date/time         : 2008-12-31, 18:48:31, 435ms
computer name     : TYREL-PC
user name         : Tyrel <admin>
registered owner  : Microsoft / Microsoft
operating system  : Windows Vista x64 Service Pack 1 build 6001
system language   : Hungarian
system up time    : 31 minutes 37 seconds
program up time   : 6 seconds
processors        : 2x Intel(R) Core(TM)2 Duo CPU E8200 @ 2.66GHz
physical memory   : 1006/2046 MB (free/total)
free disk space   : (C:) 7,46 GB (E:) 26,10 GB
display mode      : 800x600, 32 bit
process id        : $12f4
allocated memory  : 55,56 MB
executable        : Armada2.exe
current module    : FleetOpsHook.dll
module date/time  : 2008-12-17 22:53
compiled with     : Delphi 2006/07
madExcept version : 3.0h
callstack crc     : $6bf3dec5, $73eb8fe0, $73eb8fe0
exception number  : 1
exception class   : EAccessViolation
exception message : Access violation at address 6BF3DEC5 in module 'atiumdag.dll'. Read of address 00000010.

main thread ($12f8):
6bf3dec5 +000 atiumdag.dll
5aa0d684 +090 FleetOpsHook.dll Direct3D8Hook          62 +19 Direct3D8_CreateDevice_Callback
006237ab +1db Armada2.exe                                    ST3D_DeviceDirectX8.obj
006233d6 +016 Armada2.exe                                    ST3D_DeviceDirectX8.obj
006215c3 +063 Armada2.exe                                    ST3D_Device.obj
5a805a87 +067 FleetOpsHook.dll System                103  +0 @LStrCatN
5a9fcf99 +029 FleetOpsHook.dll FleetOpsFunctionsHook 729  +3 DebugException_Execute_Callback
00476042 +0d2 Armada2.exe                                    ArmadaWin.obj
76f4e3f1 +00c kernel32.dll                                   BaseThreadInitThunk

thread $13c0:
76f4e3f1 +c kernel32.dll  BaseThreadInitThunk

thread $7c8:
76f4e3f1 +c kernel32.dll  BaseThreadInitThunk

thread $da0:
76f4e3f1 +c kernel32.dll  BaseThreadInitThunk

thread $db8:
778da747 +38 ntdll.dll     EtwpNotificationThread
76f4e3f1 +0c kernel32.dll  BaseThreadInitThunk

modules:
00020000 d3d8.dll                                      E:\Star Trek Armada II Fleet Operations\data
001b0000 NetworkManager.dll                            E:\Star Trek Armada II Fleet Operations\data
00400000 Armada2.exe                43.0.0.0           E:\Star Trek Armada II Fleet Operations\data
042d0000 yskbhk.DLL                 1.0.0.1            C:\Program Files (x86)\SAMSUNG\Samsung Multimedia Keyboard
07170000 Amhooker.dll                                  C:\Windows\system32
10000000 Win2kDisableTaskSwitch.dll                    E:\Star Trek Armada II Fleet Operations\data
30000000 binkw32.dll                1.5.21.0           E:\Star Trek Armada II Fleet Operations\data
5a800000 FleetOpsHook.dll                              E:\Star Trek Armada II Fleet Operations
6bf30000 atiumdag.dll               7.14.10.630        C:\Windows\system32
6cf40000 atiumdva.dll               7.14.10.208        C:\Windows\system32
6d3e0000 dbghelp.dll                6.0.6001.18000     C:\Windows\syswow64
6da70000 d3d8.dll                   6.0.6001.18000     C:\Windows\system32
6db80000 AcGenral.DLL               6.0.6001.18000     C:\Windows\AppPatch
6e7a0000 ShimEng.dll                6.0.6000.16386     C:\Windows\system32
6fdd0000 AVIFIL32.dll               6.0.6001.18000     C:\Windows\system32
70a60000 d3d8thk.dll                6.0.6000.16386     C:\Windows\system32
70a80000 MPR.dll                    6.0.6001.18000     C:\Windows\system32
71830000 WindowsCodecs.dll          6.0.6001.18000     C:\Windows\system32
72850000 IconCodecService.dll       6.0.6000.16386     C:\Windows\system32
728a0000 apphelp.dll                6.0.6001.18000     C:\Windows\system32
729b0000 PROPSYS.dll                6.0.6001.18000     C:\Windows\system32
73030000 sfc.dll                    6.0.6000.16386     C:\Windows\system32
73040000 sfc_os.DLL                 6.0.6001.18000     C:\Windows\system32
73070000 dwmapi.dll                 6.0.6001.18000     C:\Windows\system32
73440000 DSOUND.dll                 6.0.6001.18000     C:\Windows\system32
73600000 MSVFW32.dll                6.0.6001.18000     C:\Windows\system32
73920000 POWRPROF.dll               6.0.6001.18000     C:\Windows\system32
73b10000 MSACM32.dll                6.0.6001.18000     C:\Windows\system32
73c00000 UxTheme.dll                6.0.6001.18000     C:\Windows\system32
73e50000 USERENV.dll                6.0.6001.18000     C:\Windows\system32
74430000 NETAPI32.dll               6.0.6001.18000     C:\Windows\system32
75440000 VERSION.dll                6.0.6001.18000     C:\Windows\system32
75460000 wsock32.dll                6.0.6001.18000     C:\Windows\system32
75470000 COMCTL32.dll               6.10.6001.18000    C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc
756b0000 OLEACC.dll                 4.2.5406.0         C:\Windows\system32
756f0000 WINMM.dll                  6.0.6001.18000     C:\Windows\system32
759d0000 Secur32.dll                6.0.6001.18000     C:\Windows\syswow64
75a30000 IMAGEHLP.dll               6.0.6001.18000     C:\Windows\syswow64
75a60000 SETUPAPI.dll               6.0.6001.18000     C:\Windows\syswow64
75bf0000 SHELL32.dll                6.0.6001.18000     C:\Windows\syswow64
76710000 ADVAPI32.dll               6.0.6001.18000     C:\Windows\syswow64
76900000 GDI32.dll                  6.0.6001.18000     C:\Windows\syswow64
76990000 comdlg32.dll               6.0.6001.18000     C:\Windows\syswow64
76a10000 USER32.dll                 6.0.6001.18000     C:\Windows\syswow64
76ae0000 OLEAUT32.dll               6.0.6001.18000     C:\Windows\syswow64
76b70000 MSCTF.dll                  6.0.6001.18000     C:\Windows\syswow64
76c40000 iertutil.dll               7.0.6001.18000     C:\Windows\syswow64
76c90000 IMM32.dll                  6.0.6001.18000     C:\Windows\syswow64
76cf0000 RPCRT4.dll                 6.0.6001.18000     C:\Windows\syswow64
76de0000 msvcrt.dll                 7.0.6001.18000     C:\Windows\syswow64
76e90000 WS2_32.dll                 6.0.6001.18000     C:\Windows\syswow64
76ec0000 kernel32.dll               6.0.6001.18000     C:\Windows\syswow64
76fd0000 ole32.dll                  6.0.6001.18000     C:\Windows\syswow64
77120000 SHLWAPI.dll                6.0.6001.18000     C:\Windows\syswow64
77180000 urlmon.dll                 7.0.6001.18000     C:\Windows\syswow64
772b0000 PSAPI.DLL                  6.0.6000.16386     C:\Windows\syswow64
772c0000 LPK.DLL                    6.0.6001.18000     C:\Windows\syswow64
77360000 CLBCatQ.DLL                2001.12.6931.18000 C:\Windows\syswow64
773f0000 USP10.dll                  1.626.6001.18000   C:\Windows\syswow64
77470000 NSI.dll                    6.0.6001.18000     C:\Windows\syswow64
77820000 ntdll.dll                  6.0.6001.18000     C:\Windows\SysWOW64
780c0000 MSVCP60.dll                6.0.8168.0         E:\Star Trek Armada II Fleet Operations\data

processes:
0000 Idle                   0
0004 System                 0
0178 smss.exe               0 normal
01bc csrss.exe              0 normal
01fc wininit.exe            0 high
0208 csrss.exe              1 normal
022c services.exe           0 normal
0238 lsass.exe              0 normal
0240 lsm.exe                0 normal
0288 winlogon.exe           1 high
0300 svchost.exe            0 normal
033c svchost.exe            0 normal
0364 svchost.exe            0 normal
03c8 Ati2evxx.exe           0 normal
03d8 svchost.exe            0 normal
0114 svchost.exe            0 normal
012c svchost.exe            0 normal
01a0 audiodg.exe            0
0224 SLsvc.exe              0 normal
02c0 svchost.exe            0 normal
0458 svchost.exe            0 normal
054c Ati2evxx.exe           1 normal
0554 spoolsv.exe            0 normal
0584 svchost.exe            0 normal
05fc taskeng.exe            1 normal
0620 dwm.exe                1 high
06a0 explorer.exe           1 normal
07f8 Amoumain.exe           1 normal       C:\Program Files\Mouse
03a0 sidebar.exe            1 normal
041c robotaskbaricon.exe    1 normal       C:\Program Files (x86)\Siber Systems\AI RoboForm
0438 msnmsgr.exe            1 normal       C:\Program Files (x86)\Windows Live\Messenger
05d8 DTProAgent.exe         1 normal       C:\Program Files (x86)\DAEMON Tools Pro
06d4 gpkbd.exe              1 normal       C:\Program Files (x86)\SAMSUNG\Samsung Multimedia Keyboard
082c VolPanlu.exe           1 normal       C:\Program Files (x86)\Creative\SBAudigy\Volume Panel
0834 avgtray.exe            1 normal       C:\Program Files (x86)\AVG\AVG8
0844 MOM.exe                1 normal
09c8 CCC.exe                1 normal
0a2c avgwdsvc.exe           0 normal       C:\PROGRA~2\AVG\AVG8
0a4c LSSrvc.exe             0 normal       C:\Program Files (x86)\Common Files\LightScribe
0b58 NBService.exe          0 normal       C:\Program Files (x86)\Nero\Nero8\Nero BackItUp
0ae0 PnkBstrA.exe           0 normal       C:\Windows\SysWOW64
0af8 PnkBstrB.exe           0 normal       C:\Windows\SysWOW64
0b20 svchost.exe            0 normal
0b30 RichVideo.exe          0 normal       C:\Program Files (x86)\CyberLink\Shared Files
0b64 svchost.exe            0 normal
0b8c svchost.exe            0 normal
0bd0 SearchIndexer.exe      0 normal
0518 avgrsa.exe             0 normal
03a4 avgemc.exe             0 normal       C:\PROGRA~2\AVG\AVG8
0f14 wlcomm.exe             1 normal       C:\Program Files (x86)\Windows Live\Contacts
0684 SearchProtocolHost.exe 0 idle
0ef4 taskeng.exe            0 below normal
0c94 taskeng.exe            0 below normal
07bc SearchFilterHost.exe   0 idle
11bc orca.exe               1 normal       C:\Program Files (x86)\Orca Browser
12f4 Armada2.exe            1 normal       E:\Star Trek Armada II Fleet Operations\data
10b4 dllhost.exe            1 normal

hardware:
+ Computer
  - ACPI x64 alapú PC
+ Disk drives
  - Hitachi HDT725032VLA380 ATA Device
+ Display adapters
  - ATI Radeon HD 4800 Series   (driver 8.561.0.0)
+ DVD/CD-ROM drives
  - LML 3CLMB8LEVW ATA Device
  - TSSTcorp CDDVDW SH-S203P ATA Device
+ Human Interface Devices
  - USB HID
+ IDE ATA/ATAPI controllers
  - ATA Channel 0
  - ATA Channel 0
  - ATA Channel 1
  - ATA Channel 1
  - IDE-csatorna
  - Intel(R) ICH9 Family 2 port Serial ATA Storage Controller 1 - 2921 (driver 8.6.1.1001)
  - Intel(R) ICH9 Family 2 port Serial ATA Storage Controller 2 - 2926 (driver 8.6.1.1001)
+ Imaging devices
  - Labtec WebCam Pro (driver 10.5.1.1130)
+ Keyboards
  - Szabványos PS/2 billentyűzet
+ Mice and other pointing devices
  - USB HID-compliant mouse
+ Monitors
  - Általános PnP képernyő
+ Network adapters
  - Hamachi Network Interface (driver 6.0.2.2)
  - Realtek RTL8168/8111 termékcsaládba tartozó PCI Gigabit Ethernet hálózati adapter (NDIS 6.0)
+ Ports (COM & LPT)
  - Kommunikációs port (COM1)
  - Nyomtatási port (LPT1)
+ Processors
  - Intel(R) Core(TM)2 Duo CPU     E8200  @ 2.66GHz
  - Intel(R) Core(TM)2 Duo CPU     E8200  @ 2.66GHz
+ Sound, video and game controllers
  - High Definition Audio hangeszköz
  - Labtec Mic (WebCam Pro) (driver 10.5.1.1130)
  - SB Audigy (driver 5.12.1.2004)
+ Storage controllers
  - AB4ID7KN IDE Controller
  - GIGABYTE GBB36X Controller (driver 1.17.28.0)
  - Microsoft iSCSI-kezdeményező
+ System devices
  - A rendszer CMOS vagy valós idejű órája
  - ACPI-bekapcsológomb
  - ACPI-beépített lehetőség gombja
  - Alaplap erőforrásai
  - Alaplap erőforrásai
  - Alaplap erőforrásai
  - Bővített IO-busz
  - DMA-vezérlő
  - High Definition Audio hangvezérlő
  - Intel(R) 82801 PCI-híd - 244E
  - Intel(R) 82802 belső vezérlőprogramú hub-eszköz
  - Intel(R) G33/G31/P35/P31 Express Chipset PCI Express Root Port - 29C1 (driver 8.6.1.1001)
  - Intel(R) G33/G31/P35/P31 Express Chipset Processor to I/O Controller - 29C0 (driver 8.6.1.1001)
  - Intel(R) ICH9 Family PCI Express Root Port 1 - 2940 (driver 8.3.0.1014)
  - Intel(R) ICH9 Family PCI Express Root Port 4 - 2946 (driver 8.3.0.1014)
  - Intel(R) ICH9 Family PCI Express Root Port 5 - 2948 (driver 8.3.0.1014)
  - Intel(R) ICH9 Family SMBus Controller - 2930 (driver 8.3.0.1008)
  - Intel(R) ICH9 LPC Interface Controller - 2918 (driver 8.3.0.1014)
  - Kötetkezelő
  - Microsoft ACPI szabványnak megfelelő rendszer
  - Microsoft rendszerkezelő BIOS-illesztőprogram
  - Nagy pontosságú eseményidőzítő
  - Numerikus adatprocesszor
  - Nyomtatóport logikai illesztője
  - PCI-busz
  - Plug and Play szoftveres eszköz-számbavételező
  - Programozható megszakításvezérlő
  - Rendszerhangszóró
  - Rendszeridőzítő
  - Rendszerlap
  - Terminálkiszolgáló - billentyűzet-illesztőprogram
  - Terminálkiszolgáló - egér-illesztőprogram
  - UMBus enumeráló
  - UMBus gyökérbusz-enumeráló
+ Universal Serial Bus controllers
  - Intel(R) ICH9 Family USB Universal Host Controller - 2934 (driver 8.3.0.1011)
  - Intel(R) ICH9 Family USB Universal Host Controller - 2935 (driver 8.3.0.1011)
  - Intel(R) ICH9 Family USB Universal Host Controller - 2936 (driver 8.3.0.1011)
  - Intel(R) ICH9 Family USB Universal Host Controller - 2937 (driver 8.3.0.1011)
  - Intel(R) ICH9 Family USB Universal Host Controller - 2938 (driver 8.3.0.1011)
  - Intel(R) ICH9 Family USB Universal Host Controller - 2939 (driver 8.3.0.1011)
  - Intel(R) ICH9 Family USB2 Enhanced Host Controller - 293A (driver 8.3.0.1011)
  - Intel(R) ICH9 Family USB2 Enhanced Host Controller - 293C (driver 8.3.0.1011)
  - Labtec WebCam Pro (driver 10.5.1.1130)
  - USB gyökérhub
  - USB gyökérhub
  - USB gyökérhub
  - USB gyökérhub
  - USB gyökérhub
  - USB gyökérhub
  - USB gyökérhub
  - USB gyökérhub

cpu registers:
eax = 00000000
ebx = 0017f044
ecx = 00000000
edx = 00000000
esi = 05ea2fc0
edi = 05ea2fc0
eip = 6bf3dec5
esp = 0017edf0
ebp = 00000000

stack dump:
0017edf0  af b7 d2 ad 69 87 f5 6b - c0 2f ea 05 44 f0 17 00  ....i..k./..D...
0017ee00  04 f0 17 00 b0 f9 b6 04 - 00 00 00 00 01 00 00 00  ................
0017ee10  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017ee20  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017ee30  01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017ee40  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017ee50  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017ee60  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017ee70  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017ee80  28 68 b5 04 00 00 00 00 - 00 00 00 00 00 00 00 00  (h..............
0017ee90  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017eea0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017eeb0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017eec0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017eed0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017eee0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017eef0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017ef00  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017ef10  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017ef20  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

disassembling:
[...]
5aa0d657
5aa0d659 58   mov     edx, [$5aa2aa14]
5aa0d65f      mov     [esi+$10], eax
5aa0d662 59   mov     dword ptr [esi+$14], 1
5aa0d65f 58
5aa0d669    loc_5aa0d669:
5aa0d669 62   mov     eax, [ebp+$20]
5aa0d66c      call    -$206049 ($5a807628)   ; System.@IntfClear
5aa0d66c
5aa0d671      push    eax
5aa0d672      push    esi
5aa0d673      mov     eax, [ebp+$18]
5aa0d676      push    eax
5aa0d677      mov     eax, [ebp+$14]
5aa0d67a      push    eax
5aa0d67b      mov     eax, [ebp+$10]
5aa0d67e      push    eax
5aa0d67f      push    ebx
5aa0d680      mov     eax, [ebp+8]
5aa0d683      push    eax
5aa0d684    > call    dword ptr [$5aa592ac]
5aa0d684
5aa0d68a 63   pop     esi
5aa0d68b      pop     ebx
5aa0d68c      pop     ebp
5aa0d68d      ret     $1c

date/time         : 2008-12-31, 22:10:57, 542ms
computer name     : TYREL-PC
user name         : Tyrel <admin>
registered owner  : Microsoft / Microsoft
operating system  : Windows Vista x64 Service Pack 1 build 6001
system language   : Hungarian
system up time    : 6 minutes 56 seconds
program up time   : 2 seconds
processors        : 2x Intel(R) Core(TM)2 Duo CPU E8200 @ 2.66GHz
physical memory   : 1022/2046 MB (free/total)
free disk space   : (C:) 7,05 GB (E:) 26,10 GB
display mode      : 1280x1024, 32 bit
process id        : $ea4
allocated memory  : 61,03 MB
executable        : Armada2.exe
current module    : FleetOpsHook.dll
module date/time  : 2008-12-31 16:36
compiled with     : Delphi 2006/07
madExcept version : 3.0h
contact name      : Tyrel
contact email     : yeti_64@hotmail.com
callstack crc     : $0e90ab8e, $531fe679, $531fe679
count             : 8
exception number  : 1
exception class   : EAccessViolation
exception message : Access violation at address 0065DE8E in module 'Armada2.exe'. Read of address 00000000.

main thread ($ff0):
0065de8e +00013e Armada2.exe                                    savegame.obj
00486647 +000047 Armada2.exe                                    Program.obj
0047608d +00011d Armada2.exe                                    ArmadaWin.obj
5a9fa10d +000029 FleetOpsHook.dll FleetOpsFunctionsHook 5879 +3 DebugException_Execute_Hook
5a9fa1d9 +000039 FleetOpsHook.dll FleetOpsFunctionsHook 5902 +9 A2_WinMain
006734f4 +22507c Armada2.exe                                    savegame.obj
773de3f1 +00000c kernel32.dll                                   BaseThreadInitThunk

thread $940:
773de3f1 +c kernel32.dll  BaseThreadInitThunk

thread $6dc:
773de3f1 +c kernel32.dll  BaseThreadInitThunk

thread $d14: <priority:15>
7736dce4 +00 kernel32.dll               WaitForMultipleObjectsEx
773634a4 +13 kernel32.dll               WaitForMultipleObjects
5a8bf971 +0d FleetOpsHook.dll madExcept CallThreadProcSafe
5a8bf9db +37 FleetOpsHook.dll madExcept ThreadExceptFrame
773de3f1 +0c kernel32.dll               BaseThreadInitThunk
>> created by main thread ($ff0) at:
735f8136 +00 DSOUND.dll

thread $e5c: <priority:15>
7736dce4 +00 kernel32.dll               WaitForMultipleObjectsEx
773634a4 +13 kernel32.dll               WaitForMultipleObjects
5a8bf971 +0d FleetOpsHook.dll madExcept CallThreadProcSafe
5a8bf9db +37 FleetOpsHook.dll madExcept ThreadExceptFrame
773de3f1 +0c kernel32.dll               BaseThreadInitThunk
>> created by main thread ($ff0) at:
735f8136 +00 DSOUND.dll

thread $f3c:
773de3f1 +c kernel32.dll  BaseThreadInitThunk

modules:
00020000 Amhooker.dll                                  C:\Windows\system32
001b0000 NetworkManager.dll                            E:\Star Trek Armada II Fleet Operations\data
00400000 Armada2.exe                43.0.0.0           E:\Star Trek Armada II Fleet Operations\data
10000000 Win2kDisableTaskSwitch.dll                    E:\Star Trek Armada II Fleet Operations\data
30000000 binkw32.dll                1.5.21.0           E:\Star Trek Armada II Fleet Operations\data
5a800000 FleetOpsHook.dll                              E:\Star Trek Armada II Fleet Operations
6bc40000 atiumdva.dll               7.14.10.208        C:\Windows\system32
6c380000 atiumdag.dll               7.14.10.630        C:\Windows\system32
6c790000 d3dx9_33.dll               9.18.904.15        E:\Star Trek Armada II Fleet Operations\data
6cb00000 AcGenral.DLL               6.0.6001.18000     C:\Windows\AppPatch
6cd50000 dbghelp.dll                6.0.6001.18000     C:\Windows\syswow64
6ce30000 d3d8.dll                   6.0.6001.18000     C:\Windows\system32
6d310000 ShimEng.dll                6.0.6000.16386     C:\Windows\system32
6d330000 AVIFIL32.dll               6.0.6001.18000     C:\Windows\system32
6f010000 MPR.dll                    6.0.6001.18000     C:\Windows\system32
6f330000 IconCodecService.dll       6.0.6000.16386     C:\Windows\system32
6f340000 WindowsCodecs.dll          6.0.6001.18000     C:\Windows\system32
70a40000 d3d8thk.dll                6.0.6000.16386     C:\Windows\system32
70b80000 apphelp.dll                6.0.6001.18000     C:\Windows\system32
72c90000 PROPSYS.dll                6.0.6001.18000     C:\Windows\system32
73240000 sfc.dll                    6.0.6000.16386     C:\Windows\system32
73250000 sfc_os.DLL                 6.0.6001.18000     C:\Windows\system32
73360000 dwmapi.dll                 6.0.6001.18000     C:\Windows\system32
73520000 audioeng.dll               6.0.6001.18000     C:\Windows\system32
73590000 AUDIOSES.DLL               6.0.6001.18000     C:\Windows\system32
735f0000 DSOUND.dll                 6.0.6001.18000     C:\Windows\system32
736a0000 AVRT.dll                   6.0.6001.18000     C:\Windows\system32
73c90000 POWRPROF.dll               6.0.6001.18000     C:\Windows\system32
73ce0000 MMDevApi.dll               6.0.6001.18000     C:\Windows\System32
73d40000 MSVFW32.dll                6.0.6001.18000     C:\Windows\system32
73fc0000 MSACM32.dll                6.0.6001.18000     C:\Windows\system32
73fe0000 UxTheme.dll                6.0.6001.18000     C:\Windows\system32
74120000 OLEACC.dll                 4.2.5406.0         C:\Windows\system32
74160000 WINMM.dll                  6.0.6001.18000     C:\Windows\system32
741a0000 CRYPT32.dll                6.0.6001.18000     C:\Windows\system32
742a0000 COMCTL32.dll               6.10.6001.18000    C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc
75640000 VERSION.dll                6.0.6001.18000     C:\Windows\system32
75650000 WINTRUST.dll               6.0.6001.18000     C:\Windows\system32
75680000 USERENV.dll                6.0.6001.18000     C:\Windows\system32
756a0000 MSASN1.dll                 6.0.6000.16386     C:\Windows\system32
75880000 NETAPI32.dll               6.0.6001.18000     C:\Windows\system32
75900000 wsock32.dll                6.0.6001.18000     C:\Windows\system32
75bc0000 Secur32.dll                6.0.6001.18000     C:\Windows\syswow64
75c20000 SETUPAPI.dll               6.0.6001.18000     C:\Windows\syswow64
75db0000 MSCTF.dll                  6.0.6001.18000     C:\Windows\syswow64
75e80000 PSAPI.DLL                  6.0.6000.16386     C:\Windows\syswow64
75e90000 RPCRT4.dll                 6.0.6001.18000     C:\Windows\syswow64
75f80000 LPK.DLL                    6.0.6001.18000     C:\Windows\syswow64
760b0000 USER32.dll                 6.0.6001.18000     C:\Windows\syswow64
76180000 GDI32.dll                  6.0.6001.18000     C:\Windows\syswow64
76210000 urlmon.dll                 7.0.6001.18000     C:\Windows\syswow64
76340000 ole32.dll                  6.0.6001.18000     C:\Windows\syswow64
76520000 SHLWAPI.dll                6.0.6001.18000     C:\Windows\syswow64
76580000 IMM32.dll                  6.0.6001.18000     C:\Windows\syswow64
765e0000 IMAGEHLP.dll               6.0.6001.18000     C:\Windows\syswow64
76610000 SHELL32.dll                6.0.6001.18000     C:\Windows\syswow64
77120000 WS2_32.dll                 6.0.6001.18000     C:\Windows\syswow64
77150000 CLBCatQ.DLL                2001.12.6931.18000 C:\Windows\syswow64
771e0000 USP10.dll                  1.626.6001.18000   C:\Windows\syswow64
77260000 iertutil.dll               7.0.6001.18000     C:\Windows\syswow64
772c0000 OLEAUT32.dll               6.0.6001.18000     C:\Windows\syswow64
77350000 kernel32.dll               6.0.6001.18000     C:\Windows\syswow64
77460000 ADVAPI32.dll               6.0.6001.18000     C:\Windows\syswow64
77530000 NSI.dll                    6.0.6001.18000     C:\Windows\syswow64
77540000 comdlg32.dll               6.0.6001.18000     C:\Windows\syswow64
775c0000 msvcrt.dll                 7.0.6001.18000     C:\Windows\syswow64
77a10000 ntdll.dll                  6.0.6001.18000     C:\Windows\SysWOW64
780c0000 MSVCP60.dll                6.0.8168.0         E:\Star Trek Armada II Fleet Operations\data

processes:
000 Idle                   0
004 System                 0
18c smss.exe               0 normal
1d0 csrss.exe              0 normal
208 wininit.exe            0 high
21c csrss.exe              1 normal
240 services.exe           0 normal
24c lsass.exe              0 normal
258 lsm.exe                0 normal
2c4 winlogon.exe           1 high
30c svchost.exe            0 normal
34c svchost.exe            0 normal
370 svchost.exe            0 normal
3d4 Ati2evxx.exe           0 normal
3e8 svchost.exe            0 normal
118 svchost.exe            0 normal
140 svchost.exe            0 normal
1c4 audiodg.exe            0
214 SLsvc.exe              0 normal
378 svchost.exe            0 normal
484 svchost.exe            0 normal
4ac Ati2evxx.exe           1 normal
5ac spoolsv.exe            0 normal
5f0 svchost.exe            0 normal
660 taskeng.exe            1 normal
690 dwm.exe                1 high
6f0 taskeng.exe            0 below normal
6fc explorer.exe           1 normal
498 Amoumain.exe           1 normal       C:\Program Files\Mouse
508 sidebar.exe            1 normal
5a4 robotaskbaricon.exe    1 normal       C:\Program Files (x86)\Siber Systems\AI RoboForm
5f8 msnmsgr.exe            1 normal       C:\Program Files (x86)\Windows Live\Messenger
628 DTProAgent.exe         1 normal       C:\Program Files (x86)\DAEMON Tools Pro
6bc gpkbd.exe              1 normal       C:\Program Files (x86)\SAMSUNG\Samsung Multimedia Keyboard
80c VolPanlu.exe           1 normal       C:\Program Files (x86)\Creative\SBAudigy\Volume Panel
818 avgtray.exe            1 normal       C:\Program Files (x86)\AVG\AVG8
830 MOM.exe                1 normal
99c CCC.exe                1 normal
abc avgwdsvc.exe           0 normal       C:\PROGRA~2\AVG\AVG8
ae8 LSSrvc.exe             0 normal       C:\Program Files (x86)\Common Files\LightScribe
b68 NBService.exe          0 normal       C:\Program Files (x86)\Nero\Nero8\Nero BackItUp
bc0 PnkBstrA.exe           0 normal       C:\Windows\SysWOW64
bdc PnkBstrB.exe           0 normal       C:\Windows\SysWOW64
66c svchost.exe            0 normal
4bc RichVideo.exe          0 normal       C:\Program Files (x86)\CyberLink\Shared Files
2f8 svchost.exe            0 normal
4d0 svchost.exe            0 normal
8b8 SearchIndexer.exe      0 normal
7f4 avgrsa.exe             0 normal
c20 avgemc.exe             0 normal       C:\PROGRA~2\AVG\AVG8
e48 wlcomm.exe             1 normal       C:\Program Files (x86)\Windows Live\Contacts
714 totalcmd.exe           1 normal       C:\Program Files (x86)\TC UP
2f0 orca.exe               1 normal       C:\Program Files (x86)\Orca Browser
e80 SearchProtocolHost.exe 0 idle
f5c SearchFilterHost.exe   0 idle
ea4 Armada2.exe            1 normal       E:\Star Trek Armada II Fleet Operations\data
d54 dllhost.exe            1 normal

hardware:
+ Computer
  - ACPI x64 alapú PC
+ Disk drives
  - Hitachi HDT725032VLA380 ATA Device
+ Display adapters
  - ATI Radeon HD 4800 Series   (driver 8.561.0.0)
+ DVD/CD-ROM drives
  - LML 3CLMB8LEVW ATA Device
  - TSSTcorp CDDVDW SH-S203P ATA Device
+ Human Interface Devices
  - USB HID
+ IDE ATA/ATAPI controllers
  - ATA Channel 0
  - ATA Channel 0
  - ATA Channel 1
  - ATA Channel 1
  - IDE-csatorna
  - Intel(R) ICH9 Family 2 port Serial ATA Storage Controller 1 - 2921 (driver 8.6.1.1001)
  - Intel(R) ICH9 Family 2 port Serial ATA Storage Controller 2 - 2926 (driver 8.6.1.1001)
+ Imaging devices
  - Labtec WebCam Pro (driver 10.5.1.1130)
+ Keyboards
  - Szabványos PS/2 billentyűzet
+ Mice and other pointing devices
  - USB HID-compliant mouse
+ Monitors
  - Általános PnP képernyő
+ Network adapters
  - Hamachi Network Interface (driver 6.0.2.2)
  - Realtek RTL8168/8111 termékcsaládba tartozó PCI Gigabit Ethernet hálózati adapter (NDIS 6.0)
+ Ports (COM & LPT)
  - Kommunikációs port (COM1)
  - Nyomtatási port (LPT1)
+ Processors
  - Intel(R) Core(TM)2 Duo CPU     E8200  @ 2.66GHz
  - Intel(R) Core(TM)2 Duo CPU     E8200  @ 2.66GHz
+ Sound, video and game controllers
  - High Definition Audio hangeszköz
  - Labtec Mic (WebCam Pro) (driver 10.5.1.1130)
  - SB Audigy (driver 5.12.1.2004)
+ Storage controllers
  - AGDRSN7O IDE Controller
  - GIGABYTE GBB36X Controller (driver 1.17.28.0)
  - Microsoft iSCSI-kezdeményező
+ Storage volume shadow copies
  - Általános kötet árnyékmásolata
+ System devices
  - A rendszer CMOS vagy valós idejű órája
  - ACPI-bekapcsológomb
  - ACPI-beépített lehetőség gombja
  - Alaplap erőforrásai
  - Alaplap erőforrásai
  - Alaplap erőforrásai
  - Bővített IO-busz
  - DMA-vezérlő
  - High Definition Audio hangvezérlő
  - Intel(R) 82801 PCI-híd - 244E
  - Intel(R) 82802 belső vezérlőprogramú hub-eszköz
  - Intel(R) G33/G31/P35/P31 Express Chipset PCI Express Root Port - 29C1 (driver 8.6.1.1001)
  - Intel(R) G33/G31/P35/P31 Express Chipset Processor to I/O Controller - 29C0 (driver 8.6.1.1001)
  - Intel(R) ICH9 Family PCI Express Root Port 1 - 2940 (driver 8.3.0.1014)
  - Intel(R) ICH9 Family PCI Express Root Port 4 - 2946 (driver 8.3.0.1014)
  - Intel(R) ICH9 Family PCI Express Root Port 5 - 2948 (driver 8.3.0.1014)
  - Intel(R) ICH9 Family SMBus Controller - 2930 (driver 8.3.0.1008)
  - Intel(R) ICH9 LPC Interface Controller - 2918 (driver 8.3.0.1014)
  - Kötetkezelő
  - Microsoft ACPI szabványnak megfelelő rendszer
  - Microsoft rendszerkezelő BIOS-illesztőprogram
  - Nagy pontosságú eseményidőzítő
  - Numerikus adatprocesszor
  - Nyomtatóport logikai illesztője
  - PCI-busz
  - Plug and Play szoftveres eszköz-számbavételező
  - Programozható megszakításvezérlő
  - Rendszerhangszóró
  - Rendszeridőzítő
  - Rendszerlap
  - Terminálkiszolgáló - billentyűzet-illesztőprogram
  - Terminálkiszolgáló - egér-illesztőprogram
  - UMBus enumeráló
  - UMBus gyökérbusz-enumeráló
+ Universal Serial Bus controllers
  - Intel(R) ICH9 Family USB Universal Host Controller - 2934 (driver 8.3.0.1011)
  - Intel(R) ICH9 Family USB Universal Host Controller - 2935 (driver 8.3.0.1011)
  - Intel(R) ICH9 Family USB Universal Host Controller - 2936 (driver 8.3.0.1011)
  - Intel(R) ICH9 Family USB Universal Host Controller - 2937 (driver 8.3.0.1011)
  - Intel(R) ICH9 Family USB Universal Host Controller - 2938 (driver 8.3.0.1011)
  - Intel(R) ICH9 Family USB Universal Host Controller - 2939 (driver 8.3.0.1011)
  - Intel(R) ICH9 Family USB2 Enhanced Host Controller - 293A (driver 8.3.0.1011)
  - Intel(R) ICH9 Family USB2 Enhanced Host Controller - 293C (driver 8.3.0.1011)
  - Labtec WebCam Pro (driver 10.5.1.1130)
  - USB gyökérhub
  - USB gyökérhub
  - USB gyökérhub
  - USB gyökérhub
  - USB gyökérhub
  - USB gyökérhub
  - USB gyökérhub
  - USB gyökérhub

cpu registers:
eax = 00000000
ebx = 00000074
ecx = ffffffff
edx = 00000000
esi = 007300ac
edi = 00000000
eip = 0065de8e
esp = 0017fda8
ebp = 0017fe08

stack dump:
0017fda8  27 85 5d 77 30 7b 73 00 - 78 06 00 00 44 22 36 77  '.]w0{s.x...D"6w
0017fdb8  f8 db fd 7e 06 00 00 00 - 00 00 00 00 00 00 00 00  ...~............
0017fdc8  03 00 04 00 14 dd d6 25 - dc fd 17 00 74 3a 5c 00  .......%....t:\.
0017fdd8  00 dc fd 7e 08 fe 17 00 - af dd 65 00 f4 fd 17 00  ...~......e.....
0017fde8  27 85 5d 77 30 7b 73 00 - 78 06 00 00 2e 3a 5c 00  '.]w0{s.x....:\.
0017fdf8  00 00 00 00 27 85 5d 77 - 00 00 00 00 7c 01 00 00  ....'.]w....|...
0017fe08  a8 fe 17 00 4c 66 48 00 - 00 00 00 00 32 2c 96 00  ....LfH.....2,..
0017fe18  00 00 00 00 10 00 00 00 - 68 fe 17 00 88 28 96 00  ........h....(..
0017fe28  a8 fd 17 00 b0 fd 17 00 - 74 fe 17 00 00 00 00 00  ........t.......
0017fe38  00 00 a1 77 00 00 00 00 - 84 fe 17 00 42 7a a4 77  ...w........Bz.w
0017fe48  b4 00 af 77 c0 7a a4 77 - 8d b1 be 77 54 79 72 65  ...w.z.w...wTyre
0017fe58  6c 00 00 00 00 00 00 00 - c8 00 00 00 00 40 db 7f  l............@..
0017fe68  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0017fe78  00 50 1f a7 68 04 1d 00 - 00 02 00 00 00 00 00 00  .P..h...........
0017fe88  90 01 2c 01 50 55 06 00 - 90 01 00 00 2c 01 00 00  ..,.PU......,...
0017fe98  c0 b7 85 01 b4 fe 17 00 - 2c c2 69 00 ff ff ff ff  ........,.i.....
0017fea8  e0 fe 17 00 92 60 47 00 - 0f a1 9f 5a c0 fe 17 00  .....`G....Z....
0017feb8  f0 4b 80 5a e0 fe 17 00 - 78 ff 17 00 92 a1 9f 5a  .K.Z....x......Z
0017fec8  e0 fe 17 00 00 00 00 00 - 32 2c 96 00 00 00 00 00  ........2,......
0017fed8  74 d9 ee 02 18 0f e8 02 - ec fe 17 00 de a1 9f 5a  t..............Z

disassembling:
5a9fa0e4      public FleetOpsFunctionsHook.DebugException_Execute_Hook:  ; function entry point
5a9fa0e4 5876   push    ebp
5a9fa0e5        mov     ebp, esp
5a9fa0e7        push    0
5a9fa0e9        push    0
5a9fa0eb        push    ebx
5a9fa0ec        push    esi
5a9fa0ed        push    edi
5a9fa0ee        xor     eax, eax
5a9fa0f0        push    ebp
5a9fa0f1        push    $5a9fa192              ; System.@HandleFinally
5a9fa0f6        push    dword ptr fs:[eax]
5a9fa0f9        mov     fs:[eax], esp
5a9fa0fc 5877   mov     eax, [ebp+8]
5a9fa0ff 5878   xor     edx, edx
5a9fa101        push    ebp
5a9fa102        push    $5a9fa119              ; System.@HandleAnyException
5a9fa107        push    dword ptr fs:[edx]
5a9fa10a        mov     fs:[edx], esp
5a9fa10d 5879 > call    eax
5a9fa10d
5a9fa10f        xor     eax, eax
5a9fa111        pop     edx
5a9fa112        pop     ecx
5a9fa113        pop     ecx
5a9fa114        mov     fs:[eax], edx
5a9fa117        jmp     loc_5a9fa174
5a9fa117
5a9fa117      ; ---------------------------------------------------------
5a9fa117
5a9fa119        jmp     -$1f5632 ($5a804aec)   ; System.@HandleAnyException
5a9fa119
5a9fa11e 5881   push    1
5a9fa120        push    0
5a9fa122        push    0
5a9fa124        push    0
5a9fa126        push    0
5a9fa128        push    0
5a9fa12a        push    0
5a9fa12c        push    0
[...]

