首页
社区
课程
招聘
[求助]一个3d系统解剖软件脱壳解包问题
发表于: 2015-7-3 17:28 5048

[求助]一个3d系统解剖软件脱壳解包问题

2015-7-3 17:28
5048
一个3d系统解剖软件,已经脱壳,并通过注入的方式解开了一部分文件,但允许后报错,希望某破解过的指点一二。该程序使用了mono,但是我另外按照了mono环境,程序还是运行出错

程序运行界面


确定后的错误提示


脱壳前后文件对比


附错误日志:

Unity Player [version: Unity 3.3.0f3_63049]

系统解剖_dump.exe caused an Access Violation (0xc0000005)
  in module 系统解剖_dump.exe at 001b:00411ea0.

Error occurred at 2015-07-03_171848.
E:\dll注入\系统解剖\系统解剖_dump.exe, run by Administrator.
74% memory in use.
1015 MB physical memory [256 MB free].
2445 MB paging file [1192 MB free].
2048 MB user address space [1756 MB free].
Write to location 00411ea0 caused an access violation.

Context:
EDI:    0x0b712d80  ESI: 0x091c5ec0  EAX:   0x00411ea0
EBX:    0x00000000  ECX: 0x0012f28c  EDX:   0x091722f0
EIP:    0x00411ea0  EBP: 0x0012f2c8  SegCs: 0x0000001b
EFlags: 0x00010216  ESP: 0x0012f24c  SegSs: 0x00000023

Bytes at CS:EIP:
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Stack:
0x0012f24c: 09694f00 0012f28c 0b712d80 0012f318 .Oi......-q.....
0x0012f25c: 091c5ec0 0012f308 1007f33f 00000001 .^......?.......
0x0012f26c: 091e0072 09694ed0 09694e99 09694ed0 r....Ni..Ni..Ni.
0x0012f27c: 00000000 091722f1 09172298 0b611a70 ....."..."..p.a.
0x0012f28c: 0012f2d0 00000000 0b712d80 091c5ec0 .........-q..^..
0x0012f29c: 0012f308 0012f2c8 091722f0 09172298 ........."..."..
0x0012f2ac: 091c5ec0 09694ee1 00000000 0b712d80 .^...Ni......-q.
0x0012f2bc: 091c5ec0 0012f2c8 09694ed4 0012f308 .^.......Ni.....
0x0012f2cc: 09694e99 0012f2f0 0b712d80 0012f318 .Ni......-q.....
0x0012f2dc: 0012f468 09693ff5 0b712d80 0012f3bc h....?i..-q.....
0x0012f2ec: 00000000 091722f0 00000000 0012f2fc ....."..........
0x0012f2fc: 0012f468 091c5ec0 0b712d80 0012f468 h....^...-q.h...
0x0012f30c: 09693ff5 0012f3bc 0b712d80 44074000 .?i......-q..@.D
0x0012f31c: 437c0000 00000000 44074000 437c0000 ..|C.....@.D..|C
0x0012f32c: 00000000 0b607010 00000000 00000000 .....p`.........
0x0012f33c: 0b712d70 0b76cf50 09170178 7c930060 p-q.P.v.x...`..|
0x0012f34c: 00000000 0b712d70 44074000 437c0000 ....p-q..@.D..|C
0x0012f35c: 00000000 00000000 00000000 44730000 ..............sD
0x0012f36c: 44364000 00000000 00000000 00000000 .@6D............
0x0012f37c: 00000000 00000000 00000000 00000000 ................
0x0012f38c: 00000000 00000000 00000000 00000000 ................
0x0012f39c: 00000000 00000000 00000000 00000000 ................
0x0012f3ac: 00000000 00000000 00000000 00000000 ................
0x0012f3bc: 0012f318 00010000 00000040 0012f324 ........@...$...
0x0012f3cc: 000001c1 0012f410 7c92e920 7c930060 ........ ..|`..|
0x0012f3dc: ffffffff 7c93005d 1010ae98 09170000 ....]..|........
0x0012f3ec: 00000000 1010aeb7 2b93cd6e 09335f60 ........n..+`_3.
0x0012f3fc: 09335f60 00000000 00000003 0012f3f4 `_3.............
0x0012f40c: 00000000 0012ffb0 10112260 09335f60 ........`"..`_3.
0x0012f41c: 09335f60 091c4e70 0012f438 1006183e `_3.pN..8...>...
0x0012f42c: 091c4e70 0b610680 00000000 0b6240f0 pN....a......@b.
0x0012f43c: 091759a8 091c4f04 00000018 0000f4a8 .Y...O..........
0x0012f44c: 09170000 0012f248 0012f468 0012ffb0 ....H...h.......
0x0012f45c: 0b607fa0 0012f574 09680260 0012f4a0 ..`.t...`.h.....
0x0012f46c: 0968029b 09170000 00000000 0000000c ..h.............
0x0012f47c: 00000000 00000034 00000000 00000000 ....4...........
0x0012f48c: 10001c7e 0000000c 0b610878 091742d0 ~.......x.a..B..
0x0012f49c: 0b607fa0 0012f4d0 100ee53c 00000000 ..`.....<.......
0x0012f4ac: 00000000 0012f574 09693d10 00010000 ....t....=i.....
0x0012f4bc: 77d2a301 0b610878 00000000 091c4e70 ...wx.a.....pN..
0x0012f4cc: 00000000 0012f4f4 1005eae3 0b610878 ............x.a.
0x0012f4dc: 00000000 00000000 0012f574 0094b634 ........t...4...
0x0012f4ec: 0012f574 77d2a301 77d2772b 0056f4bb t......w+w.w..V.
0x0012f4fc: 0b610878 00000000 00000000 0012f574 x.a.........t...
0x0012f50c: 0094b644 ffffffff 00000000 77d2772b D...........+w.w
0x0012f51c: 0056f48c 0b610680 0094b644 ffffffff ..V...a.D.......
0x0012f52c: 0056f583 0b610878 00000000 0012f574 ..V.x.a.....t...
0x0012f53c: 08f23008 00000001 08f7c4d4 0b3d41f8 .0...........A=.
0x0012f54c: 77d2772b 00539737 00000007 0050a0e8 +w.w7.S.......P.
0x0012f55c: 08f23008 0056f6c1 0094b634 0094b644 .0....V.4...D...
0x0012f56c: 00000000 0012f574 00000000 0054ce23 ....t.......#.T.
0x0012f57c: 0094b634 0094b644 00000000 77d19645 4...D.......E..w
0x0012f58c: ffffffff 77d2a340 00d2772b 3f800000 ....@..w+w.....?
0x0012f59c: 005d97f5 00000000 00000001 00000064 ..].........d...
0x0012f5ac: 005d9d6f 00000010 00000000 0012f600 o.].............
0x0012f5bc: 00000000 ffffffff 000000cc 7c92d80a ...............|
0x0012f5cc: 7c8305ca ffffffff 0000001a 0012f5f0 ...|............
0x0012f5dc: 00000004 00000000 000f041e 00000113 ................
0x0012f5ec: 00000001 00000000 0016b8d5 00000237 ............7...
0x0012f5fc: 000001fc 0000000f 005daf23 00000000 ........#.].....
0x0012f60c: fffffffe 0012ffc0 00000001 0112f8a8 ................
0x0012f61c: 00000000 6f6e6f00 6374652f 742e6700 .....ono/etc.g.t
0x0012f62c: 00007478 00000000 0000000f 0012f88c xt..............
0x0012f63c: 08ef9900 00656c69 7c936f0d 0012f688 ....ile..o.|....
0x0012f64c: 00000000 0000000f 00000001 ffffffff ................
0x0012f65c: 00000008 08ef8920 0012f69c 002522e8 .... ........"%.
0x0012f66c: 003c0178 0000003f 0000003f 7c936e86 x.<.?...?....n.|
0x0012f67c: 08ef88d8 002522e8 00000002 003c0178 ....."%.....x.<.
0x0012f68c: 00000030 0000003f 00000000 6f6e6f4d 0...?.......Mono
0x0012f69c: 6e6f6d2f 6c642e6f 003c006c 0000000d /mono.dll.<.....
0x0012f6ac: 0000000f 00000000 08ef98d0 08ef9908 ................
0x0012f6bc: 08ef9908 7c9300b8 08ef9500 0012f794 .......|........
0x0012f6cc: 7c930041 003c06e8 00000000 0000000f A..|..<.........
0x0012f6dc: 7c9300b8 08ef87e0 0012f7b0 7c930041 ...|........A..|
0x0012f6ec: 00150fe8 00000019 0000001f 00000000 ................
0x0012f6fc: 08f20000 0012f930 003c0808 003c0000 ....0.....<...<.
0x0012f70c: 00000000 00000007 00440033 006f0042 ........3.D.B.o.
0x0012f71c: 00790064 002e0036 4e2d0030 72487ea7 d.y.6...0.-N.~Hr
0x0012f72c: 5b98ff0c 7f5165b9 0077ff1a 00770077 ...[.eQ...w.w.w.
0x0012f73c: 0033002e 00620064 0064006f 002e0079 ..3.d.b.o.d.y...
0x0012f74c: 006e0063 00740000 00750070 005f0074 c.n...t.p.u.t._.
0x0012f75c: 006f006c 002e0067 00780074 00000074 l.o.g...t.x.t...
0x0012f76c: 0012f92c 0012f930 00000001 00150000 ,...0...........
0x0012f77c: 00150000 00000000 00157e08 0012f798 .........~......
0x0012f78c: 00000000 7c9300b8 00157e00 0012f864 .......|.~..d...
0x0012f79c: 7c930041 00151318 7c93005d 00000000 A..|....]..|....
0x0012f7ac: 00000000 0012f92c 7c80e49f 00150000 ....,......|....
0x0012f7bc: 00000000 7c80e4a9 0012f814 7ffdf000 .......|........
0x0012f7cc: 0012f8bc 7c93743e 7c99e174 7c93741c ....>t.|t..|.t.|
0x0012f7dc: 5adc0000 00009e40 5adc0000 5adc0000 ...Z@......Z...Z
0x0012f7ec: 00000000 7ffdf000 00153f08 00157e08 .........?...~..
0x0012f7fc: 0012f952 00000014 00000001 00000000 R...............
0x0012f80c: 00000000 00000010 00000010 0012f8b8 ................
0x0012f81c: 7c839b48 7c80e418 77d6b44d 0012f848 H..|...|M..wH...
0x0012f82c: 5adc9e67 5adc9e94 5adf1b74 5adc0000 g..Z...Zt..Z...Z
0x0012f83c: 00000000 5adc9e40 00000000 0012f8cc ....@..Z........
0x0012f84c: 77d27f06 00000000 0012f864 5adc0000 ...w....d......Z
0x0012f85c: 00009e40 00000000 00000064 0012f89c @.......d.......
0x0012f86c: 00150000 7c930222 0000000f 00150958 ...."..|....X...
0x0012f87c: 00150000 0015f0f0 0012f874 7c930222 ........t..."..|
0x0012f88c: 0012fab8 7c92e920 7c930228 ffffffff .... ..|(..|....
0x0012f89c: 7c930222 7c93019b 7c9301db 0012fb54 "..|...|...|T...
0x0012f8ac: 7ffdfbf8 00000094 7c930222 0012fae4 ........"..|....
0x0012f8bc: 7c92e920 7c930228 ffffffff 7c930222  ..|(..|...."..|
0x0012f8cc: 7c93019b 7c9301db 0012fb74 7ffdfbf8 ...|...|t.......
0x0012f8dc: 00000094 0012f914 08e80000 7c930222 ............"..|
0x0012f8ec: 0000000f 08e80958 08e80000 00000000 ....X...........
0x0012f8fc: 0012f8ec 00000068 0012fb30 7c92e920 ....h...0... ..|
0x0012f90c: 0000010a 0012fb40 7c931028 7c931086 ....@...(..|...|
0x0012f91c: 7c9301db 00000104 08e894f8 00000000 ...|............
0x0012f92c: 003a0043 0057005c 004e0049 004f0044 C.:.\.W.I.N.D.O.
0x0012f93c: 00530057 0073005c 00730079 00650074 W.S.\.s.y.s.t.e.
0x0012f94c: 00000000 005c0032 00780075 00150640 ....2.\.u.x.@...
0x0012f95c: 006d0065 002e0065 006c0064 77d191a9 e.m.e...d.l....w
0x0012f96c: 0012f9a4 77d18fe7 00150178 0012faa0 .......wx.......
0x0012f97c: 00000000 00000000 00000003 08e80190 ................
0x0012f98c: 00150000 7c930222 00000004 00150748 ...."..|....H...
0x0012f99c: 00150000 0015e670 0012f994 7ffdfbf8 ....p...........
0x0012f9ac: 7c92d96e 0012fa28 0012f9e4 7c92f65c n..|(.......\..|
0x0012f9bc: 7c92f661 0012fa28 7c92d96e 7ffdfbf8 a..|(...n..|....
0x0012f9cc: 0012f9c0 7c92d97a 0012fd30 7c92e920 ....z..|0... ..|
0x0012f9dc: 7c92f668 ffffffff 0012fa18 00150000 h..|............
0x0012f9ec: 7c930222 0000000f 00150958 00150000 "..|....X.......
0x0012f9fc: 0015f0f0 0012f9f0 0012fb24 0012fc34 ........$...4...
0x0012fa0c: 7c92e920 7c930228 ffffffff 7c930222  ..|(..|...."..|
0x0012fa1c: 7c93019b 0012fa54 00150000 7c930222 ...|T......."..|
0x0012fa2c: 00000005 00150778 00150000 00000000 ....x...........
0x0012fa3c: 0012fa2c 00000b0c 0012fc74 7c931028 ,.......t...(..|
0x0012fa4c: 003f0000 7c9301db 003f0000 003fca18 ..?....|..?...?.
0x0012fa5c: 00000000 00154074 00000001 00000000 ....t@..........
0x0012fa6c: 00000032 00150fe8 00150000 00153f08 2............?..
0x0012fa7c: 0012fa6c 00700073 0012fcb0 7c92e920 l...s.p..... ..|
0x0012fa8c: 7c930228 ffffffff 7c930222 7c93019b (..|...."..|...|
0x0012fa9c: 7c9301db 00000000 00000000 00000000 ...|............
0x0012faac: 0000002c 0012fad4 71a28140 0000ec03 ,.......@..q....
0x0012fabc: 0012faf0 08e80000 7c930222 0000000c ........"..|....
0x0012facc: 08e808c8 08e80000 00000000 0012fac8 ................
0x0012fadc: 0012fb74 00000000 7c92e920 000000fe t....... ..|....
0x0012faec: 08ec0000 7c931028 7c931086 7c9301db ....(..|...|...|
0x0012fafc: 0000277b 08e81e90 00000001 003f0178 {'..........x.?.
0x0012fb0c: 00000000 00000004 00150178 71a27451 ........x...Qt.q
0x0012fb1c: 00000004 00000000 00000000 0012fb58 ............X...
0x0012fb2c: 0012fb74 08ef87a0 00000004 08e894f8 t...............
0x0012fb3c: 0015f658 7c92d96e 0012fbbc 0012fb78 X...n..|....x...
0x0012fb4c: 7c92f65c 00000008 0012fbbc 7c92d96e \..|........n..|
0x0012fb5c: 00000008 003f0178 7c92d97a 08ef83a0 ....x.?.z..|....
0x0012fb6c: 00150178 7c92f668 0015f638 7c92f661 x...h..|8...a..|
0x0012fb7c: 003f0178 c0000034 08ef87a8 00000000 x.?.4...........
0x0012fb8c: 77da6ff6 0015f660 003f0178 0012fba8 .o.w`...x.?.....
0x0012fb9c: 00000001 7c9300b8 003fca18 0012fc74 .......|..?.t...
0x0012fbac: 7c930041 003f12b8 7c93005d 08ef85a0 A..|..?.]..|....
0x0012fbbc: 003fcc20 08ef83a0 00000000 00000b0c  .?.............
0x0012fbcc: 004000d8 0012fbc0 00000135 08e89810 ..@.....5.......
0x0012fbdc: 7c92e920 0000000f 003f0178 7c930323  ..|....x.?.#..|
0x0012fbec: 7c92f62d 00150178 00000000 00000008 -..|x...........
0x0012fbfc: 7c9315f9 00154074 0015f638 08ef83a0 ...|t@..8.......
0x0012fc0c: 00000078 00000081 00000208 0012fc70 x...........p...
0x0012fc1c: 00000005 7c92f668 0012fc58 00150000 ....h..|X.......
0x0012fc2c: 7c930222 00000005 00150778 00150000 "..|....x.......
0x0012fc3c: 00000000 0012fc30 08ef83a0 0012fe74 ....0.......t...
0x0012fc4c: 7c92e920 00000130 0012fe84 7c931028  ..|0.......(..|
0x0012fc5c: 7c931086 7c9301db 00a8fd98 00000001 ...|...|........
0x0012fc6c: 00000000 ffffffff 7c93005d 7c938649 ........]..|I..|
0x0012fc7c: 7c9386c5 003f0608 7c938681 00000200 ...|..?....|....
0x0012fc8c: 00000400 003fca20 00154074 00000001 .... .?.t@......
0x0012fc9c: 00000000 7c92d2aa 7c80df03 ffffffff .......|...|....
0x0012fcac: 08ef8398 ffffffff 08ef83a0 00000000 ................
0x0012fcbc: 00000000 7c80df13 08e897b8 ffffffff .......|........
0x0012fccc: 0000277b 0012fcc4 08e897b0 0012fd74 {'..........t...
0x0012fcdc: 7c839b48 7c80df18 ffffffff 7c80df13 H..|...|.......|
0x0012fcec: 71a115bf 00000000 fffffffe ffffffff ...q............
0x0012fcfc: 00150640 00000000 00000000 00000002 @...............
0x0012fd0c: 71a115ca 08e897c8 0012fd30 00150178 ...q....0...x...
0x0012fd1c: 4d4b4320 08e897b8 0000277b 00000000  CKM....{'......
0x0012fd2c: 0012fd44 71a22ba3 0000000d 08e897b8 D....+.q........
0x0012fd3c: 08e81e90 0015f680 00000008 0012fd84 ................
0x0012fd4c: 71a26b5b 71a26b63 fffffffe 00925c1c [k.qck.q.....\..
0x0012fd5c: 003fca18 00000008 08e897b8 00000000 ..?.............
0x0012fd6c: 0012fd54 00150178 0012ffb0 0015f660 T...x.......`...
0x0012fd7c: 71a26b80 ffffffff 71a26b63 007b108b .k.q....ck.q..{.
0x0012fd8c: 00150178 0012fd94 0015f688 536e6957 x...........WinS
0x0012fd9c: 206b636f 00302e32 00150178 0050004f ock 2.0.x...O.P.
0x0012fdac: 004e0045 00530053 005f004c 00610069 E.N.S.S.L._.i.a.
0x0012fdbc: 00320033 00610063 00000070 00008bba 3.2.c.a.p.......
0x0012fdcc: 007e8456 0000cccc 0000004c 00000130 V.~.....L...0...
0x0012fddc: 0043004f 00530045 003fca20 005f0052 O.C.E.S. .?.R._.
0x0012fdec: 00000041 00450056 00150178 0000000f A...V.E.x.......
0x0012fdfc: 00008bba 7c9315f9 00a8fd98 0015f660 .......|....`...
0x0012fe0c: 00000000 0000000f 00000003 0015f660 ............`...
0x0012fe1c: 0012fdd8 00000005 006a2014 00000000 ......... j.....
0x0012fe2c: 00000081 01000000 00000408 c1a409ff ................
0x0012fe3c: 0015f658 00150168 00000000 00000000 X...h...........
0x0012fe4c: 0015f658 00000028 0015f660 7c938681 X...(...`......|
0x0012fe5c: 00150178 00000028 00000001 00150000 x...(...........
0x0012fe6c: 0012fc64 08ef85d0 00000000 0012febc d...............
0x0012fe7c: 007d8241 003f0000 00000000 7c92d80a A.}...?........|
0x0012fe8c: 7c9332f0 ffffffff 00000024 0012fea4 .2.|....$.......
0x0012fe9c: 00000004 00000000 1b61fb2f 0012feb8 ......../.a.....
0x0012feac: 007d6361 08ef85d4 08ef85d4 0012fed8 ac}.............
0x0012febc: 007c68bb 138e7efb 1bf3bf6f 007d4676 .h|..~..o...vF}.
0x0012fecc: 0012fefc 007d641d 0000000e 0012fefc .....d}.........
0x0012fedc: 007d65f7 00000000 00000000 0012ff08 .e}.............
0x0012feec: 007d6604 0012ff08 007c7a08 00152336 .f}......z|.6#..
0x0012fefc: 0012ff18 007e9b5b 00000000 00a26f60 ....[.~.....`o..
0x0012ff0c: 003f2d68 003f1e90 007c6901 0012ff30 h-?...?..i|.0...
0x0012ff1c: 007e9bae 00000000 00000022 00000000 ..~.....".......
0x0012ff2c: 00000004 0012ffc0 007ca51b 00400000 ..........|...@.
0x0012ff3c: 00000000 00152338 00000001 c1a40803 ....8#..........
0x0012ff4c: 77da6a90 ffffffff 7ffd6000 00000044 .j.w.....`..D...
0x0012ff5c: 00154330 00154548 00154560 00000000 0C..HE..`E......
0x0012ff6c: 00000000 00000000 00000000 00000000 ................
0x0012ff7c: 00000000 00000000 00000401 00000001 ................
0x0012ff8c: 00000000 00000000 00010001 00000000 ................
0x0012ff9c: c0000005 00000000 00000000 0012ff48 ............H...
0x0012ffac: 0012ee60 0012ffe0 007cbe30 c116ad0b `.......0.|.....
0x0012ffbc: 00000001 0012fff0 7c816037 77da6a90 ........7`.|.j.w
0x0012ffcc: ffffffff 7ffd6000 c0000005 0012ffc8 .....`..........
0x0012ffdc: 0012ee70 ffffffff 7c839b48 7c816040 p.......H..|@`.|
0x0012ffec: 00000000 00000000 00000000 007ca408 ..............|.
0x0012fffc: 00000000                            ....

Module 1
E:\dll注入\系统解剖\系统解剖_dump.exe
Image Base: 0x00400000  Image Size: 0x007af000
File Size:  8052736     File Time:  2015-05-12_093646
Version:
   Company:   
   Product:   
   FileDesc:   
   FileVer:    3.3.0.63049
   ProdVer:    3.3.0.63049

Module 2
C:\Program Files\Debugging Tools for Windows (x86)\symsrv.dll
Image Base: 0x01d00000  Image Size: 0x00048000
File Size:  131856      File Time:  2010-02-01_122732
Version:
   Company:    Microsoft Corporation
   Product:    Debugging Tools for Windows(R)
   FileDesc:   Symbol Server
   FileVer:    6.12.2.633
   ProdVer:    6.12.2.633

Module 3
C:\WINDOWS\system32\Normaliz.dll
Image Base: 0x00400000  Image Size: 0x00009000
File Size:  23552       File Time:  2011-08-23_164316
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Unicode Normalization DLL
   FileVer:    6.0.5441.0
   ProdVer:    6.0.5441.0

Module 4
C:\WINDOWS\system32\xpsp2res.dll
Image Base: 0x00010000  Image Size: 0x00549000
File Size:  5535744     File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Service Pack 2 Messages
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 5
C:\WINDOWS\system32\xinput9_1_0.dll
Image Base: 0x00400000  Image Size: 0x00012000
File Size:  61136       File Time:  2011-04-29_094724
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? DirectX for Windows?
   FileDesc:   Microsoft Common Controller API
   FileVer:    9.10.455.0
   ProdVer:    9.10.455.0

Module 6
C:\Program Files\Debugging Tools for Windows (x86)\dbghelp.dll
Image Base: 0x03000000  Image Size: 0x00141000
File Size:  1213200     File Time:  2010-02-01_122716
Version:
   Company:    Microsoft Corporation
   Product:    Debugging Tools for Windows(R)
   FileDesc:   Windows Image Helper
   FileVer:    6.12.2.633
   ProdVer:    6.12.2.633

Module 7
E:\dll注入\系统解剖\系统解剖_dump_Data\Mono\mono.dll
Image Base: 0x10000000  Image Size: 0x00214000
File Size:  2082304     File Time:  2015-05-12_085558
Version:
   Company:   
   Product:   
   FileDesc:   
   FileVer:    0.0.0.0
   ProdVer:    0.0.0.0

Module 8
C:\WINDOWS\system32\WININET.dll
Image Base: 0x3e410000  Image Size: 0x000e7000
File Size:  920064      File Time:  2014-03-07_015850
Version:
   Company:    Microsoft Corporation
   Product:    Windows? Internet Explorer
   FileDesc:   Internet Extensions for Win32
   FileVer:    8.0.6001.23580
   ProdVer:    8.0.6001.23580

Module 9
C:\WINDOWS\system32\iertutil.dll
Image Base: 0x3eab0000  Image Size: 0x001ec000
File Size:  2006016     File Time:  2014-03-07_015850
Version:
   Company:    Microsoft Corporation
   Product:    Windows? Internet Explorer
   FileDesc:   Run time utility for Internet Explorer
   FileVer:    8.0.6001.23580
   ProdVer:    8.0.6001.23580

Module 10
C:\WINDOWS\system32\urlmon.dll
Image Base: 0x43ce0000  Image Size: 0x00134000
File Size:  1216000     File Time:  2014-03-07_015850
Version:
   Company:    Microsoft Corporation
   Product:    Windows? Internet Explorer
   FileDesc:   OLE32 Extensions for Win32
   FileVer:    8.0.6001.23580
   ProdVer:    8.0.6001.23580

Module 11
C:\WINDOWS\system32\d3d9.dll
Image Base: 0x4b640000  Image Size: 0x001a6000
File Size:  1689088     File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Microsoft Direct3D
   FileVer:    5.3.2600.5512
   ProdVer:    5.3.2600.5512

Module 12
C:\WINDOWS\system32\uxtheme.dll
Image Base: 0x5adc0000  Image Size: 0x00037000
File Size:  216064      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Microsoft UxTheme Library
   FileVer:    6.0.2900.5512
   ProdVer:    6.0.2900.5512

Module 13
C:\WINDOWS\system32\opengl32.dll
Image Base: 0x5ef10000  Image Size: 0x000cc000
File Size:  713728      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   OpenGL Client DLL
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 14
C:\WINDOWS\system32\NETAPI32.dll
Image Base: 0x5fdd0000  Image Size: 0x00055000
File Size:  337920      File Time:  2012-07-06_215854
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Net Win32 API DLL
   FileVer:    5.1.2600.6260
   ProdVer:    5.1.2600.6260

Module 15
C:\WINDOWS\system32\hnetcfg.dll
Image Base: 0x60fd0000  Image Size: 0x00055000
File Size:  333824      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Home Networking Configuration Manager
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 16
C:\WINDOWS\system32\LPK.DLL
Image Base: 0x62c20000  Image Size: 0x00009000
File Size:  22016       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Language Pack
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 17
C:\WINDOWS\system32\rsaenh.dll
Image Base: 0x68000000  Image Size: 0x00036000
File Size:  208384      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Microsoft Enhanced Cryptographic Provider
   FileVer:    5.1.2600.5507
   ProdVer:    5.1.2600.5507

Module 18
C:\WINDOWS\system32\hid.dll
Image Base: 0x68be0000  Image Size: 0x00009000
File Size:  20992       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Hid User Library
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 19
C:\WINDOWS\system32\GLU32.dll
Image Base: 0x68e20000  Image Size: 0x00020000
File Size:  121856      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   OpenGL Utility Library DLL
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 20
C:\WINDOWS\system32\d3d8thk.dll
Image Base: 0x6dd20000  Image Size: 0x00006000
File Size:  8192        File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Microsoft Direct3D OS Thunk Layer
   FileVer:    5.3.2600.5512
   ProdVer:    5.3.2600.5512

Module 21
C:\WINDOWS\system32\MSWSOCK.dll
Image Base: 0x719c0000  Image Size: 0x0003e000
File Size:  240640      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Microsoft Windows Sockets 2.0 Service Provider
   FileVer:    5.1.2600.5625
   ProdVer:    5.1.2600.5625

Module 22
C:\WINDOWS\System32\wshtcpip.dll
Image Base: 0x71a00000  Image Size: 0x00008000
File Size:  19456       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Windows Sockets Helper DLL
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 23
C:\WINDOWS\system32\WS2HELP.dll
Image Base: 0x71a10000  Image Size: 0x00008000
File Size:  19968       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Windows Socket 2.0 Helper for Windows NT
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 24
C:\WINDOWS\system32\ws2_32.dll
Image Base: 0x71a20000  Image Size: 0x00017000
File Size:  82432       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Windows Socket 2.0 32-Bit DLL
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 25
C:\WINDOWS\system32\wsock32.dll
Image Base: 0x71a40000  Image Size: 0x0000b000
File Size:  28672       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Windows Socket 32-Bit DLL
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 26
C:\WINDOWS\system32\msacm32.drv
Image Base: 0x72c80000  Image Size: 0x00008000
File Size:  20480       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Microsoft Sound Mapper
   FileVer:    5.1.2600.0
   ProdVer:    5.1.2600.0

Module 27
C:\WINDOWS\system32\wdmaud.drv
Image Base: 0x72c90000  Image Size: 0x00009000
File Size:  23552       File Time:  2008-04-13_111420
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   WDM Audio driver mapper
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 28
C:\WINDOWS\system32\msctfime.ime
Image Base: 0x73640000  Image Size: 0x0002e000
File Size:  177152      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Microsoft Text Frame Work Service IME
   FileVer:    5.1.2600.5768
   ProdVer:    5.1.2600.5768

Module 29
C:\WINDOWS\system32\DDRAW.dll
Image Base: 0x736d0000  Image Size: 0x0004b000
File Size:  279040      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Microsoft DirectDraw
   FileVer:    5.3.2600.5512
   ProdVer:    5.3.2600.5512

Module 30
C:\WINDOWS\system32\DCIMAN32.dll
Image Base: 0x73b30000  Image Size: 0x00006000
File Size:  8704        File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   DCI Manager
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 31
C:\WINDOWS\system32\KsUser.dll
Image Base: 0x73e40000  Image Size: 0x00004000
File Size:  4096        File Time:  2008-04-13_111344
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   User CSA Library
   FileVer:    5.3.2600.5512
   ProdVer:    5.3.2600.5512

Module 32
C:\WINDOWS\system32\dsound.dll
Image Base: 0x73e70000  Image Size: 0x0005c000
File Size:  367616      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   DirectSound
   FileVer:    5.3.2600.5512
   ProdVer:    5.3.2600.5512

Module 33
C:\WINDOWS\system32\USP10.dll
Image Base: 0x73fa0000  Image Size: 0x0006b000
File Size:  406016      File Time:  2013-07-10_183754
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Uniscribe Unicode script processor
   FileDesc:   Uniscribe Unicode script processor
   FileVer:    1.420.2600.6421
   ProdVer:    1.420.2600.6421

Module 34
C:\WINDOWS\system32\MSCTF.dll
Image Base: 0x74680000  Image Size: 0x0004c000
File Size:  296960      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   MSCTF Server DLL
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 35
C:\WINDOWS\system32\mlang.dll
Image Base: 0x74cf0000  Image Size: 0x00091000
File Size:  586240      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Multi Language Support DLL
   FileVer:    6.0.2900.5512
   ProdVer:    6.0.2900.5512

Module 36
C:\WINDOWS\system32\wbem\wbemsvc.dll
Image Base: 0x74e30000  Image Size: 0x0000e000
File Size:  43520       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   WMI
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 37
C:\WINDOWS\system32\wbem\wbemprox.dll
Image Base: 0x74e50000  Image Size: 0x00008000
File Size:  18944       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   WMI
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 38
C:\WINDOWS\system32\wbem\wbemcomn.dll
Image Base: 0x751f0000  Image Size: 0x00037000
File Size:  214528      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   WMI
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 39
C:\WINDOWS\system32\wbem\fastprox.dll
Image Base: 0x755f0000  Image Size: 0x00076000
File Size:  473600      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   WMI
   FileVer:    5.1.2600.5755
   ProdVer:    5.1.2600.5755

Module 40
C:\WINDOWS\system32\USERENV.dll
Image Base: 0x759d0000  Image Size: 0x000af000
File Size:  708608      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Userenv
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 41
C:\WINDOWS\system32\MSVCP60.dll
Image Base: 0x75ff0000  Image Size: 0x00065000
File Size:  413696      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft (R) Visual C++
   FileDesc:   Microsoft (R) C++ Runtime Library
   FileVer:    6.2.3104.0
   ProdVer:    6.2.3104.0

Module 42
C:\WINDOWS\system32\SETUPAPI.dll
Image Base: 0x76060000  Image Size: 0x00156000
File Size:  1389568     File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Windows Setup API
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 43
C:\WINDOWS\system32\imm32.dll
Image Base: 0x76300000  Image Size: 0x0001d000
File Size:  110080      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Windows XP IMM32 API Client DLL
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 44
C:\WINDOWS\system32\CRYPT32.dll
Image Base: 0x765e0000  Image Size: 0x00095000
File Size:  595968      File Time:  2013-10-07_185920
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Crypto API32
   FileVer:    5.131.2600.6459
   ProdVer:    5.131.2600.6459

Module 45
C:\WINDOWS\system32\cryptdll.dll
Image Base: 0x76760000  Image Size: 0x0000c000
File Size:  33280       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Cryptography Manager
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 46
C:\WINDOWS\system32\NTDSAPI.dll
Image Base: 0x76770000  Image Size: 0x00013000
File Size:  67072       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   NT5DS
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 47
C:\WINDOWS\system32\ole32.dll
Image Base: 0x76990000  Image Size: 0x0013e000
File Size:  1289216     File Time:  2013-08-05_213032
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Microsoft OLE for Windows
   FileVer:    5.1.2600.6435
   ProdVer:    5.1.2600.6435

Module 48
C:\WINDOWS\system32\WINMM.dll
Image Base: 0x76b10000  Image Size: 0x0002a000
File Size:  163840      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   MCI API DLL
   FileVer:    5.1.2600.6160
   ProdVer:    5.1.2600.6160

Module 49
C:\WINDOWS\system32\PSAPI.DLL
Image Base: 0x76bc0000  Image Size: 0x0000b000
File Size:  23040       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Process Status Helper
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 50
C:\WINDOWS\system32\WINTRUST.dll
Image Base: 0x76c00000  Image Size: 0x0002e000
File Size:  176640      File Time:  2012-08-24_215356
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Microsoft Trust Verification APIs
   FileVer:    5.131.2600.6285
   ProdVer:    5.131.2600.6285

Module 51
C:\WINDOWS\system32\IMAGEHLP.dll
Image Base: 0x76c60000  Image Size: 0x00029000
File Size:  150528      File Time:  2013-11-13_105926
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Windows NT Image Helper
   FileVer:    5.1.2600.6479
   ProdVer:    5.1.2600.6479

Module 52
C:\WINDOWS\system32\iphlpapi.dll
Image Base: 0x76d30000  Image Size: 0x00018000
File Size:  94208       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   IP Helper API
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 53
C:\WINDOWS\system32\MSASN1.dll
Image Base: 0x76db0000  Image Size: 0x00012000
File Size:  58880       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   ASN.1 Runtime APIs
   FileVer:    5.1.2600.5875
   ProdVer:    5.1.2600.5875

Module 54
C:\WINDOWS\system32\rtutils.dll
Image Base: 0x76e50000  Image Size: 0x0000e000
File Size:  44032       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Routing Utilities
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 55
C:\WINDOWS\system32\rasman.dll
Image Base: 0x76e60000  Image Size: 0x00012000
File Size:  61440       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Remote Access Connection Manager
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 56
C:\WINDOWS\system32\TAPI32.dll
Image Base: 0x76e80000  Image Size: 0x0002f000
File Size:  181760      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Microsoft(R) Windows(TM) Telephony API Client DLL
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 57
C:\WINDOWS\system32\RASAPI32.dll
Image Base: 0x76eb0000  Image Size: 0x0003c000
File Size:  236032      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Remote Access API
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 58
C:\WINDOWS\system32\DNSAPI.dll
Image Base: 0x76ef0000  Image Size: 0x00027000
File Size:  149504      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   DNS Client API DLL
   FileVer:    5.1.2600.6089
   ProdVer:    5.1.2600.6089

Module 59
C:\WINDOWS\system32\WLDAP32.dll
Image Base: 0x76f30000  Image Size: 0x0002c000
File Size:  170496      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Win32 LDAP API DLL
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 60
C:\WINDOWS\system32\rasadhlp.dll
Image Base: 0x76f90000  Image Size: 0x00006000
File Size:  7680        File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Remote Access AutoDial Helper
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 61
C:\WINDOWS\system32\CLBCATQ.DLL
Image Base: 0x76fa0000  Image Size: 0x0007f000
File Size:  498688      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    COM Services
   FileDesc:   
   FileVer:    2001.12.4414.700
   ProdVer:    3.0.0.4414

Module 62
C:\WINDOWS\system32\COMRes.dll
Image Base: 0x77020000  Image Size: 0x0009a000
File Size:  615936      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    COM 服务
   FileDesc:   
   FileVer:    2001.12.4414.700
   ProdVer:    3.0.0.4414

Module 63
C:\WINDOWS\system32\oleaut32.dll
Image Base: 0x770f0000  Image Size: 0x0008b000
File Size:  552448      File Time:  2013-01-26_115546
Version:
   Company:    Microsoft Corporation
   Product:   
   FileDesc:   
   FileVer:    5.1.2600.6341
   ProdVer:    5.1.2600.6341

Module 64
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
Image Base: 0x77180000  Image Size: 0x00103000
File Size:  1054208     File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   User Experience Controls Library
   FileVer:    6.0.2900.6028
   ProdVer:    6.0.2900.6028

Module 65
C:\WINDOWS\system32\midimap.dll
Image Base: 0x77ba0000  Image Size: 0x00007000
File Size:  18944       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Microsoft MIDI Mapper
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 66
C:\WINDOWS\system32\msacm32.dll
Image Base: 0x77bb0000  Image Size: 0x00015000
File Size:  71168       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Microsoft ACM Audio Filter
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 67
C:\WINDOWS\system32\version.dll
Image Base: 0x77bd0000  Image Size: 0x00008000
File Size:  18944       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Version Checking and File Installation Libraries
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 68
C:\WINDOWS\system32\msvcrt.dll
Image Base: 0x77be0000  Image Size: 0x00058000
File Size:  343040      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Windows NT CRT DLL
   FileVer:    7.0.2600.5512
   ProdVer:    6.1.8638.5512

Module 69
C:\WINDOWS\system32\msv1_0.dll
Image Base: 0x77c40000  Image Size: 0x00025000
File Size:  136192      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Microsoft Authentication Package v1.0
   FileVer:    5.1.2600.5876
   ProdVer:    5.1.2600.5876

Module 70
C:\WINDOWS\system32\USER32.dll
Image Base: 0x77d10000  Image Size: 0x00090000
File Size:  574976      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Windows XP USER API Client DLL
   FileVer:    5.1.2600.5512
   ProdVer:    5.1.2600.5512

Module 71
C:\WINDOWS\system32\advapi32.dll
Image Base: 0x77da0000  Image Size: 0x000a9000
File Size:  674816      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Advanced Windows 32 Base API
   FileVer:    5.1.2600.5755
   ProdVer:    5.1.2600.5755

Module 72
C:\WINDOWS\system32\RPCRT4.dll
Image Base: 0x77e50000  Image Size: 0x00093000
File Size:  591360      File Time:  2013-11-07_133852
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Remote Procedure Call Runtime
   FileVer:    5.1.2600.6477
   ProdVer:    5.1.2600.6477

Module 73
C:\WINDOWS\system32\gdi32.dll
Image Base: 0x77ef0000  Image Size: 0x00049000
File Size:  287744      File Time:  2013-10-09_211240
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   GDI Client DLL
   FileVer:    5.1.2600.6460
   ProdVer:    5.1.2600.6460

Module 74
C:\WINDOWS\system32\SHLWAPI.dll
Image Base: 0x77f40000  Image Size: 0x00076000
File Size:  473088      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Shell Light-weight Utility Library
   FileVer:    6.0.2900.5912
   ProdVer:    6.0.2900.5912

Module 75
C:\WINDOWS\system32\Secur32.dll
Image Base: 0x77fc0000  Image Size: 0x00011000
File Size:  56832       File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Security Support Provider Interface
   FileVer:    5.1.2600.5834
   ProdVer:    5.1.2600.5834

Module 76
C:\WINDOWS\system32\kernel32.dll
Image Base: 0x7c800000  Image Size: 0x0011e000
File Size:  1154048     File Time:  2014-03-12_184844
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Windows NT BASE API Client DLL
   FileVer:    5.1.2600.6532
   ProdVer:    5.1.2600.6532

Module 77
C:\WINDOWS\system32\ntdll.dll
Image Base: 0x7c920000  Image Size: 0x00096000
File Size:  601600      File Time:  2012-03-20_202020
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   NT Layer DLL
   FileVer:    5.1.2600.6055
   ProdVer:    5.1.2600.6055

Module 78
C:\WINDOWS\system32\shell32.dll
Image Base: 0x7d590000  Image Size: 0x007f4000
File Size:  8320512     File Time:  2012-06-08_222548
Version:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Windows Shell Common Dll
   FileVer:    6.0.2900.6242
   ProdVer:    6.0.2900.6242

== [end of error.log] ==

[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课

上传的附件:
收藏
免费 0
支持
分享
最新回复 (2)
雪    币: 101
活跃值: (92)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
2
什么壳啊,也没有脱壳脚本吗?
2015-7-4 08:49
0
雪    币: 45
活跃值: (26)
能力值: ( LV3,RANK:20 )
在线值:
发帖
回帖
粉丝
3
加密狗是et199 ,molebox打包
2015-7-4 16:56
0
游客
登录 | 注册 方可回帖
返回
//