Possible file format: Portable executable for AMD64 (PE) (E:\Program Files\IDA Freeware 8.4\loaders\pe64.dll)
bytes pages size description
--------- ----- ---- --------------------------------------------
524288 64 8192 allocating memory for b-tree...
65536 8 8192 allocating memory for virtual array...
262144 32 8192 allocating memory for name pointers...
851968 total memory allocated
Loading processor module E:\Program Files\IDA Freeware 8.4\procs\pc64.dll for metapc...Initializing processor module metapc...OK
Autoanalysis subsystem has been initialized.
Loading file 'E:\Projekte\fpc-qt\src\tests\test1.exe' into database...
Detected file format: Portable executable for AMD64 (PE)
0. Creating a new segment (0000000000401000-0000000000402000) ... ... OK
1. Creating a new segment (0000000000402000-0000000000404000) ... ... OK
2. Creating a new segment (0000000000404000-0000000000405000) ... ... OK
3. Creating a new segment (0000000000405000-0000000000406000) ... ... OK
4. Creating a new segment (0000000000406000-0000000000407000) ... ... OK
Reading imports directory...
5. Creating a new segment (0000000000406110-0000000000407000) ... ... OK
6. Creating a new segment (00000000004060B0-0000000000406110) ... ... OK
Type library 'mssdk64_win7' loaded. Applying types...
Types applied to 8 names.
Plan FLIRT signature: SEH for vc64 7-14
Marking typical code sequences...
Flushing buffers, please wait...ok
File 'E:\Projekte\fpc-qt\src\tests\test1.exe' has been successfully loaded into the database.
Hex-Rays Decompiler plugin has been loaded (v8.4.0.240320)
License: 48-F4EE-0000-00 Freeware version (1 user)
The decompilation hotkey is F5.
Please check the Edit/Plugins menu for more information.
Using FLIRT signature: SEH for vc64 7-14
Propagating type information...
Function argument information has been propagated
The initial autoanalysis has been finished.
400000: process E:\Projekte\fpc-qt\src\tests\test1.exe has started (pid=16088)
7FFC82C00000: loaded C:\Windows\System32\ntdll.dll
7FFC82030000: loaded C:\Windows\System32\KERNEL32.DLL
7FFC804B0000: loaded C:\Windows\System32\KERNELBASE.dll
7FFC7D390000: loaded C:\Windows\SYSTEM32\apphelp.dll
7FFC82C16A00: thread has started (tid=14888)
7FFC820F0000: loaded C:\Windows\System32\user32.dll
7FFC80A20000: loaded C:\Windows\System32\win32u.dll
10000000: loaded E:\Projekte\fpc-qt\src\tests\fpc_rtl.dll
7FFC82C16A00: thread has started (tid=4504)
7FFC81BD0000: loaded C:\Windows\System32\GDI32.dll
7FFC80270000: loaded C:\Windows\System32\gdi32full.dll
7FFC80840000: loaded C:\Windows\System32\msvcp_win.dll
7FFC80390000: loaded C:\Windows\System32\ucrtbase.dll
7FFC82C16A00: thread has started (tid=17460)
7FFC82C3CBA3: The instruction at 0x7FFC82C3CBA3 referenced memory at 0x106C6C64. The memory could not be read -> 00000000106C6C64 (exc.code c0000005, tid 16380)
PDBSRC: loading symbols for 'C:\Windows\System32\ntdll.dll'...
PDB: using PDBIDA provider
PDB: downloading http://msdl.microsoft.com/download/symbols/ntdll.pdb/3505304BE2C7C2D86FB32785BC2F9FBC1/ntdll.pdb => C:\Users\JENSKA~1\AppData\Local\Temp\ida\ntdll.pdb\3505304BE2C7C2D86FB32785BC2F9FBC1\ntdll.pdb
PDB: loading C:\Users\JENSKA~1\AppData\Local\Temp\ida\ntdll.pdb\3505304BE2C7C2D86FB32785BC2F9FBC1\ntdll.pdb