date/time : 2021-08-24, 19:24:46, 925ms computer name : NB-ALE-HP user name : utente registered owner : Utente Windows operating system : Windows 10 x64 build 19042 system language : Italian system up time : 1 day 20 hours program up time : 2 minutes 50 seconds processors : 4x Intel(R) Core(TM) i5-5300U CPU @ 2.30GHz physical memory : 10125/15779 MB (free/total) free disk space : (C:) 236,74 GB display mode : 1536x864, 32 bit process id : $830 allocated memory : 76,67 MB largest free block : 1,36 GB executable : FreeCommander.exe exec. date/time : 2020-01-02 20:41 version : 2020.0.0.810 compiled with : Delphi 10.2 Tokyo madExcept version : 5.0.0 callstack crc : $d3930be7, $0b0b555b, $5a664a4b exception number : 1 exception class : EAccessViolation exception message : Access violation at address 006CDF63 in module 'FreeCommander.exe'. Read of address 00000010. main thread ($30f0): 006cdf63 +00f FreeCommander.exe Vcl.Forms TCustomForm.IsFormSizeStored 006cdf49 +005 FreeCommander.exe Vcl.Forms TCustomForm.IsClientSizeStored 006d0808 +5a4 FreeCommander.exe Vcl.Forms TCustomForm.CreateParams 00fe37fe +012 FreeCommander.exe fcDlgCopyMoveOperationFc 477 +1 TdlgFcCopyMoveOperation.CreateParams 005cd694 +034 FreeCommander.exe Vcl.Controls TWinControl.CreateWnd 006cc365 +005 FreeCommander.exe Vcl.Forms TScrollingWinControl.CreateWnd 006d0882 +00a FreeCommander.exe Vcl.Forms TCustomForm.CreateWnd 005cdc9e +016 FreeCommander.exe Vcl.Controls TWinControl.CreateHandle 005d1c08 +01c FreeCommander.exe Vcl.Controls TWinControl.HandleNeeded 005d1c15 +005 FreeCommander.exe Vcl.Controls TWinControl.GetHandle 006d1081 +0f1 FreeCommander.exe Vcl.Forms TCustomForm.SetFocusedControl 005ce819 +1cd FreeCommander.exe Vcl.Controls TWinControl.WndProc 0062d633 +0af FreeCommander.exe Vcl.ComCtrls TCustomListView.WndProc 005ce254 +02c FreeCommander.exe Vcl.Controls TWinControl.MainWndProc 0054aec0 +014 FreeCommander.exe System.Classes StdWndProc 77093626 +016 user32.dll CallWindowProcW 77c54e7b +04b ntdll.dll KiUserCallbackDispatcher 005ca0ce +2be FreeCommander.exe Vcl.Controls TControl.WndProc 005cec35 +5e9 FreeCommander.exe Vcl.Controls TWinControl.WndProc 006ceafd +64d FreeCommander.exe Vcl.Forms TCustomForm.WndProc 01203d85 +02d FreeCommander.exe FcMain 2995 +2 TFcFormMain.WndProc 005ce254 +02c FreeCommander.exe Vcl.Controls TWinControl.MainWndProc 0054aec0 +014 FreeCommander.exe System.Classes StdWndProc 77c54e7b +04b ntdll.dll KiUserCallbackDispatcher 00409c64 +008 FreeCommander.exe System 143 +0 TObject.Free 00e8eedc +01c FreeCommander.exe RzStatus 3275 +2 TRzMarqueeStatus.Destroy 005cbe89 +0d9 FreeCommander.exe Vcl.Controls TWinControl.Destroy 005d4eb8 +01c FreeCommander.exe Vcl.Controls TCustomControl.Destroy 007d0611 +02d FreeCommander.exe RzPanel 2352 +5 TRzCustomPanel.Destroy 007d6f94 +01c FreeCommander.exe RzPanel 5966 +2 TRzStatusBar.Destroy 005cbe89 +0d9 FreeCommander.exe Vcl.Controls TWinControl.Destroy 006cc33b +04b FreeCommander.exe Vcl.Forms TScrollingWinControl.Destroy 006cd578 +11c FreeCommander.exe Vcl.Forms TCustomForm.Destroy 00409c64 +008 FreeCommander.exe System 143 +0 TObject.Free 006d303c +000 FreeCommander.exe Vcl.Forms TCustomForm.CMRelease 005ca0ce +2be FreeCommander.exe Vcl.Controls TControl.WndProc 004b2e6d +019 FreeCommander.exe madExcept InterceptClassDestroy 0052fad0 +018 FreeCommander.exe System.Classes TList.Destroy 00409c64 +008 FreeCommander.exe System 143 +0 TObject.Free 005ccdbf +19b FreeCommander.exe Vcl.Controls TWinControl.AlignControls 006cc3b6 +016 FreeCommander.exe Vcl.Forms TScrollingWinControl.AlignControls 006ced92 +00e FreeCommander.exe Vcl.Forms TCustomForm.AlignControls 005cce62 +062 FreeCommander.exe Vcl.Controls TWinControl.AlignControl 005ce254 +02c FreeCommander.exe Vcl.Controls TWinControl.MainWndProc 0054aec0 +014 FreeCommander.exe System.Classes StdWndProc 770938db +00b user32.dll DispatchMessageW 006d849b +0f3 FreeCommander.exe Vcl.Forms TApplication.ProcessMessage 006d84de +00a FreeCommander.exe Vcl.Forms TApplication.HandleMessage 006d8811 +0c9 FreeCommander.exe Vcl.Forms TApplication.Run 01232b23 +37b FreeCommander.exe FreeCommander 514 +128 initialization 7742fa27 +017 KERNEL32.DLL BaseThreadInitThunk thread $fd0: 76dfb1ad +fd KERNELBASE.dll WaitForMultipleObjectsEx 004b3091 +0d FreeCommander.exe madExcept CallThreadProcSafe 004b30f6 +32 FreeCommander.exe madExcept ThreadExceptFrame 7742fa27 +17 KERNEL32.DLL BaseThreadInitThunk >> created by main thread ($30f0) at: 75d13ff7 +00 combase.dll thread $39d4: 770995c8 +28 user32.dll GetMessageW 004b3091 +0d FreeCommander.exe madExcept CallThreadProcSafe 004b30f6 +32 FreeCommander.exe madExcept ThreadExceptFrame 7742fa27 +17 KERNEL32.DLL BaseThreadInitThunk >> created by thread $2444 at: 75d13ff7 +00 combase.dll thread $2efc (TRzChangeHandlerThread): 76dfb1ad +fd KERNELBASE.dll WaitForMultipleObjectsEx 76dfb093 +13 KERNELBASE.dll WaitForMultipleObjects 0085fe89 +6d FreeCommander.exe RzShellCtrls 3842 +11 TRzChangeHandlerThread.Execute 004b31ab +2b FreeCommander.exe madExcept HookedTThreadExecute 00547579 +49 FreeCommander.exe System.Classes ThreadProc 0040babc +28 FreeCommander.exe System 143 +0 ThreadWrapper 004b3091 +0d FreeCommander.exe madExcept CallThreadProcSafe 004b30f6 +32 FreeCommander.exe madExcept ThreadExceptFrame 7742fa27 +17 KERNEL32.DLL BaseThreadInitThunk >> created by main thread ($30f0) at: 0085fb4e +1e FreeCommander.exe RzShellCtrls 3728 +4 TRzChangeHandlerThread.Create thread $2e9c (TWorkerThread): 76dfb1ad +fd KERNELBASE.dll WaitForMultipleObjectsEx 76dfb093 +13 KERNELBASE.dll WaitForMultipleObjects 009f8c88 +34 FreeCommander.exe csWorkerThreadPool 461 +5 TWorkerThreadJobLists.WaitForNextJob 009f8e91 +1d FreeCommander.exe csWorkerThreadPool 549 +3 TWorkerThread.Execute 004b31ab +2b FreeCommander.exe madExcept HookedTThreadExecute 00547579 +49 FreeCommander.exe System.Classes ThreadProc 0040babc +28 FreeCommander.exe System 143 +0 ThreadWrapper 004b3091 +0d FreeCommander.exe madExcept CallThreadProcSafe 004b30f6 +32 FreeCommander.exe madExcept ThreadExceptFrame 7742fa27 +17 KERNEL32.DLL BaseThreadInitThunk >> created by main thread ($30f0) at: 009f8d9a +22 FreeCommander.exe csWorkerThreadPool 493 +1 TWorkerThread.Create thread $ef0 (TWorkerThread): 76dd8dc9 +039 KERNELBASE.dll CreateFile2 76c73685 +085 shcore.dll #101 76c70b33 +0d3 shcore.dll #100 76dfa1d5 +075 KERNELBASE.dll QISearch 00410724 +010 FreeCommander.exe System 143 +0 @IntfClear 0040d9dc +0e4 FreeCommander.exe System 143 +0 @FinalizeArray 007619ab +13f FreeCommander.exe MPShellUtilities 6368 +18 TNamespace.GetQueryInfoInterface 007609de +06e FreeCommander.exe MPShellUtilities 5952 +6 TNamespace.GetInfoTip 008a44bc +0c0 FreeCommander.exe fcFileItem 345 +10 TfcFileItem.GetItemInfoTip 00de7df8 +034 FreeCommander.exe fcThreadWorkerJobs 782 +3 TfcItemInfoTipWorkerJob.GetInfoTip 00de7d82 +02e FreeCommander.exe fcThreadWorkerJobs 773 +4 TfcItemInfoTipWorkerJob.Execute 009f8fac +068 FreeCommander.exe csWorkerThreadPool 594 +8 TWorkerThread.Run 009f8ec7 +053 FreeCommander.exe csWorkerThreadPool 558 +12 TWorkerThread.Execute 004b31ab +02b FreeCommander.exe madExcept HookedTThreadExecute 00547579 +049 FreeCommander.exe System.Classes ThreadProc 0040babc +028 FreeCommander.exe System 143 +0 ThreadWrapper 004b3091 +00d FreeCommander.exe madExcept CallThreadProcSafe 004b30f6 +032 FreeCommander.exe madExcept ThreadExceptFrame 7742fa27 +017 KERNEL32.DLL BaseThreadInitThunk >> created by main thread ($30f0) at: 009f8d9a +022 FreeCommander.exe csWorkerThreadPool 493 +1 TWorkerThread.Create thread $e20 (TWorkerThread): 76dfb1ad +fd KERNELBASE.dll WaitForMultipleObjectsEx 76dfb093 +13 KERNELBASE.dll WaitForMultipleObjects 009f8c88 +34 FreeCommander.exe csWorkerThreadPool 461 +5 TWorkerThreadJobLists.WaitForNextJob 009f8e91 +1d FreeCommander.exe csWorkerThreadPool 549 +3 TWorkerThread.Execute 004b31ab +2b FreeCommander.exe madExcept HookedTThreadExecute 00547579 +49 FreeCommander.exe System.Classes ThreadProc 0040babc +28 FreeCommander.exe System 143 +0 ThreadWrapper 004b3091 +0d FreeCommander.exe madExcept CallThreadProcSafe 004b30f6 +32 FreeCommander.exe madExcept ThreadExceptFrame 7742fa27 +17 KERNEL32.DLL BaseThreadInitThunk >> created by main thread ($30f0) at: 009f8d9a +22 FreeCommander.exe csWorkerThreadPool 493 +1 TWorkerThread.Create thread $188c (TWorkerThread): 76dd8dc9 +039 KERNELBASE.dll CreateFile2 76c73685 +085 shcore.dll #101 76c70aab +04b shcore.dll #100 76dfa1d5 +075 KERNELBASE.dll QISearch 00410724 +010 FreeCommander.exe System 143 +0 @IntfClear 0040d9dc +0e4 FreeCommander.exe System 143 +0 @FinalizeArray 007619ab +13f FreeCommander.exe MPShellUtilities 6368 +18 TNamespace.GetQueryInfoInterface 007609de +06e FreeCommander.exe MPShellUtilities 5952 +6 TNamespace.GetInfoTip 008a4484 +088 FreeCommander.exe fcFileItem 341 +6 TfcFileItem.GetItemInfoTip 00de7df8 +034 FreeCommander.exe fcThreadWorkerJobs 782 +3 TfcItemInfoTipWorkerJob.GetInfoTip 00de7d82 +02e FreeCommander.exe fcThreadWorkerJobs 773 +4 TfcItemInfoTipWorkerJob.Execute 009f8fac +068 FreeCommander.exe csWorkerThreadPool 594 +8 TWorkerThread.Run 009f8ec7 +053 FreeCommander.exe csWorkerThreadPool 558 +12 TWorkerThread.Execute 004b31ab +02b FreeCommander.exe madExcept HookedTThreadExecute 00547579 +049 FreeCommander.exe System.Classes ThreadProc 0040babc +028 FreeCommander.exe System 143 +0 ThreadWrapper 004b3091 +00d FreeCommander.exe madExcept CallThreadProcSafe 004b30f6 +032 FreeCommander.exe madExcept ThreadExceptFrame 7742fa27 +017 KERNEL32.DLL BaseThreadInitThunk >> created by main thread ($30f0) at: 009f8d9a +022 FreeCommander.exe csWorkerThreadPool 493 +1 TWorkerThread.Create thread $2934 (TRzChangeHandlerThread): 76dfb1ad +fd KERNELBASE.dll WaitForMultipleObjectsEx 76dfb093 +13 KERNELBASE.dll WaitForMultipleObjects 0085fe89 +6d FreeCommander.exe RzShellCtrls 3842 +11 TRzChangeHandlerThread.Execute 004b31ab +2b FreeCommander.exe madExcept HookedTThreadExecute 00547579 +49 FreeCommander.exe System.Classes ThreadProc 0040babc +28 FreeCommander.exe System 143 +0 ThreadWrapper 004b3091 +0d FreeCommander.exe madExcept CallThreadProcSafe 004b30f6 +32 FreeCommander.exe madExcept ThreadExceptFrame 7742fa27 +17 KERNEL32.DLL BaseThreadInitThunk >> created by main thread ($30f0) at: 0085fb4e +1e FreeCommander.exe RzShellCtrls 3728 +4 TRzChangeHandlerThread.Create thread $369c: 7742fa27 +17 KERNEL32.DLL BaseThreadInitThunk thread $2518: 7742fa27 +17 KERNEL32.DLL BaseThreadInitThunk thread $a98 (TfcFileOperationCopyMoveThread): 76df1113 +093 KERNELBASE.dll WaitForSingleObjectEx 76df106d +00d KERNELBASE.dll WaitForSingleObject 0045e352 +002 FreeCommander.exe System.SysUtils WaitForSyncWaitObj 0045e49b +01f FreeCommander.exe System.SysUtils WaitOrSignalObj 0040ac11 +065 FreeCommander.exe System 143 +0 TMonitor.Wait 0040aca0 +020 FreeCommander.exe System 143 +0 TMonitor.Wait 00547fb4 +140 FreeCommander.exe System.Classes TThread.Synchronize 00548081 +04d FreeCommander.exe System.Classes TThread.Synchronize 00db0bdd +0e1 FreeCommander.exe fcFileOperationThread 474 +17 TfcFileOperationThread.CopyMoveOverwriteItemCheck 00fcf143 +06b FreeCommander.exe fcFileOperationCopyMoveThread 157 +2 ExecuteOperationForFileByFC 00fcfa76 +6d2 FreeCommander.exe fcFileOperationCopyMoveThread 315 +102 TfcFileOperationCopyMoveThread.ExecuteOperation 00db03b2 +0e2 FreeCommander.exe fcFileOperationThread 243 +18 TfcFileOperationThread.Execute 004b31ab +02b FreeCommander.exe madExcept HookedTThreadExecute 00547579 +049 FreeCommander.exe System.Classes ThreadProc 0040babc +028 FreeCommander.exe System 143 +0 ThreadWrapper 004b3091 +00d FreeCommander.exe madExcept CallThreadProcSafe 004b30f6 +032 FreeCommander.exe madExcept ThreadExceptFrame 7742fa27 +017 KERNEL32.DLL BaseThreadInitThunk >> created by main thread ($30f0) at: 00db0076 +022 FreeCommander.exe fcFileOperationThread 167 +1 TfcFileOperationThread.Create thread $3700 (TVirtualImageThread): 76defff9 +059 KERNELBASE.dll CreateFileW 72770db1 +181 windows.storage.dll GetFindDataForPath 7605256e +10e shell32.dll SHParseDisplayName 76051f52 +012 shell32.dll SHGetFileInfoW 00e220ee +052 FreeCommander.exe fcIconThread 883 +7 ShellGetIconIndexFromPath 00e22239 +115 FreeCommander.exe fcIconThread 932 +41 TVirtualImageThread.ExtractIconImage 00e216ed +02d FreeCommander.exe fcIconThread 558 +2 ExtractIconInfo 00e21abd +05d FreeCommander.exe fcIconThread 648 +6 TVirtualImageThread.ExtractInfo 00e2117a +186 FreeCommander.exe fcIconThread 406 +47 TVirtualImageThread.Execute 004b31ab +02b FreeCommander.exe madExcept HookedTThreadExecute 00547579 +049 FreeCommander.exe System.Classes ThreadProc 0040babc +028 FreeCommander.exe System 143 +0 ThreadWrapper 004b3091 +00d FreeCommander.exe madExcept CallThreadProcSafe 004b30f6 +032 FreeCommander.exe madExcept ThreadExceptFrame 7742fa27 +017 KERNEL32.DLL BaseThreadInitThunk >> created by main thread ($30f0) at: 00e20cc3 +023 FreeCommander.exe fcIconThread 270 +1 TVirtualImageThread.Create modules: 00400000 FreeCommander.exe 2020.0.0.810 C:\Users\utente\Documents\nextcloud ab-tech\sw portable\FreeCommanderXE 0ab00000 cbfsMntNtf6.dll 6.1.184.329 C:\WINDOWS\System32 10000000 cbfsNetRdr6.dll 6.1.184.328 C:\WINDOWS\system32 67780000 DEVOBJ.dll 10.0.19041.1151 C:\WINDOWS\System32 68030000 tiptsf.dll 10.0.19041.746 C:\Program Files (x86)\Common Files\microsoft shared\ink 680c0000 mfmp4srcsnk.dll 10.0.19041.1110 C:\WINDOWS\System32 68290000 Windows.FileExplorer.Common.dll 10.0.19041.1151 C:\Windows\System32 684b0000 MFPlat.DLL 10.0.19041.746 C:\WINDOWS\System32 68630000 mfsrcsnk.dll 10.0.19041.906 C:\WINDOWS\System32 68790000 ActXPrxy.dll 10.0.19041.844 C:\Windows\System32 687e0000 OneCoreCommonProxyStub.dll 10.0.19041.1081 C:\Windows\System32 68820000 Windows.StateRepositoryPS.dll 10.0.19041.844 C:\Windows\System32 68a60000 msxml6.dll 6.30.19041.1081 C:\Windows\System32 68c40000 WMVCore.DLL 12.0.19041.1110 C:\WINDOWS\system32 690d0000 thumbcache.dll 10.0.19041.1151 C:\Windows\System32 69120000 WMASF.DLL 12.0.19041.1 C:\WINDOWS\system32 69160000 mfperfhelper.dll 10.0.19041.1 C:\WINDOWS\system32 69270000 audiodev.dll 10.0.19041.1 C:\WINDOWS\system32 692b0000 PortableDeviceApi.dll 10.0.19041.746 C:\Windows\System32 69340000 gdiplus.dll 10.0.19041.1151 C:\WINDOWS\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.1151_none_d951395de104724f 694b0000 wpdshext.dll 10.0.19041.1023 C:\WINDOWS\system32 69540000 MMDevApi.dll 10.0.19041.1023 C:\WINDOWS\System32 695b0000 PlayToDevice.dll 10.0.19041.746 C:\Windows\System32 69600000 dbghelp.dll 10.0.19041.1052 C:\WINDOWS\SYSTEM32 69790000 wininet.dll 11.0.19041.1151 C:\WINDOWS\SYSTEM32 69e50000 TextShaping.dll C:\WINDOWS\SYSTEM32 69ef0000 msvcp110_win.dll 10.0.19041.546 C:\WINDOWS\SYSTEM32 69f60000 policymanager.dll 10.0.19041.1151 C:\WINDOWS\SYSTEM32 6a080000 OneCoreUAPCommonProxyStub.dll 10.0.19041.1023 C:\Windows\System32 6a610000 dlnashext.dll 10.0.19041.1023 C:\Windows\System32 6a660000 apphelp.dll 10.0.19041.928 C:\WINDOWS\SYSTEM32 6a980000 CoreUIComponents.dll 10.0.19041.546 C:\WINDOWS\System32 6ac00000 textinputframework.dll 10.0.19041.1151 C:\WINDOWS\SYSTEM32 6acc0000 twinapi.appcore.dll 10.0.19041.746 C:\WINDOWS\system32 6ae50000 dcomp.dll 10.0.19041.1023 C:\WINDOWS\system32 6afc0000 d3d11.dll 10.0.19041.746 C:\WINDOWS\system32 6b1a0000 WindowsCodecs.dll 10.0.19041.1151 C:\WINDOWS\SYSTEM32 6cc70000 comctl32.dll 6.10.19041.1110 C:\WINDOWS\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_a8625c1886757984 6ce80000 ntshrui.dll 10.0.19041.844 C:\WINDOWS\SYSTEM32 6d420000 CoreMessaging.dll 10.0.19041.867 C:\WINDOWS\System32 6d530000 wintypes.dll 10.0.19041.1081 C:\WINDOWS\SYSTEM32 6d770000 mssprxy.dll 7.0.19041.1151 C:\WINDOWS\system32 6d790000 dxgi.dll 10.0.19041.964 C:\WINDOWS\system32 6da60000 DevDispItemProvider.dll 10.0.19041.546 C:\Windows\System32 6da80000 davclnt.dll 10.0.19041.546 C:\WINDOWS\System32 6dca0000 winspool.drv 10.0.19041.1023 C:\WINDOWS\SYSTEM32 6de10000 olepro32.dll 10.0.19041.84 C:\WINDOWS\SYSTEM32 6de30000 mpr.dll 10.0.19041.546 C:\WINDOWS\SYSTEM32 6df20000 msimg32.dll 10.0.19041.546 C:\WINDOWS\SYSTEM32 6df30000 dataexchange.dll 10.0.19041.1151 C:\WINDOWS\system32 6e180000 DAVHLPR.dll 10.0.19041.546 C:\WINDOWS\System32 6e600000 cscapi.dll 10.0.19041.546 C:\WINDOWS\SYSTEM32 6e790000 LINKINFO.dll 10.0.19041.546 C:\WINDOWS\SYSTEM32 6e7a0000 DWMAPI.DLL 10.0.19041.746 C:\WINDOWS\SYSTEM32 6e8c0000 iertutil.dll 11.0.19041.1081 C:\WINDOWS\SYSTEM32 6f190000 urlmon.dll 11.0.19041.1151 C:\WINDOWS\SYSTEM32 6fc40000 uxtheme.dll 10.0.19041.1081 C:\WINDOWS\system32 6fcc0000 winmm.dll 10.0.19041.546 C:\WINDOWS\SYSTEM32 6fdd0000 ntlanman.dll 10.0.19041.1151 C:\WINDOWS\System32 6fdf0000 p9np.dll 10.0.19041.1 C:\WINDOWS\System32 6fe10000 dbgcore.DLL 10.0.19041.546 C:\WINDOWS\SYSTEM32 6fe40000 FaultRep.dll 10.0.19041.1081 C:\WINDOWS\SYSTEM32 6feb0000 winmmbase.dll 10.0.19041.1 C:\WINDOWS\SYSTEM32 6fed0000 MSACM32.dll 10.0.19041.1 C:\WINDOWS\SYSTEM32 6fef0000 MsVfW32.dll 10.0.19041.1 C:\WINDOWS\SYSTEM32 70570000 propsys.dll 7.0.19041.1023 C:\WINDOWS\system32 713f0000 wkscli.dll 10.0.19041.546 C:\WINDOWS\System32 71970000 drprov.dll 10.0.19041.546 C:\WINDOWS\System32 719a0000 avifil32.dll 10.0.19041.1 C:\WINDOWS\SYSTEM32 719c0000 RTWorkQ.DLL 10.0.19041.546 C:\WINDOWS\System32 719f0000 edputil.dll 10.0.19041.546 C:\WINDOWS\SYSTEM32 71a10000 wsock32.dll 10.0.19041.1 C:\WINDOWS\SYSTEM32 71b40000 WINNSI.DLL 10.0.19041.546 C:\WINDOWS\SYSTEM32 71e60000 dhcpcsvc.DLL 10.0.19041.546 C:\WINDOWS\SYSTEM32 71e80000 DNSAPI.dll 10.0.19041.1151 C:\WINDOWS\SYSTEM32 71f20000 dhcpcsvc6.DLL 10.0.19041.546 C:\WINDOWS\SYSTEM32 721f0000 npmproxy.dll 10.0.19041.546 C:\WINDOWS\System32 72210000 netprofm.dll 10.0.19041.746 C:\WINDOWS\System32 72250000 WINSTA.dll 10.0.19041.546 C:\WINDOWS\SYSTEM32 722a0000 SRVCLI.DLL 10.0.19041.546 C:\WINDOWS\SYSTEM32 72630000 Wldp.dll 10.0.19041.662 C:\WINDOWS\SYSTEM32 72660000 windows.storage.dll 10.0.19041.1151 C:\WINDOWS\SYSTEM32 730f0000 MSASN1.dll 10.0.19041.546 C:\WINDOWS\System32 74050000 NETUTILS.DLL 10.0.19041.546 C:\WINDOWS\SYSTEM32 74080000 netapi32.dll 10.0.19041.546 C:\WINDOWS\SYSTEM32 740a0000 IPHLPAPI.DLL 10.0.19041.546 C:\Windows\System32 74ef0000 SspiCli.dll 10.0.19041.906 C:\WINDOWS\SYSTEM32 74f20000 profapi.dll 10.0.19041.844 C:\WINDOWS\SYSTEM32 750e0000 ntmarta.dll 10.0.19041.546 C:\WINDOWS\SYSTEM32 75700000 Userenv.dll 10.0.19041.572 C:\WINDOWS\SYSTEM32 757e0000 kernel.appcore.dll 10.0.19041.546 C:\WINDOWS\SYSTEM32 757f0000 wtsapi32.dll 10.0.19041.546 C:\WINDOWS\SYSTEM32 75a00000 version.dll 10.0.19041.546 C:\WINDOWS\SYSTEM32 75aa0000 coml2.dll 10.0.19041.546 C:\WINDOWS\System32 75b00000 oleaut32.dll 10.0.19041.985 C:\WINDOWS\System32 75ba0000 msvcrt.dll 7.0.19041.546 C:\WINDOWS\System32 75c60000 CFGMGR32.dll 10.0.19041.1151 C:\WINDOWS\System32 75ca0000 combase.dll 10.0.19041.1081 C:\WINDOWS\System32 75f30000 shell32.dll 10.0.19041.1151 C:\WINDOWS\System32 76550000 ucrtbase.dll 10.0.19041.789 C:\WINDOWS\System32 76670000 SETUPAPI.dll 10.0.19041.1151 C:\WINDOWS\System32 76ab0000 ole32.dll 10.0.19041.746 C:\WINDOWS\System32 76ba0000 WINTRUST.dll 10.0.19041.1151 C:\WINDOWS\System32 76c50000 shcore.dll 10.0.19041.1023 C:\WINDOWS\System32 76ce0000 KERNELBASE.dll 10.0.19041.1151 C:\WINDOWS\System32 76f00000 advapi32.dll 10.0.19041.1052 C:\WINDOWS\System32 76f80000 MSCTF.dll 10.0.19041.1081 C:\WINDOWS\System32 77060000 user32.dll 10.0.19041.1151 C:\WINDOWS\System32 77200000 SHLWAPI.dll 10.0.19041.1023 C:\WINDOWS\System32 77250000 WS2_32.dll 10.0.19041.546 C:\WINDOWS\System32 772c0000 sechost.dll 10.0.19041.906 C:\WINDOWS\System32 77340000 msvcp_win.dll 10.0.19041.789 C:\WINDOWS\System32 773c0000 IMM32.DLL 10.0.19041.546 C:\WINDOWS\System32 773f0000 bcrypt.dll 10.0.19041.1023 C:\WINDOWS\System32 77410000 KERNEL32.DLL 10.0.19041.1151 C:\WINDOWS\System32 77500000 comdlg32.dll 10.0.19041.906 C:\WINDOWS\System32 775b0000 CRYPT32.dll 10.0.19041.844 C:\WINDOWS\System32 776c0000 GDI32.dll 10.0.19041.746 C:\WINDOWS\System32 776f0000 RPCRT4.dll 10.0.19041.1081 C:\WINDOWS\System32 777d0000 win32u.dll 10.0.19041.1151 C:\WINDOWS\System32 77960000 gdi32full.dll 10.0.19041.1110 C:\WINDOWS\System32 77ad0000 bcryptPrimitives.dll 10.0.19041.1023 C:\WINDOWS\System32 77b40000 clbcatq.dll 2001.12.10941.16384 C:\WINDOWS\System32 77bc0000 NSI.dll 10.0.19041.610 C:\WINDOWS\System32 77be0000 ntdll.dll 10.0.19041.1110 C:\WINDOWS\SYSTEM32 processes: 0000 Idle 0 0 0 0004 System 0 0 0 0064 Registry 0 0 0 020c smss.exe 0 0 0 02cc csrss.exe 0 0 0 0250 wininit.exe 0 0 0 0368 services.exe 0 0 0 0384 lsass.exe 0 0 0 030c svchost.exe 0 0 0 0388 fontdrvhost.exe 0 0 0 0410 WUDFHost.exe 0 0 0 0488 svchost.exe 0 0 0 04c4 svchost.exe 0 0 0 0500 WUDFHost.exe 0 0 0 05f4 svchost.exe 0 0 0 062c svchost.exe 0 0 0 0638 svchost.exe 0 0 0 065c svchost.exe 0 0 0 0690 svchost.exe 0 0 0 06b8 svchost.exe 0 0 0 06f0 svchost.exe 0 0 0 07bc svchost.exe 0 0 0 07d0 svchost.exe 0 0 0 07f0 svchost.exe 0 0 0 07f8 svchost.exe 0 0 0 024c svchost.exe 0 0 0 0834 svchost.exe 0 0 0 0854 svchost.exe 0 0 0 0870 svchost.exe 0 0 0 0920 svchost.exe 0 0 0 0958 svchost.exe 0 0 0 0988 svchost.exe 0 0 0 099c svchost.exe 0 0 0 09a8 svchost.exe 0 0 0 0a00 Memory Compression 0 0 0 0a14 svchost.exe 0 0 0 0a4c svchost.exe 0 0 0 0a5c dasHost.exe 0 0 0 0a90 igfxCUIService.exe 0 0 0 0ab8 svchost.exe 0 0 0 0aec svchost.exe 0 0 0 0b08 svchost.exe 0 0 0 0b68 svchost.exe 0 0 0 0bac svchost.exe 0 0 0 0bd0 svchost.exe 0 0 0 08ec svchost.exe 0 0 0 0be4 svchost.exe 0 0 0 0c3c svchost.exe 0 0 0 0ce8 svchost.exe 0 0 0 0d2c svchost.exe 0 0 0 0d70 svchost.exe 0 0 0 0dec RtkAudioService64.exe 0 0 0 0e88 svchost.exe 0 0 0 0ed4 PresentationFontCache.exe 0 0 0 0ef8 svchost.exe 0 0 0 0f00 svchost.exe 0 0 0 0f10 svchost.exe 0 0 0 0f74 svchost.exe 0 0 0 1034 svchost.exe 0 0 0 10ec svchost.exe 0 0 0 114c svchost.exe 0 0 0 129c svchost.exe 0 0 0 134c svchost.exe 0 0 0 1354 svchost.exe 0 0 0 136c svchost.exe 0 0 0 137c svchost.exe 0 0 0 13c0 svchost.exe 0 0 0 0d48 svchost.exe 0 0 0 14cc spoolsv.exe 0 0 0 1518 svchost.exe 0 0 0 1574 svchost.exe 0 0 0 1654 avp.exe 0 0 0 1670 svchost.exe 0 0 0 1680 svchost.exe 0 0 0 16ac svchost.exe 0 0 0 16c8 vmcompute.exe 0 0 0 16d0 svchost.exe 0 0 0 16e4 ibtsiva.exe 0 0 0 173c openvpnserv2.exe 0 0 0 1768 openvpnserv.exe 0 0 0 1788 pdf24.exe 0 0 0 179c svchost.exe 0 0 0 17a4 sqlwriter.exe 0 0 0 17bc SynTPEnhService.exe 0 0 0 17dc svchost.exe 0 0 0 13e4 launcher-x64.exe 0 0 0 14f4 wireguard.exe 0 0 0 1570 svchost.exe 0 0 0 1808 valWBFPolicyService.exe 0 0 0 1820 svchost.exe 0 0 0 1904 svchost.exe 0 0 0 1954 conhost.exe 0 0 0 1a9c Veeam.EndPoint.Service.exe 0 0 0 1abc svchost.exe 0 0 0 1d80 svchost.exe 0 0 0 1e1c dasHost.exe 0 0 0 1ee8 svchost.exe 0 0 0 0ec8 svchost.exe 0 0 0 201c sqlservr.exe 0 0 0 21e8 SearchIndexer.exe 0 0 0 1b90 svchost.exe 0 0 0 2690 svchost.exe 0 0 0 2990 svchost.exe 0 0 0 2a2c SecurityHealthService.exe 0 0 0 2c88 svchost.exe 0 0 0 2ce0 WmiPrvSE.exe 0 0 0 09d8 gs-server.exe 0 0 0 0f6c SgrmBroker.exe 0 0 0 139c svchost.exe 0 0 0 1734 svchost.exe 0 0 0 12b8 svchost.exe 0 0 0 3598 WmiPrvSE.exe 0 0 0 2cd4 svchost.exe 0 0 0 2c2c dllhost.exe 0 0 0 07dc csrss.exe 3 0 0 26f4 winlogon.exe 3 0 0 1ab4 fontdrvhost.exe 3 0 0 1778 dwm.exe 3 0 0 28ac svchost.exe 0 0 0 083c WmiPrvSE.exe 0 0 0 3380 WUDFHost.exe 0 0 0 34c8 svchost.exe 0 0 0 03b8 RAVBg64.exe 3 0 0 2658 SynTPEnh.exe 3 90 51 above normal C:\Program Files\Synaptics\SynTP 23c4 RAVBg64.exe 3 0 0 3108 wireguard.exe 3 0 0 320c sihost.exe 3 0 15 normal C:\Windows\System32 27c4 svchost.exe 3 0 1 normal C:\Windows\System32 2cd0 ctfmon.exe 3 0 0 184c svchost.exe 3 0 6 normal C:\Windows\System32 39e8 taskhostw.exe 3 10 6 normal C:\Windows\System32 1c44 svchost.exe 0 0 0 3a38 explorer.exe 3 1288 604 normal C:\Windows 1fa8 SynTPHelper.exe 3 0 0 15b8 igfxHK.exe 3 10 14 normal C:\Windows\System32 11b0 StartMenu.exe 3 0 5 normal C:\Program Files\Open-Shell 3548 avpui.exe 3 35 45 normal C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3 1d60 svchost.exe 3 36 14 normal C:\Windows\System32 15b0 StartMenuExperienceHost.exe 3 0 20 normal C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy 27ac RuntimeBroker.exe 3 40 5 normal C:\Windows\System32 2a68 SearchApp.exe 3 12 47 normal C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy 2a38 RuntimeBroker.exe 3 42 11 normal C:\Windows\System32 20c8 TextInputHost.exe 3 0 24 normal C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp 2f40 RuntimeBroker.exe 3 0 4 normal C:\Windows\System32 17c4 smartscreen.exe 3 0 4 normal C:\Windows\System32 0578 SecurityHealthSystray.exe 3 7 6 normal C:\Windows\System32 0f30 RtkNGUI64.exe 3 41 30 normal C:\Program Files\Realtek\Audio\HDA 33fc svchost.exe 0 0 0 2df0 RAVBg64.exe 3 13 12 normal C:\Program Files\Realtek\Audio\HDA 1d7c pdf24.exe 3 24 17 normal C:\Program Files\PDF24 2008 KeyboardLeds.exe 3 88 66 normal C:\Program Files (x86)\Keyboard LEDs 061c openvpn-gui.exe 3 25 72 normal C:\Program Files\OpenVPN\bin 1e9c chrome.exe 3 22 49 normal C:\Program Files (x86)\Google\Chrome\Application 2230 chrome.exe 3 2 3 normal C:\Program Files (x86)\Google\Chrome\Application 32f0 chrome.exe 3 6 12 above normal C:\Program Files (x86)\Google\Chrome\Application 2ff4 chrome.exe 3 0 1 normal C:\Program Files (x86)\Google\Chrome\Application 3a50 chrome.exe 3 0 1 normal C:\Program Files (x86)\Google\Chrome\Application 3218 chrome.exe 3 0 0 idle C:\Program Files (x86)\Google\Chrome\Application 33c8 chrome.exe 3 0 0 normal C:\Program Files (x86)\Google\Chrome\Application 3970 chrome.exe 3 0 0 normal C:\Program Files (x86)\Google\Chrome\Application 12ec cmd.exe 3 0 0 normal C:\Windows\System32 1534 conhost.exe 3 19 11 normal C:\Windows\System32 1774 plugins_nms.exe 3 0 2 normal C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3 2d24 DiskInfo64.exe 3 0 0 328c CTRL-INS-f7-SHIFT-INS-f8.exe 3 32 13 normal C:\Users\utente\Documents\nextcloud ab-tech\ax\vari\autoit-v3\script fatti autoit\CTRL-INS-f7-SHIFT-INS-f8 33bc soffice.exe 3 0 1 normal C:\Program Files\LibreOffice\program 06ec soffice.bin 3 90 45 normal C:\Program Files\LibreOffice\program 0d04 nextcloud.exe 3 34 70 normal C:\Program Files\Nextcloud 2648 firefox.exe 3 102 84 normal C:\Program Files\Mozilla Firefox 1aec firefox.exe 3 2 26 normal C:\Program Files\Mozilla Firefox 27b0 firefox.exe 3 0 4 normal C:\Program Files\Mozilla Firefox 17b0 CompPkgSrv.exe 3 0 1 normal C:\Windows\System32 3a34 firefox.exe 3 0 2 normal C:\Program Files\Mozilla Firefox 1454 firefox.exe 3 0 2 idle C:\Program Files\Mozilla Firefox 3638 plugins_nms.exe 3 0 2 normal C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3 23a0 svchost.exe 3 0 1 normal C:\Windows\System32 0674 firefox.exe 3 0 2 idle C:\Program Files\Mozilla Firefox 38dc svchost.exe 0 0 0 0720 firefox.exe 3 0 2 normal C:\Program Files\Mozilla Firefox 2ac8 chrome.exe 3 0 0 idle C:\Program Files (x86)\Google\Chrome\Application 1208 svchost.exe 0 0 0 0c7c UserOOBEBroker.exe 3 0 2 normal C:\Windows\System32\oobe 2c48 dllhost.exe 3 0 4 normal C:\Windows\System32 0be8 rclone.exe 3 0 2 normal C:\Users\utente\Documents\nextcloud ab-tech\sw portable\rclone win\rclone 20a8 conhost.exe 3 13 9 normal C:\Windows\System32 0830 FreeCommander.exe 3 492 292 normal C:\Users\utente\Documents\nextcloud ab-tech\sw portable\FreeCommanderXE 16b8 firefox.exe 3 0 2 normal C:\Program Files\Mozilla Firefox 2378 svchost.exe 0 0 0 0f08 audiodg.exe 0 0 0 hardware: + {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc} - Brother HL-L5100DN series Printer - Coda di stampa radice - HP LaserJet MFP M130fw (FFC5B2) - CASA CARVICO - Microsoft Print to PDF - Microsoft XPS Document Writer - OneNote for Windows 10 - PDF/A DESKTOP - PDF24 - Samsung M4070FX F/R (UFFICIO TERNO) + {36fc9e60-c465-11cf-8056-444553540000} - Controller host Intel(R) USB 3.0 eXtensible - 1.0 (Microsoft) - Dispositivo USB composito - Generic USB Hub - Hub radice USB - Hub radice USB (USB 3.0) - Hub USB generico - Hub USB SuperSpeed generico - Mobile 5th Generation Intel(R) Core(TM) USB EHCI Controller - 9CA6 (driver 10.1.1.44) - Modulo scheda di rete Mobile Broadband USB + {4d36e966-e325-11ce-bfc1-08002be10318} - PC ACPI basato su x64 + {4d36e967-e325-11ce-bfc1-08002be10318} - Samsung SSD 860 EVO 500GB + {4d36e968-e325-11ce-bfc1-08002be10318} - Intel(R) HD Graphics 5500 (driver 20.19.15.5126) + {4d36e96a-e325-11ce-bfc1-08002be10318} - Controller AHCI SATA standard + {4d36e96b-e325-11ce-bfc1-08002be10318} - Standard 101/102-Key or Microsoft Natural PS/2 Keyboard for HP Hotkey Support (driver 11.0.8.1) + {4d36e96c-e325-11ce-bfc1-08002be10318} - Realtek High Definition Audio (driver 6.0.1.7561) + {4d36e96e-e325-11ce-bfc1-08002be10318} - Monitor generico Plug and Play + {4d36e96f-e325-11ce-bfc1-08002be10318} - Synaptics SMBus TouchPad (driver 19.0.19.70) + {4d36e970-e325-11ce-bfc1-08002be10318} - Realtek PCIE CardReader (driver 10.0.10143.21278) + {4d36e972-e325-11ce-bfc1-08002be10318} - Bluetooth Device (Personal Area Network) - HP lt4112 Gobi 4G Module - Intel(R) Dual Band Wireless-AC 7265 (driver 18.33.14.3) - Intel(R) Ethernet Connection (3) I218-LM (driver 12.13.17.7) - Microsoft Kernel Debug Network Adapter - Microsoft Wi-Fi Direct Virtual Adapter #3 - Microsoft Wi-Fi Direct Virtual Adapter #4 - TAP-Windows Adapter V9 (driver 9.24.6.601) - TAP-Windows Adapter V9 #2 (driver 9.24.6.601) - VirtualBox Host-Only Ethernet Adapter #2 (driver 6.1.18.42142) - WAN Miniport (IKEv2) - WAN Miniport (IP) - WAN Miniport (IPv6) - WAN Miniport (L2TP) - WAN Miniport (Network Monitor) - WAN Miniport (PPPOE) - WAN Miniport (PPTP) - WAN Miniport (SSTP) - Wintun Userspace Tunnel (driver 0.8.0.0) + {4d36e979-e325-11ce-bfc1-08002be10318} - HP LaserJet MFP M129-M134 PCLm-S (driver 24.94.1.7336) - Microsoft IPP Class Driver + {4d36e97b-e325-11ce-bfc1-08002be10318} - Controller spazi di archiviazione Microsoft + {4d36e97d-e325-11ce-bfc1-08002be10318} - Archiviazione volumi - Bus IO esteso - Bus Redirector dispositivi Desktop remoto - Complesso radice PCI Express - Controller di accesso diretto alla memoria (DMA) - Controller integrato compatibile ACPI Microsoft - Controller per High Definition Audio - Coperchio ACPI - Dispositivo legacy - Driver arbitraggio ricarica - Driver BIOS Microsoft System Management - Driver infrastruttura di virtualizzazione Hyper-V Microsoft - Driver rendering base Microsoft - Driver video base Microsoft - Enumeratore bus composito - Enumeratore bus radice UMBus - Enumeratore di dispositivi software Plug and Play - Enumeratore scheda di rete virtuale NDIS - Enumeratore unità virtuale Microsoft - HP Mobile Data Protection Sensor (driver 7.0.18.1) - Intel(R) Management Engine Interface (driver 11.7.0.1032) - Interfaccia di gestione Microsoft Windows per ACPI - Mobile 5th Generation Intel(R) Core(TM) Host Bridge - OPI - 1604 (driver 10.1.1.44) - Mobile 5th Generation Intel(R) Core(TM) PCI Express Root Port #1 - 9C90 (driver 10.1.1.44) - Mobile 5th Generation Intel(R) Core(TM) PCI Express Root Port #2 - 9C92 (driver 10.1.1.44) - Mobile 5th Generation Intel(R) Core(TM) PCI Express Root Port #4 - 9C96 (driver 10.1.1.44) - Mobile 5th Generation Intel(R) Core(TM) Premium SKU LPC Controller - 9CC3 (driver 10.1.1.44) - Nfc GPIO Driver (driver 1.0.4.0) - Orologio di sistema CMOS a tempo reale - Programmable Interrupt Controller - Provider bus macchina virtuale Hyper-V Microsoft - Pulsante caratteristica ACPI fissa - Pulsante sospensione ACPI - Risorse scheda madre - Risorse scheda madre - Risorse scheda madre - Server disco virtuale Hyper-V Microsoft - Server PCI Hyper-V Microsoft - Sistema compatibile ACPI Microsoft - Synaptics SMBus Driver (driver 19.0.19.70) - Timer di sistema - Timer eventi alta precisione - VSP di integrazione kernel Microsoft Hyper-V NT - Zona termica ACPI - Zona termica ACPI - Zona termica ACPI - Zona termica ACPI - Zona termica ACPI - Zona termica ACPI + {50127dc3-0f36-415e-a6cc-4cb3be910b65} - Intel(R) Core(TM) i5-5300U CPU @ 2.30GHz - Intel(R) Core(TM) i5-5300U CPU @ 2.30GHz - Intel(R) Core(TM) i5-5300U CPU @ 2.30GHz - Intel(R) Core(TM) i5-5300U CPU @ 2.30GHz + {5175d334-c371-4806-b3ba-71fd53c9258d} - HP GNSS Sensor (driver 1.1.17.0) + {533c5b84-ec70-11d2-9505-00c04f79deaf} - Copia shadow volume generico - Copia shadow volume generico - Copia shadow volume generico - Copia shadow volume generico - Copia shadow volume generico - Copia shadow volume generico - Copia shadow volume generico - Copia shadow volume generico - Copia shadow volume generico - Copia shadow volume generico - Copia shadow volume generico - Copia shadow volume generico - Copia shadow volume generico + {53d29ef7-377c-4d14-864b-eb3a85769359} - Synaptics FP Sensors (WBF) (PID=003f) (driver 4.5.342.0) + {5630831c-06c9-4856-b327-f5d32586e060} - NXP NearFieldProximity Provider (driver 10.0.7.0) + {5c4c3332-344d-483c-8739-259e934c9cc8} - HP LAN/WLAN/WWAN Switching and Hotkey Service (driver 7.0.15.1) - HP Radio Manager Device (driver 2.1.11.1) + {62f9c741-b25a-46ce-b54c-9bccce08b6f2} - Bluetooth - Brother HL-L5100DN series - HP LaserJet MFP M130fw (FFC5B2) - Microsoft Device Association Root Enumerator - Microsoft Radio Device Enumeration Bus - Microsoft RRAS Root Enumerator - Sintetizzatore Wavetable Microsoft GS - Wi-Fi + {72631e54-78a4-11d0-bcf7-00aa00b7b32a} - Batteria compatibile con ACPI Microsoft - Batteria compatibile con ACPI Microsoft - Scheda AC Microsoft + {745a17a0-74d3-11d0-b6fe-00a0c90f57da} - Controlli radio wireless compatibili HID - HP Wireless Button Driver (driver 2.1.4.1) + {c166523c-fe0c-4a94-a586-f1a80cfbbf3e} - Microfono (Realtek High Definition Audio) - Speakers/Headphones (Realtek High Definition Audio) + {ca3e7ab9-b4c3-4ae6-8251-579ef933890f} - HP HD Webcam (driver 5.0.8.29) + {d94ee5d8-d189-4994-83d2-f68d7d41b0e6} - Trusted Platform Module 1.2 + {e0cbf06c-cd8b-4647-bb8a-263b43f0f974} - Bluetooth Device (RFCOMM Protocol TDI) - Enumeratore Bluetooth Microsoft - Enumeratore LE Bluetooth Microsoft - Intel(R) Wireless Bluetooth(R) (driver 20.100.7.1) cpu registers: eax = 06378420 ebx = 06378420 ecx = 019eefb8 edx = 00000000 esi = 006cf030 edi = 019eefb0 eip = 006cdf63 esp = 019eef20 ebp = 000e06ae stack dump: 019eef20 4e df 6c 00 20 84 37 06 - 0d 08 6d 00 12 07 10 00 N.l. .7...m..... 019eef30 00 87 e9 01 00 00 00 00 - 00 00 00 00 58 ef 9e 01 ............X... 019eef40 20 84 37 06 20 84 37 06 - 20 84 37 06 03 38 fe 00 .7. .7. .7..8.. 019eef50 b0 ef 9e 01 20 84 37 06 - 7c f0 9e 01 9a d6 5c 00 .... .7.|.....\. 019eef60 c8 f0 9e 01 e4 b0 40 00 - 7c f0 9e 01 07 00 00 00 ......@.|....... 019eef70 20 84 37 06 20 84 37 06 - 00 00 00 00 00 00 00 00 .7. .7......... 019eef80 09 ad ce 6c 12 07 10 00 - 81 02 00 00 10 60 00 80 ...l.........`.. 019eef90 9c c7 c2 77 02 00 00 00 - 00 00 00 00 00 87 e9 01 ...w............ 019eefa0 bd a8 fd f1 74 ef 9e 01 - 00 00 14 00 bc f0 9e 01 ....t........... 019eefb0 dc 79 36 06 00 00 ce 06 - 00 00 01 00 0e 02 00 00 .y6............. 019eefc0 ab 00 00 00 dd 02 00 00 - e2 01 00 00 ae 06 0e 00 ................ 019eefd0 00 00 00 00 08 00 00 00 - 00 a4 41 00 00 00 00 00 ..........A..... 019eefe0 00 00 00 00 00 00 40 00 - 00 00 00 00 03 00 01 00 ......@......... 019eeff0 00 00 00 00 00 00 00 00 - 00 00 00 00 54 00 64 00 ............T.d. 019ef000 6c 00 67 00 46 00 63 00 - 43 00 6f 00 70 00 79 00 l.g.F.c.C.o.p.y. 019ef010 4d 00 6f 00 76 00 65 00 - 4f 00 70 00 65 00 72 00 M.o.v.e.O.p.e.r. 019ef020 61 00 74 00 69 00 6f 00 - 6e 00 00 00 00 00 00 00 a.t.i.o.n....... 019ef030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 019ef040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 019ef050 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ disassembling: [...] 00fe37ef add esp, -8 00fe37f2 mov [ebp-8], edx 00fe37f5 mov [ebp-4], eax 00fe37f8 477 mov edx, [ebp-8] 00fe37fb mov eax, [ebp-4] 00fe37fe > call -$91359f ($6d0264) ; Vcl.Forms.TCustomForm.CreateParams 00fe3803 479 mov eax, [ebp-8] 00fe3806 xor edx, edx 00fe3808 mov [eax+$1c], edx 00fe380b 480 pop ecx 00fe380c pop ecx [...] date/time : 2022-02-05, 22:43:50, 736ms computer name : NB-ALE-HP user name : utente registered owner : utente operating system : Windows 10 x64 build 22000 system language : Italian system up time : 1 day 2 hours program up time : 36 minutes 12 seconds processors : 4x Intel(R) Core(TM) i5-5300U CPU @ 2.30GHz physical memory : 11833/15779 MB (free/total) free disk space : (C:) 345,43 GB display mode : 1536x864, 32 bit process id : $1a48 allocated memory : 132,94 MB largest free block : 1,27 GB executable : FreeCommander.exe exec. date/time : 2021-12-17 18:55 version : 2022.0.0.860 compiled with : Delphi 10.4 Sydney madExcept version : 5.1.0 callstack crc : $a3ab29e1, $66ae02b8, $00000000 count : 2 exception number : 2 exception class : EAccessViolation exception message : Access violation at address 013A807C in module 'FreeCommander.exe'. Read of address 000000E0. thread $924: 013a807c +014 FreeCommander.exe fcController 1242 +1 TfcController.GetFilesList 01470c86 +026 FreeCommander.exe FcMain 10182 +1 TFcFormMain.ActionListMainExecute 005a582c +070 FreeCommander.exe System.Actions TContainedActionList.ExecuteAction 005eb155 +069 FreeCommander.exe Vcl.ActnList TCustomAction.Execute 005094fb +013 FreeCommander.exe System.Classes TBasicActionLink.Execute 0070fdcf +093 FreeCommander.exe Vcl.Menus TMenuItem.Click 00711ad7 +0ef FreeCommander.exe Vcl.Menus DoClick 00711bc3 +087 FreeCommander.exe Vcl.Menus TMenu.IsShortCut 00711be4 +0a8 FreeCommander.exe Vcl.Menus TMenu.IsShortCut 00711c11 +0d5 FreeCommander.exe Vcl.Menus TMenu.IsShortCut 00728cb9 +04d FreeCommander.exe Vcl.Forms TCustomForm.IsShortCut 0072d07e +04e FreeCommander.exe Vcl.Forms TApplication.IsShortCut 0072c686 +482 FreeCommander.exe Vcl.Forms TApplication.WndProc 0050a3fc +014 FreeCommander.exe System.Classes StdWndProc 75fc5dc1 +041 USER32.dll SendMessageW 00604468 +018 FreeCommander.exe Vcl.Controls SendAppMessage 00610e49 +07d FreeCommander.exe Vcl.Controls TWinControl.IsMenuKey 00610ffd +011 FreeCommander.exe Vcl.Controls TWinControl.CNSysKeyDown 00609772 +2be FreeCommander.exe Vcl.Controls TControl.WndProc 0060e6c7 +693 FreeCommander.exe Vcl.Controls TWinControl.WndProc 00670757 +0af FreeCommander.exe Vcl.ComCtrls TCustomListView.WndProc 0060dc14 +02c FreeCommander.exe Vcl.Controls TWinControl.MainWndProc 0060dc2f +047 FreeCommander.exe Vcl.Controls TWinControl.MainWndProc 0050a3fc +014 FreeCommander.exe System.Classes StdWndProc 75fc5eaa +07a USER32.dll CallWindowProcW 75fc5dc1 +041 USER32.dll SendMessageW 0072cf88 +084 FreeCommander.exe Vcl.Forms TApplication.IsKeyMsg 0072d233 +0cf FreeCommander.exe Vcl.Forms TApplication.ProcessMessage 0072d282 +00a FreeCommander.exe Vcl.Forms TApplication.ProcessMessages 01312a94 +04c FreeCommander.exe fcSearchFormObjectList 75 +7 TfcSearchFormList.CloseAlForms 013a76bd +15d FreeCommander.exe fcController 947 +35 TfcController.Destroy 00409f84 +008 FreeCommander.exe System 346 +0 TObject.Free 013a711e +016 FreeCommander.exe fcController 802 +1 FreePrgController 0145c4ef +50b FreeCommander.exe FcMain 2471 +150 TFcFormMain.FormDestroy 00721dbd +031 FreeCommander.exe Vcl.Forms TCustomForm.DoDestroy 0109bf80 +02c FreeCommander.exe fcWindowStateFormUnit 102 +5 TfcWindowStateForm.DoDestroy 0040a671 +009 FreeCommander.exe System 346 +0 @BeforeDestruction 00721ba2 +006 FreeCommander.exe Vcl.Forms TCustomForm.Destroy 00409f84 +008 FreeCommander.exe System 346 +0 TObject.Free 005080fa +086 FreeCommander.exe System.Classes TComponent.DestroyComponents 0071f729 +035 FreeCommander.exe Vcl.Forms DoneApplication 0045a14d +021 FreeCommander.exe System.SysUtils DoExitProc 0040bca6 +06e FreeCommander.exe System 346 +0 @Halt0 015bfa2c +3ec FreeCommander.exe FreeCommander 613 +191 initialization 76c26737 +017 KERNEL32.DLL BaseThreadInitThunk thread $924, inner exception level 1: >> EAccessViolation, Access violation at address 013A807C in module 'FreeCommander.exe'. Read of address 000000E0 013a807c +014 FreeCommander.exe fcController 1242 +1 TfcController.GetFilesList 01470c86 +026 FreeCommander.exe FcMain 10182 +1 TFcFormMain.ActionListMainExecute 005a582c +070 FreeCommander.exe System.Actions TContainedActionList.ExecuteAction 005eb155 +069 FreeCommander.exe Vcl.ActnList TCustomAction.Execute 005094fb +013 FreeCommander.exe System.Classes TBasicActionLink.Execute 0070fdcf +093 FreeCommander.exe Vcl.Menus TMenuItem.Click 00711ad7 +0ef FreeCommander.exe Vcl.Menus DoClick 00711bc3 +087 FreeCommander.exe Vcl.Menus TMenu.IsShortCut 00711be4 +0a8 FreeCommander.exe Vcl.Menus TMenu.IsShortCut 00711c11 +0d5 FreeCommander.exe Vcl.Menus TMenu.IsShortCut 00728cb9 +04d FreeCommander.exe Vcl.Forms TCustomForm.IsShortCut 0072d07e +04e FreeCommander.exe Vcl.Forms TApplication.IsShortCut 0072c686 +482 FreeCommander.exe Vcl.Forms TApplication.WndProc 0050a3fc +014 FreeCommander.exe System.Classes StdWndProc 75fc5dc1 +041 USER32.dll SendMessageW 00604468 +018 FreeCommander.exe Vcl.Controls SendAppMessage 00610e49 +07d FreeCommander.exe Vcl.Controls TWinControl.IsMenuKey 00610ffd +011 FreeCommander.exe Vcl.Controls TWinControl.CNSysKeyDown 00609772 +2be FreeCommander.exe Vcl.Controls TControl.WndProc 0060e6c7 +693 FreeCommander.exe Vcl.Controls TWinControl.WndProc 00670757 +0af FreeCommander.exe Vcl.ComCtrls TCustomListView.WndProc 0060dc14 +02c FreeCommander.exe Vcl.Controls TWinControl.MainWndProc 0060dc2f +047 FreeCommander.exe Vcl.Controls TWinControl.MainWndProc 0050a3fc +014 FreeCommander.exe System.Classes StdWndProc 75fc5eaa +07a USER32.dll CallWindowProcW 75fc5dc1 +041 USER32.dll SendMessageW 0072cf88 +084 FreeCommander.exe Vcl.Forms TApplication.IsKeyMsg 0072d233 +0cf FreeCommander.exe Vcl.Forms TApplication.ProcessMessage 0072d282 +00a FreeCommander.exe Vcl.Forms TApplication.ProcessMessages 01312a94 +04c FreeCommander.exe fcSearchFormObjectList 75 +7 TfcSearchFormList.CloseAlForms 013a76bd +15d FreeCommander.exe fcController 947 +35 TfcController.Destroy 00409f84 +008 FreeCommander.exe System 346 +0 TObject.Free 013a711e +016 FreeCommander.exe fcController 802 +1 FreePrgController 0145c4ef +50b FreeCommander.exe FcMain 2471 +150 TFcFormMain.FormDestroy 00721dbd +031 FreeCommander.exe Vcl.Forms TCustomForm.DoDestroy 0109bf80 +02c FreeCommander.exe fcWindowStateFormUnit 102 +5 TfcWindowStateForm.DoDestroy 0040a671 +009 FreeCommander.exe System 346 +0 @BeforeDestruction 00721ba2 +006 FreeCommander.exe Vcl.Forms TCustomForm.Destroy 00409f84 +008 FreeCommander.exe System 346 +0 TObject.Free 005080fa +086 FreeCommander.exe System.Classes TComponent.DestroyComponents 0071f729 +035 FreeCommander.exe Vcl.Forms DoneApplication 0045a14d +021 FreeCommander.exe System.SysUtils DoExitProc 0040bca6 +06e FreeCommander.exe System 346 +0 @Halt0 015bfa2c +3ec FreeCommander.exe FreeCommander 613 +191 initialization 76c26737 +017 KERNEL32.DLL BaseThreadInitThunk thread $3a38: 75fcee59 +39 USER32.dll MsgWaitForMultipleObjects 004bb0d5 +0d FreeCommander.exe madExcept CallThreadProcSafe 004bb13a +32 FreeCommander.exe madExcept ThreadExceptFrame 76c26737 +17 KERNEL32.DLL BaseThreadInitThunk >> created by thread $924 at: 6ac45518 +00 gdiplus.dll thread $3a08: 75fceec8 +48 USER32.dll MsgWaitForMultipleObjectsEx 004bb0d5 +0d FreeCommander.exe madExcept CallThreadProcSafe 004bb13a +32 FreeCommander.exe madExcept ThreadExceptFrame 76c26737 +17 KERNEL32.DLL BaseThreadInitThunk >> created by thread $924 at: 76a8a555 +00 shcore.dll thread $3748: 76657f9d +12d KERNELBASE.dll WaitForMultipleObjectsEx 004bb0d5 +00d FreeCommander.exe madExcept CallThreadProcSafe 004bb13a +032 FreeCommander.exe madExcept ThreadExceptFrame 76c26737 +017 KERNEL32.DLL BaseThreadInitThunk >> created by thread $3a08 at: 7629338a +000 combase.dll thread $22b8: 76c26737 +17 KERNEL32.DLL BaseThreadInitThunk thread $d4: 76c26737 +17 KERNEL32.DLL BaseThreadInitThunk modules: 00400000 FreeCommander.exe 2022.0.0.860 C:\Users\utente\nc.ab-tech.it\sw portable\FreeCommanderXE 62d30000 wlidprov.dll 10.0.22000.51 C:\Windows\System32 62dc0000 acppage.dll 10.0.22000.1 C:\Windows\system32 62de0000 SAMLIB.dll 10.0.22000.318 C:\Windows\System32 62e00000 StartMenuHelper32.dll 4.4.160.0 C:\Windows\System32 62e80000 ntshrui.dll 10.0.22000.65 C:\Windows\SYSTEM32 62ee0000 DWMAPI.DLL 10.0.22000.41 C:\Windows\SYSTEM32 62f10000 windows.staterepositorycore.dll 10.0.22000.65 C:\Windows\SYSTEM32 62f30000 Windows.System.Launcher.dll 10.0.22000.434 C:\Windows\System32 63020000 olepro32.dll 10.0.22000.65 C:\Windows\SYSTEM32 63040000 FaultRep.dll 10.0.22000.348 C:\Windows\SYSTEM32 630b0000 MSACM32.dll 10.0.22000.1 C:\Windows\SYSTEM32 630d0000 MSVFW32.dll 10.0.22000.1 C:\Windows\SYSTEM32 63100000 oledlg.dll 10.0.22000.1 C:\Windows\SYSTEM32 63130000 avifil32.dll 10.0.22000.1 C:\Windows\SYSTEM32 63160000 IDStore.dll 10.0.22000.1 C:\Windows\System32 63190000 7-zip32.dll 21.7.0.0 C:\Program Files\7-Zip 631b0000 shacct.dll 10.0.22000.1 C:\Windows\System32 631d0000 Windows.UI.dll 10.0.22000.1 C:\Windows\System32 63310000 WMASF.DLL 12.0.22000.1 C:\Windows\system32 63360000 WMVCore.DLL 12.0.22000.120 C:\Windows\system32 63530000 audiodev.dll 10.0.22000.1 C:\Windows\system32 63580000 PortableDeviceApi.dll 10.0.22000.1 C:\Windows\System32 63610000 wpdshext.dll 10.0.22000.1 C:\Windows\system32 636a0000 MMDevApi.dll 10.0.22000.1 C:\Windows\System32 63720000 OneCoreUAPCommonProxyStub.dll 10.0.22000.348 C:\Windows\System32 63c20000 SHFolder.dll 10.0.22000.1 C:\Windows\SYSTEM32 63c30000 deviceassociation.dll 10.0.22000.1 C:\Windows\SYSTEM32 63c40000 DevDispItemProvider.dll 10.0.22000.1 C:\Windows\System32 63c60000 PlayToDevice.dll 10.0.22000.1 C:\Windows\System32 63cb0000 dlnashext.dll 10.0.22000.1 C:\Windows\System32 63d00000 msvcp110_win.dll 10.0.22000.1 C:\Windows\System32 63d70000 policymanager.dll 10.0.22000.348 C:\Windows\SYSTEM32 643e0000 apphelp.dll 10.0.22000.282 C:\Windows\SYSTEM32 64480000 cscapi.dll 10.0.22000.1 C:\Windows\SYSTEM32 64490000 davclnt.dll 10.0.22000.1 C:\Windows\System32 644b0000 ntlanman.dll 10.0.22000.434 C:\Windows\System32 644d0000 drprov.dll 10.0.22000.1 C:\Windows\System32 644e0000 thumbcache.dll 10.0.22000.1 C:\Windows\System32 64530000 Windows.FileExplorer.Common.dll 10.0.22000.348 C:\Windows\System32 64590000 p9np.dll 10.0.22000.1 C:\Windows\System32 645c0000 twext.dll 10.0.22000.1 C:\Windows\system32 645f0000 bcp47mrm.dll 10.0.22000.65 C:\Windows\System32 64620000 windows.staterepositoryclient.dll 10.0.22000.65 C:\Windows\SYSTEM32 64650000 MrmCoreR.dll 10.0.22000.120 C:\Windows\System32 64720000 LINKINFO.dll 10.0.22000.1 C:\Windows\SYSTEM32 64730000 ServicingCommon.dll 10.0.22000.348 C:\Windows\system32 647f0000 sfc_os.DLL 10.0.22000.1 C:\Windows\system32 64800000 pcacli.dll 10.0.22000.1 C:\Windows\SYSTEM32 64820000 Bcp47Langs.dll 10.0.22000.71 C:\Windows\System32 64870000 appresolver.dll 10.0.22000.100 C:\Windows\System32 648f0000 Windows.StateRepositoryPS.dll 10.0.22000.65 C:\Windows\System32 64980000 VAULTCLI.dll 10.0.22000.1 C:\Windows\System32 649d0000 edputil.dll 10.0.22000.1 C:\Windows\SYSTEM32 64c40000 msxml6.dll 6.30.22000.282 C:\Windows\System32 66680000 sfc.dll 10.0.22000.1 C:\Windows\system32 66f30000 twinapi.appcore.dll 10.0.22000.318 C:\Windows\system32 68ee0000 CoreUIComponents.dll 10.0.22000.132 C:\Windows\SYSTEM32 69180000 CoreMessaging.dll 10.0.22000.71 C:\Windows\SYSTEM32 69250000 TextShaping.dll C:\Windows\SYSTEM32 692f0000 textinputframework.dll 10.0.22000.282 C:\Windows\SYSTEM32 69f90000 WindowsCodecs.dll 10.0.22000.1 C:\Windows\SYSTEM32 6a250000 wininet.dll 11.0.22000.282 C:\Windows\SYSTEM32 6a6e0000 COMCTL32.dll 6.10.22000.120 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22000.120_none_e541a94fcce8ed6d 6abd0000 gdiplus.dll 10.0.22000.434 C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.22000.434_none_1630a2eb2777c45d 6b030000 winmm.dll 10.0.22000.1 C:\Windows\SYSTEM32 6b6d0000 dataexchange.dll 10.0.22000.1 C:\Windows\system32 6b720000 uxtheme.dll 10.0.22000.120 C:\Windows\system32 6b970000 DEVOBJ.dll 10.0.22000.1 C:\Windows\System32 6bc10000 WINSTA.dll 10.0.22000.1 C:\Windows\SYSTEM32 6c1c0000 wkscli.dll 10.0.22000.434 C:\Windows\System32 6e080000 wsock32.dll 10.0.22000.1 C:\Windows\SYSTEM32 6fdc0000 netapi32.dll 10.0.22000.434 C:\Windows\SYSTEM32 708d0000 CRYPTBASE.DLL 10.0.22000.1 C:\Windows\SYSTEM32 70960000 MSASN1.dll 10.0.22000.1 C:\Windows\SYSTEM32 71ee0000 winspool.drv 10.0.22000.348 C:\Windows\SYSTEM32 71f60000 msimg32.dll 10.0.22000.1 C:\Windows\SYSTEM32 71f70000 propsys.dll 7.0.22000.37 C:\Windows\system32 72050000 SspiCli.dll 10.0.22000.434 C:\Windows\SYSTEM32 72080000 NETUTILS.DLL 10.0.22000.434 C:\Windows\SYSTEM32 72090000 SRVCLI.DLL 10.0.22000.434 C:\Windows\SYSTEM32 720b0000 iertutil.dll 11.0.22000.348 C:\Windows\System32 722e0000 urlmon.dll 11.0.22000.282 C:\Windows\SYSTEM32 738a0000 profapi.dll 10.0.22000.1 C:\Windows\SYSTEM32 73970000 wintypes.dll 10.0.22000.41 C:\Windows\SYSTEM32 73a60000 windows.storage.dll 10.0.22000.348 C:\Windows\SYSTEM32 74da0000 kernel.appcore.dll 10.0.22000.71 C:\Windows\SYSTEM32 74dc0000 CFGMGR32.dll 10.0.22000.1 C:\Windows\SYSTEM32 74e40000 ntmarta.dll 10.0.22000.1 C:\Windows\SYSTEM32 74fe0000 wtsapi32.dll 10.0.22000.1 C:\Windows\SYSTEM32 750d0000 mpr.dll 10.0.22000.1 C:\Windows\SYSTEM32 750f0000 Userenv.dll 10.0.22000.1 C:\Windows\SYSTEM32 75110000 version.dll 10.0.22000.1 C:\Windows\SYSTEM32 752a0000 bcrypt.dll 10.0.22000.1 C:\Windows\System32 75880000 oleaut32.dll 10.0.22000.1 C:\Windows\System32 75920000 WS2_32.dll 10.0.22000.1 C:\Windows\System32 75990000 SHELL32.dll 10.0.22000.434 C:\Windows\System32 75fa0000 USER32.dll 10.0.22000.282 C:\Windows\System32 761b0000 combase.dll 10.0.22000.282 C:\Windows\System32 76440000 clbcatq.dll 2001.12.10941.16384 C:\Windows\System32 764d0000 shlwapi.dll 10.0.22000.1 C:\Windows\System32 76520000 KERNELBASE.dll 10.0.22000.434 C:\Windows\System32 76780000 ole32.dll 10.0.22000.120 C:\Windows\System32 76930000 WINTRUST.dll 10.0.22000.434 C:\Windows\System32 76980000 comdlg32.dll 10.0.22000.120 C:\Windows\System32 76a40000 win32u.dll 10.0.22000.37 C:\Windows\System32 76a60000 shcore.dll 10.0.22000.71 C:\Windows\System32 76b30000 gdi32full.dll 10.0.22000.71 C:\Windows\System32 76c10000 KERNEL32.DLL 10.0.22000.434 C:\Windows\System32 76d10000 crypt32.dll 10.0.22000.348 C:\Windows\System32 76e10000 sechost.dll 10.0.22000.434 C:\Windows\System32 76e90000 psapi.dll 10.0.22000.1 C:\Windows\System32 76f40000 msvcrt.dll 7.0.22000.1 C:\Windows\System32 77010000 GDI32.dll 10.0.22000.1 C:\Windows\System32 77060000 SETUPAPI.dll 10.0.22000.194 C:\Windows\System32 774a0000 msvcp_win.dll 10.0.22000.1 C:\Windows\System32 77520000 IMM32.DLL 10.0.22000.1 C:\Windows\System32 776c0000 ucrtbase.dll 10.0.22000.1 C:\Windows\System32 777e0000 RPCRT4.dll 10.0.22000.434 C:\Windows\System32 778a0000 bcryptPrimitives.dll 10.0.22000.376 C:\Windows\System32 77910000 MSCTF.dll 10.0.22000.434 C:\Windows\System32 77a50000 advapi32.dll 10.0.22000.434 C:\Windows\System32 77ae0000 ntdll.dll 10.0.22000.434 C:\Windows\SYSTEM32 processes: 0000 Idle 0 0 0 0004 System 0 0 0 0074 Registry 0 0 0 01a8 smss.exe 0 0 0 0270 csrss.exe 0 0 0 02c4 wininit.exe 0 0 0 0358 services.exe 0 0 0 036c lsass.exe 0 0 0 03ec svchost.exe 0 0 0 016c fontdrvhost.exe 0 0 0 0210 WUDFHost.exe 0 0 0 0430 svchost.exe 0 0 0 0464 svchost.exe 0 0 0 0510 svchost.exe 0 0 0 0584 svchost.exe 0 0 0 0590 svchost.exe 0 0 0 05d4 svchost.exe 0 0 0 0604 svchost.exe 0 0 0 0614 svchost.exe 0 0 0 0634 svchost.exe 0 0 0 067c svchost.exe 0 0 0 0688 svchost.exe 0 0 0 06f4 svchost.exe 0 0 0 0794 svchost.exe 0 0 0 07c8 svchost.exe 0 0 0 0008 svchost.exe 0 0 0 0804 svchost.exe 0 0 0 0818 svchost.exe 0 0 0 088c Memory Compression 0 0 0 089c svchost.exe 0 0 0 08ac svchost.exe 0 0 0 08e0 igfxCUIService.exe 0 0 0 0910 svchost.exe 0 0 0 0918 svchost.exe 0 0 0 09a4 svchost.exe 0 0 0 09e8 svchost.exe 0 0 0 0a0c svchost.exe 0 0 0 0a60 svchost.exe 0 0 0 0a9c RtkAudioService64.exe 0 0 0 0af8 svchost.exe 0 0 0 0b00 svchost.exe 0 0 0 0b28 svchost.exe 0 0 0 0b5c svchost.exe 0 0 0 0bec svchost.exe 0 0 0 096c svchost.exe 0 0 0 0c64 spoolsv.exe 0 0 0 0cb4 svchost.exe 0 0 0 0cfc sched.exe 0 0 0 0d2c svchost.exe 0 0 0 0dac svchost.exe 0 0 0 0fc4 svchost.exe 0 0 0 1080 svchost.exe 0 0 0 1174 svchost.exe 0 0 0 119c svchost.exe 0 0 0 11a8 avguard.exe 0 0 0 11b8 protectedservice.exe 0 0 0 11c4 Avira.ServiceHost.exe 0 0 0 11d4 svchost.exe 0 0 0 11fc svchost.exe 0 0 0 1208 svchost.exe 0 0 0 121c svchost.exe 0 0 0 1248 svchost.exe 0 0 0 1264 fpCSEvtSvc.exe 0 0 0 1288 HotKeyServiceUWP.exe 0 0 0 12c0 svchost.exe 0 0 0 12d8 ibtsiva.exe 0 0 0 12ec svchost.exe 0 0 0 1334 openvpnserv2.exe 0 0 0 133c openvpnserv.exe 0 0 0 1344 pdf24.exe 0 0 0 136c svchost.exe 0 0 0 1378 svchost.exe 0 0 0 1398 SynTPEnhService.exe 0 0 0 13b4 svchost.exe 0 0 0 13bc valWBFPolicyService.exe 0 0 0 13e4 launcher-x64.exe 0 0 0 108c wireguard.exe 0 0 0 1074 svchost.exe 0 0 0 14a8 conhost.exe 0 0 0 14c0 dasHost.exe 0 0 0 16f8 dasHost.exe 0 0 0 1768 svchost.exe 0 0 0 17b4 svchost.exe 0 0 0 17d0 AggregatorHost.exe 0 0 0 0c70 svchost.exe 0 0 0 1b18 svchost.exe 0 0 0 1730 svchost.exe 0 0 0 0ed0 SearchIndexer.exe 0 0 0 23ec svchost.exe 0 0 0 19fc svchost.exe 0 0 0 24b4 avshadow.exe 0 0 0 2798 SecurityHealthService.exe 0 0 0 2c78 svchost.exe 0 0 0 2344 SgrmBroker.exe 0 0 0 11f0 svchost.exe 0 0 0 06a0 svchost.exe 0 0 0 1254 svchost.exe 0 0 0 2ab0 svchost.exe 0 0 0 1e54 svchost.exe 0 0 0 16c0 svchost.exe 0 0 0 31b8 svchost.exe 0 0 0 32ec svchost.exe 0 0 0 1ee8 svchost.exe 0 0 0 3840 csrss.exe 5 0 0 1028 winlogon.exe 5 0 0 36b0 fontdrvhost.exe 5 0 0 27b4 dwm.exe 5 0 0 0570 svchost.exe 0 0 0 1228 svchost.exe 0 0 0 2f1c RAVBg64.exe 5 0 0 0f18 wireguard.exe 5 0 0 30c0 SynTPEnh.exe 5 90 50 above normal C:\Program Files\Synaptics\SynTP 187c HPHotkeyNotification.exe 5 25 12 normal C:\Windows\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_8598cf7f18c538c5 18cc RAVBg64.exe 5 0 0 3188 sihost.exe 5 0 8 normal C:\Windows\System32 3770 svchost.exe 5 0 1 normal C:\Windows\System32 0a34 svchost.exe 5 4 4 normal C:\Windows\System32 1b50 SynTPHelper.exe 5 0 0 19ac taskhostw.exe 5 8 6 normal C:\Windows\System32 19b8 explorer.exe 5 583 348 normal C:\Windows 311c igfxHK.exe 5 10 13 normal C:\Windows\System32 2c64 igfxTray.exe 5 7 4 normal C:\Windows\System32 2a08 StartMenu.exe 5 0 5 normal C:\Program Files\Open-Shell 1f5c svchost.exe 5 36 21 normal C:\Windows\System32 39b8 StartMenuExperienceHost.exe 5 0 12 normal C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy 249c SearchHost.exe 5 14 87 normal C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy 07a4 RuntimeBroker.exe 5 0 5 normal C:\Windows\System32 342c RuntimeBroker.exe 5 40 4 normal C:\Windows\System32 0fbc svchost.exe 5 0 1 normal C:\Windows\System32 2c38 dllhost.exe 5 0 3 normal C:\Windows\System32 0fac YourPhone.exe 5 0 8 normal C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21121.256.0_x64__8wekyb3d8bbwe 39a8 ctfmon.exe 5 0 0 2318 RuntimeBroker.exe 5 0 1 normal C:\Windows\System32 33e0 TextInputHost.exe 5 14 80 high C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy 1b70 SecurityHealthSystray.exe 5 7 6 normal C:\Windows\System32 05f8 SystemSettings.exe 5 11 26 normal C:\Windows\ImmersiveControlPanel 0668 ApplicationFrameHost.exe 5 28 17 normal C:\Windows\System32 18a4 RtkNGUI64.exe 5 41 30 normal C:\Program Files\Realtek\Audio\HDA 3980 pdf24.exe 5 22 17 normal C:\Program Files\PDF24 336c rundll32.exe 5 0 3 normal C:\Windows\System32 2aa4 nextcloud.exe 5 32 68 normal C:\Program Files\Nextcloud 194c openvpn-gui.exe 5 25 80 normal C:\Program Files\OpenVPN\bin 172c CTRL-INS-f7-SHIFT-INS-f8.exe 5 30 13 normal C:\Users\utente\nc.ab-tech.it\ax\vari\autoit-v3\script fatti autoit\CTRL-INS-f7-SHIFT-INS-f8 020c jusched.exe 5 0 2 normal C:\Program Files (x86)\Common Files\Java\Java Update 3348 chrome.exe 5 21 62 normal C:\Program Files\Google\Chrome\Application 0da0 chrome.exe 5 0 3 normal C:\Program Files\Google\Chrome\Application 3bc8 chrome.exe 5 8 12 above normal C:\Program Files\Google\Chrome\Application 1628 chrome.exe 5 0 1 normal C:\Program Files\Google\Chrome\Application 1c30 chrome.exe 5 0 1 normal C:\Program Files\Google\Chrome\Application 304c chrome.exe 5 0 0 idle C:\Program Files\Google\Chrome\Application 1470 chrome.exe 5 0 0 normal C:\Program Files\Google\Chrome\Application 05e8 soffice.exe 5 0 1 normal C:\Program Files\LibreOffice\program 37d0 soffice.bin 5 101 49 normal C:\Program Files\LibreOffice\program 3a8c avgnt.exe 5 133 49 below normal C:\Program Files (x86)\Avira\Antivirus 008c winbox.exe 5 280 153 normal C:\Users\utente\nc.ab-tech.it\sw portable\a aaa sw tool shortcut\zzz exe 2a0c chrome.exe 5 0 1 normal C:\Program Files\Google\Chrome\Application 2198 Avira.Systray.exe 5 31 56 normal C:\Program Files (x86)\Avira\Launcher 1108 svchost.exe 5 0 1 normal C:\Windows\System32 2aec Notepad.exe 5 22 26 normal C:\Program Files\WindowsApps\Microsoft.WindowsNotepad_10.2103.6.0_x64__8wekyb3d8bbwe\Notepad 1310 dllhost.exe 5 0 3 normal C:\Windows\System32 18f8 Widgets.exe 5 0 17 normal C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_421.20050.505.0_x64__cw5n1h2txyewy\Dashboard 332c msedgewebview2.exe 5 25 40 normal C:\Program Files (x86)\Microsoft\EdgeWebView\Application\97.0.1072.76 2230 msedgewebview2.exe 5 0 3 normal C:\Program Files (x86)\Microsoft\EdgeWebView\Application\97.0.1072.76 3b54 msedgewebview2.exe 5 3 21 above normal C:\Program Files (x86)\Microsoft\EdgeWebView\Application\97.0.1072.76 2860 msedgewebview2.exe 5 0 1 normal C:\Program Files (x86)\Microsoft\EdgeWebView\Application\97.0.1072.76 0750 msedgewebview2.exe 5 0 1 normal C:\Program Files (x86)\Microsoft\EdgeWebView\Application\97.0.1072.76 084c msedgewebview2.exe 5 0 0 idle C:\Program Files (x86)\Microsoft\EdgeWebView\Application\97.0.1072.76 1ad4 cmd.exe 5 0 1 normal C:\Windows\System32 2b60 conhost.exe 5 25 19 normal C:\Windows\System32 1de4 notepad++.exe 5 888 436 normal C:\Program Files\Notepad++ 34c8 chrome.exe 5 0 0 idle C:\Program Files\Google\Chrome\Application 3210 cmd.exe 5 0 0 normal C:\Windows\System32 20dc conhost.exe 5 25 19 normal C:\Windows\System32 233c powershell.exe 5 0 4 normal C:\Windows\System32\WindowsPowerShell\v1.0 1a48 FreeCommander.exe 5 508 239 normal C:\Users\utente\nc.ab-tech.it\sw portable\FreeCommanderXE 2290 ShellExperienceHost.exe 5 6 31 normal C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy 13d8 RuntimeBroker.exe 5 40 4 normal C:\Windows\System32 21fc RuntimeBroker.exe 5 0 1 normal C:\Windows\System32 22d8 audiodg.exe 0 0 0 21d4 SearchProtocolHost.exe 0 0 0 13fc SearchFilterHost.exe 0 0 0 1048 SearchFilterHost.exe 0 0 0 22c8 svchost.exe 0 0 0 1cc4 smartscreen.exe 5 0 1 normal C:\Windows\System32 hardware: + {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc} - Coda di stampa radice - HP M130fw Carvico - Microsoft Print to PDF - Microsoft XPS Document Writer - NPIFFC5B2 (HP LaserJet MFP M130fw) - PDF/A DESKTOP - PDF24 - Samsung C3060 Series (SEC8425196EEB0B) - Samsung M4070 Terno + {36fc9e60-c465-11cf-8056-444553540000} - Controller host Intel(R) USB 3.0 eXtensible - 1.0 (Microsoft) - Dispositivo USB composito - Generic USB Hub - Hub radice USB - Hub radice USB (USB 3.0) - Hub USB generico - Hub USB SuperSpeed generico - Mobile 5th Generation Intel(R) Core(TM) USB EHCI Controller - 9CA6 (driver 10.1.1.44) - Modulo scheda di rete Mobile Broadband USB + {4d36e966-e325-11ce-bfc1-08002be10318} - PC ACPI basato su x64 + {4d36e967-e325-11ce-bfc1-08002be10318} - Samsung SSD 860 EVO 500GB + {4d36e968-e325-11ce-bfc1-08002be10318} - Intel(R) HD Graphics 5500 (driver 20.19.15.5126) + {4d36e96a-e325-11ce-bfc1-08002be10318} - Controller AHCI SATA standard + {4d36e96b-e325-11ce-bfc1-08002be10318} - Standard 101/102-Key or Microsoft Natural PS/2 Keyboard for HP Hotkey Support (driver 11.0.8.1) + {4d36e96c-e325-11ce-bfc1-08002be10318} - Realtek High Definition Audio (driver 6.0.1.7561) + {4d36e96e-e325-11ce-bfc1-08002be10318} - Monitor generico Plug and Play + {4d36e96f-e325-11ce-bfc1-08002be10318} - Mouse compatibile HID - Synaptics SMBus TouchPad (driver 19.0.19.63) + {4d36e970-e325-11ce-bfc1-08002be10318} - Realtek PCIE CardReader (driver 10.0.10143.21278) + {4d36e972-e325-11ce-bfc1-08002be10318} - HP lt4112 Gobi 4G Module - Intel(R) Dual Band Wireless-AC 7265 (driver 18.33.14.3) - Intel(R) Ethernet Connection (3) I218-LM (driver 12.13.17.7) - Microsoft Kernel Debug Network Adapter - Microsoft Wi-Fi Direct Virtual Adapter - Microsoft Wi-Fi Direct Virtual Adapter #2 - TAP-Windows Adapter V9 (driver 9.24.6.601) - TAP-Windows Adapter V9 #2 (driver 9.24.6.601) - VirtualBox Host-Only Ethernet Adapter (driver 6.1.30.48432) - Wintun Userspace Tunnel (driver 0.8.0.0) + {4d36e979-e325-11ce-bfc1-08002be10318} - HP LaserJet MFP M129-M134 PCLmS (driver 24.94.1.7336) - Microsoft IPP Class Driver + {4d36e97b-e325-11ce-bfc1-08002be10318} - Controller spazi di archiviazione Microsoft + {4d36e97d-e325-11ce-bfc1-08002be10318} - Archiviazione volumi - Bus IO esteso - Bus Redirector dispositivi Desktop remoto - Complesso radice PCI Express - Controller di accesso diretto alla memoria (DMA) - Controller integrato compatibile ACPI Microsoft - Controller per High Definition Audio - Coperchio ACPI - Dispositivo legacy - Driver arbitraggio ricarica - Driver BIOS Microsoft System Management - Driver infrastruttura di virtualizzazione Hyper-V Microsoft - Driver rendering base Microsoft - Driver video base Microsoft - Enumeratore bus composito - Enumeratore bus radice UMBus - Enumeratore di dispositivi software Plug and Play - Enumeratore scheda di rete virtuale NDIS - Enumeratore unità virtuale Microsoft - HP Mobile Data Protection Sensor (driver 7.0.21.30155) - Interfaccia di gestione Microsoft Windows per ACPI - Mobile 5th Generation Intel(R) Core(TM) Host Bridge - OPI - 1604 (driver 10.1.1.44) - Mobile 5th Generation Intel(R) Core(TM) PCI Express Root Port #1 - 9C90 (driver 10.1.1.44) - Mobile 5th Generation Intel(R) Core(TM) PCI Express Root Port #2 - 9C92 (driver 10.1.1.44) - Mobile 5th Generation Intel(R) Core(TM) PCI Express Root Port #4 - 9C96 (driver 10.1.1.44) - Mobile 5th Generation Intel(R) Core(TM) Premium SKU LPC Controller - 9CC3 (driver 10.1.1.44) - Orologio di sistema CMOS a tempo reale - Programmable Interrupt Controller - Pulsante caratteristica ACPI fissa - Pulsante sospensione ACPI - Risorse scheda madre - Risorse scheda madre - Risorse scheda madre - Sistema compatibile ACPI Microsoft - Synaptics SMBus Driver (driver 19.0.19.63) - Timer di sistema - Timer eventi alta precisione - Zona termica ACPI - Zona termica ACPI - Zona termica ACPI - Zona termica ACPI - Zona termica ACPI - Zona termica ACPI + {50127dc3-0f36-415e-a6cc-4cb3be910b65} - Intel(R) Core(TM) i5-5300U CPU @ 2.30GHz - Intel(R) Core(TM) i5-5300U CPU @ 2.30GHz - Intel(R) Core(TM) i5-5300U CPU @ 2.30GHz - Intel(R) Core(TM) i5-5300U CPU @ 2.30GHz + {533c5b84-ec70-11d2-9505-00c04f79deaf} - Copia shadow volume generico - Copia shadow volume generico - Copia shadow volume generico - Copia shadow volume generico - Copia shadow volume generico + {53d29ef7-377c-4d14-864b-eb3a85769359} - Synaptics FP Sensors (WBF) (PID=003f) (driver 4.5.307.0) + {5c4c3332-344d-483c-8739-259e934c9cc8} - HP LAN/WLAN/WWAN Switching and Hotkey Service (driver 7.0.15.1) + {62f9c741-b25a-46ce-b54c-9bccce08b6f2} - Bluetooth - Cellulare - HP LaserJet MFP M130fw (FFC5B2) - Microsoft Device Association Root Enumerator - Microsoft Radio Device Enumeration Bus - Samsung C3060 Series (SEC8425196EEB0B) - Sintetizzatore Wavetable Microsoft GS - Wi-Fi - Windows.Devices.Sms.SmsDevice2 + {72631e54-78a4-11d0-bcf7-00aa00b7b32a} - Batteria compatibile con ACPI Microsoft - Batteria compatibile con ACPI Microsoft - Scheda AC Microsoft + {745a17a0-74d3-11d0-b6fe-00a0c90f57da} - Controlli radio wireless compatibili HID - Dispositivo di input USB - HP Wireless Button Driver (driver 2.1.4.1) + {c166523c-fe0c-4a94-a586-f1a80cfbbf3e} - Microfono (Realtek High Definition Audio) - Speakers/Headphones (Realtek High Definition Audio) + {ca3e7ab9-b4c3-4ae6-8251-579ef933890f} - HP HD Webcam (driver 5.0.8.29) + {d94ee5d8-d189-4994-83d2-f68d7d41b0e6} - Trusted Platform Module 1.2 + {e0cbf06c-cd8b-4647-bb8a-263b43f0f974} - Intel(R) Wireless Bluetooth(R) (driver 20.100.7.1) cpu registers: eax = 00000002 ebx = 03fa93e8 ecx = 00000000 edx = 00000000 esi = 040143c0 edi = 040143c0 eip = 013a807c esp = 0019f308 ebp = 0019f314 stack dump: 0019f308 c0 43 01 04 00 00 00 02 - 00 00 00 00 28 f3 19 00 .C..........(... 0019f318 8b 0c 47 01 53 f3 19 00 - c0 43 01 04 90 25 44 08 ..G.S....C...%D. 0019f328 54 f3 19 00 2f 58 5a 00 - 84 f3 19 00 18 b4 40 00 T.../XZ.......@. 0019f338 54 f3 19 00 bc 57 5a 00 - 01 00 00 00 00 00 00 00 T....WZ......... 0019f348 c0 43 01 04 8b a3 40 00 - 00 60 3a 00 a4 f3 19 00 .C....@..`:..... 0019f358 5a b1 5e 00 a8 f0 17 06 - ec b0 5e 00 08 c7 b1 06 Z.^.......^..... 0019f368 00 95 50 00 08 c7 b1 06 - a0 c1 fe 03 d2 fd 70 00 ..P...........p. 0019f378 00 00 00 00 e0 f3 19 00 - da 1a 71 00 b0 f3 19 00 ..........q..... 0019f388 e8 b1 40 00 a4 f3 19 00 - a8 f0 17 06 88 f4 19 00 ..@............. 0019f398 00 00 00 00 b0 ab fe 03 - a8 f0 17 01 e4 f3 19 00 ................ 0019f3a8 c8 1b 71 00 e4 f3 19 00 - bc f3 19 00 e6 1b 71 00 ..q...........q. 0019f3b8 e4 f3 19 00 20 f4 19 00 - 13 1c 71 00 e4 f3 19 00 .... .....q..... 0019f3c8 3c 1b 71 00 90 25 44 08 - e0 aa fe 03 04 00 00 00 <.q..%D......... 0019f3d8 a8 f0 17 06 8b a3 73 80 - a0 c1 fe 03 00 f4 19 00 ......s......... 0019f3e8 be 8c 72 00 90 25 44 08 - 6c 8c 72 00 c0 09 fe 03 ..r..%D.l.r..... 0019f3f8 8b a3 40 00 88 f4 19 00 - 88 f4 19 00 83 d0 72 00 ..@...........r. 0019f408 00 0f 9a 05 80 f4 19 00 - 16 b0 00 00 e2 0f 9a 05 ................ 0019f418 16 b0 00 00 8b c6 72 00 - a4 f5 19 00 95 c9 72 00 ......r.......r. 0019f428 80 f4 19 00 16 b0 00 00 - e2 0f 9a 05 26 08 09 00 ............&... 0019f438 4b 91 f0 68 64 00 00 00 - 00 00 00 00 18 f5 be 07 K..hd........... disassembling: [...] 013a806e mov [ebp-5], dl 013a8071 mov [ebp-4], eax 013a8074 1242 xor eax, eax 013a8076 mov al, [ebp-5] 013a8079 mov edx, [ebp-4] 013a807c > mov eax, [edx+eax*4+$d8] 013a8083 mov [ebp-$c], eax 013a8086 1243 mov eax, [ebp-$c] 013a8089 mov esp, ebp 013a808b pop ebp 013a808c ret