Quevedo F. Distribucion Normal. Medwave 2011 May 1105
Quevedo F. Distribucion Normal. Medwave 2011 May 1105
Quevedo F. Distribucion Normal. Medwave 2011 May 1105
thread $bd4:
775a5e4a +0a ntdll.dll NtWaitForMultipleObjects
76471172 +10 kernel32.dll BaseThreadInitThunk
thread $be0:
775a5e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
76471172 +10 kernel32.dll BaseThreadInitThunk
thread $be8:
775a5e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
76471172 +10 kernel32.dll BaseThreadInitThunk
thread $bec:
775a5e6a +0a ntdll.dll NtWaitForSingleObject
75911796 +66 KERNELBASE.dll WaitForSingleObjectEx
7646effe +3e kernel32.dll WaitForSingleObjectEx
004a7205 +0d UmmyVideoDownloader.exe madExcept CallThreadProcSafe
004a726a +32 UmmyVideoDownloader.exe madExcept ThreadExceptFrame
76471172 +10 kernel32.dll BaseThreadInitThunk
>> created by thread $be8 at:
73e4325b +00 rasman.dll
thread $bf8:
775a5e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
76471172 +10 kernel32.dll BaseThreadInitThunk
thread $c1c:
775a5e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
76471172 +10 kernel32.dll BaseThreadInitThunk
cpu registers:
eax = 00000000
ebx = 00699f7d
ecx = 00000062
edx = 01f3df44
esi = 00000000
edi = 0012f934
eip = 00699fa1
esp = 0012f940
ebp = 0012f974
stack dump:
0012f940 ac fe 12 00 cc 98 40 00 - 74 f9 12 00 ac fe 12 00 ......@.t.......
0012f950 00 00 00 00 36 ad 6a 00 - 00 00 00 00 00 00 00 00 ....6.j.........
0012f960 00 00 00 00 83 a1 70 2a - 6c c3 e4 40 00 00 00 00 ......p*l..@....
0012f970 00 00 00 00 0c ff 12 00 - 51 ad 6a 00 00 00 00 00 ........Q.j.....
0012f980 7f be 52 00 20 4a fb 01 - 88 fa 12 00 b4 f9 12 00 ..R. J..........
0012f990 c0 f9 12 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012f9a0 f9 65 5a 77 88 fa 12 00 - ac fe 12 00 b8 fa 12 00 .eZw............
0012f9b0 5c fa 12 00 a0 fe 12 00 - 0d 66 5a 77 ac fe 12 00 \........fZw....
0012f9c0 70 fa 12 00 cb 65 5a 77 - 88 fa 12 00 ac fe 12 00 p....eZw........
0012f9d0 b8 fa 12 00 5c fa 12 00 - 31 ad 6a 00 00 00 00 00 ....\...1.j.....
0012f9e0 88 fa 12 00 ac fe 12 00 - 3d 8d 58 77 88 fa 12 00 ........=.Xw....
0012f9f0 ac fe 12 00 b8 fa 12 00 - 5c fa 12 00 31 ad 6a 00 ........\...1.j.
0012fa00 20 00 00 00 88 fa 12 00 - 0c 6d f3 01 00 00 00 00 ........m......
0012fa10 82 00 84 00 0c 6d f3 01 - 41 00 00 00 28 02 00 00 .....m..A...(...
0012fa20 02 00 00 00 00 00 00 00 - 82 00 00 00 00 00 00 00 ................
0012fa30 82 00 00 00 6a fb 12 00 - 0c 6d f3 01 82 00 08 02 ....j....m......
0012fa40 e8 fa 12 00 01 fa 12 01 - 8e 6d f3 01 00 00 00 00 .........m......
0012fa50 00 00 00 00 00 00 00 00 - 4d bd 5b 77 31 5d 71 77 ........M.[w1]qw
0012fa60 72 00 00 00 00 00 13 00 - 00 b0 12 00 80 fa 12 00 r...............
0012fa70 ec fd 12 00 57 64 5a 77 - 88 fa 12 00 b8 fa 12 00 ....WdZw........
disassembling:
[...]
00699f93 sub eax, 4
00699f96 mov eax, [eax]
00699f98 mov ecx, eax
00699f9a add ecx, ecx
00699f9c mov eax, [$811734]
00699fa1 > mov ebx, [eax]
00699fa3 call dword ptr [ebx+$10]
00699fa6 51 xor eax, eax
00699fa8 pop edx
00699fa9 pop ecx
00699faa pop ecx
[...]
thread $bd0:
775a5e4a +0a ntdll.dll NtWaitForMultipleObjects
76471172 +10 kernel32.dll BaseThreadInitThunk
thread $bd8:
775a5e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
76471172 +10 kernel32.dll BaseThreadInitThunk
thread $c08:
775a5e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
76471172 +10 kernel32.dll BaseThreadInitThunk
thread $c0c:
775a5e6a +0a ntdll.dll NtWaitForSingleObject
75911796 +66 KERNELBASE.dll WaitForSingleObjectEx
7646effe +3e kernel32.dll WaitForSingleObjectEx
004a7205 +0d UmmyVideoDownloader.exe madExcept CallThreadProcSafe
004a726a +32 UmmyVideoDownloader.exe madExcept ThreadExceptFrame
76471172 +10 kernel32.dll BaseThreadInitThunk
>> created by thread $c08 at:
73e4325b +00 rasman.dll
thread $c10:
775a5e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
76471172 +10 kernel32.dll BaseThreadInitThunk
thread $c54:
759c72a4 +171 WS2_32.dll gethostbyname
004a7205 +00d UmmyVideoDownloader.exe madExcept CallThreadProcSafe
004a726a +032 UmmyVideoDownloader.exe madExcept ThreadExceptFrame
76471172 +010 kernel32.dll BaseThreadInitThunk
>> created by thread $c4c at:
759c4d5c +000 WS2_32.dll
thread $cb4:
775a5e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
76471172 +10 kernel32.dll BaseThreadInitThunk
thread $cb8:
775a5e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
76471172 +10 kernel32.dll BaseThreadInitThunk
cpu registers:
eax = 00000000
ebx = 00699f7d
ecx = 0000003c
edx = 01f12efc
esi = 00000000
edi = 0012f884
eip = 00699fa1
esp = 0012f890
ebp = 0012f8c4
stack dump:
0012f890 a8 fd 12 00 cc 98 40 00 - c4 f8 12 00 a8 fd 12 00 ......@.........
0012f8a0 00 00 00 00 a9 f6 70 00 - 00 00 00 00 00 00 00 00 ......p.........
0012f8b0 00 00 00 00 b1 7b 67 2b - 6c c3 e4 40 00 00 00 00 .....{g+l..@....
0012f8c0 00 00 00 00 e4 fd 12 00 - b3 f6 70 00 00 00 00 00 ..........p.....
0012f8d0 45 b0 70 00 20 c7 ed 01 - d8 f9 12 00 04 f9 12 00 E.p. ...........
0012f8e0 10 f9 12 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012f8f0 f9 65 5a 77 d8 f9 12 00 - a8 fd 12 00 08 fa 12 00 .eZw............
0012f900 ac f9 12 00 9c fd 12 00 - 0d 66 5a 77 a8 fd 12 00 .........fZw....
0012f910 c0 f9 12 00 cb 65 5a 77 - d8 f9 12 00 a8 fd 12 00 .....eZw........
0012f920 08 fa 12 00 ac f9 12 00 - a4 f6 70 00 00 00 00 00 ..........p.....
0012f930 d8 f9 12 00 a8 fd 12 00 - 3d 8d 58 77 d8 f9 12 00 ........=.Xw....
0012f940 a8 fd 12 00 08 fa 12 00 - ac f9 12 00 a4 f6 70 00 ..............p.
0012f950 f0 83 ed 01 d8 f9 12 00 - 20 f8 de 01 38 fa 12 00 ........ ...8...
0012f960 00 00 00 00 a4 fb 12 00 - 01 00 00 00 fc 01 01 00 ................
0012f970 00 00 73 00 32 00 5f 00 - 33 00 32 00 2e 00 44 00 ..s.2._.3.2...D.
0012f980 4c 00 4c 00 00 00 5b 77 - 03 00 00 00 00 00 00 00 L.L...[w........
0012f990 00 00 00 00 d4 f9 12 00 - ad e6 5b 77 01 00 00 00 ..........[w....
0012f9a0 a4 fb 12 00 0c e7 5b 77 - 24 fa 12 00 18 fa 12 00 ......[w$.......
0012f9b0 72 00 00 00 00 00 13 00 - 00 40 12 00 00 00 00 00 r........@......
0012f9c0 3c fd 12 00 57 64 5a 77 - d8 f9 12 00 08 fa 12 00 <...WdZw........
disassembling:
[...]
00699f93 sub eax, 4
00699f96 mov eax, [eax]
00699f98 mov ecx, eax
00699f9a add ecx, ecx
00699f9c mov eax, [$811734]
00699fa1 > mov ebx, [eax]
00699fa3 call dword ptr [ebx+$10]
00699fa6 51 xor eax, eax
00699fa8 pop edx
00699fa9 pop ecx
00699faa pop ecx
[...]
thread $6dc:
77135e4a +0a ntdll.dll NtWaitForMultipleObjects
756d1172 +10 kernel32.dll BaseThreadInitThunk
thread $e18:
77135e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
756d1172 +10 kernel32.dll BaseThreadInitThunk
thread $d34:
77135e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
756d1172 +10 kernel32.dll BaseThreadInitThunk
thread $df4:
77135e6a +0a ntdll.dll NtWaitForSingleObject
75321796 +66 KERNELBASE.dll WaitForSingleObjectEx
756ceffe +3e kernel32.dll WaitForSingleObjectEx
004a7205 +0d UmmyVideoDownloader.exe madExcept CallThreadProcSafe
004a726a +32 UmmyVideoDownloader.exe madExcept ThreadExceptFrame
756d1172 +10 kernel32.dll BaseThreadInitThunk
>> created by thread $d34 at:
7382325b +00 rasman.dll
thread $2a8:
77135e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
756d1172 +10 kernel32.dll BaseThreadInitThunk
thread $d10:
77135e6a +0a ntdll.dll NtWaitForSingleObject
75321796 +66 KERNELBASE.dll WaitForSingleObjectEx
756ceffe +3e kernel32.dll WaitForSingleObjectEx
756cefad +0d kernel32.dll WaitForSingleObject
004a7205 +0d UmmyVideoDownloader.exe madExcept CallThreadProcSafe
004a726a +32 UmmyVideoDownloader.exe madExcept ThreadExceptFrame
756d1172 +10 kernel32.dll BaseThreadInitThunk
>> created by thread $4b8 at:
767e4d5c +00 WS2_32.dll
thread $290:
77135e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
756d1172 +10 kernel32.dll BaseThreadInitThunk
thread $4f0:
77135e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
756d1172 +10 kernel32.dll BaseThreadInitThunk
cpu registers:
eax = 00000000
ebx = 00000000
ecx = 00000000
edx = 00000000
esi = 042ad870
edi = ffffffff
eip = 007e7aef
esp = 0012f9b0
ebp = 0012fa64
stack dump:
0012f9b0 98 d1 e7 01 40 0d e7 01 - 84 7c 7e 00 6c fa 12 00 ....@....|~.l...
0012f9c0 cc 98 40 00 64 fa 12 00 - 98 d1 e7 01 40 0d e7 01 ..@.d.......@...
0012f9d0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012f9e0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012f9f0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fa00 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fa10 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fa20 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fa30 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fa40 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fa50 00 00 00 00 00 00 00 00 - 00 00 00 00 18 e3 e7 01 ................
0012fa60 70 d8 2a 04 2c fb 12 00 - 69 73 7e 00 3c fb 12 00 p.*.,...is~.<...
0012fa70 cc 98 40 00 2c fb 12 00 - 88 fc 12 00 80 32 eb 01 ..@.,........2..
0012fa80 40 0d e7 01 00 00 00 00 - 00 00 00 00 00 00 00 00 @...............
0012fa90 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012faa0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fab0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fac0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fad0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fae0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
disassembling:
[...]
007e7ad6 689 mov edx, ebx
007e7ad8 mov eax, [esi+$3b4]
007e7ade call -$1fa88f ($5ed254) ; Vcl.ExtCtrls.TTimer.SetEnabled
007e7ae3 690 mov [esi+$3e8], bl
007e7ae9 692 mov eax, [esi+$3b8]
007e7aef > mov edx, [eax]
007e7af1 call dword ptr [edx+$a4]
007e7af7 693 pop esi
007e7af8 pop ebx
007e7af9 ret
thread $e5c:
77715e4a +0a ntdll.dll NtWaitForMultipleObjects
775c1172 +10 kernel32.dll BaseThreadInitThunk
thread $ed0:
77715e6a +0a ntdll.dll NtWaitForSingleObject
759c1796 +66 KERNELBASE.dll WaitForSingleObjectEx
775beffe +3e kernel32.dll WaitForSingleObjectEx
004a7221 +0d UmmyVideoDownloader.exe madExcept CallThreadProcSafe
004a7286 +32 UmmyVideoDownloader.exe madExcept ThreadExceptFrame
775c1172 +10 kernel32.dll BaseThreadInitThunk
>> created by thread $918 at:
73d5325b +00 rasman.dll
thread $870:
77715e6a +0a ntdll.dll NtWaitForSingleObject
759c1796 +66 KERNELBASE.dll WaitForSingleObjectEx
775beffe +3e kernel32.dll WaitForSingleObjectEx
775befad +0d kernel32.dll WaitForSingleObject
004a7221 +0d UmmyVideoDownloader.exe madExcept CallThreadProcSafe
004a7286 +32 UmmyVideoDownloader.exe madExcept ThreadExceptFrame
775c1172 +10 kernel32.dll BaseThreadInitThunk
>> created by thread $e3c at:
76424d5c +00 WS2_32.dll
thread $d8:
77715e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
775c1172 +10 kernel32.dll BaseThreadInitThunk
thread $3d8:
77715e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
775c1172 +10 kernel32.dll BaseThreadInitThunk
thread $f48:
77715e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
775c1172 +10 kernel32.dll BaseThreadInitThunk
thread $ea0:
77715e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
775c1172 +10 kernel32.dll BaseThreadInitThunk
thread $294:
77715e7a +0a ntdll.dll NtWaitForWorkViaWorkerFactory
775c1172 +10 kernel32.dll BaseThreadInitThunk
cpu registers:
eax = 5f315f31
ebx = 00000000
ecx = 1205004a
edx = 0000000a
esi = 0403f6c8
edi = 00000000
eip = 5f315f31
esp = 0625fcc8
ebp = 00000000
stack dump:
0625fcc8 3f 0b 06 11 c8 f6 03 04 - 0a 00 00 00 00 00 00 00 ?...............
0625fcd8 00 00 00 00 c8 f6 03 04 - 50 fd 25 06 80 c1 2e 02 ........P.%.....
0625fce8 80 c1 2e 02 20 0c 06 11 - c8 f6 03 04 0a 00 00 00 .... ...........
0625fcf8 00 00 00 00 00 00 00 00 - 5d 44 6d 00 c8 f6 03 04 ........]Dm.....
0625fd08 58 fd 25 06 cc 98 40 00 - 50 fd 25 06 00 00 00 00 X.%...@.P.%.....
0625fd18 03 00 00 00 80 c1 2e 02 - 00 00 00 00 00 00 00 00 ................
0625fd28 ff 60 6d 00 07 61 6d 00 - 00 00 00 00 03 00 00 00 .`m..am.........
0625fd38 80 c1 2e 02 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0625fd48 00 00 00 00 00 00 00 00 - 9c fd 25 06 8f b8 6d 00 ..........%...m.
0625fd58 a4 fd 25 06 cc 98 40 00 - 9c fd 25 06 00 00 00 00 ..%...@...%.....
0625fd68 01 00 00 00 80 c1 2e 02 - 00 00 00 00 00 00 00 00 ................
0625fd78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0625fd88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0625fd98 00 00 00 00 c8 fd 25 06 - 7e 7b 6d 00 d0 fd 25 06 ......%.~{m...%.
0625fda8 cc 98 40 00 c8 fd 25 06 - 01 00 00 00 80 c1 2e 02 ..@...%.........
0625fdb8 00 00 00 00 00 00 00 00 - 00 00 00 00 01 00 00 00 ................
0625fdc8 f8 fd 25 06 4c 76 6d 00 - 00 fe 25 06 cc 98 40 00 ..%.Lvm...%...@.
0625fdd8 f8 fd 25 06 00 00 00 00 - 80 c1 2e 02 01 00 00 00 ..%.............
0625fde8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0625fdf8 28 fe 25 06 da 99 6d 00 - 3c fe 25 06 cc 98 40 00 (.%...m.<.%...@.
disassembling:
[...]
006d444b mov [ebp-4], eax
006d444e 15495 jmp loc_6d44e1
006d4453 15497 push edi
006d4454 mov eax, [$8228c0]
006d4459 mov eax, [eax]
006d445b > call eax
006d445d pop ecx
006d445e mov [ebp-4], eax
006d4461 15499 mov dl, 8
006d4463 mov eax, esi
006d4465 mov ecx, [eax]
[...]