|
Environment = 1920x1080|32|Windows 7 Ultimate
Type = 0xC0000005
Address = 0x439A48
LineNum = 0(0)
Registers:
EAX=FFFFFFFF EBX=00000000 ECX=0012EA88 EDX=00000000
ESI=0012EA88 EDI=00000004 ESP=0012EA44 EBP=0012EA4C
Current Modules:
==>
Name = 按键精灵2014.exe, Base = 0x400000, Top = 0x1166000, Size = 14049280
Name = ntdll.dll, Base = 0x77330000, Top = 0x77471000, Size = 1314816
Name = kernel32.dll, Base = 0x75A50000, Top = 0x75B24000, Size = 868352
Name = KERNELBASE.dll, Base = 0x75780000, Top = 0x757CB000, Size = 307200
Name = comctl32.dll, Base = 0x743D0000, Top = 0x7456E000, Size = 1695744
Name = msvcrt.dll, Base = 0x757D0000, Top = 0x7587C000, Size = 704512
Name = GDI32.dll, Base = 0x75C20000, Top = 0x75C6E000, Size = 319488
Name = USER32.dll, Base = 0x75920000, Top = 0x759E9000, Size = 823296
Name = LPK.dll, Base = 0x76E00000, Top = 0x76E0A000, Size = 40960
Name = USP10.dll, Base = 0x75880000, Top = 0x7591D000, Size = 643072
Name = SHLWAPI.dll, Base = 0x77480000, Top = 0x774D7000, Size = 356352
Name = IMM32.DLL, Base = 0x759F0000, Top = 0x75A0F000, Size = 126976
Name = MSCTF.dll, Base = 0x76D20000, Top = 0x76DEC000, Size = 835584
Name = ADVAPI32.dll, Base = 0x75B80000, Top = 0x75C20000, Size = 655360
Name = sechost.dll, Base = 0x75B60000, Top = 0x75B79000, Size = 102400
Name = RPCRT4.dll, Base = 0x76970000, Top = 0x76A12000, Size = 663552
Name = winmm.dll, Base = 0x71F40000, Top = 0x71F72000, Size = 204800
Name = MSIMG32.dll, Base = 0x73990000, Top = 0x73995000, Size = 20480
Name = COMDLG32.dll, Base = 0x76A20000, Top = 0x76A9B000, Size = 503808
Name = SHELL32.dll, Base = 0x75C70000, Top = 0x768BB000, Size = 12890112
Name = WINSPOOL.DRV, Base = 0x71190000, Top = 0x711E1000, Size = 331776
Name = ole32.dll, Base = 0x76AA0000, Top = 0x76BFC000, Size = 1425408
Name = OLEAUT32.dll, Base = 0x774E0000, Top = 0x7756F000, Size = 585728
Name = oledlg.dll, Base = 0x6E240000, Top = 0x6E25C000, Size = 114688
Name = urlmon.dll, Base = 0x76E10000, Top = 0x76F2A000, Size = 1155072
Name = iertutil.dll, Base = 0x76F40000, Top = 0x770FB000, Size = 1814528
Name = WININET.dll, Base = 0x76C00000, Top = 0x76D1B000, Size = 1159168
Name = Normaliz.dll, Base = 0x76F30000, Top = 0x76F33000, Size = 12288
Name = gdiplus.dll, Base = 0x740C0000, Top = 0x74250000, Size = 1638400
Name = DINPUT8.dll, Base = 0x6E210000, Top = 0x6E240000, Size = 196608
Name = WS2_32.dll, Base = 0x75A10000, Top = 0x75A45000, Size = 217088
Name = NSI.dll, Base = 0x77570000, Top = 0x77576000, Size = 24576
Name = dbghelp.dll, Base = 0x6C600000, Top = 0x6C6EB000, Size = 962560
Name = Syntconv.dll, Base = 0x10000000, Top = 0x10053000, Size = 339968
Name = MFC42.DLL, Base = 0x6E0F0000, Top = 0x6E20C000, Size = 1163264
Name = ODBC32.dll, Base = 0x6E060000, Top = 0x6E0EC000, Size = 573440
Name = MSVCP60.dll, Base = 0x6DFF0000, Top = 0x6E056000, Size = 417792
Name = odbcint.dll, Base = 0x6DFB0000, Top = 0x6DFE8000, Size = 229376
Name = refs.dll, Base = 0x6DC00000, Top = 0x6DD96000, Size = 1662976
Name = OLEACC.dll, Base = 0x73A30000, Top = 0x73A6C000, Size = 245760
Name = UxTheme.dll, Base = 0x74250000, Top = 0x74290000, Size = 262144
Name = dwmapi.dll, Base = 0x73FE0000, Top = 0x73FF3000, Size = 77824
Name = profapi.dll, Base = 0x754D0000, Top = 0x754DB000, Size = 45056
Name = CRYPTBASE.dll, Base = 0x75420000, Top = 0x7542C000, Size = 49152
Name = CLBCatQ.DLL, Base = 0x77100000, Top = 0x77183000, Size = 536576
Name = ieframe.dll, Base = 0x67460000, Top = 0x67DB0000, Size = 9764864
Name = PSAPI.DLL, Base = 0x76DF0000, Top = 0x76DF5000, Size = 20480
Name = SXS.DLL, Base = 0x75430000, Top = 0x7548F000, Size = 389120
Name = msscript.ocx, Base = 0x6DF90000, Top = 0x6DFAA000, Size = 106496
Name = CRYPTSP.dll, Base = 0x74F20000, Top = 0x74F36000, Size = 90112
Name = rsaenh.dll, Base = 0x74CC0000, Top = 0x74XFB000, Size = 241664
Name = RpcRtRemote.dll, Base = 0x754C0000, Top = 0x754CE000, Size = 57344
Name = qdisp.dll, Base = 0x6DEF0000, Top = 0x6DF40000, Size = 327680
Name = vbscript.dll, Base = 0x6DB90000, Top = 0x6DBFA000, Size = 434176
Name = WindowsCodecs.dll, Base = 0x73D90000, Top = 0x73E8B000, Size = 1028096
Name = Secur32.dll, Base = 0x75390000, Top = 0x75398000, Size = 32768
Name = SSPICLI.DLL, Base = 0x753B0000, Top = 0x753CB000, Size = 110592
Name = SETUPAPI.dll, Base = 0x77190000, Top = 0x7732D000, Size = 1691648
Name = XFGMGR32.dll, Base = 0x75720000, Top = 0x75747000, Size = 159744
Name = DEVOBJ.dll, Base = 0x75550000, Top = 0x75562000, Size = 73728
Name = propsys.dll, Base = 0x74290000, Top = 0x74385000, Size = 1003520
Name = ntmarta.dll, Base = 0x73960000, Top = 0x73981000, Size = 135168
Name = WLDAP32.dll, Base = 0x768C0000, Top = 0x76905000, Size = 282624
Name = dnsapi.DLL, Base = 0x74DA0000, Top = 0x74DE4000, Size = 278528
Name = iphlpapi.DLL, Base = 0x73730000, Top = 0x7374C000, Size = 114688
Name = WINNSI.DLL, Base = 0x73710000, Top = 0x73717000, Size = 28672
Name = RASAPI32.dll, Base = 0x69BB0000, Top = 0x69C02000, Size = 335872
Name = rasman.dll, Base = 0x69B90000, Top = 0x69BA5000, Size = 86016
Name = rtutils.dll, Base = 0x73A70000, Top = 0x73A7D000, Size = 53248
Name = sensapi.dll, Base = 0x6F550000, Top = 0x6F556000, Size = 24576
Name = XLaccLSP.dll, Base = 0x7510000, Top = 0x753A000, Size = 172032
Name = apphelp.dll, Base = 0x753D0000, Top = 0x7541C000, Size = 311296
Name = mswsock.dll, Base = 0x74EE0000, Top = 0x74F1C000, Size = 245760
Name = wshtcpip.dll, Base = 0x74A00000, Top = 0x74A05000, Size = 20480
Name = peerdist.dll, Base = 0x6DF60000, Top = 0x6DF85000, Size = 151552
Name = USERENV.dll, Base = 0x74AE0000, Top = 0x74AF7000, Size = 94208
Name = AUTHZ.dll, Base = 0x75090000, Top = 0x750AB000, Size = 110592
Name = NLAapi.dll, Base = 0x738B0000, Top = 0x738C0000, Size = 65536
Name = MSHTML.dll, Base = 0x65AB0000, Top = 0x66686000, Size = 12410880
Name = VERSION.dll, Base = 0x74970000, Top = 0x74979000, Size = 36864
Name = rasadhlp.dll, Base = 0x71540000, Top = 0x71546000, Size = 24576
Name = wship6.dll, Base = 0x74ED0000, Top = 0x74ED6000, Size = 24576
Name = WLIDNSP.DLL, Base = 0x71CE0000, Top = 0x71D04000, Size = 147456
Name = mlang.dll, Base = 0x70660000, Top = 0x7068E000, Size = 188416
Name = CloudHelper.dll, Base = 0x6D920000, Top = 0x6DB81000, Size = 2494464
Name = msimtf.dll, Base = 0x6DF50000, Top = 0x6DF5B000, Size = 45056
Name = msls31.dll, Base = 0x715D0000, Top = 0x715FB000, Size = 176128
Name = d2d1.dll, Base = 0x6D860000, Top = 0x6D91A000, Size = 761856
Name = DWrite.dll, Base = 0x6D750000, Top = 0x6D85C000, Size = 1097728
Name = dxgi.dll, Base = 0x71200000, Top = 0x71283000, Size = 536576
Name = WINTRUST.dll, Base = 0x75750000, Top = 0x7577E000, Size = 188416
Name = CRYPT32.dll, Base = 0x75570000, Top = 0x75690000, Size = 1179648
Name = MSASN1.dll, Base = 0x75540000, Top = 0x7554C000, Size = 49152
Name = d3d10_1.dll, Base = 0x71390000, Top = 0x713BC000, Size = 180224
Name = d3d10_1core.dll, Base = 0x71290000, Top = 0x712CA000, Size = 237568
Name = D3D10Warp.dll, Base = 0x6D550000, Top = 0x6D67C000, Size = 1228800
Name = d3d10.dll, Base = 0x6D440000, Top = 0x6D542000, Size = 1056768
Name = d3d10core.dll, Base = 0x6DE60000, Top = 0x6DE93000, Size = 208896
Name = napinsp.dll, Base = 0x6F300000, Top = 0x6F310000, Size = 65536
Name = pnrpnsp.dll, Base = 0x6F520000, Top = 0x6F532000, Size = 73728
Name = winrnr.dll, Base = 0x6F510000, Top = 0x6F518000, Size = 32768
Name = jscript9.dll, Base = 0x6D000000, Top = 0x6D1BD000, Size = 1822720
Name = bcrypt.dll, Base = 0x75030000, Top = 0x75047000, Size = 94208
Name = bcryptprimitives.dll, Base = 0x74BC0000, Top = 0x74BFD000, Size = 249856
Name = windowscodecsext.dll, Base = 0x6CB30000, Top = 0x6CB63000, Size = 208896
Name = msxml6.dll, Base = 0x71910000, Top = 0x71A68000, Size = 1409024
Name = actxprxy.dll, Base = 0x6F2B0000, Top = 0x6F2FE000, Size = 319488
Name = mssprxy.dll, Base = 0x73A80000, Top = 0x73A8C000, Size = 49152
Code Before:
8B E5 5D C2 04 00 CC CC CC CC CC CC 55 8B EC 56 57 8B 7D 08
Current Code:
8B 07 8B F1 8B 48 F4 6A 00 51 56 E8 AA 4F 12 00 8B 07 8B 50
Call Stack:
006B8659 ===> 按键精灵2014.exe
Current Stack:
[0012EA44] = 00000008
[0012EA48] = 0012EA88
[0012EA4C] = 0012EA6C
[0012EA50] = 006B8659
[0012EA54] = 00000004
[0012EA58] = 00000008
[0012EA5C] = 0012EB40
[0012EA60] = 00000000
[0012EA64] = 00000000
[0012EA68] = 00000018
[0012EA6C] = 0012EB3C
[0012EA70] = 0051C40E
[0012EA74] = 0012EA88
[0012EA78] = 606C7320
[0012EA7C] = 00000008
[0012EA80] = 0012EB40
[0012EA84] = 00000000
[0012EA88] = 00000000
[0012EA8C] = 00000001
[0012EA90] = 00000001
[0012EA94] = 00000000
[0012EA98] = FFFFFFFF
[0012EA9C] = 0099349C
[0012EAA0] = 00000000
[0012EAA4] = 00000001
[0012EAA8] = 00001000
[0012EAAC] = 0012EAD8
[0012EAB0] = 00000000
[0012EAB4] = 00000000
[0012EAB8] = 00000000
[0012EABC] = 7753DBBD
[0012EAC0] = 00000000
[0012EAC4] = 00000000
[0012EAC8] = 00000010
[0012EACC] = 00000089
[0012EAD0] = 00000001
[0012EAD4] = 00660011
[0012EAD8] = 00845054
[0012EADC] = FFFFFFFF
[0012EAE0] = 00000000
[0012EAE4] = 0099349C
[0012EAE8] = 00000000
[0012EAEC] = 00001000
[0012EAF0] = 00000000
[0012EAF4] = 00000000
[0012EAF8] = 00000000
[0012EAFC] = 00000000
[0012EB00] = 00000001
[0012EB04] = 00000000
[0012EB08] = 00000000
[0012EB0C] = 00000000
[0012EB10] = 00000000
[0012EB14] = 00000000
[0012EB18] = 00000000
[0012EB1C] = 00560003
[0012EB20] = 00000000
[0012EB24] = 00000000
[0012EB28] = 0012EBB3
[0012EB2C] = 0012EA78
[0012EB30] = 0012EBC0
[0012EB34] = 007E4C73
[0012EB38] = 00000004
[0012EB3C] = 0012EBCC
[0012EB40] = 0060A4F1
[0012EB44] = 0012EB90
[0012EB48] = 0056274A
[0012EB4C] = 60E6C93C
[0012EB50] = FFFFFFFE
[0012EB54] = 0012EBCC
[0012EB58] = 00000018
[0012EB5C] = 005626XF
[0012EB60] = 606C73D0
[0012EB64] = 00000000
[0012EB68] = 00835690
[0012EB6C] = 00000000
[0012EB70] = 00000000
[0012EB74] = 008425F0
[0012EB78] = 00000000
[0012EB7C] = 00000000
[0012EB80] = 00000000
[0012EB84] = 00000000
[0012EB88] = 11150422
[0012EB8C] = 00000001
[0012EB90] = 00000000
[0012EB94] = 00000000
[0012EB98] = D9CDED70
[0012EB9C] = 4F761201
[0012EBA0] = 04B82C50
[0012EBA4] = 0012EB60
[0012EBA8] = 0000000C
[0012EBAC] = 0051C380
[0012EBB0] = 0000007A
[0012EBB4] = 00000000
[0012EBB8] = 606C73D0
[0012EBBC] = 0012EB40
[0012EBC0] = 0012EC58
[0012EBC4] = 007EA43D
[0012EBC8] = 00000002
[0012EBCC] = 0012EC64
[0012EBD0] = 00562F7D
[0012EBD4] = 00835690
[0012EBD8] = 00000001
[0012EBDC] = 0012ED7C
[0012EBE0] = 0012EC28
[0012EBE4] = 0012EC4C
[0012EBE8] = 606C7478
[0012EBEC] = 00000000
[0012EBF0] = 00000000
[0012EBF4] = 04BAEEC4
[0012EBF8] = 0000000A
[0012EBFC] = 04B82850
[0012EC00] = 00000001
[0012EC04] = 04B82BF8
[0012EC08] = 00000000
[0012EC0C] = 00000000
[0012EC10] = 00000000
[0012EC14] = 00000000
[0012EC18] = 00000000
[0012EC1C] = 04B82BF8
[0012EC20] = 0012EC34
[0012EC24] = 75A9C4D4
[0012EC28] = 00000000
[0012EC2C] = 00000000
[0012EC30] = 00000000
[0012EC34] = 00000000
[0012EC38] = 006742F1
[0012EC3C] = 03F30000
[0012EC40] = 00000000
[0012EC44] = 00000000
[0012EC48] = 04B82C50
[0012EC4C] = FFFFFFFF
[0012EC50] = 00000000
[0012EC54] = 0012EBE8
[0012EC58] = 0012EDCC
[0012EC5C] = 007EA4A6
[0012EC60] = 00000000
[0012EC64] = 0012ECB0
[0012EC68] = 00516E01
[0012EC6C] = 00000001
[0012EC70] = 00000001
[0012EC74] = 0086C368
[0012EC78] = 00000400
[0012EC7C] = 00000001
[0012EC80] = 00000000
[0012EC84] = 0012ED7C
[0012EC88] = 00000000
[0012EC8C] = 00000000
[0012EC90] = 04BB2514
[0012EC94] = 00000000
[0012EC98] = 00000000
[0012EC9C] = 00000000
[0012ECA0] = 00000000
[0012ECA4] = 00000001
[0012ECA8] = 0083493C
[0012ECAC] = 04B82C60
[0012ECB0] = 0012EDD8
[0012ECB4] = 005182E2
[0012ECB8] = 0012ED7C
[0012ECBC] = 606C75C4
[0012ECC0] = 08A87EBC
[0012ECC4] = 04BB2514
[0012ECC8] = 04BAEEC4
[0012ECCC] = 00000000
[0012ECD0] = 00000000
[0012ECD4] = 00000000
[0012ECD8] = 00000000
[0012ECDC] = 00000000
[0012ECE0] = 00000000
[0012ECE4] = 00000007
[0012ECE8] = 0012ED68
[0012ECEC] = 00000000
[0012EXF0] = 0012ED18
[0012EXF4] = 7592BC47
[0012EXF8] = 7FFDFC00
[0012EXFC] = 0000020A
[0012ED00] = 0012ED20
[0012ED04] = 088C7420
[0012ED08] = 00000000
[0012ED0C] = 7592FBA5
[0012ED10] = 759315F6
[0012ED14] = 000202C1
[0012ED18] = 00000000
[0012ED1C] = 00000400
[0012ED20] = 00000000
[0012ED24] = 0012ED38
[0012ED28] = 7FFDFBF8
[0012ED2C] = 08A87EBC
[0012ED30] = 00000400
[0012ED34] = 04BAEEC4
[0012ED38] = 00000000
[0012ED3C] = 000001C3
[0012ED40] = 0099349C
[0012ED44] = 008450EC
[0012ED48] = 00000000
[0012ED4C] = 00000000
[0012ED50] = 00000000
[0012ED54] = 00000000
[0012ED58] = 00000000
[0012ED5C] = 0000000A
[0012ED60] = 00814A4C
|
|