|
发表于 2008-2-20 15:03:52
|
显示全部楼层
按键精灵 6.60.2075版
Type = 0xC0000005
Address = 0x73D3439C
Registers:
EAX=A0C047BF EBX=00444840 ECX=02DCBB60 EDX=73E0E578
ESI=0012F880 EDI=02D0F6C0 ESP=0012F874 EBP=02DC8008
Current Modules:
Name = 按键精灵6.exe, Base = 0x400000, Top = 0x827000
Name = ntdll.dll, Base = 0x7C920000, Top = 0x7C9B4000
Name = kernel32.dll, Base = 0x7C800000, Top = 0x7C91D000
Name = COMCTL32.dll, Base = 0x77180000, Top = 0x77283000
Name = msvcrt.dll, Base = 0x77BE0000, Top = 0x77C38000
Name = ADVAPI32.dll, Base = 0x77DA0000, Top = 0x77E49000
Name = RPCRT4.dll, Base = 0x77E50000, Top = 0x77EE2000
Name = Secur32.dll, Base = 0x77FC0000, Top = 0x77FD1000
Name = GDI32.dll, Base = 0x77EF0000, Top = 0x77F37000
Name = USER32.dll, Base = 0x77D10000, Top = 0x77D9F000
Name = SHLWAPI.dll, Base = 0x77F40000, Top = 0x77FB6000
Name = IMM32.DLL, Base = 0x76300000, Top = 0x7631D000
Name = LPK.DLL, Base = 0x62C20000, Top = 0x62C29000
Name = USP10.dll, Base = 0x73FA0000, Top = 0x7400B000
Name = ijt_base.dll, Base = 0x70000000, Top = 0x70014000
Name = SHELL32.dll, Base = 0x7D590000, Top = 0x7DD83000
Name = olemon.dll, Base = 0x10000000, Top = 0x1000F000
Name = ole32.dll, Base = 0x76990000, Top = 0x76ACD000
Name = winmm.dll, Base = 0x76B10000, Top = 0x76B3A000
Name = qmhelper.dll, Base = 0x2850000, Top = 0x2858000
==>
Name = MFC42.DLL, Base = 0x73D30000, Top = 0x73E2E000
Name = MFC42LOC.DLL, Base = 0x61BE0000, Top = 0x61BED000
Name = OLEAUT32.dll, Base = 0x770F0000, Top = 0x7717B000
Name = urlmon.dll, Base = 0x420B0000, Top = 0x421D7000
Name = iertutil.dll, Base = 0x41D50000, Top = 0x41D95000
Name = MSVCP60.dll, Base = 0x75FF0000, Top = 0x76055000
Name = WINIO.dll, Base = 0x29A0000, Top = 0x29B3000
Name = helper.dll, Base = 0x2AD0000, Top = 0x2ADE000
Name = BException.dll, Base = 0x2BF0000, Top = 0x2BFD000
Name = WS2_32.dll, Base = 0x71A20000, Top = 0x71A37000
Name = WS2HELP.dll, Base = 0x71A10000, Top = 0x71A18000
Name = comdlg32.dll, Base = 0x76320000, Top = 0x76367000
Name = uxtheme.dll, Base = 0x5ADC0000, Top = 0x5ADF7000
Name = msimg32.dll, Base = 0x762F0000, Top = 0x762F5000
Name = safemon.dll, Base = 0x2DE0000, Top = 0x2DFD000
Name = MSCTF.dll, Base = 0x74680000, Top = 0x746CC000
Name = WININET.dll, Base = 0x41FD0000, Top = 0x4209F000
Name = Normaliz.dll, Base = 0x2F60000, Top = 0x2F69000
Name = cooper.dll, Base = 0x3180000, Top = 0x31ED000
Name = RASAPI32.dll, Base = 0x76EB0000, Top = 0x76EEC000
Name = rasman.dll, Base = 0x76E60000, Top = 0x76E72000
Name = NETAPI32.dll, Base = 0x5FDD0000, Top = 0x5FE24000
Name = TAPI32.dll, Base = 0x76E80000, Top = 0x76EAF000
Name = rtutils.dll, Base = 0x76E50000, Top = 0x76E5E000
Name = USERENV.dll, Base = 0x759D0000, Top = 0x75A7E000
Name = mswsock.dll, Base = 0x719C0000, Top = 0x719FE000
Name = hnetcfg.dll, Base = 0x60FD0000, Top = 0x61025000
Name = msv1_0.dll, Base = 0x77C40000, Top = 0x77C63000
Name = iphlpapi.dll, Base = 0x76D30000, Top = 0x76D48000
Name = wshtcpip.dll, Base = 0x71A00000, Top = 0x71A08000
Name = sensapi.dll, Base = 0x72240000, Top = 0x72245000
Name = DNSAPI.dll, Base = 0x76EF0000, Top = 0x76F17000
Name = msctfime.ime, Base = 0x73640000, Top = 0x7366E000
Name = winrnr.dll, Base = 0x76F80000, Top = 0x76F88000
Name = WLDAP32.dll, Base = 0x76F30000, Top = 0x76F5C000
Name = CLBCATQ.DLL, Base = 0x76FA0000, Top = 0x7701F000
Name = COMRes.dll, Base = 0x77020000, Top = 0x770BA000
Name = VERSION.dll, Base = 0x77BD0000, Top = 0x77BD8000
Name = rasadhlp.dll, Base = 0x76F90000, Top = 0x76F96000
Name = ieframe.dll, Base = 0x422B0000, Top = 0x4287D000
Name = PSAPI.DLL, Base = 0x76BC0000, Top = 0x76BCB000
Name = apphelp.dll, Base = 0x76D70000, Top = 0x76D92000
Name = SXS.DLL, Base = 0x75E00000, Top = 0x75EAE000
Name = DHCPCSVC.DLL, Base = 0x76D50000, Top = 0x76D6D000
Name = netman.dll, Base = 0x77CD0000, Top = 0x77D03000
Name = MPRAPI.dll, Base = 0x76D10000, Top = 0x76D28000
Name = ACTIVEDS.dll, Base = 0x77C90000, Top = 0x77CC2000
Name = adsldpc.dll, Base = 0x76DE0000, Top = 0x76E05000
Name = ATL.DLL, Base = 0x76AF0000, Top = 0x76B01000
Name = SAMLIB.dll, Base = 0x71B70000, Top = 0x71B83000
Name = SETUPAPI.dll, Base = 0x76060000, Top = 0x761B6000
Name = netshell.dll, Base = 0x74770000, Top = 0x7490A000
Name = credui.dll, Base = 0x76BD0000, Top = 0x76BFD000
Name = WZCSAPI.DLL, Base = 0x72FA0000, Top = 0x72FB0000
Name = WZCSvc.DLL, Base = 0x77290000, Top = 0x772FE000
Name = WMI.dll, Base = 0x76D00000, Top = 0x76D04000
Name = CRYPT32.dll, Base = 0x765E0000, Top = 0x76672000
Name = MSASN1.dll, Base = 0x76DB0000, Top = 0x76DC2000
Name = WTSAPI32.dll, Base = 0x76F20000, Top = 0x76F28000
Name = WINSTA.dll, Base = 0x762D0000, Top = 0x762E0000
Name = ESENT.dll, Base = 0x5DF20000, Top = 0x5E026000
Name = xpsp2res.dll, Base = 0x20000000, Top = 0x20549000
Name = vgr.dll, Base = 0x4B50000, Top = 0x4B59000
Name = mshtml.dll, Base = 0x42990000, Top = 0x42D04000
Name = msls31.dll, Base = 0x2EF0000, Top = 0x2F19000
Name = MLANG.dll, Base = 0x74CF0000, Top = 0x74D81000
Name = msimtf.dll, Base = 0x74650000, Top = 0x7467A000
Name = wdmaud.drv, Base = 0x72C90000, Top = 0x72C99000
Name = WINTRUST.dll, Base = 0x76C00000, Top = 0x76C2E000
Name = IMAGEHLP.dll, Base = 0x76C60000, Top = 0x76C88000
Name = msacm32.drv, Base = 0x72C80000, Top = 0x72C88000
Name = MSACM32.dll, Base = 0x77BB0000, Top = 0x77BC5000
Name = midimap.dll, Base = 0x77BA0000, Top = 0x77BA7000
Name = MSScript.ocx, Base = 0x6B980000, Top = 0x6B999000
Name = VBScript.dll, Base = 0x73300000, Top = 0x73365000
Name = BkgndColor.dll, Base = 0x6110000, Top = 0x6125000
Name = Console.dll, Base = 0x6230000, Top = 0x623D000
Name = File.dll, Base = 0x6350000, Top = 0x635F000
Name = GetSysInfo.dll, Base = 0x6470000, Top = 0x6482000
Name = Memory.dll, Base = 0x4690000, Top = 0x46A5000
Name = Window.dll, Base = 0x46C0000, Top = 0x46C8000
Name = mshtmled.dll, Base = 0x41F50000, Top = 0x41FC7000
Name = RavScrCh.dll, Base = 0x4750000, Top = 0x4778000
Name = jscript.dll, Base = 0x63380000, Top = 0x633F8000
Name = QMDISP~1.DLL, Base = 0x3F10000, Top = 0x3F5E000
Code Before:
5B C2 04 00 CC CC CC CC CC 8B FF 56 8B F1 8B 4C 24 08 8B 01
Current Code:
83 78 F4 00 7C 0E 89 06 83 C0 F4 50 FF 15 24 62 DD 73 EB 10
Call Stack:
02D34008
02DC8008
06997F30
02DD4AA0
00390178
00390178
02DB7AB8
02D3E0B0
02D41B68
02D14208
02D26980
02D500D0
00000000
Current Stack:
[0012F874] = 06980D88
[0012F878] = 00444702
[0012F87C] = 02DCBB60
[0012F880] = 0012F8A8
[0012F884] = 02D0F6C0
[0012F888] = 02DC8008
[0012F88C] = 0012F948
[0012F890] = 001D0770
[0012F894] = 06980D80
[0012F898] = 77C05C94
[0012F89C] = 77BE2070
[0012F8A0] = FFFFFFFF
[0012F8A4] = 0012F880
[0012F8A8] = 0012F8C0
[0012F8AC] = 00594ED0
[0012F8B0] = 00000000
[0012F8B4] = 0044495D
[0012F8B8] = 02DC8008
[0012F8BC] = 000003FF
[0012F8C0] = 0012F93C
[0012F8C4] = 00594EE8
[0012F8C8] = 00000000
[0012F8CC] = 73D31FCC
[0012F8D0] = 0698C3B0
[0012F8D4] = 000003FF
[0012F8D8] = 02DC8008
[0012F8DC] = 02DC8008
[0012F8E0] = 00169160
[0012F8E4] = 00000000
[0012F8E8] = 00000000
[0012F8EC] = 00000000
[0012F8F0] = 73DC82B0
[0012F8F4] = 00000004
[0012F8F8] = 0012F9C8
[0012F8FC] = 001D0770
[0012F900] = 00169160
[0012F904] = 0012F8C8
[0012F908] = 0012F954
[0012F90C] = 73DCEFA4
[0012F910] = 00000000
[0012F914] = 0012F934
[0012F918] = 73D31A58
[0012F91C] = 00000000
[0012F920] = 00000000
[0012F924] = 00000215
[0012F928] = 00000000
[0012F92C] = 00000000
[0012F930] = 73DC8444
[0012F934] = 005B3530
[0012F938] = 00000000
[0012F93C] = 0012F9BC
[0012F940] = 73DCEFF1
[0012F944] = FFFFFFFF
[0012F948] = 0012F968
[0012F94C] = 73D31B9B
[0012F950] = 00000112
[0012F954] = 0000F060
[0012F958] = 005B3568
[0012F95C] = 0012F964
[0012F960] = 00000112
[0012F964] = 00000000
[0012F968] = 0012F9C8
[0012F96C] = 73D31B05
[0012F970] = 00000112
[0012F974] = 0000F060
[0012F978] = 000003FF
[0012F97C] = 0012FA7C
[0012F980] = 001D0770
[0012F984] = 00000000
[0012F988] = 001D0770
[0012F98C] = 000000A1
[0012F990] = 00000014
[0012F994] = 000003FF
[0012F998] = 00000000
[0012F99C] = 00000000
[0012F9A0] = 00000000
[0012F9A4] = 73DC82B0
[0012F9A8] = 00000004
[0012F9AC] = 0012FA7C
[0012F9B0] = 001D0770
[0012F9B4] = 00169160
[0012F9B8] = 0012F97C
[0012F9BC] = 0012FA08
[0012F9C0] = 73DCEFA4
[0012F9C4] = 00000000
[0012F9C8] = 0012F9E8
[0012F9CC] = 73D31A58
[0012F9D0] = 02DC8008
[0012F9D4] = 00000000
[0012F9D8] = 00000112
[0012F9DC] = 0000F060
[0012F9E0] = 000003FF
[0012F9E4] = 73DC8444
[0012F9E8] = 0012FA14
[0012F9EC] = 73DC847D
[0012F9F0] = 001D0770
[0012F9F4] = 00000112
[0012F9F8] = 0000F060
[0012F9FC] = 000003FF
[0012FA00] = 00169558 |
|