Ban to Visit(禁访)
论坛巨匠
- 帖子
- 122791
- 精华
- 709
- 积分
- 2835
- 金币
- -45 枚
- 原创
- 0 贴
- 威望
- 0 点
- 支持
- 0 度
- 感谢
- 7223 度
- 贡献
- 0 值
- 赞助
- 0 次
- 推广
- 0 人
- 阅读权限
- 0
- 注册时间
- 2020-11-16
|
8楼
大 中
小 发表于 2020-11-3 18:14 只看该作者
版主留言Type = 0xC0000005
| Address = 0x48D152
| LineNum = 0(0)
|
| Registers:
| EAX=FFFFFFFF EBX=00000000 ECX=064030B8 EDX=FFFFFFFF
| ESI=064051AC EDI=064051A8 ESP=0019DA94 EBP=0019DC14
|
| Current Modules:
| ==>
| Name = 按键精灵2014.exe, Base = 0x400000, Top = 0x1150000, Size = 13959168
| Name = ntdll.dll, Base = 0x76E90000, Top = 0x7702A000, Size = 1679360
| Name = KERNEL32.DLL, Base = 0x76100000, Top = 0x761E0000, Size = 917504
| Name = KERNELBASE.dll, Base = 0x765D0000, Top = 0x767CC000, Size = 2080768
| Name = comctl32.dll, Base = 0x6F690000, Top = 0x6F89F000, Size = 2158592
| Name = msvcrt.dll, Base = 0x746A0000, Top = 0x7475F000, Size = 782336
| Name = combase.dll, Base = 0x768D0000, Top = 0x76B46000, Size = 2580480
| Name = ucrtbase.dll, Base = 0x75020000, Top = 0x7513F000, Size = 1175552
| Name = RPCRT4.dll, Base = 0x75ED0000, Top = 0x75F8B000, Size = 765952
| Name = SspiCli.dll, Base = 0x74660000, Top = 0x74680000, Size = 131072
| Name = CRYPTBASE.dll, Base = 0x74650000, Top = 0x7465A000, Size = 40960
| Name = bcryptPrimitives.dll, Base = 0x76B50000, Top = 0x76BAF000, Size = 389120
| Name = sechost.dll, Base = 0x74FA0000, Top = 0x75016000, Size = 483328
| Name = GDI32.dll, Base = 0x75F90000, Top = 0x75FB1000, Size = 135168
| Name = win32u.dll, Base = 0x74790000, Top = 0x747A7000, Size = 94208
| Name = gdi32full.dll, Base = 0x74E40000, Top = 0x74F9A000, Size = 1417216
| Name = msvcp_win.dll, Base = 0x76BB0000, Top = 0x76C2C000, Size = 507904
| Name = USER32.dll, Base = 0x757D0000, Top = 0x75965000, Size = 1658880
| Name = IMM32.DLL, Base = 0x74760000, Top = 0x74785000, Size = 151552
| Name = ADVAPI32.dll, Base = 0x74D30000, Top = 0x74DA9000, Size = 495616
| Name = winmm.dll, Base = 0x741D0000, Top = 0x741F4000, Size = 147456
| Name = winmmbase.dll, Base = 0x741A0000, Top = 0x741C3000, Size = 143360
| Name = cfgmgr32.dll, Base = 0x75970000, Top = 0x759AB000, Size = 241664
| Name = MSIMG32.dll, Base = 0x6F680000, Top = 0x6F686000, Size = 24576
| Name = COMDLG32.dll, Base = 0x75150000, Top = 0x751FF000, Size = 716800
| Name = shcore.dll, Base = 0x74DB0000, Top = 0x74E34000, Size = 540672
| Name = SHLWAPI.dll, Base = 0x76520000, Top = 0x76564000, Size = 278528
| Name = SHELL32.dll, Base = 0x747B0000, Top = 0x74D24000, Size = 5718016
| Name = windows.storage.dll, Base = 0x75200000, Top = 0x757C1000, Size = 6033408
| Name = profapi.dll, Base = 0x75A60000, Top = 0x75A77000, Size = 94208
| Name = powrprof.dll, Base = 0x76580000, Top = 0x765C3000, Size = 274432
| Name = UMPDC.dll, Base = 0x76E70000, Top = 0x76E7D000, Size = 53248
| Name = kernel.appcore.dll, Base = 0x76570000, Top = 0x7657F000, Size = 61440
| Name = cryptsp.dll, Base = 0x75FC0000, Top = 0x75FD3000, Size = 77824
| Name = WINSPOOL.DRV, Base = 0x6A890000, Top = 0x6A8FD000, Size = 446464
| Name = bcrypt.dll, Base = 0x76450000, Top = 0x76469000, Size = 102400
| Name = IPHLPAPI.DLL, Base = 0x744D0000, Top = 0x74502000, Size = 204800
| Name = PROPSYS.dll, Base = 0x70740000, Top = 0x70805000, Size = 806912
| Name = OLEAUT32.dll, Base = 0x767D0000, Top = 0x76862000, Size = 598016
| Name = ole32.dll, Base = 0x76350000, Top = 0x76447000, Size = 1011712
| Name = oledlg.dll, Base = 0x60F90000, Top = 0x60FBC000, Size = 180224
| Name = urlmon.dll, Base = 0x72F30000, Top = 0x730DB000, Size = 1748992
| Name = iertutil.dll, Base = 0x728A0000, Top = 0x72AC9000, Size = 2265088
| Name = gdiplus.dll, Base = 0x73890000, Top = 0x739F9000, Size = 1478656
| Name = PSAPI.DLL, Base = 0x75FE0000, Top = 0x75FE6000, Size = 24576
| Name = VERSION.dll, Base = 0x74640000, Top = 0x74648000, Size = 32768
| Name = DINPUT8.dll, Base = 0x60F50000, Top = 0x60F87000, Size = 225280
| Name = SensApi.dll, Base = 0x60070000, Top = 0x60078000, Size = 32768
| Name = WININET.dll, Base = 0x72AD0000, Top = 0x72F2B000, Size = 4567040
| Name = inputhost.dll, Base = 0x68870000, Top = 0x68923000, Size = 733184
| Name = CoreMessaging.dll, Base = 0x6F180000, Top = 0x6F209000, Size = 561152
| Name = wintypes.dll, Base = 0x6F0A0000, Top = 0x6F17A000, Size = 892928
| Name = CoreUIComponents.dll, Base = 0x6E570000, Top = 0x6E7CE000, Size = 2482176
| Name = ntmarta.dll, Base = 0x70460000, Top = 0x70489000, Size = 167936
| Name = WS2_32.dll, Base = 0x75A00000, Top = 0x75A5E000, Size = 385024
| Name = dbghelp.dll, Base = 0x71AE0000, Top = 0x71C6F000, Size = 1634304
| Name = Syntconv.dll, Base = 0x10000000, Top = 0x10053000, Size = 339968
| Name = MFC42.DLL, Base = 0x5FA40000, Top = 0x5FB64000, Size = 1196032
| Name = MSVCP60.dll, Base = 0x6CC40000, Top = 0x6CCB0000, Size = 458752
| Name = refs.dll, Base = 0x5F3F0000, Top = 0x5F586000, Size = 1662976
| Name = OLEACC.dll, Base = 0x723A0000, Top = 0x723F3000, Size = 339968
| Name = UxTheme.dll, Base = 0x6FEB0000, Top = 0x6FF2A000, Size = 499712
| Name = dwmapi.dll, Base = 0x623D0000, Top = 0x623F5000, Size = 151552
| Name = MSCTF.dll, Base = 0x75FF0000, Top = 0x760F5000, Size = 1069056
| Name = clbcatq.dll, Base = 0x76D90000, Top = 0x76E10000, Size = 524288
| Name = ieframe.dll, Base = 0x6B890000, Top = 0x6BE73000, Size = 6172672
| Name = NETAPI32.dll, Base = 0x73FC0000, Top = 0x73FD3000, Size = 77824
| Name = WINHTTP.dll, Base = 0x73170000, Top = 0x7322D000, Size = 774144
| Name = WKSCLI.DLL, Base = 0x72240000, Top = 0x72250000, Size = 65536
| Name = NETUTILS.DLL, Base = 0x73FB0000, Top = 0x73FBB000, Size = 45056
| Name = ondemandconnroutehelper.dll, Base = 0x6FF30000, Top = 0x6FF42000, Size = 73728
| Name = mswsock.dll, Base = 0x734E0000, Top = 0x73532000, Size = 335872
| Name = NSI.dll, Base = 0x76510000, Top = 0x76517000, Size = 28672
| Name = WINNSI.DLL, Base = 0x70610000, Top = 0x70618000, Size = 32768
| Name = dataexchange.dll, Base = 0x5FA00000, Top = 0x5FA31000, Size = 200704
| Name = dcomp.dll, Base = 0x5F0A0000, Top = 0x5F209000, Size = 1478656
| Name = d3d11.dll, Base = 0x5F210000, Top = 0x5F3EE000, Size = 1957888
| Name = dxgi.dll, Base = 0x644E0000, Top = 0x645A0000, Size = 786432
| Name = dxcore.dll, Base = 0x64400000, Top = 0x64419000, Size = 102400
| Name = twinapi.appcore.dll, Base = 0x60220000, Top = 0x60404000, Size = 1982464
| Name = RMCLIENT.dll, Base = 0x60200000, Top = 0x6021F000, Size = 126976
| Name = sxs.dll, Base = 0x651A0000, Top = 0x65228000, Size = 557056
| Name = DNSAPI.dll, Base = 0x73D20000, Top = 0x73DB1000, Size = 593920
| Name = mdnsNSP.dll, Base = 0x70880000, Top = 0x708A1000, Size = 135168
| Name = rasadhlp.dll, Base = 0x70870000, Top = 0x70878000, Size = 32768
| Name = coml2.dll, Base = 0x76870000, Top = 0x768CE000, Size = 385024
| Name = fwpuclnt.dll, Base = 0x70810000, Top = 0x70861000, Size = 331776
| Name = msscript.ocx, Base = 0x5F9E0000, Top = 0x5F9FC000, Size = 114688
| Name = vbscript.dll, Base = 0x5F950000, Top = 0x5F9D5000, Size = 544768
| Name = amsi.dll, Base = 0x704A0000, Top = 0x704AF000, Size = 61440
| Name = USERENV.dll, Base = 0x74610000, Top = 0x7462E000, Size = 122880
| Name = WLDP.DLL, Base = 0x72660000, Top = 0x72682000, Size = 139264
| Name = CRYPT32.dll, Base = 0x76C30000, Top = 0x76D2B000, Size = 1028096
| Name = MSASN1.dll, Base = 0x75140000, Top = 0x7514E000, Size = 57344
| Name = WINTRUST.dll, Base = 0x759B0000, Top = 0x759F6000, Size = 286720
| Name = WindowsCodecs.dll, Base = 0x6D5D0000, Top = 0x6D739000, Size = 1478656
| Name = msIso.dll, Base = 0x5EFF0000, Top = 0x5F033000, Size = 274432
| Name = MSHTML.dll, Base = 0x5DDA0000, Top = 0x5EFE1000, Size = 19140608
| Name = schannel.dll, Base = 0x6BF90000, Top = 0x6C007000, Size = 487424
| Name = mskeyprotect.dll, Base = 0x6F920000, Top = 0x6F930000, Size = 65536
| Name = ncrypt.dll, Base = 0x6F210000, Top = 0x6F231000, Size = 135168
| Name = NTASN1.dll, Base = 0x6EFE0000, Top = 0x6F008000, Size = 163840
| Name = DPAPI.DLL, Base = 0x70490000, Top = 0x70498000, Size = 32768
| Name = rsaenh.dll, Base = 0x74070000, Top = 0x7409F000, Size = 192512
| Name = cryptnet.dll, Base = 0x718A0000, Top = 0x718C6000, Size = 155648
| Name = dhcpcsvc6.DLL, Base = 0x73B00000, Top = 0x73B13000, Size = 77824
| Name = dhcpcsvc.DLL, Base = 0x740E0000, Top = 0x740F5000, Size = 86016
| Name = webio.dll, Base = 0x6FB10000, Top = 0x6FB87000, Size = 487424
|
| Code Before:
| 8B C8 E8 6B D2 31 00 85 C0 75 04 33 D2 EB 0E 8B D0 8D 5A 01
| Current Code:
| 8A 0A 42 84 C9 75 F9 2B D3 52 50 8D 4F 08 E8 6B B2 F7 FF 68
|
| Call Stack:
| 00440ADE ===> 按键精灵2014.exe
|
| Current Stack:
| [0019DA94] = 1D93E374
| [0019DA98] = 8F35A5F8
| [0019DA9C] = 0019DC18
| [0019DAA0] = 00000000
| [0019DAA4] = 06408768
| [0019DAA8] = 0019D974
| [0019DAAC] = 00000107
| [0019DAB0] = 00000000
| [0019DAB4] = 0019DB50
| [0019DAB8] = 06409BA8
| [0019DABC] = 064087F8
| [0019DAC0] = 0019D974
| [0019DAC4] = 00000107
| [0019DAC8] = 00000000
| [0019DACC] = 0019DC68
| [0019DAD0] = 00000000
| [0019DAD4] = 009E7390
| [0019DAD8] = 064022A8
| [0019DADC] = 06405438
| [0019DAE0] = 064066A8
| [0019DAE4] = 065BC2A8
| [0019DAE8] = 064051D0
| [0019DAEC] = 00000008
| [0019DAF0] = 00000000
| [0019DAF4] = 00000001
| [0019DAF8] = 064062A8
| [0019DAFC] = 065BC258
| [0019DB00] = 00000000
| [0019DB04] = 00000000
| [0019DB08] = 00000000
| [0019DB0C] = 00000000
| [0019DB10] = 06401860
| [0019DB14] = 064060F8
| [0019DB18] = 065B0000
| [0019DB1C] = 00000004
| [0019DB20] = 00000000
| [0019DB24] = 0000003B
| [0019DB28] = 0000003F
| [0019DB2C] = 059A01C8
| [0019DB30] = 064060F8
| [0019DB34] = 06406133
| [0019DB38] = 06406133
| [0019DB3C] = 06406133
| [0019DB40] = 0019DAA4
| [0019DB44] = 00000000
| [0019DB48] = 0019DB68
| [0019DB4C] = 76ECADCE
| [0019DB50] = 00000013
| [0019DB54] = 00000000
| [0019DB58] = 0000000F
| [0019DB5C] = 00000000
| [0019DB60] = 00010001
| [0019DB64] = 065BC3F8
| [0019DB68] = 06405360
| [0019DB6C] = 00000008
| [0019DB70] = 00000000
| [0019DB74] = 00000001
| [0019DB78] = 06401B10
| [0019DB7C] = 065BC3C8
| [0019DB80] = 00000000
| [0019DB84] = 00000000
| [0019DB88] = 00000000
| [0019DB8C] = 00000000
| [0019DB90] = 009E7380
| [0019DB94] = 064030D8
| [0019DB98] = 00408290
| [0019DB9C] = 06401B20
| [0019DBA0] = 00000002
| [0019DBA4] = 0000002D
| [0019DBA8] = 0000002F
| [0019DBAC] = 006BC0E7
| [0019DBB0] = 064030D8
| [0019DBB4] = 06403105
| [0019DBB8] = 06403105
| [0019DBBC] = 06403105
| [0019DBC0] = 0019DABC
| [0019DBC4] = 00408400
| [0019DBC8] = 06401B20
| [0019DBCC] = 00000002
| [0019DBD0] = 00965B28
| [0019DBD4] = 00000000
| [0019DBD8] = 0000000F
| [0019DBDC] = 064051A8
| [0019DBE0] = 00010001
| [0019DBE4] = 0019DC10
| [0019DBE8] = 064064A0
| [0019DBEC] = 00965B28
| [0019DBF0] = 00000000
| [0019DBF4] = 1D93E370
| [0019DBF8] = 0000003B
| [0019DBFC] = 0000003F
| [0019DC00] = 0019DC18
| [0019DC04] = 1D93E374
| [0019DC08] = 0019E0BC
| [0019DC0C] = 008A1F25
| [0019DC10] = 0000000A
| [0019DC14] = 0019E0CC
| [0019DC18] = 00440ADE
| [0019DC1C] = 1D93E340
| [0019DC20] = 7580B220
| [0019DC24] = 065BC278
| [0019DC28] = 06405258
| [0019DC2C] = 00000000
| [0019DC30] = 064051A8
| [0019DC34] = 00000001
| [0019DC38] = 06484728
| [0019DC3C] = 06401CC0
| [0019DC40] = 00000004
| [0019DC44] = 0000003D
| [0019DC48] = 009E7390
| [0019DC4C] = 06484728
| [0019DC50] = 00000003
| [0019DC54] = 00000003
| [0019DC58] = 0000003D
| [0019DC5C] = 009E7390
| [0019DC60] = 064845C0
| [0019DC64] = 009E7390
| [0019DC68] = 06463B40
| [0019DC6C] = 064098D8
| [0019DC70] = 00000002
| [0019DC74] = 010901A4
| [0019DC78] = 0648CAA8
| [0019DC7C] = 01C028C0
| [0019DC80] = 00000010
| [0019DC84] = 00000001
| [0019DC88] = 0000003D
| [0019DC8C] = 065B4F90
| [0019DC90] = 065B0000
| [0019DC94] = 0000002D
| [0019DC98] = 065B0000
| [0019DC9C] = 0648CAA8
| [0019DCA0] = 06492318
| [0019DCA4] = 02000002
| [0019DCA8] = 00000000
| [0019DCAC] = 065B0000
| [0019DCB0] = 76EEB776
| [0019DCB4] = 0000003D
| [0019DCB8] = 0019DD98
| [0019DCBC] = 76ECE760
| [0019DCC0] = 00000001
| [0019DCC4] = 0648CAB0
| [0019DCC8] = 0000003D
| [0019DCCC] = 76ECE9D9
| [0019DCD0] = 22533ED9
| [0019DCD4] = 0648CAA8
| [0019DCD8] = 065B0000
| [0019DCDC] = 00000000
| [0019DCE0] = 2D00002D
| [0019DCE4] = 0019DEC4
| [0019DCE8] = 00000030
| [0019DCEC] = 766C58A2
| [0019DCF0] = 01330000
| [0019DCF4] = 00000002
| [0019DCF8] = 7FFA0002
| [0019DCFC] = 00000031
| [0019DD00] = 00000000
| [0019DD04] = 065B0000
| [0019DD08] = 00000010
| [0019DD0C] = 0648CAC0
| [0019DD10] = 0000003D
| [0019DD14] = 06409599
| [0019DD18] = 0000002D
| [0019DD1C] = 01332B68
| [0019DD20] = 0019DD34
| [0019DD24] = 6B9FBA0F
| [0019DD28] = 0740B948
| [0019DD2C] = 0740BA88
| [0019DD30] = 6BA208D0
| [0019DD34] = 0019DD4C
| [0019DD38] = 766D6CB7
| [0019DD3C] = 0740B928
| [0019DD40] = 0019DDD0
| [0019DD44] = 0740B928
| [0019DD48] = 6B8DAB4C
| [0019DD4C] = 0019DD74
| [0019DD50] = 6B965F55
| [0019DD54] = 0740B928
| [0019DD58] = 6B896090
| [0019DD5C] = 6B8DAB4C
| [0019DD60] = 0019DDD0
| [0019DD64] = 0740B948
| [0019DD68] = 6B89D06C
| [0019DD6C] = 6B965F30
| [0019DD70] = 0740B944
| [0019DD74] = 0019DD90
| [0019DD78] = 6B965F11
| [0019DD7C] = 6B8DAB4C
| [0019DD80] = 0019DDD0
| [0019DD84] = 7680A190
| [0019DD88] = 6B89D06C
| [0019DD8C] = 0740B9F8
| [0019DD90] = 6B967160
| [0019DD94] = 6BA21130
| [0019DD98] = 013F1A00
| [0019DD9C] = 0740B948
| [0019DDA0] = 0019DDB4
| [0019DDA4] = 6B967154
| [0019DDA8] = 0740B948
| [0019DDAC] = 0019DDC0
| [0019DDB0] = 013B47B0
| 二钱(2020-11-4 19:39):无红点 -1W 私庄结算 以此为准
|
| 不好意思老谢,按键精灵没弄好,把代码复制上了! | |
|