|  | 
 
 发表于 2021-1-30 20:46:39
|
显示全部楼层 
| qmacro 版本:2014.06.19549/1.1.0.19486 Environment = 1920x1080|32|Windows 7 Ultimate
 Type = 0xC0000005
 Address = 0x583D0AF4
 LineNum = 0(0)
 
 Registers:
 EAX=8007000E EBX=00000000 ECX=00000004 EDX=000000AC
 ESI=039405A8 EDI=56831FD0 ESP=06EFF5A0 EBP=06EFF628
 
 Current Modules:
 Name = Runner.exe, Base = 0x400000, Top = 0xB42000, Size = 7610368
 Name = ntdll.dll, Base = 0x77020000, Top = 0x771A0000, Size = 1572864
 Name = kernel32.dll, Base = 0x767C0000, Top = 0x768D0000, Size = 1114112
 Name = KERNELBASE.dll, Base = 0x76B20000, Top = 0x76B67000, Size = 290816
 Name = comctl32.dll, Base = 0x745B0000, Top = 0x7474E000, Size = 1695744
 Name = msvcrt.dll, Base = 0x751E0000, Top = 0x7528C000, Size = 704512
 Name = GDI32.dll, Base = 0x75140000, Top = 0x751D0000, Size = 589824
 Name = USER32.dll, Base = 0x766C0000, Top = 0x767C0000, Size = 1048576
 Name = ADVAPI32.dll, Base = 0x74A90000, Top = 0x74B31000, Size = 659456
 Name = sechost.dll, Base = 0x762D0000, Top = 0x762E9000, Size = 102400
 Name = RPCRT4.dll, Base = 0x74B40000, Top = 0x74C30000, Size = 983040
 Name = SspiCli.dll, Base = 0x749A0000, Top = 0x74A00000, Size = 393216
 Name = CRYPTBASE.dll, Base = 0x74990000, Top = 0x7499C000, Size = 49152
 Name = LPK.dll, Base = 0x75F40000, Top = 0x75F4A000, Size = 40960
 Name = USP10.dll, Base = 0x75FE0000, Top = 0x7607D000, Size = 643072
 Name = SHLWAPI.dll, Base = 0x76600000, Top = 0x76657000, Size = 356352
 Name = IMM32.DLL, Base = 0x74C80000, Top = 0x74CE0000, Size = 393216
 Name = MSCTF.dll, Base = 0x76200000, Top = 0x762CC000, Size = 835584
 Name = winmm.dll, Base = 0x72530000, Top = 0x72562000, Size = 204800
 Name = MSIMG32.dll, Base = 0x74280000, Top = 0x74285000, Size = 20480
 Name = COMDLG32.dll, Base = 0x74EC0000, Top = 0x74F3B000, Size = 503808
 Name = SHELL32.dll, Base = 0x752F0000, Top = 0x75F3B000, Size = 12890112
 Name = WINSPOOL.DRV, Base = 0x727A0000, Top = 0x727F1000, Size = 331776
 Name = ole32.dll, Base = 0x76300000, Top = 0x7645C000, Size = 1425408
 Name = OLEAUT32.dll, Base = 0x75F50000, Top = 0x75FDF000, Size = 585728
 Name = oledlg.dll, Base = 0x72700000, Top = 0x7271C000, Size = 114688
 Name = gdiplus.dll, Base = 0x72570000, Top = 0x72700000, Size = 1638400
 Name = VERSION.dll, Base = 0x74750000, Top = 0x74759000, Size = 36864
 Name = DINPUT8.dll, Base = 0x61140000, Top = 0x61170000, Size = 196608
 Name = WININET.dll, Base = 0x74F50000, Top = 0x75134000, Size = 1982464
 Name = api-ms-win-downlevel-user32-l1-1-0.dll, Base = 0x74C30000, Top = 0x74C34000, Size = 16384
 Name = api-ms-win-downlevel-shlwapi-l1-1-0.dll, Base = 0x765C0000, Top = 0x765C4000, Size = 16384
 Name = api-ms-win-downlevel-version-l1-1-0.dll, Base = 0x768D0000, Top = 0x768D4000, Size = 16384
 Name = api-ms-win-downlevel-normaliz-l1-1-0.dll, Base = 0x762F0000, Top = 0x762F3000, Size = 12288
 Name = normaliz.DLL, Base = 0x76460000, Top = 0x76463000, Size = 12288
 Name = iertutil.dll, Base = 0x768E0000, Top = 0x76B12000, Size = 2301952
 Name = api-ms-win-downlevel-advapi32-l1-1-0.dll, Base = 0x74C70000, Top = 0x74C75000, Size = 20480
 Name = USERENV.dll, Base = 0x76B70000, Top = 0x76B87000, Size = 94208
 Name = profapi.dll, Base = 0x751D0000, Top = 0x751DB000, Size = 45056
 Name = OLEACC.dll, Base = 0x723F0000, Top = 0x7242C000, Size = 245760
 Name = imagehlp.dll, Base = 0x76690000, Top = 0x766BB000, Size = 176128
 Name = UxTheme.dll, Base = 0x72720000, Top = 0x727A0000, Size = 524288
 Name = urlmon.dll, Base = 0x76470000, Top = 0x765BA000, Size = 1351680
 Name = api-ms-win-downlevel-ole32-l1-1-0.dll, Base = 0x76660000, Top = 0x76664000, Size = 16384
 Name = dwmapi.dll, Base = 0x723D0000, Top = 0x723E3000, Size = 77824
 Name = CLBCatQ.DLL, Base = 0x76B90000, Top = 0x76C13000, Size = 536576
 Name = MSScript.ocx, Base = 0x60940000, Top = 0x6095A000, Size = 106496
 Name = dbghelp.dll, Base = 0x72440000, Top = 0x7252B000, Size = 962560
 Name = qdisp.dll, Base = 0x10000000, Top = 0x1000A000, Size = 40960
 Name = MFC42.DLL, Base = 0x56820000, Top = 0x5693C000, Size = 1163264
 Name = ODBC32.dll, Base = 0x59620000, Top = 0x596AC000, Size = 573440
 Name = odbcint.dll, Base = 0x605C0000, Top = 0x605F8000, Size = 229376
 ==>
 Name = vbscript.dll, Base = 0x583A0000, Top = 0x5841F000, Size = 520192
 Name = ieframe.dll, Base = 0x688E0000, Top = 0x69522000, Size = 12853248
 Name = api-ms-win-downlevel-shell32-l1-1-0.dll, Base = 0x70F60000, Top = 0x70F64000, Size = 16384
 Name = api-ms-win-downlevel-shlwapi-l2-1-0.dll, Base = 0x71960000, Top = 0x71964000, Size = 16384
 Name = SXS.DLL, Base = 0x669B0000, Top = 0x66A0F000, Size = 389120
 Name = cfgdll.dll, Base = 0x50C0000, Top = 0x50CF000, Size = 61440
 Name = HID.DLL, Base = 0x6EE40000, Top = 0x6EE49000, Size = 36864
 Name = SETUPAPI.DLL, Base = 0x74D20000, Top = 0x74EBD000, Size = 1691648
 Name = CFGMGR32.dll, Base = 0x74C40000, Top = 0x74C67000, Size = 159744
 Name = DEVOBJ.dll, Base = 0x76670000, Top = 0x76682000, Size = 73728
 Name = WINTRUST.dll, Base = 0x765D0000, Top = 0x765FE000, Size = 188416
 Name = CRYPT32.dll, Base = 0x760E0000, Top = 0x76200000, Size = 1179648
 Name = MSASN1.dll, Base = 0x760D0000, Top = 0x760DC000, Size = 49152
 Name = ntmarta.dll, Base = 0x74580000, Top = 0x745A1000, Size = 135168
 Name = WLDAP32.dll, Base = 0x76080000, Top = 0x760C5000, Size = 282624
 Name = Access.dll, Base = 0x4870000, Top = 0x487B000, Size = 45056
 Name = Bkgnd.dll, Base = 0x4880000, Top = 0x4897000, Size = 94208
 Name = MSVCP60.dll, Base = 0x610D0000, Top = 0x61136000, Size = 417792
 Name = BkgndColor.dll, Base = 0x48A0000, Top = 0x48A9000, Size = 36864
 Name = Color.dll, Base = 0x48B0000, Top = 0x48C0000, Size = 65536
 Name = ColorEx.dll, Base = 0x48C0000, Top = 0x48CC000, Size = 49152
 Name = Console.dll, Base = 0x48D0000, Top = 0x48D8000, Size = 32768
 Name = Encrypt.dll, Base = 0x48E0000, Top = 0x48EF000, Size = 61440
 Name = File.dll, Base = 0x48F0000, Top = 0x4901000, Size = 69632
 Name = GetSysInfo.dll, Base = 0x4910000, Top = 0x4918000, Size = 32768
 Name = Media.dll, Base = 0x4920000, Top = 0x4929000, Size = 36864
 Name = Memory.dll, Base = 0x4930000, Top = 0x493B000, Size = 45056
 Name = Msg.dll, Base = 0x4940000, Top = 0x494A000, Size = 40960
 Name = Net.dll, Base = 0x11000000, Top = 0x11007000, Size = 28672
 Name = MSVBVM60.DLL, Base = 0x72940000, Top = 0x72A93000, Size = 1388544
 Name = Office.dll, Base = 0x4950000, Top = 0x4959000, Size = 36864
 Name = Oracle.dll, Base = 0x4960000, Top = 0x496B000, Size = 45056
 Name = Pic.dll, Base = 0x4970000, Top = 0x4981000, Size = 69632
 Name = SQLServer.dll, Base = 0x49D0000, Top = 0x49DB000, Size = 45056
 Name = Sys.dll, Base = 0x49E0000, Top = 0x49E9000, Size = 36864
 Name = SysEx.dll, Base = 0x49F0000, Top = 0x4A59000, Size = 430080
 Name = Web.dll, Base = 0x4A60000, Top = 0x4A6F000, Size = 61440
 Name = Window.dll, Base = 0x4A70000, Top = 0x4A7D000, Size = 53248
 Name = CRYPTSP.dll, Base = 0x70E40000, Top = 0x70E56000, Size = 90112
 Name = rsaenh.dll, Base = 0x70E00000, Top = 0x70E3B000, Size = 241664
 
 Code Before:
 FE FF FF 75 B8 E8 36 77 02 00 E9 14 5C FE FF B9 04 00 00 00
 Current Code:
 CD 29 E9 9B 5B FE FF B9 04 00 00 00 CD 29 E9 FC 5B FE FF B9
 
 Call Stack:
 583B6834   ===> vbscript.dll
 
 Current Stack:
 [06EFF5A0] = 00000000
 [06EFF5A4] = 00000001
 [06EFF5A8] = 039405A8
 [06EFF5AC] = 03960740
 [06EFF5B0] = 00000000
 [06EFF5B4] = 00000000
 [06EFF5B8] = 00000000
 [06EFF5BC] = 00000000
 [06EFF5C0] = 039408F0
 [06EFF5C4] = 06EFF898
 [06EFF5C8] = 00000000
 [06EFF5CC] = 00000000
 [06EFF5D0] = 039405A8
 [06EFF5D4] = 00000000
 [06EFF5D8] = 10006430
 [06EFF5DC] = 00000000
 [06EFF5E0] = 00000000
 [06EFF5E4] = EBEB87A6
 [06EFF5E8] = 4054E151
 [06EFF5EC] = E0A645AB
 [06EFF5F0] = 4B33C594
 [06EFF5F4] = 5840D87C
 [06EFF5F8] = 06EFF664
 [06EFF5FC] = 583A6150
 [06EFF600] = 583A60E0
 [06EFF604] = 06EFF628
 [06EFF608] = 583A5060
 [06EFF60C] = 583A5826
 [06EFF610] = 0FB7B70B
 [06EFF614] = 06EFF628
 [06EFF618] = 0395E1F0
 [06EFF61C] = 00000001
 [06EFF620] = 0395E1F0
 [06EFF624] = A862DE92
 [06EFF628] = 06EFF65C
 [06EFF62C] = 583B6834
 [06EFF630] = 00000000
 [06EFF634] = 06EFF898
 [06EFF638] = 00000000
 [06EFF63C] = 00000000
 [06EFF640] = 06EFF684
 [06EFF644] = 03940870
 [06EFF648] = 06EFF948
 [06EFF64C] = 00000000
 [06EFF650] = 06EFF898
 [06EFF654] = 03955C6C
 [06EFF658] = 06EFF670
 [06EFF65C] = 06EFF670
 [06EFF660] = 583B67B3
 [06EFF664] = 0395E1F0
 [06EFF668] = 06EFF684
 [06EFF66C] = 583B6780
 [06EFF670] = 06EFF68C
 [06EFF674] = 583A4787
 [06EFF678] = 06EFF898
 [06EFF67C] = 00000001
 [06EFF680] = 0395E1F0
 [06EFF684] = 5840D87C
 [06EFF688] = 583A2110
 [06EFF68C] = 06EFF8DC
 [06EFF690] = 583A4737
 [06EFF694] = 06EFF898
 [06EFF698] = 00000001
 [06EFF69C] = 0395E1F0
 [06EFF6A0] = 00000000
 [06EFF6A4] = 00000000
 [06EFF6A8] = 039405A8
 [06EFF6AC] = 00000000
 [06EFF6B0] = 06EFF948
 [06EFF6B4] = 00001000
 [06EFF6B8] = 06EFF6D4
 [06EFF6BC] = 583A9D17
 [06EFF6C0] = 0394F4FC
 [06EFF6C4] = 0000068D
 [06EFF6C8] = 583A2100
 [06EFF6CC] = 00E646B8
 [06EFF6D0] = 00000001
 [06EFF6D4] = 039551C0
 [06EFF6D8] = 583B12F4
 [06EFF6DC] = 00000004
 [06EFF6E0] = 06EFF910
 [06EFF6E4] = 000007FF
 [06EFF6E8] = 00000001
 [06EFF6EC] = 000007FF
 [06EFF6F0] = 00000024
 [06EFF6F4] = 06EFF718
 [06EFF6F8] = 00000000
 [06EFF6FC] = 0394F75C
 [06EFF700] = 00000C20
 [06EFF704] = 00E60000
 [06EFF708] = 03940A30
 [06EFF70C] = 00003BF8
 [06EFF710] = 000007FF
 [06EFF714] = 03910000
 [06EFF718] = 00000006
 [06EFF71C] = 0395DB78
 [06EFF720] = 000000CC
 [06EFF724] = 0395DBF0
 [06EFF728] = 00E60000
 [06EFF72C] = 03960FE0
 [06EFF730] = 7705DE40
 [06EFF734] = 00000000
 [06EFF738] = 00000687
 [06EFF73C] = 00000000
 [06EFF740] = 000005B2
 [06EFF744] = 06EFF830
 [06EFF748] = 000000CC
 [06EFF74C] = 00E60000
 [06EFF750] = 0395DBF0
 [06EFF754] = 06EFF830
 [06EFF758] = 770534E7
 [06EFF75C] = 77053516
 [06EFF760] = 712D4763
 [06EFF764] = 00000002
 [06EFF768] = 00E64A2C
 [06EFF76C] = 00E60000
 [06EFF770] = 00E646B8
 [06EFF774] = 00E646B8
 [06EFF778] = 77053111
 [06EFF77C] = 00E646B8
 [06EFF780] = 770530ED
 [06EFF784] = 00E64798
 [06EFF788] = 00000000
 [06EFF78C] = 000005B2
 [06EFF790] = 00000600
 [06EFF794] = 00E646B8
 [06EFF798] = 000005FE
 [06EFF79C] = 03940A38
 [06EFF7A0] = 0394A758
 [06EFF7A4] = 0000067E
 [06EFF7A8] = 751EAC05
 [06EFF7AC] = 000000CC
 [06EFF7B0] = 00E646B8
 [06EFF7B4] = 03000003
 [06EFF7B8] = 00000000
 [06EFF7BC] = 03000003
 [06EFF7C0] = 00000000
 [06EFF7C4] = 03955CA0
 [06EFF7C8] = 0000000C
 [06EFF7CC] = 0FB7B70B
 [06EFF7D0] = 00000001
 [06EFF7D4] = 000007FF
 [06EFF7D8] = 00000000
 [06EFF7DC] = 000007FF
 [06EFF7E0] = 03940A38
 [06EFF7E4] = D90028F1
 [06EFF7E8] = 03940A38
 [06EFF7EC] = 00000001
 [06EFF7F0] = 00000008
 [06EFF7F4] = 00000002
 [06EFF7F8] = 00000008
 [06EFF7FC] = 0395DBF8
 [06EFF800] = 0395DBF8
 [06EFF804] = 0395DBF3
 [06EFF808] = 00000059
 [06EFF80C] = 00000000
 [06EFF810] = 00E60000
 [06EFF814] = 01E64730
 [06EFF818] = 06EFF760
 [06EFF81C] = 77096325
 [06EFF820] = 06EFFC30
 [06EFF824] = 77096325
 [06EFF828] = 00C676A3
 [06EFF82C] = FFFFFFFE
 [06EFF830] = 77053516
 [06EFF834] = 77053541
 [06EFF838] = 00000658
 [06EFF83C] = 03960710
 [06EFF840] = 0395DBF2
 [06EFF844] = 0395DBF0
 [06EFF848] = 00000002
 [06EFF84C] = 00000000
 [06EFF850] = 7704E1B6
 [06EFF854] = 06EFF8C0
 [06EFF858] = 77096325
 [06EFF85C] = 00000002
 [06EFF860] = FFFFFFFE
 [06EFF864] = 770530ED
 [06EFF868] = 77052CE5
 [06EFF86C] = 00000000
 [06EFF870] = 03955C48
 [06EFF874] = 0000000C
 [06EFF878] = CA51C71F
 [06EFF87C] = 00CE0001
 [06EFF880] = 06EFF8B8
 [06EFF884] = 60945B72
 [06EFF888] = 06EFF948
 [06EFF88C] = 583A4750
 [06EFF890] = 00000002
 [06EFF894] = 5840D87C
 [06EFF898] = 00000001
 [06EFF89C] = 00000000
 [06EFF8A0] = 5840D87C
 [06EFF8A4] = 00000000
 [06EFF8A8] = 06EFF91C
 [06EFF8AC] = 6094F346
 [06EFF8B0] = CE1CE790
 [06EFF8B4] = 00000002
 [06EFF8B8] = 00000002
 [06EFF8BC] = 583A2EE0
 
 
 
 | 
 |