欲罷不能的苦行者
- UID
- 26099
- 主題
- 18
- 帖子
- 593
- 精華
- 0
- DB
- 818
- 魂
- 0
- 櫻花
- 0
- 閱讀權限
- 50
- 註冊時間
- 2004-12-17
- 在線時間
- 401 小時
- 最後登錄
- 2024-06-12
- 帖子
- 593
- 精華
- 0
- DB
- 818
- 魂
- 0
- 註冊時間
- 2004-12-17
|
痴漢は犯罪!非法操作问题!
发生应用程序意外错误:
应用程序: N:\痴漢は犯罪!\FULLTIME\痴漢は犯罪!\痴漢は犯罪!.exe (pid=3192)
时间: 2004/12/18 @ 14:38:38.843
意外情况编号: c0000005 (访问侵犯)
*----> 系统信息 <----*
计算机名: 青龙萨玛斯
用户名: 青龙皇
终端会话 Id: 0
处理器数量: 1
处理器类型: x86 Family 6 Model 8 Stepping 0
Windows 版本: 5.1
当前内部版本号: 2600
Service Pack: 2
当前类型: Uniprocessor Free
注册的单位: ????????????????????????????????
注册的所有者: ????????
*----> 任务列表 <----*
0 System Process
4 System
488 smss.exe
564 csrss.exe
588 winlogon.exe
632 services.exe
644 lsass.exe
792 svchost.exe
864 svchost.exe
940 svchost.exe
1008 svchost.exe
1204 spoolsv.exe
1284 svchost.exe
1344 GHOSTS~2.EXE
1376 inetinfo.exe
1396 KAVSvc.EXE
1444 MDM.EXE
1484 msdtc.exe
1512 nvsvc32.exe
1676 CCENTER.EXE
1756 Error 0x8007007A
1784 tcpsvcs.exe
1816 snmp.exe
1848 svchost.exe
1868 wdfmgr.exe
1916 mqsvc.exe
516 Error 0x8007007A
392 mqtgsvc.exe
1292 alg.exe
2224 Explorer.EXE
2372 conime.exe
2556 RUNDLL32.EXE
2584 GhostStartTrayApp.exe
2644 Kulansyn.EXE
2652 KpopMon.EXE
2692 KWatchUI.EXE
2736 VM_STI.EXE
2768 RavTimer.exe
2872 Error 0x8007007A
2948 daemon.exe
2988 Error 0x8007007A
2996 ctfmon.exe
3032 KAVPlus.EXE
3036 MsnMsgr.Exe
3048 svchost.exe
3152 Error 0x8007007A
3876 Ravmond.exe
3524 WinWPS.exe
2208 S.exe
3408 Error 0x8007007A
784 Error 0x8007007A
2908 Error 0x8007007A
2776 msiexec.exe
3192 Error 0x8007007A
3436 drwtsn32.exe
*----> 模块清单 <----*
(0000000000400000 - 000000000041d000: N:\?s???í?????I\FULLTIME\?s???í?????I\?s???í?????I.exe
(0000000020000000 - 0000000020549000: E:\WINXP\system32\xpsp2res.dll
(0000000023000000 - 0000000023018000: E:\WINXP\AppPatch\AlLayer.DLL
(000000005adc0000 - 000000005adf7000: E:\WINXP\system32\uxtheme.dll
(000000005cc30000 - 000000005cc56000: E:\WINXP\system32\ShimEng.dll
(000000005d170000 - 000000005d207000: E:\WINXP\system32\COMCTL32.dll
(0000000062c20000 - 0000000062c29000: E:\WINXP\system32\LPK.DLL
(0000000073640000 - 000000007366e000: E:\WINXP\system32\msctfime.ime
(0000000073e70000 - 0000000073ecc000: E:\WINXP\system32\dsound.dll
(0000000073fa0000 - 000000007400b000: E:\WINXP\system32\USP10.dll
(0000000074680000 - 00000000746cb000: E:\WINXP\system32\MSCTF.dll
(0000000076300000 - 000000007631d000: E:\WINXP\system32\IMM32.DLL
(0000000076990000 - 0000000076acc000: E:\WINXP\system32\ole32.dll
(0000000076b10000 - 0000000076b3a000: E:\WINXP\system32\WINMM.dll
(0000000076d70000 - 0000000076d92000: E:\WINXP\system32\apphelp.dll
(0000000076fa0000 - 000000007701f000: E:\WINXP\system32\CLBCATQ.DLL
(0000000077020000 - 00000000770ba000: E:\WINXP\system32\COMRes.dll
(00000000770f0000 - 000000007717c000: E:\WINXP\system32\OLEAUT32.dll
(0000000077180000 - 0000000077282000: E:\WINXP\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
(00000000773a0000 - 0000000077b91000: E:\WINXP\system32\SHELL32.dll
(0000000077bd0000 - 0000000077bd8000: E:\WINXP\system32\VERSION.dll
(0000000077be0000 - 0000000077c38000: E:\WINXP\system32\msvcrt.dll
(0000000077d10000 - 0000000077d9f000: E:\WINXP\system32\USER32.dll
(0000000077da0000 - 0000000077e49000: E:\WINXP\system32\ADVAPI32.dll
(0000000077e50000 - 0000000077ee1000: E:\WINXP\system32\RPCRT4.dll
(0000000077ef0000 - 0000000077f36000: E:\WINXP\system32\GDI32.dll
(0000000077f40000 - 0000000077fb6000: E:\WINXP\system32\SHLWAPI.dll
(000000007c800000 - 000000007c91c000: E:\WINXP\system32\kernel32.dll
(000000007c920000 - 000000007c9b4000: E:\WINXP\system32\ntdll.dll
*----> 线程 ID 0xe84 的状态转储 <----*
eax=00413f30 ebx=00000000 ecx=005438e8 edx=00000000 esi=ffffffff edi=00000000
eip=004124b1 esp=0013fb24 ebp=0054391c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
*** WARNING: Unable to verify checksum for N:\?s???í?????I\FULLTIME\?s???í?????I\?s???í?????I.exe
*** ERROR: Module load completed but symbols could not be loaded for N:\?s???í?????I\FULLTIME\?s???í?????I\?s???í?????I.exe
函数: 痴漢は犯罪!
0041249d 90 nop
0041249e 90 nop
0041249f 90 nop
004124a0 53 push ebx
004124a1 55 push ebp
004124a2 56 push esi
004124a3 8b35f4364100 mov esi,[?s???í?????I+0x136f4 (004136f4)]
004124a9 57 push edi
004124aa 8b7c2414 mov edi,[esp+0x14]
004124ae 8d6934 lea ebp,[ecx+0x34]
错误 ->004124b1 8b4708 mov eax,[edi+0x8] ds:0023:00000008=????????
004124b4 8bd8 mov ebx,eax
004124b6 3bf3 cmp esi,ebx
004124b8 7302 jnb ?s???í?????I+0x124bc (004124bc)
004124ba 8bde mov ebx,esi
004124bc 3bef cmp ebp,edi
004124be 755e jnz ?s???í?????I+0x1251e (0041251e)
004124c0 395d08 cmp [ebp+0x8],ebx
004124c3 7305 jnb ?s???í?????I+0x124ca (004124ca)
004124c5 e81e46ffff call ?s???í?????I+0x6ae8 (00406ae8)
004124ca 8bcd mov ecx,ebp
*----> 堆栈反向跟踪 <---*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0054391c 00000000 00000000 00000000 00000000 ?s???í?????I+0x124b1
*----> 原始堆栈转储 <----*
000000000013fb24 b8 fb 13 00 e8 38 54 00 - 7c fb 13 00 00 00 00 00 .....8T.|.......
000000000013fb34 d4 67 40 00 00 00 00 00 - 40 2f 40 00 e8 38 54 00 .g@.....@/@..8T.
000000000013fb44 d4 fb 13 00 2b 2d 41 00 - ff ff ff ff fa 2f 40 00 ....+-A....../@.
000000000013fb54 09 87 d1 77 52 01 0a 00 - 01 04 00 00 00 00 00 00 ...wR...........
000000000013fb64 00 00 00 00 40 2f 40 00 - cd ab ba dc 00 00 00 00 ....@/@.........
000000000013fb74 b8 fb 13 00 40 2f 40 00 - e4 fb 13 00 eb 87 d1 77 ....@/@........w
000000000013fb84 40 2f 40 00 52 01 0a 00 - 01 04 00 00 00 00 00 00 @/@.R...........
000000000013fb94 00 00 00 00 01 04 00 00 - 40 2f 40 00 00 00 00 00 ........@/@.....
000000000013fba4 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000013fbb4 10 00 00 00 00 00 00 00 - be 00 0b 00 01 00 00 00 ................
000000000013fbc4 00 00 00 00 00 00 00 00 - 98 fb 13 00 48 f7 13 00 ............H...
000000000013fbd4 48 fe 13 00 94 04 d4 77 - 08 88 d1 77 00 00 00 00 H......w...w....
000000000013fbe4 14 fc 13 00 0e c0 d1 77 - 00 00 00 00 40 2f 40 00 .......w....@/@.
000000000013fbf4 52 01 0a 00 01 04 00 00 - 00 00 00 00 00 00 00 00 R...............
000000000013fc04 00 00 00 00 00 00 00 00 - 00 00 00 00 01 04 00 00 ................
000000000013fc14 34 fc 13 00 66 e3 d1 77 - 40 2f 40 00 52 01 0a 00 4...f..w@/@.R...
000000000013fc24 01 04 00 00 00 00 00 00 - 00 00 00 00 01 00 00 00 ................
000000000013fc34 9c fd 13 00 f9 4b 00 23 - 40 2f 40 00 52 01 0a 00 .....K.#@/@.R...
000000000013fc44 01 04 00 00 00 00 00 00 - 00 00 00 00 2c fe 13 00 ............,...
000000000013fc54 00 00 00 00 00 00 00 00 - 11 01 00 00 f0 03 00 00 ................
*----> 线程 ID 0xc7c 的状态转储 <----*
eax=00f4ff54 ebx=00000000 ecx=0016d848 edx=7c92eb94 esi=0016d848 edi=00000000
eip=7c92eb94 esp=00f4fe1c ebp=00f4ff80 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
*** ERROR: Symbol file could not be found. Defaulted to export symbols for E:\WINXP\system32\ntdll.dll -
函数: ntdll!KiFastSystemCallRet
7c92eb89 90 nop
7c92eb8a 90 nop
ntdll!KiFastSystemCall:
7c92eb8b 8bd4 mov edx,esp
7c92eb8d 0f34 sysenter
7c92eb8f 90 nop
7c92eb90 90 nop
7c92eb91 90 nop
7c92eb92 90 nop
7c92eb93 90 nop
ntdll!KiFastSystemCallRet:
7c92eb94 c3 ret
7c92eb95 8da42400000000 lea esp,[esp]
7c92eb9c 8d642400 lea esp,[esp]
7c92eba0 90 nop
7c92eba1 90 nop
7c92eba2 90 nop
7c92eba3 90 nop
7c92eba4 90 nop
ntdll!KiIntSystemCall:
7c92eba5 8d542408 lea edx,[esp+0x8]
7c92eba9 cd2e int 2e
*----> 堆栈反向跟踪 <---*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for E:\WINXP\system32\RPCRT4.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for E:\WINXP\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
00f4ff80 77e56c22 00f4ffa8 77e56a3b 0016d848 ntdll!KiFastSystemCallRet
00f4ff88 77e56a3b 0016d848 00000000 0013d2a0 RPCRT4!I_RpcBCacheFree+0x5ea
00f4ffa8 77e56c0a 0016d9e0 00f4ffec 7c80b50b RPCRT4!I_RpcBCacheFree+0x403
00f4ffb4 7c80b50b 00173d18 00000000 0013d2a0 RPCRT4!I_RpcBCacheFree+0x5d2
00f4ffec 00000000 77e56bf0 00173d18 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> 原始堆栈转储 <----*
0000000000f4fe1c 99 e3 92 7c 03 67 e5 77 - 3c 01 00 00 70 ff f4 00 ...|.g.w<...p...
0000000000f4fe2c 00 00 00 00 e0 b5 17 00 - 54 ff f4 00 05 00 00 00 ........T.......
0000000000f4fe3c 00 2b d6 f4 00 00 00 00 - fc e4 50 81 2c e5 50 81 .+........P.,.P.
0000000000f4fe4c 88 e4 50 81 05 00 00 00 - 05 00 00 00 60 05 58 e2 ..P.........`.X.
0000000000f4fe5c 98 95 01 e1 02 00 00 00 - fe ff f8 00 b8 82 9b e1 ................
0000000000f4fe6c 60 05 58 e2 b0 45 56 00 - 00 00 00 00 00 00 00 00 `.X..EV.........
0000000000f4fe7c 5c 00 52 00 ff ff ff ff - ec 2b d6 f4 6c 48 56 80 \.R......+..lHV.
0000000000f4fe8c 49 03 00 00 34 00 00 c0 - 88 e4 50 81 80 9b 01 e1 I...4.....P.....
0000000000f4fe9c 2c e5 50 81 2c 2c d6 f4 - 98 9b 01 e1 80 9b 01 e1 ,.P.,,..........
0000000000f4feac ec 2b d6 f4 77 48 56 80 - fc e4 50 81 2c e5 50 81 .+..wHV...P.,.P.
0000000000f4febc 88 e4 50 81 10 00 f8 00 - 2a 82 9b e1 7c 00 f8 00 ..P.....*...|...
0000000000f4fecc 3a 82 9b e1 7c 9b 01 e1 - 6a 44 4e 80 c8 2b d6 f4 :...|...jDN..+..
0000000000f4fedc 3c e5 50 81 82 8f 56 80 - 80 9b 01 e1 00 00 00 00 <.P...V.........
0000000000f4feec 00 00 00 00 10 2c d6 f4 - 00 8a bb 81 38 c0 54 80 .....,......8.T.
0000000000f4fefc 00 00 00 00 18 e5 50 81 - 88 e4 50 81 a4 e4 50 81 ......P...P...P.
0000000000f4ff0c 88 e4 50 81 00 7d 26 e1 - bc 91 37 81 24 2c d6 f4 ..P..}&...7.$,..
0000000000f4ff1c 62 d8 4d 80 6a d8 4d 80 - 8c 91 37 81 20 90 37 81 b.M.j.M...7. .7.
0000000000f4ff2c 54 90 37 81 80 ff f4 00 - 99 66 e5 77 4c ff f4 00 T.7......f.wL...
0000000000f4ff3c a9 66 e5 77 ed 10 92 7c - e0 3a 17 00 18 3d 17 00 .f.w...|.:...=..
0000000000f4ff4c 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......
*----> 线程 ID 0xe30 的状态转储 <----*
eax=0000045a ebx=00000000 ecx=00000410 edx=0002f815 esi=0016d848 edi=0016d8ec
eip=7c92eb94 esp=0114fe1c ebp=0114ff80 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
函数: ntdll!KiFastSystemCallRet
7c92eb89 90 nop
7c92eb8a 90 nop
ntdll!KiFastSystemCall:
7c92eb8b 8bd4 mov edx,esp
7c92eb8d 0f34 sysenter
7c92eb8f 90 nop
7c92eb90 90 nop
7c92eb91 90 nop
7c92eb92 90 nop
7c92eb93 90 nop
ntdll!KiFastSystemCallRet:
7c92eb94 c3 ret
7c92eb95 8da42400000000 lea esp,[esp]
7c92eb9c 8d642400 lea esp,[esp]
7c92eba0 90 nop
7c92eba1 90 nop
7c92eba2 90 nop
7c92eba3 90 nop
7c92eba4 90 nop
ntdll!KiIntSystemCall:
7c92eba5 8d542408 lea edx,[esp+0x8]
7c92eba9 cd2e int 2e
*----> 堆栈反向跟踪 <---*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0114ff80 77e56c22 0114ffa8 77e56a3b 0016d848 ntdll!KiFastSystemCallRet
0114ff88 77e56a3b 0016d848 00000000 00d40178 RPCRT4!I_RpcBCacheFree+0x5ea
0114ffa8 77e56c0a 0016d9e0 0114ffec 7c80b50b RPCRT4!I_RpcBCacheFree+0x403
0114ffb4 7c80b50b 00176e00 00000000 00d40178 RPCRT4!I_RpcBCacheFree+0x5d2
0114ffec 00000000 77e56bf0 00176e00 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> 原始堆栈转储 <----*
000000000114fe1c 99 e3 92 7c 03 67 e5 77 - 3c 01 00 00 70 ff 14 01 ...|.g.w<...p...
000000000114fe2c 00 00 00 00 98 86 17 00 - 4c ff 14 01 a0 ee 2f 81 ........L...../.
000000000114fe3c 00 e0 fd 7f fc 07 30 c0 - 78 ff 1f c0 45 06 00 00 ......0.x...E...
000000000114fe4c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000114fe5c 00 00 80 ff 04 2c 5e f5 - 0e d1 4e 80 fc 07 30 c0 .....,^...N...0.
000000000114fe6c 04 2c 5e f5 86 cf 4e 80 - 00 e0 fd 7f 00 00 00 00 .,^...N.........
000000000114fe7c 00 00 00 00 90 62 55 81 - a8 ec 2f 81 01 ed 2f 81 .....bU.../.../.
000000000114fe8c 00 00 00 00 78 ff 1f c0 - 00 00 00 00 4e 4f 4e 80 ....x.......NON.
000000000114fe9c 48 0d 9b 81 88 2f 53 81 - b0 5c a5 81 88 2b 5e f5 H..../S..\...+^.
000000000114feac 8b a6 d4 f9 ec 2f 53 81 - 00 00 00 00 00 00 00 00 ...../S.........
000000000114febc 9c 2b 5e f5 2a 9f 1d f6 - e8 2f 53 81 00 00 00 00 .+^.*..../S.....
000000000114fecc 00 e0 fd 7f c4 2b 5e f5 - 9a 01 86 f9 10 7a 8c 81 .....+^......z..
000000000114fedc 88 2f 53 81 a9 01 86 f9 - 08 23 77 81 01 00 00 00 ./S......#w.....
000000000114feec 10 5e a5 81 01 00 00 00 - 50 40 bf 81 28 39 21 e1 .^......P@..(9!.
000000000114fefc 02 00 00 00 20 2c 5e f5 - 00 77 bb 81 38 c0 54 80 .... ,^..w..8.T.
000000000114ff0c 90 62 55 81 a8 ec 2f 81 - 34 42 39 81 24 2c 5e f5 .bU.../.4B9.$,^.
000000000114ff1c 62 d8 4d 80 6a d8 4d 80 - 04 42 39 81 98 40 39 81 b.M.j.M..B9..@9.
000000000114ff2c cc 40 39 81 80 ff 14 01 - 99 66 e5 77 4c ff 14 01 .@9......f.wL...
000000000114ff3c a9 66 e5 77 ed 10 92 7c - 18 68 17 00 00 6e 17 00 .f.w...|.h...n..
000000000114ff4c 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......
以上是本人的错误记录日志,希望高手研究下。
错误 ->004124b1 8b4708 mov eax,[edi+0x8] ds:0023:00000008=????????
以上面这个错误来看,似乎是程序调用了某些系统不存在的东西,但本人刚接触反汇编,看不明白。希望有高人来指教一下。 |
|