能力值:
( LV3,RANK:20 )
4 楼
molebox解包应该完整了,我根据其他能运行的程序解包的,可能还是在于脱壳过程,我q:1930988
错误日志中应该是访问系统dll
Direct3D:
Version: Direct3D 9.0c [igxprd32.dll 6.14.10.4926]
Renderer: Mobile Intel(R) 945 Express Chipset Family
Vendor: Intel
VRAM: 64 MB
Caps: Shader=20 DepthRT=0 NativeDepth=0 NativeShadow=0 DF16=0 DF24=0 INTZ=0 RAWZ=0 NULL=0 RESZ=0 SlowINTZ=0
desktop: 1024x768 60Hz; virtual: 1024x768 at 0,0
<I> Initializing (RawInput).
<RI> Input initialized.
Non platform assembly: data-093641C8 (this message is harmless)
Non platform assembly: data-093C8A70 (this message is harmless)
Non platform assembly: data-093CCED8 (this message is harmless)
Non platform assembly: data-093E6D48 (this message is harmless)
Non platform assembly: data-093E8F70 (this message is harmless)
Platform assembly: E:\dll娉ㄥ叆\绯荤粺瑙e墫\绯荤粺瑙e墫_dump_Data\Managed\System.Xml.dll (this message is harmless)
Crash!!!
========== Outputing stack ==================
SymInit: Symbol-SearchPath: '.;E:\dll注入\系统解剖;E:\dll注入\系统解剖;C:\WINDOWS;C:\WINDOWS\system32;SRV*C:\websymbols*http://msdl.microsoft.com/downl', symOptions: 530, UserName: 'Administrator'
OS-Version: 5.1.2600 (Service Pack 3) 0x100-0x1
E:\dll注入\系统解剖\系统解剖_dump.exe:系统解剖_dump.exe (00400000), size: 8056832 (result: 0), SymType: '-exported-', PDB: 'E:\dll注入\系统解剖\系统解?, fileVersion: 3.3.0.63049
C:\WINDOWS\system32\ntdll.dll:ntdll.dll (7C920000), size: 614400 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\ntdll.dll', fileVersion: 5.1.2600.6055
C:\WINDOWS\system32\kernel32.dll:kernel32.dll (7C800000), size: 1171456 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\kernel32.dll', fileVersion: 5.1.2600.6532
C:\WINDOWS\system32\advapi32.dll:advapi32.dll (77DA0000), size: 692224 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\advapi32.dll', fileVersion: 5.1.2600.5755
C:\WINDOWS\system32\RPCRT4.dll:RPCRT4.dll (77E50000), size: 602112 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\RPCRT4.dll', fileVersion: 5.1.2600.6477
C:\WINDOWS\system32\Secur32.dll:Secur32.dll (77FC0000), size: 69632 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\Secur32.dll', fileVersion: 5.1.2600.5834
C:\WINDOWS\system32\gdi32.dll:gdi32.dll (77EF0000), size: 299008 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\gdi32.dll', fileVersion: 5.1.2600.6460
C:\WINDOWS\system32\USER32.dll:USER32.dll (77D10000), size: 589824 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\USER32.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\hid.dll:hid.dll (68BE0000), size: 36864 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\hid.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\msvcrt.dll:msvcrt.dll (77BE0000), size: 360448 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\msvcrt.dll', fileVersion: 7.0.2600.5512
C:\WINDOWS\system32\imm32.dll:imm32.dll (76300000), size: 118784 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\imm32.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\msacm32.dll:msacm32.dll (77BB0000), size: 86016 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\msacm32.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\WINMM.dll:WINMM.dll (76B10000), size: 172032 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\WINMM.dll', fileVersion: 5.1.2600.6160
C:\WINDOWS\system32\oleaut32.dll:oleaut32.dll (770F0000), size: 569344 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\oleaut32.dll', fileVersion: 5.1.2600.6341
C:\WINDOWS\system32\ole32.dll:ole32.dll (76990000), size: 1302528 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\ole32.dll', fileVersion: 5.1.2600.6435
C:\WINDOWS\system32\opengl32.dll:opengl32.dll (5EF10000), size: 835584 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\opengl32.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\GLU32.dll:GLU32.dll (68E20000), size: 131072 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\GLU32.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\DDRAW.dll:DDRAW.dll (736D0000), size: 307200 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\DDRAW.dll', fileVersion: 5.3.2600.5512
C:\WINDOWS\system32\DCIMAN32.dll:DCIMAN32.dll (73B30000), size: 24576 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\DCIMAN32.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\shell32.dll:shell32.dll (7D590000), size: 8339456 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\shell32.dll', fileVersion: 6.0.2900.6242
C:\WINDOWS\system32\SHLWAPI.dll:SHLWAPI.dll (77F40000), size: 483328 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\SHLWAPI.dll', fileVersion: 6.0.2900.5912
C:\WINDOWS\system32\version.dll:version.dll (77BD0000), size: 32768 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\version.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\ws2_32.dll:ws2_32.dll (71A20000), size: 94208 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\ws2_32.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\WS2HELP.dll:WS2HELP.dll (71A10000), size: 32768 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\WS2HELP.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\wsock32.dll:wsock32.dll (71A40000), size: 45056 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\wsock32.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\LPK.DLL:LPK.DLL (62C20000), size: 36864 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\LPK.DLL', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\USP10.dll:USP10.dll (73FA0000), size: 438272 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\USP10.dll', fileVersion: 1.420.2600.6421
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll:comctl32.dll (77180000), size: 1060864 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll', fileVersion: 6.0.2900.6028
C:\WINDOWS\system32\uxtheme.dll:uxtheme.dll (5ADC0000), size: 225280 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\uxtheme.dll', fileVersion: 6.0.2900.5512
E:\dll注入\系统解剖\系统解剖_dump_Data\Mono\mono.dll:mono.dll (10000000), size: 2179072 (result: 0), SymType: '-exported-', PDB: 'E:\dll注入\系统解剖\系统解剖_dump_Data\Mon'
C:\WINDOWS\system32\PSAPI.DLL:PSAPI.DLL (76BC0000), size: 45056 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\PSAPI.DLL', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\MSWSOCK.dll:MSWSOCK.dll (719C0000), size: 253952 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\MSWSOCK.dll', fileVersion: 5.1.2600.5625
C:\WINDOWS\system32\d3d9.dll:d3d9.dll (4B640000), size: 1728512 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\d3d9.dll', fileVersion: 5.3.2600.5512
C:\WINDOWS\system32\d3d8thk.dll:d3d8thk.dll (6DD20000), size: 24576 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\d3d8thk.dll', fileVersion: 5.3.2600.5512
C:\WINDOWS\system32\MSCTF.dll:MSCTF.dll (74680000), size: 311296 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\MSCTF.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\CLBCATQ.DLL:CLBCATQ.DLL (76FA0000), size: 520192 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\CLBCATQ.DLL', fileVersion: 2001.12.4414.700
C:\WINDOWS\system32\COMRes.dll:COMRes.dll (77020000), size: 630784 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\COMRes.dll', fileVersion: 2001.12.4414.700
C:\WINDOWS\system32\wbem\wbemprox.dll:wbemprox.dll (74E50000), size: 32768 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\wbem\wbemprox.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\wbem\wbemcomn.dll:wbemcomn.dll (751F0000), size: 225280 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\wbem\wbemcomn.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\xpsp2res.dll:xpsp2res.dll (09A40000), size: 5541888 (result: 0), SymType: '-nosymbols-', PDB: 'C:\WINDOWS\system32\xpsp2res.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\wbem\wbemsvc.dll:wbemsvc.dll (74E30000), size: 57344 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\wbem\wbemsvc.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\wbem\fastprox.dll:fastprox.dll (755F0000), size: 483328 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\wbem\fastprox.dll', fileVersion: 5.1.2600.5755
C:\WINDOWS\system32\MSVCP60.dll:MSVCP60.dll (75FF0000), size: 413696 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\MSVCP60.dll', fileVersion: 6.2.3104.0
C:\WINDOWS\system32\NTDSAPI.dll:NTDSAPI.dll (76770000), size: 77824 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\NTDSAPI.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\DNSAPI.dll:DNSAPI.dll (76EF0000), size: 159744 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\DNSAPI.dll', fileVersion: 5.1.2600.6089
C:\WINDOWS\system32\NETAPI32.dll:NETAPI32.dll (5FDD0000), size: 348160 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\NETAPI32.dll', fileVersion: 5.1.2600.6260
C:\WINDOWS\system32\WLDAP32.dll:WLDAP32.dll (76F30000), size: 180224 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\WLDAP32.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\msctfime.ime:msctfime.ime (73640000), size: 188416 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\msctfime.ime', fileVersion: 5.1.2600.5768
C:\WINDOWS\system32\xinput9_1_0.dll:xinput9_1_0.dll (0A4D0000), size: 73728 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\xinput9_1_0.dll', fileVersion: 9.10.455.0
C:\WINDOWS\system32\SETUPAPI.dll:SETUPAPI.dll (76060000), size: 1400832 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\SETUPAPI.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\WINTRUST.dll:WINTRUST.dll (76C00000), size: 188416 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\WINTRUST.dll', fileVersion: 5.131.2600.6285
C:\WINDOWS\system32\CRYPT32.dll:CRYPT32.dll (765E0000), size: 610304 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\CRYPT32.dll', fileVersion: 5.131.2600.6459
C:\WINDOWS\system32\MSASN1.dll:MSASN1.dll (76DB0000), size: 73728 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\MSASN1.dll', fileVersion: 5.1.2600.5875
C:\WINDOWS\system32\IMAGEHLP.dll:IMAGEHLP.dll (76C60000), size: 167936 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\IMAGEHLP.dll', fileVersion: 5.1.2600.6479
C:\WINDOWS\system32\wdmaud.drv:wdmaud.drv (72C90000), size: 36864 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\wdmaud.drv', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\msacm32.drv:msacm32.drv (72C80000), size: 32768 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\msacm32.drv', fileVersion: 5.1.2600.0
C:\WINDOWS\system32\midimap.dll:midimap.dll (77BA0000), size: 28672 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\midimap.dll', fileVersion: 5.1.2600.5512
C:\WINDOWS\system32\dsound.dll:dsound.dll (73E70000), size: 376832 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\dsound.dll', fileVersion: 5.3.2600.5512
C:\WINDOWS\system32\KsUser.dll:KsUser.dll (73E40000), size: 16384 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\KsUser.dll', fileVersion: 5.3.2600.5512
C:\WINDOWS\system32\mlang.dll:mlang.dll (74CF0000), size: 593920 (result: 0), SymType: 'PDB', PDB: 'C:\WINDOWS\system32\mlang.dll', fileVersion: 6.0.2900.5512
C:\Program Files\Debugging Tools for Windows (x86)\dbghelp.dll:dbghelp.dll (0BBA0000), size: 1314816 (result: 0), SymType: 'PDB', PDB: 'C:\Program Files\Debugging Tools for Windows (x86)\dbghelp.dll', fileVersion: 6.12.2.633
ERROR: SymGetSymFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 00411EA0)
ERROR: SymGetLineFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 00411EA0)
00411EA0 (系统解剖_): (filename not available): (function-name not available)
ERROR: SymGetSymFromAddr64, GetLastError: '找不到指定的模块。
' (Address: 09694E99)
ERROR: SymGetLineFromAddr64, GetLastError: '找不到指定的模块。
' (Address: 09694E99)
ERROR: SymGetModuleInfo64, GetLastError: '动态链接库(DLL)初始化例程失败。
' (Address: 09694E99)
09694E99 ((module-name not available)): (filename not available): (function-name not available)
ERROR: SymGetLineFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 7C93005D)
7C93005D (ntdll): (filename not available): RtlFreeHeap
ERROR: SymGetSymFromAddr64, GetLastError: '找不到指定的模块。
' (Address: 0968029B)
ERROR: SymGetLineFromAddr64, GetLastError: '找不到指定的模块。
' (Address: 0968029B)
ERROR: SymGetModuleInfo64, GetLastError: '动态链接库(DLL)初始化例程失败。
' (Address: 0968029B)
0968029B ((module-name not available)): (filename not available): (function-name not available)
ERROR: SymGetLineFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 100EE53C)
100EE53C (mono): (filename not available): mono_set_defaults
ERROR: SymGetLineFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 1005EAE3)
1005EAE3 (mono): (filename not available): mono_runtime_invoke
ERROR: SymGetSymFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 0056F4BB)
ERROR: SymGetLineFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 0056F4BB)
0056F4BB (系统解剖_): (filename not available): (function-name not available)
ERROR: SymGetSymFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 0056F48C)
ERROR: SymGetLineFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 0056F48C)
0056F48C (系统解剖_): (filename not available): (function-name not available)
ERROR: SymGetSymFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 0056F583)
ERROR: SymGetLineFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 0056F583)
0056F583 (系统解剖_): (filename not available): (function-name not available)
ERROR: SymGetSymFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 00539737)
ERROR: SymGetLineFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 00539737)
00539737 (系统解剖_): (filename not available): (function-name not available)
ERROR: SymGetSymFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 0050A0E8)
ERROR: SymGetLineFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 0050A0E8)
0050A0E8 (系统解剖_): (filename not available): (function-name not available)
ERROR: SymGetSymFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 0056F6C1)
ERROR: SymGetLineFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 0056F6C1)
0056F6C1 (系统解剖_): (filename not available): (function-name not available)
ERROR: SymGetSymFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 0054CE23)
ERROR: SymGetLineFromAddr64, GetLastError: '试图访问无效的地址。
' (Address: 0054CE23)
0054CE23 (系统解剖_): (filename not available): (function-name not available)
========== End of Outputing stack ===========