date/time          : 2018-06-29, 12:42:56, 53ms
computer name      : 
wts client name    : 
user name          : 
registered owner   : Windows User
operating system   : Windows 2012 R2 Tablet PC x64 build 9600
system language    : English
system up time     : 46 days 6 hours
program up time    : 4 days
processors         : 4x Intel(R) Xeon(R) CPU X7560 @ 2.27GHz
physical memory    : 2360/24576 MB (free/total)
free disk space    : (C:) 7.82 GB
display mode       : 1920x1080, 32 bit
process id         : $1594
allocated memory   : 68.22 MB
largest free block : 1.12 GB
executable         : bTray.exe
exec. date/time    : 2018-06-05 16:21
version            : 7.3.0.390
compiled with      : Delphi 10.2 Tokyo
bTray.exe.mad      : $001b5a48, $69394cc5, $866832bf
madExcept version  : 4.0.18
callstack crc      : $4cc6f02f, $3bd4f5d3, $3bd4f5d3
exception number   : 1
exception class    : EAccessViolation
exception message  : Access violation at address 00C82C2D in module 'bTray.exe'. Read of address 00000014.

main thread ($3544):
00c82c2d +009 bTray.exe            segment%296  public%55822
010c05e3 +05f bTray.exe            segment%614  public%74235
010c074a +076 bTray.exe            segment%614  public%74236
0163c46c +050 bTray.exe            segment%1078 public%99407
01b72d37 +027 bTray.exe            segment%1363 public%132509
004d006b +00f bTray.exe            segment%22   public%6078
00538822 +086 bTray.exe            segment%43   public%9512
004cfed7 +013 bTray.exe            segment%22   public%6064
0064c7db +093 bTray.exe            segment%74   public%15630
0064df3c +018 bTray.exe            segment%74   public%15694
0064f1ce +082 bTray.exe            segment%74   public%15743
0064f11d +01d bTray.exe            segment%74   public%15742
004d0dd0 +014 bTray.exe            segment%22   public%6123
77620664 +034 ntdll.dll                         KiUserCallbackDispatcher
74ef4d46 +016 USER32.dll                        TrackPopupMenu
0064f8fd +09d bTray.exe            segment%74   public%15754
010bbd81 +235 bTray.exe            segment%610  public%74145
004d0dd0 +014 bTray.exe            segment%22   public%6123
77620664 +034 ntdll.dll                         KiUserCallbackDispatcher
0736f8a8 +008 bResourceStrings.bpl System       TObject.Free
0124633c +0c0 bTray.exe            segment%724  public%80928
0163ddab +04b bTray.exe            segment%1079 public%99424
0736f8a8 +008 bResourceStrings.bpl System       TObject.Free
0163e0e6 +00e bTray.exe            segment%1079 public%99429
01781936 +022 bTray.exe            segment%1182 public%105975
01b76056 +1b2 bTray.exe            segment%1363 public%132559
010c00b6 +026 bTray.exe            segment%613  public%74228
004ccfc9 +125 bTray.exe            segment%22   public%5914
00667b73 +76b bTray.exe            segment%78   public%16231
004d0dd0 +014 bTray.exe            segment%22   public%6123
74eca6db +00b USER32.dll                        DispatchMessageW
00668533 +0f3 bTray.exe            segment%78   public%16252
00668576 +00a bTray.exe            segment%78   public%16254
006688a9 +0c9 bTray.exe            segment%78   public%16259
01bb4a18 +198 bTray.exe            segment%1898 public%133396
6e4d51e7 +067 gdiplus.dll                       GdipSaveImageToStream
76677c02 +022 KERNEL32.DLL                      BaseThreadInitThunk

thread $2854:
75072b7d +4d KERNELBASE.dll  SleepEx
7507104a +0a KERNELBASE.dll  Sleep
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $17c8:
75072b7d +4d KERNELBASE.dll  SleepEx
7507104a +0a KERNELBASE.dll  Sleep
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $10b8:
75072b7d +4d KERNELBASE.dll  SleepEx
7507104a +0a KERNELBASE.dll  Sleep
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $3064:
75072b7d +4d KERNELBASE.dll  SleepEx
7507104a +0a KERNELBASE.dll  Sleep
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $30d8:
75072b7d +4d KERNELBASE.dll  SleepEx
7507104a +0a KERNELBASE.dll  Sleep
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $340c:
75072b7d +4d KERNELBASE.dll  SleepEx
7507104a +0a KERNELBASE.dll  Sleep
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $1654:
75072b7d +4d KERNELBASE.dll  SleepEx
7507104a +0a KERNELBASE.dll  Sleep
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $2500:
75072b7d +4d KERNELBASE.dll  SleepEx
7507104a +0a KERNELBASE.dll  Sleep
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $336c:
75072cc1 +b1 KERNELBASE.dll  WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll  WaitForSingleObject
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $2ff0:
75072cc1 +b1 KERNELBASE.dll  WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll  WaitForSingleObject
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $26f0:
75072cc1 +b1 KERNELBASE.dll  WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll  WaitForSingleObject
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $13e8:
75072cc1 +b1 KERNELBASE.dll  WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll  WaitForSingleObject
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $1388:
75072cc1 +b1 KERNELBASE.dll  WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll  WaitForSingleObject
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $418:
75072cc1 +b1 KERNELBASE.dll  WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll  WaitForSingleObject
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $6c8:
75072cc1 +b1 KERNELBASE.dll  WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll  WaitForSingleObject
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $33f8:
75072cc1 +b1 KERNELBASE.dll  WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll  WaitForSingleObject
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $2b90:
75072cc1 +b1 KERNELBASE.dll  WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll  WaitForSingleObject
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $1b4c:
75072cc1 +b1 KERNELBASE.dll  WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll  WaitForSingleObject
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $2994:
75072cc1 +b1 KERNELBASE.dll  WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll  WaitForSingleObject
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $1d90:
75072cc1 +b1 KERNELBASE.dll  WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll  WaitForSingleObject
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $2e60:
75072cc1 +b1 KERNELBASE.dll  WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll  WaitForSingleObject
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $31e8:
75072cc1 +b1 KERNELBASE.dll  WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll  WaitForSingleObject
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $2d04:
75072cc1 +b1 KERNELBASE.dll  WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll  WaitForSingleObject
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $2228:
75072cc1 +b1 KERNELBASE.dll  WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll  WaitForSingleObject
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

thread $1580:
75072b7d +4d KERNELBASE.dll  SleepEx
7507104a +0a KERNELBASE.dll  Sleep
76677c02 +22 KERNEL32.DLL    BaseThreadInitThunk

Ugn Manager_TimerThread ($284):
75072cc1 +b1 KERNELBASE.dll             WaitForSingleObjectEx
75072bfd +0d KERNELBASE.dll             WaitForSingleObject
010bfe89 +15 bTray.exe      segment%613 public%74224
00c7d9d3 +2b bTray.exe      segment%295 public%55767
004cd12d +49 bTray.exe      segment%22  public%5915
00c7d8b9 +0d bTray.exe      segment%295 public%55765
00c7d91e +32 bTray.exe      segment%295 public%55766
76677c02 +22 KERNEL32.DLL               BaseThreadInitThunk
>> created by main thread ($3544) at:
010bffc7 +23 bTray.exe      segment%613 public%74226

thread $2b88:
00c7d8b9 +0d bTray.exe    segment%295 public%55765
00c7d91e +32 bTray.exe    segment%295 public%55766
76677c02 +22 KERNEL32.DLL             BaseThreadInitThunk
>> created by main thread ($3544) at:
76de3f05 +00 combase.dll

f_WaitTmr_TimerThread ($36c4):
75072cc1 +0b1 KERNELBASE.dll                   WaitForSingleObjectEx
75072bfd +00d KERNELBASE.dll                   WaitForSingleObject
004214b2 +002 bTray.exe            segment%12  public%1769
004215fb +01f bTray.exe            segment%12  public%1776
07370901 +065 bResourceStrings.bpl System      TMonitor.Wait
07370990 +020 bResourceStrings.bpl System      TMonitor.Wait
004cdb68 +140 bTray.exe            segment%22  public%5941
004cdc35 +04d bTray.exe            segment%22  public%5943
010bfec2 +04e bTray.exe            segment%613 public%74224
00c7d9d3 +02b bTray.exe            segment%295 public%55767
004cd12d +049 bTray.exe            segment%22  public%5915
00c7d8b9 +00d bTray.exe            segment%295 public%55765
00c7d91e +032 bTray.exe            segment%295 public%55766
76677c02 +022 KERNEL32.DLL                     BaseThreadInitThunk
>> created by main thread ($3544) at:
010bffc7 +023 bTray.exe            segment%613 public%74226

thread $2a28:
00c7d8b9 +00d bTray.exe    segment%295 public%55765
00c7d91e +032 bTray.exe    segment%295 public%55766
76677c02 +022 KERNEL32.DLL             BaseThreadInitThunk
>> created by main thread ($3544) at:
726e143a +23a netbios.dll              Netbios

thread $190:
76677c02 +22 KERNEL32.DLL  BaseThreadInitThunk

thread $2e40 (TTimerThread): <suspended>
010bffc7 +23 bTray.exe segment%613 public%74226

IpcComm Timer_TimerThread ($3018):
75072cc1 +0b1 KERNELBASE.dll                   WaitForSingleObjectEx
75072bfd +00d KERNELBASE.dll                   WaitForSingleObject
004214b2 +002 bTray.exe            segment%12  public%1769
004215fb +01f bTray.exe            segment%12  public%1776
07370901 +065 bResourceStrings.bpl System      TMonitor.Wait
07370990 +020 bResourceStrings.bpl System      TMonitor.Wait
004cdb68 +140 bTray.exe            segment%22  public%5941
004cdc35 +04d bTray.exe            segment%22  public%5943
010bfec2 +04e bTray.exe            segment%613 public%74224
00c7d9d3 +02b bTray.exe            segment%295 public%55767
004cd12d +049 bTray.exe            segment%22  public%5915
00c7d8b9 +00d bTray.exe            segment%295 public%55765
00c7d91e +032 bTray.exe            segment%295 public%55766
76677c02 +022 KERNEL32.DLL                     BaseThreadInitThunk
>> created by main thread ($3544) at:
010bffc7 +023 bTray.exe            segment%613 public%74226

modules:
00400000 bTray.exe                   7.3.0.390           C:\Program Files (x86)\Softland\Backup4all 7
07360000 bResourceStrings.bpl        1.0.0.0             C:\Program Files (x86)\Softland\Backup4all 7
09760000 libeay32.dll                1.0.1.7             C:\Program Files (x86)\Softland\Backup4all 7
098a0000 ssleay32.dll                1.0.1.7             C:\Program Files (x86)\Softland\Backup4all 7
10000000 AES.DLL                     1.0.0.1             C:\Program Files (x86)\Softland\Backup4all 7
58210000 StarBurn.dll                15.7.1.2339         C:\Program Files (x86)\Softland\Backup4all 7
5f550000 webio.dll                   6.3.9600.17415      C:\Windows\SYSTEM32
5f630000 LINKINFO.dll                6.3.9600.17415      C:\Windows\SYSTEM32
5fe70000 davclnt.dll                 6.3.9600.17923      C:\Windows\System32
5fe90000 ntlanman.dll                6.3.9600.17415      C:\Windows\System32
5feb0000 NetworkExplorer.dll         6.3.9600.17415      C:\Windows\system32
60860000 DAVHLPR.dll                 6.3.9600.17415      C:\Windows\System32
60870000 drprov.dll                  6.3.9600.17415      C:\Windows\System32
608c0000 ondemandconnroutehelper.dll 6.3.9600.17415      C:\Windows\SYSTEM32
61e00000 sqlite3.dll                 3.19.3.0            C:\Program Files (x86)\Softland\Backup4all 7
62640000 ncryptsslp.dll              6.3.9600.18377      C:\Windows\system32
62700000 schannel.dll                6.3.9600.18970      C:\Windows\SYSTEM32
62820000 ntshrui.dll                 6.3.9600.18458      C:\Windows\SYSTEM32
6d570000 urlmon.dll                  11.0.9600.19003     C:\Windows\SYSTEM32
6e3d0000 taskschd.dll                6.3.9600.17415      C:\Windows\SYSTEM32
6e4a0000 gdiplus.dll                 6.3.9600.18790      C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9600.18790_none_dae0e7de5bc4763c
6e720000 wpnapps.dll                 6.3.9600.17415      C:\Windows\System32
6e7f0000 wbemdisp.dll                6.3.9600.17415      C:\Windows\system32\wbem
6e830000 dssenh.dll                  6.3.9600.17415      C:\Windows\system32
6e860000 Rstrtmgr.dll                6.3.9600.17415      C:\Windows\SYSTEM32
6e890000 Credui.dll                  6.3.9600.17415      C:\Windows\SYSTEM32
6e8c0000 sptdintf.dll                2.2.0.0             C:\Program Files (x86)\Softland\Backup4all 7
6e8e0000 CRYPTUI.DLL                 6.3.9600.17415      C:\Windows\SYSTEM32
6ea40000 tiptsf.dll                  6.3.9600.17415      C:\Program Files (x86)\Common Files\microsoft shared\ink
6eb00000 dwmapi.dll                  6.3.9600.17415      C:\Windows\system32
6eb80000 msimg32.dll                 6.3.9600.17415      C:\Windows\SYSTEM32
6eb90000 NTASN1.dll                  6.3.9600.17415      C:\Windows\SYSTEM32
6ebc0000 ncrypt.dll                  6.3.9600.18970      C:\Windows\SYSTEM32
6ec10000 olepro32.dll                6.3.9600.18508      C:\Windows\SYSTEM32
6ec30000 oleacc.dll                  7.2.9600.17415      C:\Windows\SYSTEM32
6ec80000 iertutil.dll                11.0.9600.19003     C:\Windows\SYSTEM32
6eec0000 wininet.dll                 11.0.9600.19003     C:\Windows\SYSTEM32
6f190000 sxs.dll                     6.3.9600.17415      C:\Windows\SYSTEM32
6f530000 gpapi.dll                   6.3.9600.18339      C:\Windows\SYSTEM32
6f550000 cryptnet.dll                6.3.9600.18878      C:\Windows\SYSTEM32
6f610000 propsys.dll                 7.0.9600.17415      C:\Windows\system32
6fc00000 winrnr.dll                  6.3.9600.17415      C:\Windows\System32
6fc10000 NLAapi.dll                  6.3.9600.18895      C:\Windows\system32
6fc30000 napinsp.dll                 6.3.9600.17415      C:\Windows\system32
6ffa0000 fastprox.dll                6.3.9600.18946      C:\Windows\system32\wbem
70070000 wbemsvc.dll                 6.3.9600.17415      C:\Windows\system32\wbem
701d0000 msxml6.dll                  6.30.9600.18895     C:\Windows\SYSTEM32
703f0000 security.dll                6.3.9600.16384      C:\Windows\SYSTEM32
71160000 fwpuclnt.dll                6.3.9600.18229      C:\Windows\System32
72480000 wbemprox.dll                6.3.9600.17415      C:\Windows\system32\wbem
72490000 wbemcomn.dll                6.3.9600.17415      C:\Windows\SYSTEM32
72500000 wmiutils.dll                6.3.9600.17415      C:\Windows\system32\wbem
725a0000 uxtheme.dll                 6.3.9600.18835      C:\Windows\system32
72690000 WINSTA.dll                  6.3.9600.17415      C:\Windows\SYSTEM32
726e0000 netbios.dll                 6.3.9600.17415      C:\Windows\SYSTEM32
726f0000 oledlg.dll                  6.3.9600.17415      C:\Windows\SYSTEM32
72710000 FaultRep.dll                6.3.9600.17550      C:\Windows\SYSTEM32
72770000 cscapi.dll                  6.3.9600.17415      C:\Windows\SYSTEM32
72880000 DEVOBJ.dll                  6.3.9600.17415      C:\Windows\SYSTEM32
728b0000 WINMMBASE.dll               6.3.9600.17415      C:\Windows\SYSTEM32
728e0000 winmm.dll                   6.3.9600.17415      C:\Windows\SYSTEM32
72910000 winspool.drv                6.3.9600.18467      C:\Windows\SYSTEM32
73070000 comctl32.dll                6.10.9600.18006     C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.18006_none_a9ec6aab013aafee
73560000 MSVCR90.dll                 9.0.30729.8387      C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.8387_none_5094ca96bcb6b2bb
738f0000 mpr.dll                     6.3.9600.17415      C:\Windows\SYSTEM32
73aa0000 version.dll                 6.3.9600.17415      C:\Windows\SYSTEM32
73ab0000 apphelp.dll                 6.3.9600.17415      C:\Windows\SYSTEM32
73be0000 rasadhlp.dll                6.3.9600.17415      C:\Windows\System32
73bf0000 DNSAPI.dll                  6.3.9600.18817      C:\Windows\SYSTEM32
73c70000 dhcpcsvc.DLL                6.3.9600.17415      C:\Windows\SYSTEM32
73c90000 dhcpcsvc6.DLL               6.3.9600.17415      C:\Windows\SYSTEM32
73cb0000 mswsock.dll                 6.3.9600.18340      C:\Windows\system32
73d00000 WINNSI.DLL                  6.3.9600.17415      C:\Windows\SYSTEM32
73d10000 iphlpapi.dll                6.3.9600.18264      C:\Windows\SYSTEM32
741c0000 kernel.appcore.dll          6.3.9600.17415      C:\Windows\SYSTEM32
741d0000 ntmarta.dll                 6.3.9600.17415      C:\Windows\SYSTEM32
74200000 SHCORE.DLL                  6.3.9600.17666      C:\Windows\SYSTEM32
742e0000 bcrypt.dll                  6.3.9600.18541      C:\Windows\SYSTEM32
74300000 rsaenh.dll                  6.3.9600.17415      C:\Windows\system32
74330000 CRYPTSP.dll                 6.3.9600.17415      C:\Windows\SYSTEM32
74350000 wsock32.dll                 6.3.9600.17415      C:\Windows\SYSTEM32
74620000 profapi.dll                 6.3.9600.17415      C:\Windows\SYSTEM32
74630000 wkscli.dll                  6.3.9600.17415      C:\Windows\SYSTEM32
74650000 srvcli.dll                  6.3.9600.17415      C:\Windows\SYSTEM32
74670000 netutils.dll                6.3.9600.17415      C:\Windows\SYSTEM32
74690000 winhttp.dll                 6.3.9600.18895      C:\Windows\SYSTEM32
74920000 XmlLite.dll                 6.3.9600.17415      C:\Windows\SYSTEM32
74950000 wtsapi32.dll                6.3.9600.17415      C:\Windows\SYSTEM32
74960000 USERENV.dll                 6.3.9600.17415      C:\Windows\SYSTEM32
74d30000 SECUR32.DLL                 6.3.9600.17415      C:\Windows\SYSTEM32
74d40000 netapi32.dll                6.3.9600.17415      C:\Windows\SYSTEM32
74d60000 bcryptPrimitives.dll        6.3.9600.18895      C:\Windows\SYSTEM32
74dc0000 CRYPTBASE.dll               6.3.9600.17415      C:\Windows\SYSTEM32
74e70000 sechost.dll                 6.3.9600.17734      C:\Windows\SYSTEM32
74ec0000 USER32.dll                  6.3.9600.18535      C:\Windows\SYSTEM32
75020000 WS2_32.dll                  6.3.9600.18340      C:\Windows\SYSTEM32
75070000 KERNELBASE.dll              6.3.9600.18938      C:\Windows\SYSTEM32
75150000 NSI.dll                     6.3.9600.17415      C:\Windows\SYSTEM32
75160000 IMAGEHLP.DLL                6.3.9600.17415      C:\Windows\SYSTEM32
751e0000 MSCTF.dll                   6.3.9600.18819      C:\Windows\SYSTEM32
75300000 WINTRUST.dll                6.3.9600.18508      C:\Windows\SYSTEM32
75340000 SHELL32.dll                 6.3.9600.18895      C:\Windows\SYSTEM32
76600000 WLDAP32.dll                 6.3.9600.18783      C:\Windows\SYSTEM32
76660000 KERNEL32.DLL                6.3.9600.17415      C:\Windows\SYSTEM32
767a0000 RPCRT4.dll                  6.3.9600.18941      C:\Windows\SYSTEM32
76860000 MSASN1.dll                  6.3.9600.17415      C:\Windows\SYSTEM32
76880000 SETUPAPI.dll                6.3.9600.17415      C:\Windows\SYSTEM32
76a40000 crypt32.dll                 6.3.9600.18653      C:\Windows\SYSTEM32
76bd0000 cfgmgr32.dll                6.3.9600.17415      C:\Windows\SYSTEM32
76c10000 SspiCli.dll                 6.3.9600.17415      C:\Windows\SYSTEM32
76c30000 oleaut32.dll                6.3.9600.19003      C:\Windows\SYSTEM32
76cd0000 msvcrt.dll                  7.0.9600.17415      C:\Windows\SYSTEM32
76da0000 combase.dll                 6.3.9600.18895      C:\Windows\SYSTEM32
76f20000 ADVAPI32.dll                6.3.9600.18895      C:\Windows\SYSTEM32
76fa0000 IMM32.DLL                   6.3.9600.17415      C:\Windows\system32
77140000 comdlg32.dll                6.3.9600.17415      C:\Windows\SYSTEM32
771e0000 GDI32.dll                   6.3.9600.18818      C:\Windows\SYSTEM32
772f0000 ole32.dll                   6.3.9600.18895      C:\Windows\SYSTEM32
77420000 clbcatq.dll                 2001.12.10530.17415 C:\Windows\SYSTEM32
774c0000 shlwapi.dll                 6.3.9600.17415      C:\Windows\SYSTEM32
775e0000 ntdll.dll                   6.3.9600.18895      C:\Windows\SYSTEM32

processes:
0000 Idle                         0  0   0
0004 System                       0  0   0
00f8 smss.exe                     0  0   0
0158 csrss.exe                    0  0   0
0194 wininit.exe                  0  0   0
01ec services.exe                 0  0   0
01f4 lsass.exe                    0  0   0
0238 svchost.exe                  0  0   0
0264 svchost.exe                  0  0   0
02c4 svchost.exe                  0  0   0
02e8 kavfs.exe                    0  0   0
037c svchost.exe                  0  0   0
03a4 kavfswp.exe                  0  0   0
03ac svchost.exe                  0  0   0
03f4 svchost.exe                  0  0   0
00d0 conhost.exe                  0  0   0
03b8 svchost.exe                  0  0   0
0488 spoolsv.exe                  0  0   0
04e8 kavfswp.exe                  0  0   0
04f0 conhost.exe                  0  0   0
054c VisionAgentService.exe       0  0   0
0560 svchost.exe                  0  0   0
0568 VAgent-NF4.exe               0  0   0
057c conhost.exe                  0  0   0
0604 cvd.exe                      0  0   0
063c klnagent.exe                 0  0   0
065c msmdsrv.exe                  0  0   0   normal
06e8 sqlservr.exe                 0  0   0   normal
07cc sqlservr.exe                 0  0   0   normal
0810 nimbus.exe                   0  0   0
0818 conhost.exe                  0  0   0
0838 controller.exe               0  0   0
08a0 ReportingServicesService.exe 0  0   0   normal
0904 snmp.exe                     0  0   0
0920 SQLBackupMaster.Service.exe  0  0   0
0928 snmp.exe                     0  0   0
0930 conhost.exe                  0  0   0
098c sqlbrowser.exe               0  0   0
0a00 sqlceip.exe                  0  0   0   below normal
0a2c sqlwriter.exe                0  0   0
0a44 sysaxservd.exe               0  0   0
0aec svchost.exe                  0  0   0
0afc vmtoolsd.exe                 0  0   0
0b4c WmiApSrv.exe                 0  0   0
0b64 EvMgrC.exe                   0  0   0
0b80 GXHSMService.exe             0  0   0
0c74 SQLAGENT.EXE                 0  0   0   normal
0c90 conhost.exe                  0  0   0
0e94 Launchpad.exe                0  0   0   normal
0dd4 hdb.exe                      0  0   0
0d5c cdm.exe                      0  0   0
1064 fdlauncher.exe               0  0   0   normal
1078 fdhost.exe                   0  0   0   normal
1080 conhost.exe                  0  0   0
10c8 fdlauncher.exe               0  0   0   normal
1154 svchost.exe                  0  0   0
1184 svchost.exe                  0  0   0
1298 WUDFHost.exe                 0  0   0
12bc msdtc.exe                    0  0   0
12c8 fdhost.exe                   0  0   0   normal
12d0 conhost.exe                  0  0   0
15ec svchost.exe                  0  0   0
1930 svchost.exe                  0  0   0
067c csrss.exe                    3  0   0
18f8 winlogon.exe                 3  0   0
143c dwm.exe                      3  0   0
0f00 SearchIndexer.exe            0  0   0
155c armsvc.exe                   0  0   0
11b4 csrss.exe                    9  0   0
0fcc winlogon.exe                 9  0   0
17a4 dwm.exe                      9  0   0
1290 taskhostex.exe               9  0   0   normal
1470 rdpclip.exe                  9  0   0   normal
01e8 rdpinput.exe                 9  0   0   normal
14fc explorer.exe                 9  0   0   normal
150c TabTip.exe                   9  0   0   high
1c04 TabTip32.exe                 9  0   0   normal       C:\Program Files (x86)\Common Files\Microsoft Shared\Ink
1de0 kavtray.exe                  9  0   0   normal       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security 10 for Windows Server
0618 csrss.exe                    11 0   0
1970 winlogon.exe                 11 0   0
1570 dwm.exe                      11 0   0
2030 taskhostex.exe               11 0   0   normal
205c rdpclip.exe                  11 0   0   normal
20f4 explorer.exe                 11 0   0   normal
23e0 kavtray.exe                  11 0   0   normal       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security 10 for Windows Server
1454 Ssms.exe                     9  0   0   normal       C:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\ManagementStudio
1a74 csrss.exe                    13 0   0
2510 winlogon.exe                 13 0   0
1adc dwm.exe                      13 0   0
0c68 taskhostex.exe               13 0   0   normal
1c84 rdpclip.exe                  13 0   0   normal
271c explorer.exe                 13 0   0   normal
1e54 kavtray.exe                  13 0   0   normal       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security 10 for Windows Server
1b90 csrss.exe                    17 0   0
10d8 winlogon.exe                 17 0   0
0dec dwm.exe                      17 0   0
1b94 taskhostex.exe               17 9   11  normal
185c rdpclip.exe                  17 11  31  normal
2050 explorer.exe                 17 795 464 normal
0aa0 rdpinput.exe                 17 9   5   normal
2770 TabTip.exe                   17 33  33  high
176c TabTip32.exe                 17 4   6   normal       C:\Program Files (x86)\Common Files\Microsoft Shared\Ink
1a80 kavtray.exe                  17 13  7   normal       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security 10 for Windows Server
1870 csrss.exe                    18 0   0
1a14 winlogon.exe                 18 0   0
0804 dwm.exe                      18 0   0
1e20 taskhostex.exe               18 0   0   normal
13f8 rdpclip.exe                  18 0   0   normal
0338 rdpinput.exe                 18 0   0   normal
1b0c explorer.exe                 18 0   0   normal
20bc kavtray.exe                  18 0   0   normal       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security 10 for Windows Server
15b8 winrshost.exe                0  0   0
2374 conhost.exe                  0  0   0
1cd4 csrss.exe                    26 0   0
0b40 winlogon.exe                 26 0   0
19fc dwm.exe                      26 0   0
204c taskhostex.exe               26 0   0   normal
27ec rdpclip.exe                  26 0   0   normal
25d8 explorer.exe                 26 0   0   normal
23cc kavtray.exe                  26 0   0   normal       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security 10 for Windows Server
1e78 Ssms.exe                     26 0   0   normal       C:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\ManagementStudio
2730 csrss.exe                    28 0   0
2174 winlogon.exe                 28 0   0
208c dwm.exe                      28 0   0
2478 taskhostex.exe               28 0   0   normal
0fb8 rdpclip.exe                  28 0   0   normal
2284 explorer.exe                 28 0   0   normal
2c70 vmtoolsd.exe                 28 0   0   normal
238c kavtray.exe                  28 0   0   normal       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security 10 for Windows Server
2d44 mmc.exe                      28 0   0   normal
1550 Ssms.exe                     28 0   0   normal       C:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\ManagementStudio
018c Ssms.exe                     18 0   0   normal       C:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\ManagementStudio
3758 Ssms.exe                     18 0   0   normal       C:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\ManagementStudio
377c WerFault.exe                 18 0   0   normal       C:\Windows\SysWOW64
3524 VscSrv2008x64.exe            17 9   2   normal
3454 conhost.exe                  17 22  8   normal
1b58 VSSVC.exe                    0  0   0
1958 svchost.exe                  0  0   0
2520 HelpLibAgent.exe             17 27  20  normal
31b4 spooler.exe                  0  0   0
2ca4 Ssms.exe                     17 554 272 normal       C:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\ManagementStudio
1594 bTray.exe                    17 357 113 normal       C:\Program Files (x86)\Softland\Backup4all 7
0e9c Taskmgr.exe                  17 758 288 normal
1f58 mmc.exe                      17 174 101 normal
1d40 Backup4all.EXE               17 235 80  normal       C:\Program Files (x86)\Softland\Backup4all 7
30b0 csrss.exe                    29 0   0
1ba4 winlogon.exe                 29 0   0
20d8 dwm.exe                      29 0   0
349c taskhostex.exe               29 0   0   normal
2870 rdpclip.exe                  29 0   0   normal
3738 explorer.exe                 29 0   0   normal
07a4 vmtoolsd.exe                 29 0   0   normal
30f4 kavtray.exe                  29 0   0   normal       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security 10 for Windows Server
2c74 Ssms.exe                     29 0   0   normal       C:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\ManagementStudio
0290 taskhostex.exe               3  0   0   normal
0a7c explorer.exe                 3  0   0   normal
37c0 vmtoolsd.exe                 3  0   0   normal
27fc kavtray.exe                  3  0   0   normal       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security 10 for Windows Server
1494 Ssms.exe                     11 0   0   normal       C:\Program Files (x86)\Microsoft SQL Server\110\Tools\Binn\ManagementStudio
1198 csrss.exe                    31 0   0
1a58 winlogon.exe                 31 0   0
18dc LogonUI.exe                  31 0   0
33e0 dwm.exe                      31 0   0
28fc WmiPrvSE.exe                 0  0   0
2224 bService.exe                 0  0   0

hardware:
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
  - Fax (redirected 17)
  - Microsoft XPS Document Writer
  - Microsoft XPS Document Writer (redirected 17)
  - Root Print Queue
+ {4d36e965-e325-11ce-bfc1-08002be10318}
  - NECVMWar VMware IDE CDR10 ATA Device
+ {4d36e966-e325-11ce-bfc1-08002be10318}
  - ACPI x64-based PC
+ {4d36e967-e325-11ce-bfc1-08002be10318}
  - Microsoft Virtual Disk
  - VMware Virtual disk SCSI Disk Device
  - VMware Virtual disk SCSI Disk Device
  - VMware Virtual disk SCSI Disk Device
+ {4d36e968-e325-11ce-bfc1-08002be10318}
  - VMware SVGA 3D (driver 7.14.1.2021)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
  - ATA Channel 0
  - ATA Channel 1
  - Intel(R) 82371AB/EB PCI Bus Master IDE Controller
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
  - Remote Desktop Keyboard Device
  - Standard PS/2 Keyboard
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
  - Generic Non-PnP Monitor
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
  - Remote Desktop Mouse Device
  - VMware Pointing Device (driver 12.5.2.0)
+ {4d36e972-e325-11ce-bfc1-08002be10318}
  - Microsoft ISATAP Adapter
  - Microsoft Kernel Debug Network Adapter
  - vmxnet3 Ethernet Adapter (driver 1.5.2.0)
  - WAN Miniport (IKEv2)
  - WAN Miniport (IP)
  - WAN Miniport (IPv6)
  - WAN Miniport (L2TP)
  - WAN Miniport (Network Monitor)
  - WAN Miniport (PPPOE)
  - WAN Miniport (PPTP)
  - WAN Miniport (SSTP)
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
  - LSI Adapter, SAS 3000 series, 8-port with 1068 (driver 1.34.3.82)
  - Microsoft Storage Spaces Controller
  - Microsoft VHD Loopback Controller
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
  - ACPI Fixed Feature Button
  - Composite Bus Enumerator
  - Direct memory access controller
  - EISA programmable interrupt controller
  - Generic Bus
  - High precision event timer
  - Intel 82371AB/EB PCI to ISA bridge (ISA mode)
  - Intel 82443BX Pentium(R) II Processor to PCI Bridge
  - Microsoft ACPI-Compliant System
  - Microsoft Basic Display Driver
  - Microsoft Basic Render Driver
  - Microsoft Hyper-V Generation Counter
  - Microsoft System Management BIOS Driver
  - Microsoft Virtual Drive Enumerator
  - Motherboard resources
  - Motherboard resources
  - NDIS Virtual Network Adapter Enumerator
  - PCI bus
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI Express standard Root Port
  - PCI standard PCI-to-PCI bridge
  - PCI standard PCI-to-PCI bridge
  - Plug and Play Software Device Enumerator
  - Remote Desktop Device Redirector Bus
  - System CMOS/real time clock
  - System speaker
  - System timer
  - UMBus Enumerator
  - UMBus Root Bus Enumerator
  - VMware VMCI Bus Device (driver 9.3.51.0)
  - VMware VMCI Host Device (driver 9.3.51.0)
  - Volume Manager
+ {50127dc3-0f36-415e-a6cc-4cb3be910b65}
  - Intel(R) Xeon(R) CPU           X7560  @ 2.27GHz
  - Intel(R) Xeon(R) CPU           X7560  @ 2.27GHz
  - Intel(R) Xeon(R) CPU           X7560  @ 2.27GHz
  - Intel(R) Xeon(R) CPU           X7560  @ 2.27GHz
+ {533c5b84-ec70-11d2-9505-00c04f79deaf}
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
  - Generic volume shadow copy
+ {62f9c741-b25a-46ce-b54c-9bccce08b6f2}
  - Microsoft IPv4 IPv6 Transition Adapter Bus
  - Smart Card Device Enumeration Bus
+ {72631e54-78a4-11d0-bcf7-00aa00b7b32a}
  - Microsoft AC Adapter
+ {eec5ad98-8080-425f-922a-dabf3de3f69a}
  - D:\
  - E:\

cpu registers:
eax = 07fe80d0
ebx = 07fe80d0
ecx = 00c8290c
edx = 00000000
esi = 00000000
edi = 00000000
eip = 00c82c2d
esp = 0018dbc8
ebp = 0018dc08

stack dump:
0018dbc8  00 00 00 00 00 00 00 00 - b0 c1 ff 07 e5 05 0c 01  ................
0018dbd8  20 dc 18 00 14 0e 37 07 - 08 dc 18 00 00 00 00 00   .....7.........
0018dbe8  00 00 00 00 11 1d 2c 08 - 00 00 00 00 00 00 00 00  ......,.........
0018dbf8  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 11  ................
0018dc08  4c dc 18 00 4f 07 0c 01 - 00 00 00 00 00 00 00 00  L...O...........
0018dc18  00 00 00 00 c0 81 fe 07 - 2c dc 18 00 14 0e 37 07  ........,.....7.
0018dc28  4c dc 18 00 64 dc 18 00 - 14 0e 37 07 4c dc 18 00  L...d.....7.L...
0018dc38  80 ba fb 07 d8 85 4f 00 - 00 00 00 00 00 00 00 00  ......O.........
0018dc48  a0 a3 5e 0a 80 dc 18 00 - 71 c4 63 01 00 00 00 00  ..^.....q.c.....
0018dc58  00 00 00 00 00 00 00 00 - 00 00 00 00 cc dc 18 00  ................
0018dc68  14 0e 37 07 80 dc 18 00 - d8 85 4f 00 30 00 2b 0a  ..7.......O.0.+.
0018dc78  00 00 00 00 00 00 00 00 - 1c dd 18 00 3c 2d b7 01  ............<-..
0018dc88  80 ba fb 07 6e 00 4d 00 - 01 00 00 00 27 88 53 00  ....n.M.....'.S.
0018dc98  00 00 00 00 9c 87 53 00 - 80 73 2e 08 dc fe 4c 00  ......S..s....L.
0018dca8  80 73 2e 08 c0 c2 fb 07 - de c7 64 00 c0 c2 fb 07  .s........d.....
0018dcb8  00 00 00 00 3f df 64 00 - 48 dd 18 00 01 00 00 00  ....?.d.H.......
0018dcc8  d3 f1 64 00 24 dd 18 00 - 14 0e 37 07 1c dd 18 00  ..d.$.....7.....
0018dcd8  2c 0f 4e 07 11 01 00 00 - 00 00 00 00 00 00 00 00  ,.N.............
0018dce8  1b d9 12 28 68 dd 18 00 - 11 01 00 00 78 dd 18 00  ...(h.......x...
0018dcf8  00 00 00 00 1b d9 12 28 - e8 dc 18 00 a7 d3 33 36  .......(......36

disassembling:
[...]
00c82c25   push    esi
00c82c26   push    edi
00c82c27   mov     esi, edx
00c82c29   mov     ebx, eax
00c82c2b   mov     edi, esi
00c82c2d > mov     eax, [edi+$14]
00c82c30   mov     [ebx+$14], eax
00c82c33   mov     eax, [edi+4]
00c82c36   mov     [ebx+4], eax
00c82c39   lea     eax, [ebx+8]
00c82c3c   mov     edx, [edi+8]
[...]

