\Windows\system32
73ff0000 USERENV.dll                      6.1.7601.17514     C:\Windows\system32
74390000 version.dll                      6.1.7600.16385     C:\Windows\system32
74440000 WINNSI.DLL                       6.1.7601.23889     C:\Windows\system32
74450000 IPHLPAPI.DLL                     6.1.7601.17514     C:\Windows\system32
74680000 CRYPTBASE.dll                    6.1.7601.23915     C:\Windows\syswow64
74690000 SspiCli.dll                      6.1.7601.23915     C:\Windows\syswow64
746f0000 MSCTF.dll                        6.1.7601.23915     C:\Windows\syswow64
747f0000 NSI.dll                          6.1.7601.23889     C:\Windows\syswow64
74800000 wininet.dll                      9.0.8112.16737     C:\Windows\syswow64
74920000 USP10.dll                        1.626.7601.23894   C:\Windows\syswow64
749c0000 comdlg32.dll                     6.1.7601.17514     C:\Windows\syswow64
74a40000 WINTRUST.dll                     6.1.7601.23769     C:\Windows\syswow64
74a70000 crypt32.dll                      6.1.7601.23769     C:\Windows\syswow64
74ba0000 Normaliz.dll                     6.1.7600.16385     C:\Windows\syswow64
74bb0000 SETUPAPI.dll                     6.1.7601.17514     C:\Windows\syswow64
74d50000 SHLWAPI.dll                      6.1.7601.17514     C:\Windows\syswow64
74db0000 ADVAPI32.dll                     6.1.7601.23915     C:\Windows\syswow64
74e60000 shell32.dll                      6.1.7601.23893     C:\Windows\syswow64
75ab0000 ole32.dll                        6.1.7601.23889     C:\Windows\syswow64
75c10000 PSAPI.DLL                        6.1.7600.16385     C:\Windows\syswow64
75c20000 kernel32.dll                     6.1.7601.23915     C:\Windows\syswow64
75d30000 LPK.dll                          6.1.7601.23930     C:\Windows\syswow64
75d40000 KERNELBASE.dll                   6.1.7601.23915     C:\Windows\syswow64
75d90000 IMM32.DLL                        6.1.7601.17514     C:\Windows\system32
75df0000 urlmon.dll                       9.0.8112.16737     C:\Windows\syswow64
75f10000 CLBCatQ.DLL                      2001.12.8530.16385 C:\Windows\syswow64
75fa0000 WLDAP32.dll                      6.1.7601.23889     C:\Windows\syswow64
75ff0000 CFGMGR32.dll                     6.1.7601.17621     C:\Windows\syswow64
76020000 user32.dll                       6.1.7601.23594     C:\Windows\syswow64
76210000 DEVOBJ.dll                       6.1.7601.17621     C:\Windows\syswow64
76230000 RPCRT4.dll                       6.1.7601.23915     C:\Windows\syswow64
76320000 msvcrt.dll                       7.0.7601.17744     C:\Windows\syswow64
763d0000 iertutil.dll                     9.0.8112.16737     C:\Windows\syswow64
76590000 WS2_32.dll                       6.1.7601.23451     C:\Windows\syswow64
765d0000 GDI32.dll                        6.1.7601.23914     C:\Windows\syswow64
76660000 oleaut32.dll                     6.1.7601.23775     C:\Windows\syswow64
76700000 sechost.dll                      6.1.7601.18869     C:\Windows\SysWOW64
76fd0000 MSASN1.dll                       6.1.7601.17514     C:\Windows\syswow64
77000000 ntdll.dll                        6.1.7601.23915     C:\Windows\SysWOW64

processes:
0000 Idle                   0 0   0
0004 System                 0 0   0
01b8 smss.exe               0 0   0
027c csrss.exe              0 0   0
02f0 wininit.exe            0 0   0
02f8 csrss.exe              1 0   0
0328 services.exe           0 0   0
034c winlogon.exe           1 0   0
0368 lsass.exe              0 0   0
0370 lsm.exe                0 0   0
03d4 svchost.exe            0 0   0
0084 HipsDaemon.exe         0 0   0
01cc nvvsvc.exe             0 0   0
028c svchost.exe            0 0   0
036c svchost.exe            0 0   0
0410 svchost.exe            0 0   0
042c svchost.exe            0 0   0
0454 svchost.exe            0 0   0
0498 usysdiag.exe           0 0   0
0574 svchost.exe            0 0   0
05f4 ZhuDongFangYu.exe      0 0   0
0640 svchost.exe            0 0   0
065c nvxdsync.exe           1 0   0
079c spoolsv.exe            0 0   0
04a4 svchost.exe            0 0   0
05a8 taskhost.exe           1 26  21  normal
082c dwm.exe                1 18  2   high
0870 explorer.exe           1 621 332 normal
08ac FlashHelperService.exe 0 0   0
08e4 svchost.exe            0 0   0
0994 pcas.exe               0 0   0
09dc phpStudyServer.exe     0 0   0
0a48 taskeng.exe            1 9   3   normal
0a98 QQProtect.exe          0 0   0
0ad8 secbizsrv.exe          0 0   0
0ae0 mysqld.exe             0 0   0
0b00 svchost.exe            0 0   0
061c nginx.exe              0 0   0
08a4 WmiPrvSE.exe           0 0   0
08f8 xp.cn_cgi.exe          0 0   0
09d8 xp.cn_cgi.exe          0 0   0
0434 xp.cn_cgi.exe          0 0   0
0a80 xp.cn_cgi.exe          0 0   0
0c0c php-cgi.exe            0 0   0
0c18 php-cgi.exe            0 0   0
0c30 conhost.exe            0 0   0
0c38 php-cgi.exe            0 0   0
0c50 php-cgi.exe            0 0   0
0cc4 conhost.exe            0 0   0
0cd4 nginx.exe              0 0   0
0ce8 conhost.exe            0 0   0
0cf8 conhost.exe            0 0   0
0d18 conhost.exe            0 0   0
0d40 nginx.exe              0 0   0
0d5c conhost.exe            0 0   0
0d78 nginx.exe              0 0   0
0d8c conhost.exe            0 0   0
0dbc nginx.exe              0 0   0
0dc4 conhost.exe            0 0   0
0ef0 RAVCpl64.exe           1 54  20  normal
0f04 HipsTray.exe           1 105 45  normal       C:\Program Files (x86)\Huorong\Sysdiag\bin
0fe4 yundetectservice.exe   1 9   5   normal       C:\Users\Administrator.USER-20201004XA\AppData\Roaming\baidu\BaiduNetdisk
0cf4 360tray.exe            1 286 68  normal       C:\Program Files (x86)\360\360Safe719015\360Safe\safemon
0f50 sesvc.exe              1 9   3   normal       C:\Users\Administrator.USER-20201004XA\AppData\Roaming\secoresdk\360se6\Application\components\sesvc
03a4 360DesktopLite64.exe   1 219 58  normal
113c svchost.exe            0 0   0
1170 sesvc.exe              1 9   3   normal       C:\Users\Administrator.USER-20201004XA\AppData\Roaming\secoresdk\360se6\Application\components\sesvc
1218 360bdoctor.exe         1 14  5   normal       C:\Users\Administrator.USER-20201004XA\AppData\Roaming\secoresdk\360se6\Application\12.2.1768.0
14c4 SoftMgrLite.exe        1 215 141 normal       C:\Program Files (x86)\360\360Safe719015\360Safe\SoftMgr\SML
16d8 svchost.exe            0 0   0
1738 aliwssv.exe            1 4   1   normal       C:\Program Files (x86)\alipay\aliedit\5.1.0.3754
1754 conhost.exe            1 26  1   normal
17f4 svchost.exe            0 0   0
0f4c 360Newsld.exe          1 80  7   normal       C:\Users\Administrator.USER-20201004XA\appdata\roaming\360Safe\SoftMgr
1578 MultiTip.exe           1 21  8   normal       C:\Users\Administrator.USER-20201004XA\AppData\Roaming\360Safe\SoftMgr
1758 sesvc.exe              1 56  26  normal       C:\Users\Administrator.USER-20201004XA\AppData\Roaming\secoresdk\360se6\Application\components\sesvc
18c0 ComputerZTray.exe      1 23  44  below normal C:\Program Files (x86)\LuDaShi
185c 360wpsrv.exe           1 32  79  below normal C:\Program Files (x86)\BirdWallpaper
190c guardhp.exe            1 27  16  below normal C:\Program Files (x86)\BirdWallpaper\wallpaperhelper
1954 ComputerZService.exe   1 9   16  below normal C:\Program Files (x86)\LuDaShi
1bcc unsecapp.exe           1 9   5   normal
0808 MobileDeviceSrv.exe    1 21  15  below normal C:\Program Files (x86)\BirdWallpaper\Utils
1fbc WeChat.exe             1 229 96  normal       D:\ProGrame\WeChat
1f94 WeChat.exe             1 151 63  normal       D:\ProGrame\WeChat
06c8 WeChatWeb.exe          1 5   3   normal       D:\ProGrame\WeChat
02a8 WeChatWeb.exe          1 5   1   normal       D:\ProGrame\WeChat
100c WeChatApp.exe          1 20  52  normal       D:\ProGrame\WeChat
1214 WeChatApp.exe          1 23  60  normal       D:\ProGrame\WeChat
1574 SearchIndexer.exe      0 0   0
06c4 wdswfsafe.exe          1 9   3   normal       C:\Program Files (x86)\360\360Safe719015\360Safe\safemon
229c 360UDiskPro.exe        1 56  33  normal       C:\Program Files (x86)\360\360Safe719015\360Safe\safemon
20d8 WUDFHost.exe           0 0   0
11d4 WeChatWeb.exe          1 9   1   normal       D:\ProGrame\WeChat
20b8 FlashFXP.exe           1 261 197 normal       O:\ù߰\flashftp
1d98 360se.exe              1 329 117 normal       C:\Users\Administrator.USER-20201004XA\AppData\Roaming\secoresdk\360se6\Application
1a5c 360se.exe              1 14  6   normal       C:\Users\Administrator.USER-20201004XA\AppData\Roaming\secoresdk\360se6\Application
1df0 360se.exe              1 4   1   normal       C:\Users\Administrator.USER-20201004XA\AppData\Roaming\secoresdk\360se6\Application
10dc 360se.exe              1 4   2   normal       C:\Users\Administrator.USER-20201004XA\AppData\Roaming\secoresdk\360se6\Application
2094 360se.exe              1 4   2   normal       C:\Users\Administrator.USER-20201004XA\AppData\Roaming\secoresdk\360se6\Application
1d6c 360se.exe              1 4   2   normal       C:\Users\Administrator.USER-20201004XA\AppData\Roaming\secoresdk\360se6\Application
0ecc 360se.exe              1 4   2   normal       C:\Users\Administrator.USER-20201004XA\AppData\Roaming\secoresdk\360se6\Application
2038 360se.exe              1 9   3   normal       C:\Users\Administrator.USER-20201004XA\AppData\Roaming\secoresdk\360se6\Application
1cc0 audiodg.exe            0 0   0
0760 360se.exe              1 4   2   normal       C:\Users\Administrator.USER-20201004XA\AppData\Roaming\secoresdk\360se6\Application

hardware:
+ Batteries
  - Microsoft Composite Battery
+ Computer
  - ACPI x64-based PC
+ Disk drives
  - aigo U310 USB Device
  - GALAX TA1D0240A
  - ST500DM002-1BD142
  - tigo SSD
+ Display adapters
  - NVIDIA GeForce GTX 660 (driver 10.18.13.6881)
+ DVD/CD-ROM drives
  - PIONEER DVD-RW  DVR-219L
+ Human Interface Devices
  - HID-compliant device
  - USB 豸
  - USB 豸
  - USB 豸
  -  HID ׼û豸
+ IDE ATA/ATAPI controllers
  - Intel(R) ICH10R SATA AHCI Controller (driver 11.1.0.1006)
+ Imaging devices
  - USB2.0 PC CAMERA
+ Keyboards
  - HID Keyboard Device
+ Mice and other pointing devices
  - HID-compliant mouse
+ Monitors
  - ͨü弴ü
+ Network adapters
  - Realtek PCIe GBE Family Controller (driver 7.53.216.2012)
+ Portable Devices
  - ëU
+ Ports (COM & LPT)
  - ͨŶ˿ (COM1)
+ Processors
  - Intel(R) Xeon(R) CPU           X5677  @ 3.47GHz
  - Intel(R) Xeon(R) CPU           X5677  @ 3.47GHz
  - Intel(R) Xeon(R) CPU           X5677  @ 3.47GHz
  - Intel(R) Xeon(R) CPU           X5677  @ 3.47GHz
  - Intel(R) Xeon(R) CPU           X5677  @ 3.47GHz
  - Intel(R) Xeon(R) CPU           X5677  @ 3.47GHz
  - Intel(R) Xeon(R) CPU           X5677  @ 3.47GHz
  - Intel(R) Xeon(R) CPU           X5677  @ 3.47GHz
+ Sound, video and game controllers
  - NVIDIA High Definition Audio (driver 1.3.34.15)
  - Realtek High Definition Audio (driver 6.0.1.6383)
  - USB2.0 MIC
+ Storage volume shadow copies
  - ͨþӰ
  - ͨþӰ
  - ͨþӰ
+ System devices
  - ACPI Fixed Feature Button
  - ACPI Power Button
  - Direct memory access controller
  - High Definition Audio 
  - High Definition Audio 
  - Intel Device (driver 10.0.27.0)
  - Intel(R) 5520/5500/X58 I/O Hub to ESI Port - 3406 (driver 9.1.9.1005)
  - Intel(R) 7500/5520/5500/X58 I/O Hub Control Status and RAS Registers - 3423 (driver 9.1.9.1005)
  - Intel(R) 7500/5520/5500/X58 I/O Hub GPIO and Scratch Pad Registers - 3422 (driver 9.1.9.1005)
  - Intel(R) 7500/5520/5500/X58 I/O Hub PCI Express Root Port 1 - 3408 (driver 9.1.9.1005)
  - Intel(R) 7500/5520/5500/X58 I/O Hub PCI Express Root Port 3 - 340A - 340a (driver 9.1.9.1005)
  - Intel(R) 7500/5520/5500/X58 I/O Hub PCI Express Root Port 7 - 340E - 340e (driver 9.1.9.1005)
  - Intel(R) 7500/5520/5500/X58 I/O Hub System Management Registers - 342E - 342e (driver 9.1.9.1005)
  - Intel(R) 7500/5520/5500/X58 I/O Hub Throttle Registers - 3438 (driver 9.1.9.1005)
  - Intel(R) 82801 PCI Bridge - 244E
  - Intel(R) ICH10 LPC ӿڿ - 3A18
  - Intel(R) ICH10 ϵ PCI Express ˿ 1 - 3A40
  - Intel(R) ICH10 ϵ PCI Express ˿ 3 - 3A44
  - Microsoft ACPI-Compliant System
  - Microsoft System Management BIOS Driver
  - Microsoft ö
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Motherboard resources
  - Numeric data processor
  - PCI  (driver 4.0.4.51)
  - Plug and Play Software Device Enumerator
  - Programmable interrupt controller
  - Remote Desktop Device Redirector Bus
  - System board
  - System board
  - System CMOS/real time clock
  - System speaker
  - System timer
  - Terminal Server Keyboard Driver
  - Terminal Server Mouse Driver
  - UMBus Enumerator
  - UMBus Enumerator
  - UMBus Root Bus Enumerator
  - Volume Manager
  - ö
  - ļΪ
+ Universal Serial Bus controllers
  - Intel(R) ICH10 Family USB Enhanced Host Controller - 3A3A
  - Intel(R) ICH10 Family USB Enhanced Host Controller - 3A3C
  - Intel(R) ICH10 Family USB Universal Host Controller - 3A34
  - Intel(R) ICH10 Family USB Universal Host Controller - 3A35
  - Intel(R) ICH10 Family USB Universal Host Controller - 3A36
  - Intel(R) ICH10 Family USB Universal Host Controller - 3A37
  - Intel(R) ICH10 Family USB Universal Host Controller - 3A38
  - Intel(R) ICH10 Family USB Universal Host Controller - 3A39
  - USB Composite Device
  - USB Composite Device
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB Root Hub
  - USB 洢豸

cpu registers:
eax = 98800000
ebx = 00000000
ecx = 00bf0a70
edx = 00000000
esi = 007bddb8
edi = 02977fc0
eip = 0073a983
esp = 0018fb18
ebp = 0018fb28

stack dump:
0018fb18  c8 4f 99 02 c8 4f 99 02 - 04 00 00 00 d0 5e 95 02  .O...O.......^..
0018fb28  74 00 00 00 86 cb 41 00 - f4 48 46 00 a2 45 46 00  t.....A..HF..EF.
0018fb38  c0 7f 97 02 0e 00 00 00 - c8 4f 99 02 57 4e 46 00  .........O..WNF.
0018fb48  40 4e 46 00 e4 48 46 00 - 6c fb 18 00 00 00 00 00  @NF..HF.l.......
0018fb58  00 00 00 00 02 00 00 00 - c1 9e 44 00 a8 7c 94 02  ..........D..|..
0018fb68  6c 26 46 00 8c fb 18 00 - 39 9f 44 00 8c fb 18 00  l&F.....9.D.....
0018fb78  d0 5e 95 02 70 b7 77 00 - 22 00 00 00 80 fd 18 00  .^..p.w.".......
0018fb88  d0 5e 95 02 80 fd 18 00 - 7e b7 77 00 63 83 45 00  .^......~.w.c.E.
0018fb98  60 96 8d 02 01 45 6f 74 - 00 fd 18 00 00 bd 00 00  `....Eot........
0018fba8  80 fd 18 00 60 96 8d 02 - a3 83 45 00 00 bd 00 00  ....`.....E.....
0018fbb8  80 fd 18 00 60 96 8d 02 - 38 3e 45 00 00 bd 00 00  ....`...8>E.....
0018fbc8  80 fd 18 00 60 96 8d 02 - a7 66 45 00 00 bd 00 00  ....`....fE.....
0018fbd8  80 fd 18 00 60 96 8d 02 - 00 00 00 00 a0 86 01 00  ....`...........
0018fbe8  00 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00  ................
0018fbf8  48 44 50 04 14 fc 18 00 - 90 ea 51 04 bc 05 00 00  HDP.......Q.....
0018fc08  0c fc 18 00 a0 86 01 00 - 00 00 00 00 00 43 db 05  .............C..
0018fc18  44 26 5f 0f bc 05 00 00 - 00 00 00 00 bf b3 c1 98  D&_.............
0018fc28  28 38 db 05 20 82 da 05 - 50 fc 18 00 00 43 db 05  (8......P....C..
0018fc38  b1 fb 01 77 d3 10 d5 75 - b8 05 00 00 00 00 00 00  ...w...u........
0018fc48  d4 fc 18 00 13 e1 53 0f - b8 05 00 00 0f 21 5f 0f  ......S......!_.

disassembling:
[...]
0073a921         mov     al, [ebp-5]
0073a924         imul    ebx, eax, $117
0073a92a         mov     eax, [esi+ebx*2-$11b]
0073a931         cmp     byte ptr [eax+$34], 0
0073a935         jnz     loc_73aa5d
0073a93b         cmp     byte ptr [esi+ebx*2-$c6], 0
0073a943         jnz     loc_73aa5d
0073a949 10248   lea     edx, [esi+ebx*2-$16a]
0073a950         mov     cl, 1
0073a952         mov     eax, [ebp-4]
0073a955         call    +$4642 ($73ef9c)       ; FrmMain1.TFrmMain.ConnectToHost
0073a95a 10249   mov     edx, [esi+ebx*2-$11f]
0073a961         mov     eax, [ebp-4]
0073a964         call    +$428af ($77d218)      ; FrmMain1.TFrmMain.WaitForConnect
0073a969         test    al, al
0073a96b         jz      loc_73aa5d
0073a971 10252   xor     eax, eax
0073a973         mov     al, [ebp-5]
0073a976         imul    ebx, eax, $117
0073a97c         mov     eax, [esi+ebx*2-$11f]
0073a983       > cmp     byte ptr [eax+$2d0], 0
0073a98a         jz      loc_73aa5d
0073a990         cmp     byte ptr [esi+ebx*2-$102], 0
0073a998         jnz     loc_73aa5d
0073a99e         mov     eax, [esi+ebx*2-$137]
0073a9a5         mov     edx, [eax]
0073a9a7         call    dword ptr [edx+$50]
0073a9aa         test    al, al
0073a9ac         jz      loc_73aa5d
0073a9b2         cmp     byte ptr [esi+ebx*2-$da], 0
0073a9ba         jnz     loc_73aa5d
0073a9c0 10255   mov     cl, 1
0073a9c2         mov     dl, [ebp-5]
0073a9c5         mov     eax, [ebp-4]
0073a9c8         call    -$10dcd ($729c00)      ; FrmMain1.TFrmMain.SetBusy
0073a9cd 10256   xor     eax, eax
0073a9cf         push    ebp
0073a9d0         push    $73aa33                ; System.@HandleFinally
0073a9d5         push    dword ptr fs:[eax]
0073a9d8         mov     fs:[eax], esp
0073a9db 10257   push    1
[...]

date/time         : 2023-09-13, 11:22:12, 974ms
computer name     : WIN-20230519PJP
user name         : Administrator <admin>
registered owner  : Windows û
operating system  : Windows NT New x64 (6.2.9200) build 9200
system language   : Chinese (Simplified)
system up time    : 3 hours 2 minutes
program up time   : 43 minutes 18 seconds
processors        : 12x Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
physical memory   : 12062/16313 MB (free/total)
free disk space   : (C:) 93.06 GB (K:) 407.71 GB
display mode      : 1920x1080, 32 bit
process id        : $658
allocated memory  : 100.07 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $10003d50, $a3e38aaa, $a3e38aaa
exception number  : 1
exception class   : EExternalException
exception message : External exception C0000006.

main thread ($4298):
10003d50 +0000 ???
00621fd7 +0013 FlashFXP.exe OpenSSLHeaders          Unload
00622188 +002c FlashFXP.exe OpenSSLHeaders          Finalization
00403d92 +0036 FlashFXP.exe System                  FInitUnits
004bc2d8 +0054 FlashFXP.exe madExcept               Ebp
00403fae +0086 FlashFXP.exe System                  @Halt0
00796548 +1cc4 FlashFXP.exe FlashFXP       939 +649 initialization
763d00c7 +0017 KERNEL32.DLL                         BaseThreadInitThunk

thread $49f0:
763d00c7 +17 KERNEL32.DLL  BaseThreadInitThunk

thread $49c8:
75952ded +fd KERNELBASE.dll  WaitForMultipleObjectsEx
763d00c7 +17 KERNEL32.DLL    BaseThreadInitThunk

modules:
00400000 FlashFXP.exe                    4.0.0.1534          K:\flashftp
04f40000 WMASF.DLL                       12.0.19041.1        C:\Windows\system32
0b270000 ssleay32.dll                                        K:\flashftp
10000000 libeay32.dll                                        K:\flashftp
58560000 explorerframe.dll               6.2.19041.1949      C:\Windows\system32
587e0000 iNetSafe.dll                    1.0.2.1820          C:\Program Files (x86)\360\360Safe\safemon
5bbe0000 PalmInputTSF.dll                3.1.0.1008          C:\Windows\System32
5cdc0000 cscapi.dll                      6.2.19041.546       C:\Windows\SYSTEM32
5cdd0000 DAVHLPR.dll                     6.2.19041.546       C:\Windows\System32
5cde0000 davclnt.dll                     6.2.19041.546       C:\Windows\System32
5ce00000 ntlanman.dll                    6.2.19041.2604      C:\Windows\System32
5ce20000 thumbcache.dll                  6.2.19041.1466      C:\Windows\System32
5d880000 apphelp.dll                     6.2.19041.2913      C:\Windows\SYSTEM32
5db50000 drprov.dll                      6.2.19041.546       C:\Windows\System32
5e420000 dataexchange.dll                6.2.19041.1387      C:\Windows\system32
601c0000 sppc.dll                        6.2.19041.1682      C:\Windows\System32
601e0000 SLC.dll                         6.2.19041.1682      C:\Windows\System32
60200000 Bcp47Langs.dll                  6.2.19041.1566      C:\Windows\System32
60250000 appresolver.dll                 6.2.19041.1620      C:\Windows\System32
61f30000 dcomp.dll                       6.2.19041.2913      C:\Windows\system32
620a0000 d3d11.dll                       6.2.19041.2913      C:\Windows\system32
63050000 mfperfhelper.dll                6.2.19041.1         C:\Windows\system32
635f0000 LINKINFO.dll                    6.2.19041.546       C:\Windows\SYSTEM32
63840000 MMDevApi.dll                    6.2.19041.2075      C:\Windows\System32
63950000 CoreUIComponents.dll            6.2.19041.546       C:\Windows\System32
63bd0000 CoreMessaging.dll               6.2.19041.2193      C:\Windows\System32
63c70000 wintypes.dll                    6.2.19041.2788      C:\Windows\SYSTEM32
63ec0000 textinputframework.dll          6.2.19041.2913      C:\Windows\SYSTEM32
64110000 twinapi.appcore.dll             6.2.19041.1865      C:\Windows\system32
642a0000 comctl32.dll                    6.10.19041.1110     C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_a8625c1886757984
646c0000 winspool.drv                    6.2.19041.2788      C:\Windows\SYSTEM32
6f640000 TextShaping.dll                                     C:\Windows\SYSTEM32
6f6e0000 WindowsCodecs.dll               6.2.19041.1706      C:\Windows\SYSTEM32
70870000 wsock32.dll                     6.2.19041.1         C:\Windows\SYSTEM32
70970000 WINNSI.DLL                      6.2.19041.546       C:\Windows\SYSTEM32
70980000 winhttp.dll                     6.2.19041.2673      C:\Windows\SYSTEM32
70a50000 ondemandconnroutehelper.dll     6.2.19041.2311      C:\Windows\SYSTEM32
71700000 MSVCR90.dll                     9.0.30729.9625      C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.9625_none_508ef7e4bcbbe589
718f0000 MPR.dll                         6.2.19041.1806      C:\Windows\SYSTEM32
71ac0000 DEVOBJ.dll                      6.2.19041.1620      C:\Windows\System32
71b50000 uxtheme.dll                     6.2.19041.2193      C:\Windows\system32
71e00000 MSIMG32.dll                     6.2.19041.1466      C:\Windows\System32
71e10000 ntmarta.dll                     6.2.19041.546       C:\Windows\SYSTEM32
71e70000 SAMLIB.dll                      6.2.19041.2788      C:\Windows\SYSTEM32
72000000 Windows.FileExplorer.Common.dll 6.2.19041.1566      C:\Windows\System32
72070000 mswsock.dll                     6.2.19041.546       C:\Windows\system32
72980000 WKSCLI.DLL                      6.2.19041.1645      C:\Windows\SYSTEM32
72a40000 OLEACC.dll                      7.2.19041.746       C:\Windows\SYSTEM32
72aa0000 propsys.dll                     7.0.19041.1741      C:\Windows\system32
72b70000 safemon.dll                     8.6.0.3780          C:\Program Files (x86)\360\360Safe\safemon
72ed0000 iertutil.dll                    11.0.19041.2965     C:\Windows\System32
73120000 SafeWrapper32.dll               2.0.0.1250          C:\Program Files (x86)\360\360Safe\safemon
73130000 urlmon.dll                      11.0.19041.2788     C:\Windows\System32
732e0000 dbghelp.dll                     6.2.19041.1052      C:\Windows\System32
735d0000 MSASN1.dll                      6.2.19041.2251      C:\Windows\SYSTEM32
735e0000 dbgcore.DLL                     6.2.19041.2788      C:\Windows\System32
739f0000 profapi.dll                     6.2.19041.844       C:\Windows\SYSTEM32
73ae0000 gdiplus.dll                     6.2.19041.2251      C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.2251_none_d9513b1fe1046fc7
73d30000 srvcli.dll                      6.2.19041.1645      C:\Windows\SYSTEM32
73d80000 CRYPTBASE.dll                   6.2.19041.546       C:\Windows\SYSTEM32
73f20000 rsaenh.dll                      6.2.19041.1052      C:\Windows\system32
73ff0000 CRYPTSP.dll                     6.2.19041.546       C:\Windows\SYSTEM32
74010000 wininet.dll                     11.0.19041.2193     C:\Windows\SYSTEM32
74670000 windows.storage.dll             6.2.19041.2788      C:\Windows\SYSTEM32
74f20000 samcli.dll                      6.2.19041.1466      C:\Windows\SYSTEM32
74f40000 NETUTILS.DLL                    6.2.19041.1466      C:\Windows\SYSTEM32
74f50000 NETAPI32.dll                    6.2.19041.2130      C:\Windows\SYSTEM32
75000000 Wldp.dll                        6.2.19041.2788      C:\Windows\SYSTEM32
75090000 SSPICLI.DLL                     6.2.19041.2130      C:\Windows\SYSTEM32
750c0000 Secur32.dll                     6.2.19041.546       C:\Windows\SYSTEM32
75160000 winmm.dll                       6.2.19041.546       C:\Windows\SYSTEM32
75360000 WINSTA.dll                      6.2.19041.2075      C:\Windows\System32
754f0000 IPHLPAPI.DLL                    6.2.19041.2788      C:\Windows\SYSTEM32
75640000 USERENV.dll                     6.2.19041.572       C:\Windows\System32
75680000 version.dll                     6.2.19041.546       C:\Windows\SYSTEM32
75800000 IMM32.DLL                       6.2.19041.2673      C:\Windows\System32
75830000 KERNELBASE.dll                  6.2.19041.2965      C:\Windows\System32
75a70000 shell32.dll                     6.2.19041.2788      C:\Windows\System32
76040000 dxgi.dll                        6.2.19041.2311      C:\Windows\System32
76110000 WS2_32.dll                      6.2.19041.546       C:\Windows\System32
76180000 ole32.dll                       6.2.19041.2965      C:\Windows\System32
76270000 NSI.dll                         6.2.19041.610       C:\Windows\System32
76280000 msvcrt.dll                      7.0.19041.546       C:\Windows\System32
76340000 kernel.appcore.dll              6.2.19041.546       C:\Windows\System32
76350000 bcryptPrimitives.dll            6.2.19041.2486      C:\Windows\System32
763b0000 KERNEL32.DLL                    6.2.19041.2913      C:\Windows\System32
764a0000 combase.dll                     6.2.19041.2788      C:\Windows\System32
76740000 RPCRT4.dll                      6.2.19041.2965      C:\Windows\System32
76800000 MSCTF.dll                       6.2.19041.2673      C:\Windows\System32
769d0000 SHLWAPI.dll                     6.2.19041.2075      C:\Windows\System32
76a20000 oleaut32.dll                    6.2.19041.985       C:\Windows\System32
76b10000 shcore.dll                      6.2.19041.1645      C:\Windows\System32
76ba0000 bcrypt.dll                      6.2.19041.2486      C:\Windows\System32
76bc0000 PSAPI.DLL                       6.2.19041.546       C:\Windows\System32
76bd0000 sechost.dll                     6.2.19041.2913      C:\Windows\System32
76cb0000 comdlg32.dll                    6.2.19041.1806      C:\Windows\System32
76d80000 SETUPAPI.dll                    6.2.19041.2193      C:\Windows\System32
771c0000 crypt32.dll                     6.2.19041.2965      C:\Windows\System32
772c0000 win32u.dll                      6.2.19041.2913      C:\Windows\System32
772e0000 ucrtbase.dll                    6.2.19041.789       C:\Windows\System32
77460000 gdi32full.dll                   6.2.19041.2965      C:\Windows\System32
77550000 GDI32.dll                       6.2.19041.2913      C:\Windows\System32
77580000 WINTRUST.dll                    6.2.19041.2913      C:\Windows\System32
775d0000 user32.dll                      6.2.19041.2965      C:\Windows\System32
777f0000 clbcatq.dll                     2001.12.10941.16384 C:\Windows\System32
77880000 msvcp_win.dll                   6.2.19041.789       C:\Windows\System32
779b0000 advapi32.dll                    6.2.19041.2913      C:\Windows\System32
77a90000 CFGMGR32.dll                    6.2.19041.1620      C:\Windows\System32
77ae0000 ntdll.dll                       6.2.19041.2965      C:\Windows\SYSTEM32
78460000 tiptsf.dll                      6.2.19041.746       C:\Program Files (x86)\Common Files\microsoft shared\ink
78620000 dlnashext.dll                   6.2.19041.1949      C:\Windows\System32
78670000 PlayToDevice.dll                6.2.19041.746       C:\Windows\System32
786c0000 DevDispItemProvider.dll         6.2.19041.546       C:\Windows\System32
786e0000 wpdshext.dll                    6.2.19041.1949      C:\Windows\system32
78770000 PortableDeviceApi.dll           6.2.19041.746       C:\Windows\System32
78800000 audiodev.dll                    6.2.19041.1         C:\Windows\system32
78840000 WMVCore.DLL                     12.0.19041.2604     C:\Windows\system32
78a80000 dssenh.dll                      6.2.19041.1052      C:\Windows\system32
78ab0000 msohevi.dll                     14.0.4730.1010      C:\Program Files (x86)\Microsoft Office\Office14
795a0000 PortableDeviceTypes.dll         6.2.19041.746       C:\Windows\System32
79ae0000 ntshrui.dll                     6.2.19041.844       C:\Windows\SYSTEM32
79b40000 policymanager.dll               6.2.19041.2913      C:\Windows\SYSTEM32
79bd0000 msvcp110_win.dll                6.2.19041.546       C:\Windows\SYSTEM32

processes:
0000 Idle                        0 0    0
0004 System                      0 0    0
0094 Registry                    0 0    0
0240 smss.exe                    0 0    0
02ec csrss.exe                   0 0    0
0364 wininit.exe                 0 0    0
036c csrss.exe                   1 0    0
03b4 services.exe                0 0    0
03c0 lsass.exe                   0 0    0
01c4 winlogon.exe                1 0    0
0320 svchost.exe                 0 0    0
041c WUDFHost.exe                0 0    0
0424 fontdrvhost.exe             1 0    0
042c fontdrvhost.exe             0 0    0
0494 svchost.exe                 0 0    0
04fc svchost.exe                 0 0    0
0554 dwm.exe                     1 0    0
0598 svchost.exe                 0 0    0
05f4 svchost.exe                 0 0    0
05fc svchost.exe                 0 0    0
0604 svchost.exe                 0 0    0
060c svchost.exe                 0 0    0
06a0 svchost.exe                 0 0    0
06a8 svchost.exe                 0 0    0
06dc svchost.exe                 0 0    0
0708 svchost.exe                 0 0    0
0784 svchost.exe                 0 0    0
07b0 svchost.exe                 0 0    0
07d4 atiesrxx.exe                0 0    0
02e4 svchost.exe                 0 0    0
0808 svchost.exe                 0 0    0
0824 svchost.exe                 0 0    0
08a0 svchost.exe                 0 0    0
08e8 svchost.exe                 0 0    0
09d4 svchost.exe                 0 0    0
09dc svchost.exe                 0 0    0
09e4 atieclxx.exe                1 0    0
0a2c svchost.exe                 0 0    0
0a4c svchost.exe                 0 0    0
0a54 svchost.exe                 0 0    0
0b10 svchost.exe                 0 0    0
0b58 svchost.exe                 0 0    0
0be8 svchost.exe                 0 0    0
0bf0 360rps.exe                  0 0    0
0bf8 svchost.exe                 0 0    0
0840 ZhuDongFangYu.exe           0 0    0
0854 svchost.exe                 0 0    0
0c1c svchost.exe                 0 0    0
0c58 spoolsv.exe                 0 0    0
0d08 svchost.exe                 0 0    0
0d34 svchost.exe                 0 0    0
0dac svchost.exe                 0 0    0
0db4 svchost.exe                 0 0    0
0df0 svchost.exe                 0 0    0
0e80 svchost.exe                 0 0    0
0e88 svchost.exe                 0 0    0
0e90 HPSIsvc.exe                 0 0    0
0e98 360DesktopService64.exe     0 0    0
0ea0 svchost.exe                 0 0    0
0ea8 svchost.exe                 0 0    0
0eb0 QQProtect.exe               0 0    0
0ec4 360bpsvc.exe                0 0    0
0ecc secbizsrv.exe               0 0    0
0ef4 pcas.exe                    0 0    0
0f14 WMIRegistrationService.exe  0 0    0
0f20 FlashHelperService.exe      0 0    0
0f68 phpStudyServer.exe          0 0    0
1004 svchost.exe                 0 0    0
1020 svchost.exe                 0 0    0
1078 svchost.exe                 0 0    0
10a8 svchost.exe                 0 0    0
1158 jhi_service.exe             0 0    0
05b8 SgrmBroker.exe              0 0    0
07dc svchost.exe                 0 0    0
0af0 svchost.exe                 0 0    0
1574 svchost.exe                 0 0    0
05a8 sihost.exe                  1 0    9   normal       C:\Windows\System32
095c svchost.exe                 1 0    1   normal       C:\Windows\System32
04b4 svchost.exe                 1 0    4   normal       C:\Windows\System32
1548 svchost.exe                 0 0    0
17f0 svchost.exe                 0 0    0
083c ctfmon.exe                  1 2    22  high         C:\Windows\System32
0834 taskhostw.exe               1 8    6   normal       C:\Windows\System32
0838 Explorer.exe                1 1015 686 normal       C:\Windows
06ec 360rp.exe                   1 6    2   normal       C:\Program Files\360\360sd
0324 360sd.exe                   1 434  232 normal       C:\Program Files\360\360sd
0940 aliwssv.exe                 0 0    0
0cb4 conhost.exe                 0 0    0
1190 svchost.exe                 1 0    8   normal       C:\Windows\System32
0334 ChsIME.exe                  1 0    4   normal       C:\Windows\System32\InputMethod\CHS
07fc StartMenuExperienceHost.exe 1 0    13  normal       C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy
15c4 RuntimeBroker.exe           1 0    1   normal       C:\Windows\System32
15ac SearchApp.exe               1 25   71  normal       C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy
0c18 RuntimeBroker.exe           1 36   4   normal       C:\Windows\System32
186c SearchIndexer.exe           0 0    0
1884 TextInputHost.exe           1 0    49  normal       C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy
18a0 PalmInputGuard.exe          1 0    4   normal       C:\Program Files (x86)\PalmInput\Extensions\Guard\2.6.0.49
19c4 360se.exe                   1 530  139 normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
19cc svchost.exe                 0 0    0
1b5c 360se.exe                   1 11   17  above normal C:\Users\Administrator\AppData\Roaming\360se6\Application
1b70 360se.exe                   1 0    3   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
1858 360se.exe                   1 0    1   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
1d64 svchost.exe                 0 0    0
1d8c 360huabao.exe               1 0    15  normal       C:\Users\Administrator\AppData\Roaming\360huabao
1dfc sesvc.exe                   1 0    15  normal       C:\Users\Administrator\AppData\Roaming\360se6\Application\components\sesvc
1e84 360se.exe                   1 0    2   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
1ec4 360se.exe                   1 0    2   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
1ecc 360se.exe                   1 0    2   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
2160 RAVCpl64.exe                1 69   18  normal       C:\Program Files\Realtek\Audio\HDA
2248 360DesktopLite64.exe        1 249  70  normal       D:\SoftCenter\DesktopLite
2288 360tray.exe                 1 318  70  normal       C:\Program Files (x86)\360\360Safe\safemon
2364 SeAppService.exe            1 27   22  normal       C:\Users\Administrator\AppData\Roaming\360se6\Application\components\seapp
1f18 PalmInputService.exe        1 18   17  normal       C:\Program Files (x86)\PalmInput\3.1.0.1008
2240 RadeonSoftware.exe          1 45   71  normal       C:\Program Files\AMD\CNext\CNext
26e4 AMDRSServ.exe               1 8    15  normal       C:\Program Files\AMD\CNext\CNext
27ac amdow.exe                   1 3    37  normal       C:\Program Files\AMD\CNext\CNext
2250 taskhostw.exe               1 0    2   normal       C:\Windows\System32
2504 svchost.exe                 1 0    1   normal       C:\Windows\System32
05d8 svchost.exe                 0 0    0
21d0 WmiPrvSE.exe                0 0    0
2270 WeChat.exe                  1 288  99  normal       D:\SoftCenter\Tencent\WeChat
0550 WeChat.exe                  1 188  84  normal       D:\SoftCenter\Tencent\WeChat
1164 mmcrashpad_handler64.exe    1 0    4   normal       D:\SoftCenter\Tencent\WeChat\[3.9.6.33]
22e8 mmcrashpad_handler64.exe    1 0    4   normal       D:\SoftCenter\Tencent\WeChat\[3.9.6.33]
2128 WeChatAppEx.exe             1 33   58  normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
2648 WeChatAppEx.exe             1 31   59  normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
096c WeChatAppEx.exe             1 0    4   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
2470 WeChatAppEx.exe             1 0    4   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
285c WeChatAppEx.exe             1 0    1   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
2874 WeChatAppEx.exe             1 0    1   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
28d0 WeChatAppEx.exe             1 7    29  above normal C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
2920 WeChatAppEx.exe             1 7    30  above normal C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
2ad0 QQ.exe                      1 129  142 normal       D:\SoftCenter\Tencent\QQ\Bin
2ad8 WeChatAppEx.exe             1 0    0   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
2afc WeChatAppEx.exe             1 0    0   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
2cfc TXPlatform.exe              1 0    2   normal       D:\SoftCenter\Tencent\QQ\Bin
2f2c QQGuild.exe                 1 22   56  normal       C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.12-197
2b30 QQGuild.exe                 1 3    24  above normal C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.12-197
03f4 QQGuild.exe                 1 0    1   normal       C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.12-197
2760 QQGuild.exe                 1 0    0   normal       C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.12-197
24f0 QQGuild.exe                 1 0    0   normal       C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.12-197
1904 WeChatPlayer.exe            1 0    1   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\ThumbPlayer\4063\extracted
3398 WeChatUtility.exe           1 0    1   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\WeChatUtility\8077\extracted
1098 WeChatOCR.exe               1 0    1   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\WeChatOCR\7053\extracted
2190 WeChatAppEx.exe             1 0    1   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
3150 WeChatAppEx.exe             1 0    0   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
0d9c WeChatAppEx.exe             1 0    0   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
30f8 WeChatAppEx.exe             1 0    0   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
2eac WeChatPlayer.exe            1 0    1   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\ThumbPlayer\4063\extracted
33ac WeChatUtility.exe           1 0    1   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\WeChatUtility\8077\extracted
2530 WeChatOCR.exe               1 0    1   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\WeChatOCR\7053\extracted
296c WeChatAppEx.exe             1 0    1   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
1f00 WeChatAppEx.exe             1 0    0   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
1490 WeChatAppEx.exe             1 0    0   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
21cc WeChatAppEx.exe             1 0    0   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
3268 WeChatAppEx.exe             1 0    0   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
32a4 WeChatAppEx.exe             1 0    0   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\8391\extracted\runtime
1aec dllhost.exe                 0 0    0
03d4 ΢ſ߹.exe          1 0    1   normal       D:\SoftCenter\Tencent\΢web߹
3120 wechatdevtools.exe          1 40   69  normal       D:\SoftCenter\Tencent\΢web߹
2a84 wechatdevtools.exe          1 0    4   normal       D:\SoftCenter\Tencent\΢web߹
06c8 wechatdevtools.exe          1 9    25  above normal D:\SoftCenter\Tencent\΢web߹
2910 wechatdevtools.exe          1 0    1   normal       D:\SoftCenter\Tencent\΢web߹
2908 wechatdevtools.exe          1 0    1   normal       D:\SoftCenter\Tencent\΢web߹
2804 wechatdevtools.exe          1 0    1   normal       D:\SoftCenter\Tencent\΢web߹
2d48 wechatdevtools.exe          1 0    1   normal       D:\SoftCenter\Tencent\΢web߹
0ab0 wechatdevtools.exe          1 0    1   idle         D:\SoftCenter\Tencent\΢web߹
3528 wxfilewatcher_x64.exe       1 0    3   normal       D:\SoftCenter\Tencent\΢web߹
3538 conhost.exe                 1 10   3   normal       C:\Windows\System32
3624 wechatdevtools.exe          1 0    1   normal       D:\SoftCenter\Tencent\΢web߹
36d0 wechatdevtools.exe          1 0    1   idle         D:\SoftCenter\Tencent\΢web߹
37e0 wechatdevtools.exe          1 0    1   normal       D:\SoftCenter\Tencent\΢web߹
36d8 wxfilewatcher_x64.exe       1 0    2   normal       D:\SoftCenter\Tencent\΢web߹
3704 conhost.exe                 1 10   3   normal       C:\Windows\System32
36b4 node.exe                    1 0    3   normal       D:\SoftCenter\Tencent\΢web߹
3688 conhost.exe                 1 10   3   normal       C:\Windows\System32
34cc wxfilewatcher_x64.exe       1 0    3   normal       D:\SoftCenter\Tencent\΢web߹
3510 conhost.exe                 1 10   3   normal       C:\Windows\System32
35f8 node.exe                    1 0    3   normal       D:\SoftCenter\Tencent\΢web߹
34dc conhost.exe                 1 10   3   normal       C:\Windows\System32
3978 wechatdevtools.exe          1 0    1   normal       D:\SoftCenter\Tencent\΢web߹
39b0 audiodg.exe                 0 0    0
39ec svchost.exe                 0 0    0
3aa0 node.exe                    1 0    3   normal       D:\SoftCenter\Tencent\΢web߹
3ab0 conhost.exe                 1 10   3   normal       C:\Windows\System32
3b1c node.exe                    1 0    3   normal       D:\SoftCenter\Tencent\΢web߹
3b3c node.exe                    1 0    3   normal       D:\SoftCenter\Tencent\΢web߹
3bb4 node.exe                    1 0    3   normal       D:\SoftCenter\Tencent\΢web߹
3958 node.exe                    1 0    3   normal       D:\SoftCenter\Tencent\΢web߹
3ab8 node.exe                    1 0    3   normal       D:\SoftCenter\Tencent\΢web߹
3248 conhost.exe                 1 10   3   normal       C:\Windows\System32
3854 wechatdevtools.exe          1 0    1   normal       D:\SoftCenter\Tencent\΢web߹
38c0 node.exe                    1 41   3   normal       D:\SoftCenter\Tencent\΢web߹
3b60 360se.exe                   1 0    1   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
3c04 360UDiskPro.exe             1 95   38  normal       C:\Program Files (x86)\360\360Safe\safemon
3d0c WUDFHost.exe                0 0    0
28cc cmd.exe                     1 0    0   normal       C:\Windows\System32
3dac conhost.exe                 1 27   21  normal       C:\Windows\System32
4568 dllhost.exe                 1 0    3   normal       C:\Windows\System32
44c0 RuntimeBroker.exe           1 36   1   normal       C:\Windows\System32
3ee0 360se.exe                   1 0    2   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
3d38 360se.exe                   1 0    2   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
4698 360se.exe                   1 0    2   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
1104 360se.exe                   1 0    11  normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
1bb4 phpstudy_pro.exe            1 117  46  normal       E:\phpstudy_pro\COM
0a44 mysqld.exe                  1 0    2   normal       E:\phpstudy_pro\Extensions\MySQL5.7.26\bin
2c48 360se.exe                   1 0    2   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
0658 FlashFXP.exe                1 118  82  normal
3cf4 baidunetdisk.exe            1 208  131 normal       C:\Users\Administrator\AppData\Roaming\baidu\BaiduNetdisk
4b0c yundetectservice.exe        1 0    5   normal       C:\Users\Administrator\AppData\Roaming\baidu\BaiduNetdisk
1530 baidunetdiskhost.exe        1 0    11  normal       C:\Users\Administrator\AppData\Roaming\baidu\BaiduNetdisk
0e5c baidunetdiskhost.exe        1 10   9   normal       C:\Users\Administrator\AppData\Roaming\baidu\BaiduNetdisk
32ec Explorer.exe                1 435  169 normal       C:\Windows
4344 360se.exe                   1 0    2   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
4acc xp.cn_cgi.exe               1 0    0   normal       E:\phpstudy_pro\COM
1bf0 nginx.exe                   1 0    1   normal       E:\phpstudy_pro\Extensions\Nginx1.15.11
33b4 xp.cn_cgi.exe               1 0    0   normal       E:\phpstudy_pro\COM
44ec xp.cn_cgi.exe               1 0    0   normal       E:\phpstudy_pro\COM
3e60 php-cgi.exe                 1 0    4   normal       E:\phpstudy_pro\Extensions\php\php5.4.45nts
4a78 php-cgi.exe                 1 0    1   normal       E:\phpstudy_pro\Extensions\php\php7.2.9nts
45ac php-cgi.exe                 1 0    1   normal       E:\phpstudy_pro\Extensions\php\php7.3.4nts
1584 conhost.exe                 1 8    3   normal       C:\Windows\System32
41e4 conhost.exe                 1 8    3   normal       C:\Windows\System32
498c conhost.exe                 1 8    3   normal       C:\Windows\System32
4830 nginx.exe                   1 0    1   normal       E:\phpstudy_pro\Extensions\Nginx1.15.11
460c conhost.exe                 1 8    3   normal       C:\Windows\System32
4b68 nginx.exe                   1 0    1   normal       E:\phpstudy_pro\Extensions\Nginx1.15.11
34bc conhost.exe                 1 8    3   normal       C:\Windows\System32
49e0 nginx.exe                   1 0    1   normal       E:\phpstudy_pro\Extensions\Nginx1.15.11
32f4 conhost.exe                 1 8    3   normal       C:\Windows\System32
45e8 nginx.exe                   1 0    1   normal       E:\phpstudy_pro\Extensions\Nginx1.15.11
4230 conhost.exe                 1 8    3   normal       C:\Windows\System32
3e90 360se.exe                   1 0    2   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
4564 360se.exe                   1 0    2   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
48e4 360se.exe                   1 0    9   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
361c 360se.exe                   1 0    2   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
1b1c 360se.exe                   1 0    2   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
444c php-cgi.exe                 1 0    1   normal       E:\phpstudy_pro\Extensions\php\php7.2.9nts
4be8 conhost.exe                 1 8    3   normal       C:\Windows\System32
150c mhtab.exe                   1 136  26  normal       F:\\my
3108 mhmain.exe                  1 64   22  normal       F:\\my
3a7c xyqsvc.exe                  1 1    4   normal       F:\\my
3c3c xyqsvc.exe                  1 0    2   normal       F:\\my
4678 mhrender.exe                1 10   17  normal       F:\\my\athena\Engine\Binaries\Win64
4b28 SearchProtocolHost.exe      1 0    1   idle         C:\Windows\System32
4904 svchost.exe                 0 0    0
4474 360se.exe                   1 0    2   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
46d4 360se.exe                   1 0    2   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
2e40 360se.exe                   1 0    2   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application
2aec Dreamweaver.exe             1 831  605 normal       C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6
3db0 CS6ServiceManager.exe       1 0    5   normal       C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager
09ac SearchFilterHost.exe        0 0    0   idle         C:\Windows\System32
3990 svchost.exe                 0 0    0
47dc SearchProtocolHost.exe      0 0    0
49a4 dllhost.exe                 1 0    4   normal       C:\Windows\System32

hardware:
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
  - Fax
  - Foxit PDF Reader Printer
  - HP LaserJet Professional P1606dn
  - Microsoft Print to PDF
  - Microsoft XPS Document Writer
  - ΪWPS PDF
  - ӡ
+ {36fc9e60-c465-11cf-8056-444553540000}
  - Intel(R) USB 3.0 չ - 1.0 (Microsoft)
  - USB Composite Device
  - USB 洢豸
  - USB 洢豸
  - USB (USB 3.0)
+ {4d36e965-e325-11ce-bfc1-08002be10318}
  - MATSHITA DVD-RAM UJ8C0 USB Device
+ {4d36e966-e325-11ce-bfc1-08002be10318}
  -  ACPI x64 ĵ
+ {4d36e967-e325-11ce-bfc1-08002be10318}
  - Extemal usb3.0 SCSI Disk Device
  - GALAX BA1M0250N
  - SMI USB DISK USB Device
  - ST1000DM010-2EP102
+ {4d36e968-e325-11ce-bfc1-08002be10318}
  - AMD Radeon R5 M240 (driver 27.20.14501.28009)
  - OrayIddDriver Device (driver 17.1.58.818)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
  - ׼ SATA AHCI 
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
  - HID Keyboard Device
  - HID Keyboard Device
  - PS/2 ׼
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
  - AMD High Definition Audio Device (driver 10.0.1.24)
  - Realtek High Definition Audio (driver 6.0.9239.1)
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
  - ͨü弴ü
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
  - HID-compliant mouse
  - HID-compliant mouse
  - HID-compliant mouse
  - Microsoft PS/2 
+ {4d36e972-e325-11ce-bfc1-08002be10318}
  - iNode VPN Virtual NIC (driver 1.0.0.0)
  - Realtek PCIe GbE Family Controller (driver 10.63.1014.2022)
  - Virtual Network Adapter (driver 9.0.0.2)
+ {4d36e978-e325-11ce-bfc1-08002be10318}
  - ͨŶ˿ (COM1)
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
  - Microsoft 洢ռ
  - USB Attached SCSI (UAS) 洢豸
  - ׼ NVM Express 
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
  - ACPI ۺ
  - ACPI Դť
  - ACPI 
  - ACPI 
  - ACPI 
  - ACPI 
  - ACPI 
  - ACPI ̶ܰť
  - ACPI Ѿ
  - ACPI 
  - ACPI ˯߰ť
  - High Definition Audio 
  - High Definition Audio 
  - Intel(R) Management Engine Interface #1 (driver 2251.4.2.0)
  - Intel(R) PMC - A3A1 (driver 10.1.33.5)
  - Intel(R) Power Engine Plug-in
  - Intel(R) Serial IO GPIO Host Controller - INT3451 (driver 30.100.1943.2)
  - Intel(R) Serial IO I2C Host Controller - A3E0 (driver 30.100.1943.2)
  - Intel(R) Serial IO I2C Host Controller - A3E1 (driver 30.100.1943.2)
  - Intel(R) SMBus - A3A3 (driver 10.1.33.5)
  - Intel(R) Thermal Subsystem - A3B1 (driver 10.1.33.5)
  - Intel(R) Watchdog Timer Driver (Intel(R) WDT) (driver 11.7.0.1000)
  - Intel(R) Xeon(R) E3 - 1200/1500 v5/6th Gen Intel(R) Core(TM) Gaussian Mixture Model - 1911 (driver 10.1.1.45)
  - Microsoft ACPI-Compliant System
  - Microsoft Hyper-V ⻯ṹ
  - Microsoft System Management BIOS Driver
  - Microsoft Windows Management Interface for ACPI
  - Microsoft Windows Management Interface for ACPI
  - Microsoft 
  - Microsoft ʾ
  - Microsoft ö
  - NDIS ö
  - Oray Virtual Game Controller (driver 1.0.0.0)
  - Pci Bus (driver 20.50.0.0)
  - PCI Express ˿
  - PCI Express ˿
  - PCI Express ˿
  - PCI ׼ ISA 
  - PCI ׼ CPU 
  - UMBus Root Bus Enumerator
  - ö
  - ߾¼ʱ
  - 弴豸ö
  - 
  - ɱжϿ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ֵݴ
  - ϵͳʱ
  - Զ豸ض
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
+ {533c5b84-ec70-11d2-9505-00c04f79deaf}
  - ͨþӰ
  - ͨþӰ
  - ͨþӰ
  - ͨþӰ
+ {5c4c3332-344d-483c-8739-259e934c9cc8}
  - Intel(R) Dynamic Application Loader Host Interface (driver 1.41.2021.121)
  - Intel(R) iCLS Client (driver 1.63.1155.1)
  - Intel(R) Management Engine WMI Provider (driver 2130.1.15.0)
+ {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
  - Microsoft Device Association Root Enumerator
  - Microsoft GS ϳ
  - Microsoft Radio Device Enumeration Bus
  - Microsoft RRAS Root Enumerator
+ {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
  - HID-compliant device (driver 4.0.0.0)
  - HID-compliant device (driver 4.0.0.0)
  - HID-compliant game controller
  - Microsoft Input Configuration Device
  - Oray VHID (driver 6.1.7600.16385)
  - USB 豸
  - USB 豸
  - USB 豸
  - USB 豸
  -  HID ׼ֻ
  -  HID ׼ϵͳ
  -  HID ׼û豸
+ {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
  - 1 - HDMI (AMD High Definition Audio Device)
  - ˷ (Realtek High Definition Audio)
  -  (Realtek High Definition Audio)
+ {eec5ad98-8080-425f-922a-dabf3de3f69a}
  - EFI
  - 
  - ëU

cpu registers:
eax = 00000000
ebx = 000000c8
ecx = 02dddd08
edx = 02ddd9a0
esi = 00793dbc
edi = 007b64a4
eip = 10003d50
esp = 0019fed8
ebp = 0019fee8

stack dump:
0019fed8  dd 1f 62 00 a4 64 7b 00 - bc 3d 79 00 c8 00 00 00  ..b..d{..=y.....
0019fee8  fc fe 19 00 8d 21 62 00 - 04 ff 19 00 ac 3a 40 00  .....!b......:@.
0019fef8  fc fe 19 00 1c ff 19 00 - 94 3d 40 00 64 ff 19 00  .........=@.d...
0019ff08  9b 3b 40 00 1c ff 19 00 - 3c 60 7b 00 38 60 7b 00  .;@.....<`{.8`{.
0019ff18  a4 64 7b 00 90 a9 40 00 - de c2 4b 00 b3 3f 40 00  .d{...@...K..?@.
0019ff28  70 ff 19 00 84 48 79 00 - 84 48 79 00 00 f0 34 00  p....Hy..Hy...4.
0019ff38  4d 65 79 00 00 00 00 00 - 00 00 00 00 00 00 00 00  Mey.............
0019ff48  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0019ff58  00 00 00 00 00 00 00 00 - 00 00 00 00 cc ff 19 00  ................
0019ff68  98 3c 40 00 70 ff 19 00 - 80 ff 19 00 c9 00 3d 76  .<@.p.........=v
0019ff78  00 f0 34 00 b0 00 3d 76 - dc ff 19 00 4e 7b b4 77  ..4...=v....N{.w
0019ff88  00 f0 34 00 c6 6a f3 11 - 00 00 00 00 00 00 00 00  ..4..j..........
0019ff98  00 f0 34 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ..4.............
0019ffa8  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0019ffb8  00 00 00 00 00 00 00 00 - 00 00 00 00 8c ff 19 00  ................
0019ffc8  00 00 00 00 e4 ff 19 00 - 00 ae b5 77 ea 5c 54 66  ...........w.\Tf
0019ffd8  00 00 00 00 ec ff 19 00 - 1e 7b b4 77 ff ff ff ff  .........{.w....
0019ffe8  87 8c b6 77 00 00 00 00 - 00 00 00 00 84 48 79 00  ...w.........Hy.
0019fff8  00 f0 34 00 00 00 00 00                            ..4.....

disassembling:
[...]
00796513       ret
00796514       jmp     -$392a9d ($403a7c)     ; System.@HandleFinally
00796519       jmp     loc_7964ff
0079651b       xor     eax, eax
0079651d       pop     edx
0079651e       pop     ecx
0079651f       pop     ecx
00796520       mov     fs:[eax], edx
00796523       push    $796545
00796528       lea     eax, [ebp-$2c]
0079652b       mov     edx, 7
00796530       call    -$392435 ($404100)     ; System.@LStrArrayClr
00796535       lea     eax, [ebp-$10]
00796538       call    -$38fff9 ($406544)     ; System.@IntfClear
0079653d       ret
0079653e       jmp     -$392ac7 ($403a7c)     ; System.@HandleFinally
00796543       jmp     loc_796528
00796545 939   pop     edi
00796546       pop     esi
00796547       pop     ebx
00796548     > call    -$392625 ($403f28)     ; System.@Halt0

date/time         : 2024-03-19, 14:54:23, 447ms
computer name     : WIN-20240227HNP
user name         : Administrator <admin>
registered owner  : Windows û
operating system  : Windows NT New x64 (6.2.9200) build 9200
system language   : Chinese (Simplified)
system up time    : 6 hours 30 minutes
program up time   : 6 hours 19 minutes
processors        : 12x Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
physical memory   : 9748/16313 MB (free/total)
free disk space   : (C:) 114.20 GB (L:) 625.45 GB
display mode      : 1920x1080, 32 bit
process id        : $be4
allocated memory  : 101.77 MB
executable        : FlashFXP.exe
exec. date/time   : 2011-02-10 14:04
executable hash   : D84AD91A8B7B4991A5C31CE21C98C2CD
version           : 4.0.0.1534
language          : chinese simplified
callstack crc     : $392841d5, $0870768a, $bfb686e3
exception number  : 1
exception class   : EAccessViolation
exception message : Access violation at address 0073A8DB in module 'FlashFXP.exe'. ȡ of address 0F800047.

main thread ($1be8):
0073a8db +0047 FlashFXP.exe FrmMain1    10238   +5 TFrmMain.mnuRefreshClick
0041cb83 +000f FlashFXP.exe Classes                TBasicAction.Execute
0046459d +0031 FlashFXP.exe ActnList               TContainedAction.Execute
00464e52 +0012 FlashFXP.exe ActnList               TCustomAction.Execute
004648df +004b FlashFXP.exe ActnList               TCustomActionList.IsShortCut
00449ebc +003c FlashFXP.exe Forms        5034   +3 DispatchShortCut
00449f34 +0060 FlashFXP.exe Forms        5045   +3 TCustomForm.IsShortCut
0077b779 +0009 FlashFXP.exe FrmMain1    32669   +0 TFrmMain.IsShortCut
0045835e +0066 FlashFXP.exe Controls               TWinControl.IsMenuKey
0045839e +0012 FlashFXP.exe Controls               TWinControl.CNKeyDown
00635b4a +0016 FlashFXP.exe UPTTreeList            TPTCustomListView.CNKeyDown
00453e35 +0111 FlashFXP.exe Controls               TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls               TWinControl.WndProc
004f5c5e +0072 FlashFXP.exe ComCtrls               TCustomListView.WndProc
0045632c +002c FlashFXP.exe Controls               TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms        1529   +8 StdWndProc
76d359a6 +0016 user32.dll                          CallWindowProcW
76d24418 +0048 user32.dll                          SendMessageA
0044c934 +0050 FlashFXP.exe Forms        7051  +11 TApplication.IsKeyMsg
0044ca82 +006e FlashFXP.exe Forms        7113  +30 TApplication.ProcessMessage
0078ff43 +0117 FlashFXP.exe FDSock       6391  +20 TSFTP.IntMessageLoop
0061ba0a +0112 FlashFXP.exe SBSftp                 TElSftpClient.Read
0061bbd9 +0059 FlashFXP.exe SBSftp                 TElSftpClient.ReadSync
00629d33 +0607 FlashFXP.exe FDFtp        2581 +150 TFDFTP.Download
0075bd37 +0d97 FlashFXP.exe FrmMain1    21495 +331 TFrmMain.DownloadFile
0072fbb2 +162a FlashFXP.exe FrmMain1     5980 +511 TFrmMain.Transfer1Click
007288f5 +0039 FlashFXP.exe FrmMain1     3177   +9 TFrmMain.WMTRANS
00453e35 +0111 FlashFXP.exe Controls               TControl.WndProc
004566a2 +01ae FlashFXP.exe Controls               TWinControl.WndProc
00446bcd +0571 FlashFXP.exe Forms        3235 +139 TCustomForm.WndProc
00509afb +003f FlashFXP.exe ThemeMgr               TWindowProcList.DispatchMessage
0050a448 +00dc FlashFXP.exe ThemeMgr               TThemeManager.FormWindowProc
0050b939 +0009 FlashFXP.exe ThemeMgr               TThemeManager.PreFormWindowProc
0045632c +002c FlashFXP.exe Controls               TWinControl.MainWndProc
00443c9c +0014 FlashFXP.exe Forms        1529   +8 StdWndProc
76d27fbb +000b user32.dll                          DispatchMessageA
0044ca9f +008b FlashFXP.exe Forms        7117  +34 TApplication.ProcessMessage
0044cad6 +000a FlashFXP.exe Forms        7155   +1 TApplication.HandleMessage
0044cd8b +00bf FlashFXP.exe Forms        7259  +26 TApplication.Run
007964ed +1c69 FlashFXP.exe FlashFXP      920 +630 initialization
76c2fcc7 +0017 KERNEL32.DLL                        BaseThreadInitThunk

thread $21b0:
77374f2d +0fd KERNELBASE.dll                           WaitForMultipleObjectsEx
77374e13 +013 KERNELBASE.dll                           WaitForMultipleObjects
00640bd3 +07b FlashFXP.exe   UPTShellControls 4370 +13 TChangeHandlerThread.Execute
0041bfc4 +230 FlashFXP.exe   Classes                   HexToBin
00404080 +028 FlashFXP.exe   System                    ThreadWrapper
76c2fcc7 +017 KERNEL32.DLL                             BaseThreadInitThunk

thread $21d4:
76c2fcc7 +17 KERNEL32.DLL  BaseThreadInitThunk

thread $18a8: <priority:1>
76c2fcc7 +17 KERNEL32.DLL  BaseThreadInitThunk

thread $2a54:
77374f2d +0fd KERNELBASE.dll               WaitForMultipleObjectsEx
77374e13 +013 KERNELBASE.dll               WaitForMultipleObjects
00662068 +10c FlashFXP.exe   SaveToFileThd TSaveFileWorker.Execute
0041bfc4 +230 FlashFXP.exe   Classes       HexToBin
00404080 +028 FlashFXP.exe   System        ThreadWrapper
76c2fcc7 +017 KERNEL32.DLL                 BaseThreadInitThunk

thread $5738:
76c2fcc7 +17 KERNEL32.DLL  BaseThreadInitThunk

modules:
00400000 FlashFXP.exe                    4.0.0.1534          L:\flashftp
0b440000 ssleay32.dll                    1.0.0.3             L:\flashftp
10000000 libeay32.dll                    1.0.0.3             L:\flashftp
513e0000 TortoiseSVN32.dll                                   C:\Program Files\TortoiseSVN\bin
55ff0000 sppc.dll                        6.2.19041.3636      C:\Windows\System32
56010000 SLC.dll                         6.2.19041.3636      C:\Windows\System32
56030000 Bcp47Langs.dll                  6.2.19041.3636      C:\Windows\System32
56080000 appresolver.dll                 6.2.19041.3996      C:\Windows\System32
58940000 cscapi.dll                      6.2.19041.3636      C:\Windows\SYSTEM32
589d0000 thumbcache.dll                  6.2.19041.3636      C:\Windows\System32
58a20000 TortoiseStub32.dll                                  C:\Program Files\TortoiseSVN\bin
58a40000 ntshrui.dll                     6.2.19041.3636      C:\Windows\SYSTEM32
59640000 dssenh.dll                      6.2.19041.3636      C:\Windows\system32
59670000 tiptsf.dll                      6.2.19041.3636      C:\Program Files (x86)\Common Files\microsoft shared\ink
59700000 policymanager.dll               6.2.19041.4116      C:\Windows\SYSTEM32
59790000 iNetSafe.dll                    1.0.2.1900          C:\Program Files (x86)\360\360Safe\safemon
59a10000 msvcp110_win.dll                6.2.19041.3636      C:\Windows\SYSTEM32
59f30000 TortoiseOverlays.dll                                C:\Program Files (x86)\Common Files\TortoiseOverlays
59f50000 olepro32.dll                    6.2.19041.3636      C:\Windows\SYSTEM32
5daf0000 apphelp.dll                     6.2.19041.3636      C:\Windows\SYSTEM32
5db90000 PalmInputTSF.dll                3.1.0.1010          C:\Windows\System32
5e5e0000 LINKINFO.dll                    6.2.19041.3636      C:\Windows\SYSTEM32
5e9f0000 explorerframe.dll               6.2.19041.3996      C:\Windows\system32
63290000 d3d11.dll                       6.2.19041.3636      C:\Windows\system32
63470000 dataexchange.dll                6.2.19041.3636      C:\Windows\system32
63910000 dcomp.dll                       6.2.19041.3693      C:\Windows\system32
63e60000 CoreUIComponents.dll            6.2.19041.3636      C:\Windows\System32
640e0000 CoreMessaging.dll               6.2.19041.4116      C:\Windows\System32
64180000 wintypes.dll                    6.2.19041.4116      C:\Windows\SYSTEM32
64350000 textinputframework.dll          6.2.19041.4116      C:\Windows\SYSTEM32
64620000 twinapi.appcore.dll             6.2.19041.4116      C:\Windows\system32
647c0000 comctl32.dll                    6.10.19041.3636     C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db
64be0000 winspool.drv                    6.2.19041.3693      C:\Windows\SYSTEM32
6fa40000 TextShaping.dll                                     C:\Windows\SYSTEM32
6fae0000 WindowsCodecs.dll               6.2.19041.3636      C:\Windows\SYSTEM32
6ff80000 safemon.dll                     8.6.0.3810          C:\Program Files (x86)\360\360Safe\safemon
708c0000 wsock32.dll                     6.2.19041.1         C:\Windows\SYSTEM32
709a0000 ntmarta.dll                     6.2.19041.3636      C:\Windows\SYSTEM32
70aa0000 uxtheme.dll                     6.2.19041.3996      C:\Windows\system32
71290000 WKSCLI.DLL                      6.2.19041.3636      C:\Windows\SYSTEM32
712b0000 MPR.dll                         6.2.19041.3636      C:\Windows\SYSTEM32
714c0000 OLEACC.dll                      7.2.19041.3636      C:\Windows\SYSTEM32
71530000 MSIMG32.dll                     6.2.19041.3636      C:\Windows\System32
715b0000 SafeWrapper32.dll               2.0.0.1270          C:\Program Files (x86)\360\360Safe\safemon
716d0000 SAMLIB.dll                      6.2.19041.3996      C:\Windows\SYSTEM32
716f0000 Windows.FileExplorer.Common.dll 6.2.19041.3636      C:\Windows\System32
71890000 WINNSI.DLL                      6.2.19041.3636      C:\Windows\SYSTEM32
718a0000 ondemandconnroutehelper.dll     6.2.19041.3636      C:\Windows\SYSTEM32
71e40000 propsys.dll                     7.0.19041.3636      C:\Windows\system32
724d0000 iertutil.dll                    11.0.19041.4116     C:\Windows\System32
72710000 winhttp.dll                     6.2.19041.3636      C:\Windows\SYSTEM32
727e0000 dbgcore.DLL                     6.2.19041.3636      C:\Windows\System32
72810000 urlmon.dll                      11.0.19041.3996     C:\Windows\System32
72a60000 dbghelp.dll                     6.2.19041.3996      C:\Windows\System32
730b0000 gdiplus.dll                     6.2.19041.3996      C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3996_none_d954cb49e10154a6
73340000 srvcli.dll                      6.2.19041.3636      C:\Windows\SYSTEM32
73430000 rsaenh.dll                      6.2.19041.3636      C:\Windows\system32
73460000 profapi.dll                     6.2.19041.3636      C:\Windows\SYSTEM32
73480000 CRYPTSP.dll                     6.2.19041.3636      C:\Windows\SYSTEM32
734d0000 MSASN1.dll                      6.2.19041.3636      C:\Windows\SYSTEM32
735d0000 CRYPTBASE.DLL                   6.2.19041.3636      C:\Windows\SYSTEM32
73770000 WININET.dll                     11.0.19041.3636     C:\Windows\SYSTEM32
73d60000 windows.storage.dll             6.2.19041.4116      C:\Windows\SYSTEM32
74620000 samcli.dll                      6.2.19041.3636      C:\Windows\SYSTEM32
74640000 NETUTILS.DLL                    6.2.19041.3636      C:\Windows\SYSTEM32
746e0000 Wldp.dll                        6.2.19041.4116      C:\Windows\SYSTEM32
74770000 Secur32.dll                     6.2.19041.3636      C:\Windows\SYSTEM32
74810000 winmm.dll                       6.2.19041.3636      C:\Windows\SYSTEM32
74a60000 SSPICLI.DLL                     6.2.19041.3636      C:\Windows\SYSTEM32
74be0000 mswsock.dll                     6.2.19041.3636      C:\Windows\system32
74c40000 NETAPI32.dll                    6.2.19041.3636      C:\Windows\SYSTEM32
74fe0000 IPHLPAPI.DLL                    6.2.19041.3636      C:\Windows\SYSTEM32
75260000 USERENV.dll                     6.2.19041.3636      C:\Windows\System32
75290000 version.dll                     6.2.19041.3636      C:\Windows\SYSTEM32
752d0000 combase.dll                     6.2.19041.4116      C:\Windows\System32
756c0000 shell32.dll                     6.2.19041.4116      C:\Windows\System32
75ca0000 sechost.dll                     6.2.19041.3930      C:\Windows\System32
75d20000 GDI32.dll                       6.2.19041.3996      C:\Windows\System32
75d50000 PSAPI.DLL                       6.2.19041.3636      C:\Windows\System32
75d60000 CFGMGR32.dll                    6.2.19041.3996      C:\Windows\System32
75e00000 bcrypt.dll                      6.2.19041.3636      C:\Windows\System32
75e20000 gdi32full.dll                   6.2.19041.4116      C:\Windows\System32
75fe0000 bcryptPrimitives.dll            6.2.19041.3636      C:\Windows\System32
76130000 oleaut32.dll                    6.2.19041.3636      C:\Windows\System32
761d0000 shcore.dll                      6.2.19041.3636      C:\Windows\System32
76260000 dxgi.dll                        6.2.19041.3636      C:\Windows\System32
76330000 ucrtbase.dll                    6.2.19041.3636      C:\Windows\System32
76450000 crypt32.dll                     6.2.19041.3636      C:\Windows\System32
76b30000 MSCTF.dll                       6.2.19041.4116      C:\Windows\System32
76c10000 KERNEL32.DLL                    6.2.19041.3636      C:\Windows\System32
76d00000 user32.dll                      6.2.19041.4116      C:\Windows\System32
76ea0000 msvcrt.dll                      7.0.19041.3636      C:\Windows\System32
76f60000 clbcatq.dll                     2001.12.10941.16384 C:\Windows\System32
76fe0000 win32u.dll                      6.2.19041.4116      C:\Windows\System32
77000000 WS2_32.dll                      6.2.19041.3636      C:\Windows\System32
77070000 SHLWAPI.dll                     6.2.19041.3636      C:\Windows\System32
770c0000 advapi32.dll                    6.2.19041.4116      C:\Windows\System32
77140000 RPCRT4.dll                      6.2.19041.4116      C:\Windows\System32
77250000 KERNELBASE.dll                  6.2.19041.4116      C:\Windows\System32
77490000 kernel.appcore.dll              6.2.19041.3758      C:\Windows\System32
774b0000 NSI.dll                         6.2.19041.3636      C:\Windows\System32
774c0000 IMM32.DLL                       6.2.19041.3996      C:\Windows\System32
774f0000 msvcp_win.dll                   6.2.19041.3636      C:\Windows\System32
77570000 ole32.dll                       6.2.19041.3636      C:\Windows\System32
77660000 comdlg32.dll                    6.2.19041.3758      C:\Windows\System32
77720000 ntdll.dll                       6.2.19041.3996      C:\Windows\SYSTEM32

processes:
0000 Idle                        0 0    0
0004 System                      0 0    0
0094 Registry                    0 0    0
0220 smss.exe                    0 0    0
02d0 csrss.exe                   0 0    0
0348 wininit.exe                 0 0    0
0350 csrss.exe                   1 0    0
0394 services.exe                0 0    0
039c lsass.exe                   0 0    0
03ec winlogon.exe                1 0    0
0344 svchost.exe                 0 0    0
03b4 WUDFHost.exe                0 0    0
0250 fontdrvhost.exe             0 0    0
0404 fontdrvhost.exe             1 0    0
046c svchost.exe                 0 0    0
04d4 svchost.exe                 0 0    0
0538 dwm.exe                     1 0    0
05a0 svchost.exe                 0 0    0
05c0 svchost.exe                 0 0    0
05c8 svchost.exe                 0 0    0
05d8 svchost.exe                 0 0    0
0688 svchost.exe                 0 0    0
0690 svchost.exe                 0 0    0
069c svchost.exe                 0 0    0
06a8 svchost.exe                 0 0    0
06b8 svchost.exe                 0 0    0
0748 svchost.exe                 0 0    0
0774 svchost.exe                 0 0    0
079c svchost.exe                 0 0    0
07ac svchost.exe                 0 0    0
04c8 svchost.exe                 0 0    0
085c svchost.exe                 0 0    0
0870 svchost.exe                 0 0    0
0878 atiesrxx.exe                0 0    0
08d4 svchost.exe                 0 0    0
08fc svchost.exe                 0 0    0
0964 svchost.exe                 0 0    0
09f4 svchost.exe                 0 0    0
0ae0 svchost.exe                 0 0    0
0ae8 svchost.exe                 0 0    0
0af0 atieclxx.exe                1 0    0
0b38 svchost.exe                 0 0    0
0b5c svchost.exe                 0 0    0
0b64 svchost.exe                 0 0    0
0a08 svchost.exe                 0 0    0
0b20 svchost.exe                 0 0    0
0c64 svchost.exe                 0 0    0
0c70 svchost.exe                 0 0    0
0c78 360rps.exe                  0 0    0
0c80 ZhuDongFangYu.exe           0 0    0
0ca0 svchost.exe                 0 0    0
0d44 iNodeMon.exe                0 0    0
0d6c svchost.exe                 0 0    0
0d88 iNodeImg.exe                1 0    0
0da4 conhost.exe                 1 0    0
0e50 spoolsv.exe                 0 0    0
0e94 svchost.exe                 0 0    0
0eb8 svchost.exe                 0 0    0
0f3c svchost.exe                 0 0    0
0f44 svchost.exe                 0 0    0
0f7c svchost.exe                 0 0    0
0ed0 svchost.exe                 0 0    0
0eac svchost.exe                 0 0    0
0fc0 360DesktopService64.exe     0 0    0
1008 svchost.exe                 0 0    0
1010 svchost.exe                 0 0    0
1018 QQProtect.exe               0 0    0
1020 svchost.exe                 0 0    0
102c FlashCenterSvc.exe          0 0    0
1034 FlashHelperService.exe      0 0    0
103c pcas.exe                    0 0    0
1044 RstMwService.exe            0 0    0
104c secbizsrv.exe               0 0    0
1054 WMIRegistrationService.exe  0 0    0
10e8 phpStudyServer.exe          0 0    0
1108 svchost.exe                 0 0    0
114c svchost.exe                 0 0    0
1280 jhi_service.exe             0 0    0
15d0 xp.cn_cgi.exe               0 0    0
15d8 xp.cn_cgi.exe               0 0    0
15e0 xp.cn_cgi.exe               0 0    0
15f0 xp.cn_cgi.exe               0 0    0
1658 php-cgi.exe                 0 0    0
1670 conhost.exe                 0 0    0
1688 php-cgi.exe                 0 0    0
16a8 php-cgi.exe                 0 0    0
16c0 conhost.exe                 0 0    0
16d8 conhost.exe                 0 0    0
1720 php-cgi.exe                 0 0    0
1730 conhost.exe                 0 0    0
178c iNodeCmn.exe                1 0    0
1794 conhost.exe                 1 0    0
17a8 iNodeSec.exe                1 0    0
17bc conhost.exe                 1 0    0
17ec iNodeSslvpn.exe             1 0    0
0570 conhost.exe                 1 0    0
1a68 svchost.exe                 0 0    0
1af4 SgrmBroker.exe              0 0    0
1b4c svchost.exe                 0 0    0
1bf8 svchost.exe                 0 0    0
1ab0 sihost.exe                  1 0    11   normal       C:\Windows\System32
089c svchost.exe                 1 0    1    normal       C:\Windows\System32
1ad8 svchost.exe                 1 0    4    normal       C:\Windows\System32
13b0 svchost.exe                 0 0    0
1a94 Explorer.exe                1 705  628  normal       C:\Windows
14c4 360rp.exe                   1 6    2    normal       C:\Program Files\360\360sd
0a58 svchost.exe                 0 0    0
1754 360sd.exe                   1 396  207  normal       C:\Program Files\360\360sd
19dc ctfmon.exe                  1 2    22   high         C:\Windows\System32
1078 taskhostw.exe               1 8    6    normal       C:\Windows\System32
09ac svchost.exe                 1 0    6    normal       C:\Windows\System32
11d8 aliwssv.exe                 0 0    0
062c conhost.exe                 0 0    0
1540 6fcd63.rbf                  1 0    4    normal       C:\Config.Msi
1914 StartMenuExperienceHost.exe 1 0    13   normal       C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy
0c24 ChsIME.exe                  1 0    4    normal       C:\Windows\System32\InputMethod\CHS
1bbc RuntimeBroker.exe           1 40   1    normal       C:\Windows\System32
1924 SearchApp.exe               1 12   50   normal       C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy
0a60 RuntimeBroker.exe           1 0    4    normal       C:\Windows\System32
0ba4 TextInputHost.exe           1 0    51   normal       C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy
1c38 PalmInputGuard.exe          1 0    4    normal       C:\Program Files (x86)\PalmInput\Extensions\Guard\2.6.0.49
21c4 birdtray.exe                1 38   46   normal       C:\Program Files (x86)\BirdWallpaper
2254 guardhp.exe                 1 30   23   normal       C:\Program Files (x86)\BirdWallpaper\Utils
2330 PalmInputService.exe        1 18   17   normal       C:\Program Files (x86)\PalmInput\3.1.0.1010
2064 conhost.exe                 1 16   11   normal       C:\Windows\System32
2160 birdsrvhost.exe             1 12   74   normal       C:\Program Files (x86)\BirdWallpaper
0708 sesvc.exe                   1 0    17   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application\components\sesvc
1154 RAVCpl64.exe                1 69   18   normal       C:\Program Files\Realtek\Audio\HDA
2514 AAM Updates Notifier.exe    1 11   10   normal       C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA
2624 360DesktopLite64.exe        1 261  68   normal       D:\SoftCenter\DesktopLite
2638 ApifoxAppAgent.exe          1 0    4    normal       C:\Users\Administrator\AppData\Roaming\apifox
26e4 360tray.exe                 1 312  73   normal       C:\Program Files (x86)\360\360Safe\safemon
253c WUDFHost.exe                0 0    0
2900 RadeonSoftware.exe          1 45   68   normal       C:\Program Files\AMD\CNext\CNext
2b54 SeAppService.exe            1 27   22   normal       C:\Users\Administrator\AppData\Roaming\360se6\Application\components\seapp
29e8 AMDRSServ.exe               1 8    13   normal       C:\Program Files\AMD\CNext\CNext
2b98 amdow.exe                   1 3    37   normal       C:\Program Files\AMD\CNext\CNext
0a6c 360UDiskPro.exe             1 95   37   normal       C:\Program Files (x86)\360\360Safe\safemon
0368 taskhostw.exe               1 40   4    normal       C:\Windows\System32
0be4 FlashFXP.exe                1 232  199  normal       L:\flashftp
24a8 svchost.exe                 1 0    1    normal       C:\Windows\System32
2a0c WeChat.exe                  1 152  98   normal       D:\SoftCenter\Tencent\WeChat
1e88 WeChat.exe                  1 129  90   normal       D:\SoftCenter\Tencent\WeChat
2b60 mmcrashpad_handler64.exe    1 0    4    normal       D:\SoftCenter\Tencent\WeChat\[3.9.9.43]
2b40 mmcrashpad_handler64.exe    1 0    4    normal       D:\SoftCenter\Tencent\WeChat\[3.9.9.43]
256c WeChatAppEx.exe             1 26   57   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
05b8 WeChatAppEx.exe             1 33   61   normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
1e74 WeChatAppEx.exe             1 0    4    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
0354 WeChatAppEx.exe             1 0    4    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
2810 QQ.exe                      1 77   145  normal       D:\SoftCenter\Tencent\QQ\Bin
0a98 WeChatAppEx.exe             1 0    1    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
173c WeChatAppEx.exe             1 0    1    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
05d4 WeChatAppEx.exe             1 11   29   above normal C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
2c08 WeChatAppEx.exe             1 7    31   above normal C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
2e78 TXPlatform.exe              1 0    2    normal       D:\SoftCenter\Tencent\QQ\Bin
2fd8 QQ.exe                      1 144  156  normal       D:\SoftCenter\Tencent\QQ\Bin
2d94 QQGuild.exe                 1 22   55   normal       C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.22-513
2cd8 QQGuild.exe                 1 3    28   above normal C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.22-513
21b8 QQGuild.exe                 1 0    1    normal       C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.22-513
3258 QQGuild.exe                 1 0    0    normal       C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.22-513
3350 QQGuild.exe                 1 0    0    normal       C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.22-513
3280 QQ.exe                      1 87   149  normal       D:\SoftCenter\Tencent\QQ\Bin
33bc QQGuild.exe                 1 22   55   normal       C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.22-513
320c QQGuild.exe                 1 3    29   above normal C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.22-513
319c QQGuild.exe                 1 0    1    normal       C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.22-513
3590 QQGuild.exe                 1 22   55   normal       C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.22-513
3690 QQGuild.exe                 1 3    28   above normal C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.22-513
375c QQGuild.exe                 1 0    1    normal       C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.22-513
34b0 QQGuild.exe                 1 0    0    normal       C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.22-513
38f0 QQGuild.exe                 1 0    0    normal       C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.22-513
39a4 QQGuild.exe                 1 0    0    normal       C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.22-513
3ac4 QQGuild.exe                 1 0    0    normal       C:\Users\Administrator\AppData\Local\Tencent\QQGuild\9.7.22-513
3578 WeChatPlayer.exe            1 0    1    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\ThumbPlayer\4067\extracted
3954 WeChatAppEx.exe             1 0    1    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
39bc WeChatUtility.exe           1 0    1    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\WeChatUtility\8085\extracted
3a40 WeChatAppEx.exe             1 0    0    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
3aec WeChatOCR.exe               1 0    1    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\WeChatOCR\7071\extracted
3808 WeChatAppEx.exe             1 0    0    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
39f4 CompPkgSrv.exe              1 0    1    normal       C:\Windows\System32
3d7c WeChatAppEx.exe             1 0    0    idle         C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
26ec svchost.exe                 0 0    0
3e14 WmiPrvSE.exe                0 0    0
1380 svchost.exe                 0 0    0
3c6c WeChatPlayer.exe            1 0    1    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\ThumbPlayer\4067\extracted
3d3c WeChatUtility.exe           1 0    1    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\WeChatUtility\8085\extracted
2a20 WeChatAppEx.exe             1 0    1    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
3c04 WeChatOCR.exe               1 0    1    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\WeChatOCR\7071\extracted
10b4 WeChatAppEx.exe             1 0    0    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
1e00 WeChatAppEx.exe             1 0    0    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
42b8 WeChatAppEx.exe             1 0    0    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
43cc WeChatAppEx.exe             1 0    0    idle         C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
077c WeChatAppEx.exe             1 0    0    idle         C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
1a14 dllhost.exe                 0 0    0
0a80 svchost.exe                 0 0    0
196c svchost.exe                 0 0    0
3960 YIIOTHomePCClientIntl.exe   1 64   127  normal       D:\SoftCenter\YIIOTHomePCClientIntl
1d98 YIIOTHomePCClientIntl.exe   1 1    5    normal       D:\SoftCenter\YIIOTHomePCClientIntl
3384 audiodg.exe                 0 0    0
29a8 SearchIndexer.exe           0 0    0
18f0 SearchProtocolHost.exe      0 0    0
3c78 phpstudy_pro.exe            1 109  45   normal       E:\phpstudy_pro\COM
473c mysqld.exe                  1 0    2    normal       E:\phpstudy_pro\Extensions\MySQL5.7.26\bin
2f00 xp.cn_cgi.exe               1 0    0    normal       E:\phpstudy_pro\COM
4600 nginx.exe                   1 0    1    normal       E:\phpstudy_pro\Extensions\Nginx1.15.11
197c xp.cn_cgi.exe               1 0    0    normal       E:\phpstudy_pro\COM
1da8 xp.cn_cgi.exe               1 0    0    normal       E:\phpstudy_pro\COM
4718 php-cgi.exe                 1 0    1    normal       E:\phpstudy_pro\Extensions\php\php5.4.45nts
4804 php-cgi.exe                 1 0    1    normal       E:\phpstudy_pro\Extensions\php\php5.6.9nts
0530 php-cgi.exe                 1 0    1    normal       E:\phpstudy_pro\Extensions\php\php7.3.4nts
4f58 conhost.exe                 1 8    3    normal       C:\Windows\System32
1df8 conhost.exe                 1 8    3    normal       C:\Windows\System32
40c8 conhost.exe                 1 8    3    normal       C:\Windows\System32
44d0 nginx.exe                   1 0    1    normal       E:\phpstudy_pro\Extensions\Nginx1.15.11
4ec8 conhost.exe                 1 8    3    normal       C:\Windows\System32
1e70 nginx.exe                   1 0    1    normal       E:\phpstudy_pro\Extensions\Nginx1.15.11
4390 conhost.exe                 1 8    3    normal       C:\Windows\System32
4508 nginx.exe                   1 0    1    normal       E:\phpstudy_pro\Extensions\Nginx1.15.11
4bdc conhost.exe                 1 8    3    normal       C:\Windows\System32
4388 nginx.exe                   1 0    1    normal       E:\phpstudy_pro\Extensions\Nginx1.15.11
4bec conhost.exe                 1 8    3    normal       C:\Windows\System32
4ac8 php-cgi.exe                 0 0    0
4940 conhost.exe                 0 0    0
2694 Dreamweaver.exe             1 1017 1174 normal       C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6
181c CS6ServiceManager.exe       1 0    5    normal       C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager
4fb0 WeChatAppEx.exe             1 0    0    normal       C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
1ef8 svchost.exe                 0 0    0
48bc svchost.exe                 0 0    0
11dc svchost.exe                 0 0    0
4514 svchost.exe                 0 0    0
4260 wpscloudsvr.exe             1 46   317  normal       D:\SoftCenter\Kingsoft\WPS Office\12.1.0.16388\office6
4e3c WeChatAppEx.exe             1 0    0    idle         C:\Users\Administrator\AppData\Roaming\Tencent\WeChat\XPlugin\Plugins\RadiumWMPF\9079\extracted\runtime
56fc php-cgi.exe                 0 0    0
5040 conhost.exe                 0 0    0
4530 BaiduNetdisk.exe            1 163  128  normal       D:\SoftCenter\baidu\BaiduNetdisk
52ac YunDetectService.exe        1 0    5    normal       D:\SoftCenter\baidu\BaiduNetdisk
1978 BaiduNetdiskHost.exe        1 0    11   normal       D:\SoftCenter\baidu\BaiduNetdisk
51c4 BaiduNetdiskHost.exe        1 10   8    normal       D:\SoftCenter\baidu\BaiduNetdisk
4dfc svchost.exe                 0 0    0
515c backgroundTaskHost.exe      1 0    2    normal       C:\Windows\System32
57c4 RuntimeBroker.exe           1 0    1    normal       C:\Windows\System32
3cb4 WmiPrvSE.exe                0 0    0
48e8 SearchFilterHost.exe        0 0    0    idle         C:\Windows\System32
5730 360bdoctor.exe              1 1    1    normal       C:\Users\Administrator\AppData\Roaming\360se6\Application\15.0.1473.0
51cc sesvc.exe                   1 0    7    normal       C:\Users\Administrator\AppData\Roaming\360se6\Application\components\sesvc
2fe0 sesvc.exe                   1 0    7    normal       C:\Users\Administrator\AppData\Roaming\360se6\Application\components\sesvc

hardware:
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
  - Fax
  - Microsoft Print to PDF
  - Microsoft XPS Document Writer
  - ΪWPS PDF
  - ӡ
+ {36fc9e60-c465-11cf-8056-444553540000}
  - Intel(R) USB 3.0 չ - 1.0 (Microsoft)
  - USB Composite Device
  - USB (USB 3.0)
+ {4d36e966-e325-11ce-bfc1-08002be10318}
  -  ACPI x64 ĵ
+ {4d36e967-e325-11ce-bfc1-08002be10318}
  - GALAX BA1M0250N
  - ST1000DM010-2EP102
  - WD Elements SE SSD SCSI Disk Device
+ {4d36e968-e325-11ce-bfc1-08002be10318}
  - AMD Radeon R5 M240 (driver 27.20.14501.28009)
  - OrayIddDriver Device (driver 17.1.58.818)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
  - Intel(R) 400 Series Chipset Family SATA AHCI Controller (driver 17.8.11.1080)
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
  - HID Keyboard Device
  - PS/2 ׼
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
  - AMD High Definition Audio Device (driver 10.0.1.24)
  - Realtek High Definition Audio (driver 6.0.9239.1)
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
  - ͨü弴ü
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
  - HID-compliant mouse
  - Microsoft PS/2 
+ {4d36e972-e325-11ce-bfc1-08002be10318}
  - Bluetooth Device (Personal Area Network)
  - iNode VPN Virtual NIC (driver 1.0.0.0)
  - Realtek PCIe GbE Family Controller (driver 10.68.815.2023)
  - Virtual Network Adapter (driver 9.0.0.2)
+ {4d36e978-e325-11ce-bfc1-08002be10318}
  - ͨŶ˿ (COM1)
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
  - Microsoft 洢ռ
  - USB Attached SCSI (UAS) 洢豸
  - ׼ NVM Express 
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
  - ACPI ۺ
  - ACPI Դť
  - ACPI 
  - ACPI 
  - ACPI 
  - ACPI 
  - ACPI 
  - ACPI ̶ܰť
  - ACPI Ѿ
  - ACPI 
  - ACPI ˯߰ť
  - High Definition Audio 
  - High Definition Audio 
  - Intel(R) Management Engine Interface #1 (driver 2251.4.2.0)
  - Intel(R) PMC - A3A1 (driver 10.1.33.5)
  - Intel(R) Power Engine Plug-in
  - Intel(R) Serial IO GPIO Host Controller - INT3451 (driver 30.100.1943.2)
  - Intel(R) Serial IO I2C Host Controller - A3E0 (driver 30.100.1943.2)
  - Intel(R) Serial IO I2C Host Controller - A3E1 (driver 30.100.1943.2)
  - Intel(R) SMBus - A3A3 (driver 10.1.33.5)
  - Intel(R) Thermal Subsystem - A3B1 (driver 10.1.33.5)
  - Intel(R) Watchdog Timer Driver (Intel(R) WDT) (driver 11.7.0.1000)
  - Intel(R) Xeon(R) E3 - 1200/1500 v5/6th Gen Intel(R) Core(TM) Gaussian Mixture Model - 1911 (driver 10.1.1.45)
  - Microsoft ACPI-Compliant System
  - Microsoft Hyper-V ⻯ṹ
  - Microsoft System Management BIOS Driver
  - Microsoft Windows Management Interface for ACPI
  - Microsoft Windows Management Interface for ACPI
  - Microsoft 
  - Microsoft ʾ
  - Microsoft ö
  - NDIS ö
  - Oray Virtual Game Controller (driver 1.0.0.0)
  - Pci Bus (driver 20.50.0.0)
  - PCI Express ˿
  - PCI Express ˿
  - PCI Express ˿
  - PCI ׼ ISA 
  - PCI ׼ CPU 
  - UMBus Root Bus Enumerator
  - ö
  - ߾¼ʱ
  - 弴豸ö
  - 
  - ɱжϿ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ĸԴ
  - ֵݴ
  - ϵͳʱ
  - Զ豸ض
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
  - Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
+ {533c5b84-ec70-11d2-9505-00c04f79deaf}
  - ͨþӰ
  - ͨþӰ
+ {5c4c3332-344d-483c-8739-259e934c9cc8}
  - Intel(R) Dynamic Application Loader Host Interface (driver 1.41.2021.121)
  - Intel(R) iCLS Client (driver 1.63.1155.1)
  - Intel(R) Management Engine WMI Provider (driver 2130.1.15.0)
+ {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
  - Microsoft Device Association Root Enumerator
  - Microsoft GS ϳ
  - Microsoft Radio Device Enumeration Bus
  - 
+ {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
  - USB 豸
  - USB 豸
  - USB 豸
  - USB 豸
  -  HID ׼ĹӦ̶豸
  -  HID ׼ϵͳ
  -  HID ׼û豸
+ {c166523c-fe0c-4a94-a586-f1a80cfbbf3e}
  - 1 - HDMI (AMD High Definition Audio Device)
  - ˷ (Realtek High Definition Audio)
  -  (Realtek High Definition Audio)
+ {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
  - Bluetooth Device (RFCOMM Protocol TDI)
  - Generic Bluetooth Radio
  - Microsoft  LE ö
  - Microsoft ö
+ {eec5ad98-8080-425f-922a-dabf3de3f69a}
  - ɿƼ

cpu registers:
eax = 0f800000
ebx = 0285dc98
ecx = 0021b000
edx = 00000000
esi = 007bddb8
edi = 02864ff0
eip = 0073a8db
esp = 0019f148
ebp = 0019f158

stack dump:
0019f148  98 dc 85 02 98 dc 85 02 - 04 00 00 00 d0 53 7c 02  .............S|.
0019f158  74 00 00 00 86 cb 41 00 - f4 48 46 00 a2 45 46 00  t.....A..HF..EF.
0019f168  f0 4f 86 02 0e 00 00 00 - 98 dc 85 02 57 4e 46 00  .O..........WNF.
0019f178  40 4e 46 00 e4 48 46 00 - 9c f1 19 00 00 00 00 00  @NF..HF.........
0019f188  00 00 00 00 02 00 00 00 - c1 9e 44 00 10 f3 7f 02  ..........D.....
0019f198  6c 26 46 00 bc f1 19 00 - 39 9f 44 00 bc f1 19 00  l&F.....9.D.....
0019f1a8  d0 53 7c 02 70 b7 77 00 - 22 00 00 00 88 f3 19 00  .S|.p.w.".......
0019f1b8  d0 53 7c 02 88 f3 19 00 - 7e b7 77 00 63 83 45 00  .S|.....~.w.c.E.
0019f1c8  e0 8c 60 06 01 f3 19 00 - 40 f3 19 00 00 bd 00 00  ..`.....@.......
0019f1d8  88 f3 19 00 e0 8c 60 06 - a3 83 45 00 00 bd 00 00  ......`...E.....
0019f1e8  88 f3 19 00 e0 8c 60 06 - 4f 5b 63 00 00 bd 00 00  ......`.O[c.....
0019f1f8  88 f3 19 00 e0 8c 60 06 - 38 3e 45 00 00 bd 00 00  ......`.8>E.....
0019f208  88 f3 19 00 e0 8c 60 06 - a7 66 45 00 00 bd 00 00  ......`..fE.....
0019f218  88 f3 19 00 e0 8c 60 06 - 00 00 00 00 20 00 00 00  ......`.........
0019f228  36 00 12 00 c8 f2 19 00 - 54 9b 89 04 c0 f2 19 00  6.......T.......
0019f238  af 62 76 77 33 00 00 00 - 20 00 00 00 a8 ee 78 02  .bvw3.........x.
0019f248  00 00 78 02 58 5a 88 04 - 3b 00 00 00 7f 00 00 00  ..x.XZ..;.......
0019f258  00 00 00 00 00 00 78 02 - 4e 12 76 77 18 00 00 00  ......x.N.vw....
0019f268  d0 07 41 06 64 00 00 00 - 00 00 00 00 18 00 00 00  ..A.d...........
0019f278  00 00 00 00 40 7b 88 04 - 40 9b 89 04 00 00 00 00  ....@{..@.......

disassembling:
[...]
0073a89a         push    ebx
0073a89b         push    esi
0073a89c         mov     [ebp-4], eax
0073a89f         mov     esi, $7bddb8
0073a8a4 10234   mov     al, [$7be234]
0073a8a9         mov     [ebp-5], al
0073a8ac 10236   mov     al, [ebp-5]
0073a8af         not     al
0073a8b1         dec     eax
0073a8b2         sub     al, 2
0073a8b4         jb      loc_73aa5d
0073a8ba 10238   xor     eax, eax
0073a8bc         mov     al, [ebp-5]
0073a8bf         imul    eax, eax, $117
0073a8c5         mov     eax, [esi+eax*2-$12b]
0073a8cc         test    eax, eax
0073a8ce         jz      loc_73a8fd
0073a8d0         xor     edx, edx
0073a8d2         mov     dl, [ebp-5]
0073a8d5         imul    edx, edx, $117
0073a8db       > cmp     byte ptr [eax+$47], 0
0073a8df         jz      loc_73a8fd
0073a8e1 10240   xor     edx, edx
0073a8e3         mov     dl, [ebp-5]
0073a8e6         imul    edx, edx, $117
0073a8ec         mov     edx, eax
0073a8ee         mov     cl, 1
0073a8f0         mov     eax, [ebp-4]
0073a8f3         call    +$2f8a0 ($76a198)      ; FrmMain1.TFrmMain.LocalRefresh
0073a8f8 10241   jmp     loc_73aa5d
0073a8fd 10244   xor     eax, eax
0073a8ff         mov     al, [ebp-5]
0073a902         imul    eax, eax, $117
0073a908         cmp     byte ptr [esi+eax*2-$7e], 0
0073a90d         jz      loc_73a971
0073a90f         mov     eax, [esi+eax*2-$11f]
0073a916         cmp     byte ptr [eax+$2d0], 0
0073a91d         jnz     loc_73a971
0073a91f 10246   xor     eax, eax
0073a921         mov     al, [ebp-5]
0073a924         imul    ebx, eax, $117
[...]

