|
按键精灵 2014.05.17762 版
Environment = 1366x768|32|Windows 10 Enterprise
Type = 0xC0000005
Address = 0x48D152
LineNum = 0(0)
Registers:
EAX=FFFFFFFF EBX=00000000 ECX=063A37F0 EDX=FFFFFFFF
ESI=063A5224 EDI=063A5220 ESP=0019DA94 EBP=0019DC14
Current Modules:
==>
Name = 按键精灵2014.exe, Base = 0x400000, Top = 0x1179000, Size = 14127104
Name = ntdll.dll, Base = 0x77040000, Top = 0x771DA000, Size = 1679360
Name = KERNEL32.DLL, Base = 0x76230000, Top = 0x76310000, Size = 917504
Name = KERNELBASE.dll, Base = 0x74990000, Top = 0x74B8C000, Size = 2080768
Name = comctl32.dll, Base = 0x727B0000, Top = 0x729BF000, Size = 2158592
Name = msvcrt.dll, Base = 0x74EE0000, Top = 0x74F9F000, Size = 782336
Name = combase.dll, Base = 0x74C60000, Top = 0x74ED6000, Size = 2580480
Name = ucrtbase.dll, Base = 0x76510000, Top = 0x7662F000, Size = 1175552
Name = RPCRT4.dll, Base = 0x75130000, Top = 0x751EB000, Size = 765952
Name = SspiCli.dll, Base = 0x74810000, Top = 0x74830000, Size = 131072
Name = CRYPTBASE.dll, Base = 0x74800000, Top = 0x7480A000, Size = 40960
Name = bcryptPrimitives.dll, Base = 0x764A0000, Top = 0x764FF000, Size = 389120
Name = sechost.dll, Base = 0x753E0000, Top = 0x75456000, Size = 483328
Name = GDI32.dll, Base = 0x74960000, Top = 0x74981000, Size = 135168
Name = win32u.dll, Base = 0x74C40000, Top = 0x74C57000, Size = 94208
Name = gdi32full.dll, Base = 0x75250000, Top = 0x753AA000, Size = 1417216
Name = msvcp_win.dll, Base = 0x75A20000, Top = 0x75A9C000, Size = 507904
Name = USE**.dll, Base = 0x766B0000, Top = 0x76847000, Size = 1667072
Name = IMM32.DLL, Base = 0x76850000, Top = 0x76875000, Size = 151552
Name = ADVAPI32.dll, Base = 0x750B0000, Top = 0x75129000, Size = 495616
Name = winmm.dll, Base = 0x725D0000, Top = 0x725F4000, Size = 147456
Name = winmmbase.dll, Base = 0x71FD0000, Top = 0x71FF3000, Size = 143360
Name = cfgmg**.dll, Base = 0x76980000, Top = 0x769BB000, Size = 241664
Name = MSIMG32.dll, Base = 0x70C90000, Top = 0x70C96000, Size = 24576
Name = COMDLG32.dll, Base = 0x75000000, Top = 0x750B0000, Size = 720896
Name = shcore.dll, Base = 0x748D0000, Top = 0x74954000, Size = 540672
Name = SHLWAPI.dll, Base = 0x75200000, Top = 0x75244000, Size = 278528
Name = SHELL32.dll, Base = 0x75AC0000, Top = 0x7603A000, Size = 5742592
Name = windows.storage.dll, Base = 0x76A50000, Top = 0x77015000, Size = 6049792
Name = profapi.dll, Base = 0x75AA0000, Top = 0x75AB7000, Size = 94208
Name = powrprof.dll, Base = 0x76310000, Top = 0x76353000, Size = 274432
Name = UMPDC.dll, Base = 0x76640000, Top = 0x7664D000, Size = 53248
Name = kernel.appcore.dll, Base = 0x77020000, Top = 0x7702F000, Size = 61440
Name = cryptsp.dll, Base = 0x753C0000, Top = 0x753D3000, Size = 77824
Name = WINSPOOL.DRV, Base = 0x661E0000, Top = 0x6624B000, Size = 438272
Name = bcrypt.dll, Base = 0x76380000, Top = 0x76399000, Size = 102400
Name = PROPSYS.dll, Base = 0x70AB0000, Top = 0x70B75000, Size = 806912
Name = IPHLPAPI.DLL, Base = 0x743B0000, Top = 0x743E2000, Size = 204800
Name = OLEAUT32.dll, Base = 0x74830000, Top = 0x748C2000, Size = 598016
Name = ole32.dll, Base = 0x76880000, Top = 0x76977000, Size = 1011712
Name = oledlg.dll, Base = 0x63110000, Top = 0x6313C000, Size = 180224
Name = urlmon.dll, Base = 0x72600000, Top = 0x727AB000, Size = 1748992
Name = iertutil.dll, Base = 0x71DA0000, Top = 0x71FC9000, Size = 2265088
Name = gdiplus.dll, Base = 0x72000000, Top = 0x72169000, Size = 1478656
Name = PSAPI.DLL, Base = 0x76630000, Top = 0x76636000, Size = 24576
Name = VERSION.dll, Base = 0x74400000, Top = 0x74408000, Size = 32768
Name = DINPUT8.dll, Base = 0x630D0000, Top = 0x63107000, Size = 225280
Name = SensApi.dll, Base = 0x630C0000, Top = 0x630C8000, Size = 32768
Name = WININET.dll, Base = 0x72170000, Top = 0x725CC000, Size = 4571136
Name = inputhost.dll, Base = 0x65FB0000, Top = 0x66072000, Size = 794624
Name = CoreMessaging.dll, Base = 0x71780000, Top = 0x71809000, Size = 561152
Name = CoreUIComponents.dll, Base = 0x71520000, Top = 0x7177E000, Size = 2482176
Name = wintypes.dll, Base = 0x71440000, Top = 0x7151A000, Size = 892928
Name = ntmarta.dll, Base = 0x73C30000, Top = 0x73C59000, Size = 167936
Name = WS2_32.dll, Base = 0x76650000, Top = 0x766AE000, Size = 385024
Name = dbghelp.dll, Base = 0x738B0000, Top = 0x73A3F000, Size = 1634304
Name = Syntconv.dll, Base = 0x10000000, Top = 0x10053000, Size = 339968
Name = MSVCP60.dll, Base = 0x62F20000, Top = 0x62F90000, Size = 458752
Name = MFC42.DLL, Base = 0x62F90000, Top = 0x630B4000, Size = 1196032
Name = refs.dll, Base = 0x62D80000, Top = 0x62F16000, Size = 1662976
Name = OLEACC.dll, Base = 0x70CA0000, Top = 0x70CF3000, Size = 339968
Name = UxTheme.dll, Base = 0x71**000, Top = 0x71BCA000, Size = 499712
Name = dwmapi.dll, Base = 0x63C10000, Top = 0x63C35000, Size = 151552
Name = MSCTF.dll, Base = 0x75460000, Top = 0x75563000, Size = 1060864
Name = clbcatq.dll, Base = 0x76040000, Top = 0x760C0000, Size = 524288
Name = ieframe.dll, Base = 0x62780000, Top = 0x62D7A000, Size = 6266880
Name = NETAPI32.dll, Base = 0x62760000, Top = 0x62773000, Size = 77824
Name = WINHTTP.dll, Base = 0x66120000, Top = 0x661DE000, Size = 778240
Name = WKSCLI.DLL, Base = 0x660D0000, Top = 0x660E0000, Size = 65536
Name = NETUTILS.DLL, Base = 0x660C0000, Top = 0x660CB000, Size = 45056
Name = msIso.dll, Base = 0x62710000, Top = 0x62753000, Size = 274432
Name = ondemandconnroutehelper.dll, Base = 0x626F0000, Top = 0x62702000, Size = 73728
Name = mswsock.dll, Base = 0x73C60000, Top = 0x73CB2000, Size = 335872
Name = NSI.dll, Base = 0x76500000, Top = 0x76507000, Size = 28672
Name = WINNSI.DLL, Base = 0x626E0000, Top = 0x626E8000, Size = 32768
Name = dataexchange.dll, Base = 0x63DB0000, Top = 0x63DE1000, Size = 200704
Name = d3d11.dll, Base = 0x73D20000, Top = 0x73EFE000, Size = 1957888
Name = dcomp.dll, Base = 0x63C40000, Top = 0x63DA9000, Size = 1478656
Name = dxgi.dll, Base = 0x73F20000, Top = 0x73FE1000, Size = 790528
Name = dxcore.dll, Base = 0x73F00000, Top = 0x73F19000, Size = 102400
Name = twinapi.appcore.dll, Base = 0x65DB0000, Top = 0x65F94000, Size = 1982464
Name = RMCLIENT.dll, Base = 0x66080000, Top = 0x6609F000, Size = 126976
Name = sxs.dll, Base = 0x63E30000, Top = 0x63EB8000, Size = 557056
Name = DNSAPI.dll, Base = 0x73B90000, Top = 0x73C21000, Size = 593920
Name = rasadhlp.dll, Base = 0x73B40000, Top = 0x73B48000, Size = 32768
Name = coml2.dll, Base = 0x74BE0000, Top = 0x74C3E000, Size = 385024
Name = msscript.ocx, Base = 0x626C0000, Top = 0x626DC000, Size = 114688
Name = vbscript.dll, Base = 0x62630000, Top = 0x626**00, Size = 544768
Name = amsi.dll, Base = 0x71D90000, Top = 0x71D9F000, Size = 61440
Name = USERENV.dll, Base = 0x74300000, Top = 0x7431E000, Size = 122880
Name = WLDP.DLL, Base = 0x62600000, Top = 0x62622000, Size = 139264
Name = CRYPT32.dll, Base = 0x763A0000, Top = 0x7649B000, Size = 1028096
Name = MSASN1.dll, Base = 0x751F0000, Top = 0x751FE000, Size = 57344
Name = WI**UST.dll, Base = 0x74B90000, Top = 0x74BD6000, Size = 286720
Name = WindowsCodecs.dll, Base = 0x718A0000, Top = 0x71A09000, Size = 1478656
Name = fwpuclnt.dll, Base = 0x73AE0000, Top = 0x73B31000, Size = 331776
Name = TextInputFramework.dll, Base = 0x71810000, Top = 0x71894000, Size = 540672
Name = MSHTML.dll, Base = 0x60150000, Top = 0x61393000, Size = 19148800
Name = schannel.dll, Base = 0x62360000, Top = 0x623D6000, Size = 483328
Name = mskeyprotect.dll, Base = 0x62350000, Top = 0x62360000, Size = 65536
Name = ncrypt.dll, Base = 0x73B60000, Top = 0x73B81000, Size = 135168
Name = NTASN1.dll, Base = 0x72D40000, Top = 0x72D68000, Size = 163840
Name = DPAPI.DLL, Base = 0x65FA0000, Top = 0x65FA8000, Size = 32768
Name = rsaenh.dll, Base = 0x73CD0000, Top = 0x73CFF000, Size = 192512
Name = cryptnet.dll, Base = 0x63B70000, Top = 0x63B96000, Size = 155648
Name = ncryptsslp.dll, Base = 0x62330000, Top = 0x6234F000, Size = 126976
Code Before:
8B C8 E8 6B D2 31 00 85 C0 75 04 33 D2 EB 0E 8B D0 8D 5A 01
Current Code:
8A 0A 42 84 C9 75 F9 2B D3 52 50 8D 4F 08 E8 6B B2 F7 FF 68
Call Stack:
00440ADE ===> 按键精灵2014.exe
Current Stack:
[0019DA94] = 9F7454BF
[0019DA98] = 5D9E3AF8
[0019DA9C] = 0019DC18
[0019DAA0] = 00000000
[0019DAA4] = 063A6C68
[0019DAA8] = 0019D974
[0019DAAC] = 00000107
[0019DAB0] = 00000000
[0019DAB4] = 0019D**
[0019DAB8] = 06429C68
[0019DABC] = 063A6DA0
[0019DAC0] = 0019D974
[0019DAC4] = 00000107
[0019DAC8] = 00000000
[0019DACC] = 0019DC68
[0019DAD0] = 00000000
[0019DAD4] = 009E7390
[0019DAD8] = 063A6A60
[0019DADC] = 063A51E0
[0019DAE0] = 063AE9A8
[0019DAE4] = 063AAF28
[0019DAE8] = 063A5158
[0019DAEC] = 00000008
[0019DAF0] = 00000000
[0019DAF4] = 00000001
[0019DAF8] = 063AE7A0
[0019DAFC] = 063AADD8
[0019DB00] = 00000000
[0019DB04] = 00000000
[0019DB08] = 00000000
[0019DB0C] = 00000000
[0019DB10] = 063A5890
[0019DB14] = 063AE878
[0019DB18] = 05C00000
[0019DB1C] = 00000004
[0019DB20] = 00000000
[0019DB24] = 0000003D
[0019DB28] = 0000003F
[0019DB2C] = 05A501C8
[0019DB30] = 063AE878
[0019DB34] = 063AE8B5
[0019DB38] = 063AE8B5
[0019DB3C] = 063AE8B5
[0019DB40] = 0019DAA4
[0019DB44] = 00000000
[0019DB48] = 0019DB68
[0019DB4C] = 7707ADEE
[0019D**] = 00000013
[0019DB54] = 00000000
[0019D**] = 0000000F
[0019DB5C] = 00000000
[0019DB60] = 00010001
[0019DB64] = 063AAED8
[0019DB68] = 063A50E0
[0019DB6C] = 00000008
[0019DB70] = 00000000
[0019DB74] = 00000001
[0019DB78] = 063A5E00
[0019DB7C] = 063AAEE8
[0019DB80] = 00000000
[0019DB84] = 00000000
[0019DB88] = 00000000
[0019DB8C] = 00000000
[0019DB90] = 009E7380
[0019DB94] = 063A3768
[0019DB98] = 00408290
[0019DB9C] = 063A5E10
[0019DBA0] = 00000002
[0019DBA4] = 0000002D
[0019DBA8] = 0000002F
[0019DBAC] = 006BC0E7
[0019DBB0] = 063A3768
[0019DBB4] = 063A3795
[0019DBB8] = 063A3795
[0019DBBC] = 063A3795
[0019DBC0] = 0019DABC
[0019DBC4] = 00408400
[0019DBC8] = 063A5E10
[0019DBCC] = 00000002
[0019DBD0] = 00965B28
[0019DBD4] = 00000000
[0019DBD8] = 0000000F
[0019DBDC] = 063A5220
[0019DBE0] = 00010001
[0019DBE4] = 0019DC10
[0019DBE8] = 063AE9E0
[0019DBEC] = 00965B28
[0019DBF0] = 00000000
[0019DBF4] = 9F7454BB
[0019DBF8] = 0000003D
[0019DBFC] = 0000003F
[0019DC00] = 0019DC18
[0019DC04] = 9F7454BF
[0019DC08] = 0019E0BC
[0019DC0C] = 008A1F25
[0019DC10] = 0000000A
[0019DC14] = 0019E0CC
[0019DC18] = 00440ADE
[0019DC1C] = 9F74548B
[0019DC20] = 766EB000
[0019DC24] = 063AAF08
[0019DC28] = 063A0D40
[0019DC2C] = 02000002
[0019DC30] = 063A5220
[0019DC34] = 00000001
[0019DC38] = 06429030
[0019DC3C] = 063A5CB0
[0019DC40] = 00000004
[0019DC44] = 00000011
[0019DC48] = 009E7390
[0019DC4C] = 06429030
[0019DC50] = 00000003
[0019DC54] = 00000003
[0019DC58] = 00000011
[0019DC5C] = 009E7390
[0019DC60] = 06428F40
[0019DC64] = 009E7390
[0019DC68] = 06406B98
[0019DC6C] = 063ADB08
[0019DC70] = 00000002
[0019DC74] = 0119DCA4
[0019DC78] = 06406B80
[0019DC7C] = 12000012
[0019DC80] = 00000010
[0019DC84] = 00000001
[0019DC88] = 00000011
[0019DC8C] = 05C00270
[0019DC90] = 05C00000
[0019DC94] = 05C0C298
[0019DC98] = 0000000C
[0019DC9C] = 05C00270
[0019DCA0] = 05C00000
[0019DCA4] = 02000002
[0019DCA8] = 05C00000
[0019DCAC] = 06407900
[0019DCB0] = 06406B88
[0019DCB4] = 02000002
[0019DCB8] = 00000000
[0019DCBC] = 05C00000
[0019DCC0] = 7709B783
[0019DCC4] = 0000000C
[0019DCC8] = 0019DDA8
[0019DCCC] = 7707E780
[0019DCD0] = 00000001
[0019DCD4] = 06407908
[0019DCD8] = 0000000C
[0019DCDC] = 7707E9F9
[0019DCE0] = 53E42408
[0019DCE4] = 06407900
[0019DCE8] = 05C00000
[0019DCEC] = 00000000
[0019DCF0] = 23010022
[0019DCF4] = 00000002
[0019DCF8] = 7FFA0002
[0019DCFC] = 00000031
[0019DD00] = 00000000
[0019DD04] = 05C00000
[0019DD08] = 00000011
[0019DD0C] = 06406B98
[0019DD10] = 00000011
[0019DD14] = 05C00000
[0019DD18] = 0000000C
[0019DD1C] = 01433710
[0019DD20] = 0000000C
[0019DD24] = 628FBE9F
[0019DD28] = 015046E8
[0019DD2C] = 01504828
[0019DD30] = 62935B20
[0019DD34] = 0019DD4C
[0019DD38] = 06407900
[0019DD3C] = 015046C8
[0019DD40] = 00000001
[0019DD44] = 015046C8
[0019DD48] = 00000000
[0019DD4C] = 05C002D4
[0019DD50] = 00000001
[0019DD54] = 00000000
[0019DD58] = 014D4230
[0019DD5C] = 01430011
[0019DD60] = 11000011
[0019DD64] = 015046E8
[0019DD68] = 62788AE0
[0019DD6C] = 0000000C
[0019DD70] = 015046E4
[0019DD74] = 00000000
[0019DD78] = 01010064
[0019DD7C] = 06407960
[0019DD80] = 014C0000
[0019DD84] = 00000000
[0019DD88] = 0000000C
[0019DD8C] = 01010002
[0019DD90] = 014D3D88
[0019DD94] = 014D4230
[0019DD98] = 0019DED0
[0019DD9C] = 770B9F80
[0019DDA0] = 24E9A090
[0019DDA4] = FFFFFFFE
[0019DDA8] = 0019DE04
[0019DDAC] = 770C6CDB
[0019DDB0] = 00000000
|
|