Вы находитесь на странице: 1из 25

date/time

: 2011-12-03, 23:34:48, 728ms


computer name
: PC-ALT
user name
: Rui <admin>
operating system : Windows NT New Service Pack 1 build 7601
system language : Portuguese
system up time
: 8 hours 29 minutes
program up time : 21 minutes 40 seconds
processors
: 2x Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
physical memory : 1425/3071 MB (free/total)
free disk space : (C:) 179,35 GB
display mode
: 1280x800, 32 bit
process id
: $cc8
allocated memory : 30,21 MB
command line
: "C:\Users\Rui\Documents\Amxx\AMXX_Studio.exe" "C:\Users\Rui\
AppData\Local\Temp\winter_environment.sma"
executable
: AMXX_Studio.exe
exec. date/time : 2006-12-19 13:34
version
: 1.4.3.3
madExcept version : 3.0b
callstack crc
: $1a6e0b1b, $b01561b6, $0f91fcdd
exception number : 1
exception class : EStringListError
exception message : Listenindex berschreitet das Maximum (1292).
main thread ($16d8):
00468154 +001c AMXX_Studio.exe
00667c02 +2076 AMXX_Studio.exe
00665b38 +0074 AMXX_Studio.exe
006881ee +00ea AMXX_Studio.exe
seDown
004bcf0e +002a AMXX_Studio.exe
004bcf92 +0076 AMXX_Studio.exe
004bcfde +003e AMXX_Studio.exe
n
004bcd24 +0188 AMXX_Studio.exe
004bfc6f +0157 AMXX_Studio.exe
004bf8ec +002c AMXX_Studio.exe
oc
00471ef0 +0014 AMXX_Studio.exe
77232e3c +000a USER32.dll
004dc0c7 +0083 AMXX_Studio.exe
essage
004dc0fe +000a AMXX_Studio.exe
ssage
004dc32e +0096 AMXX_Studio.exe
0068f336 +081e AMXX_Studio.exe
7738ed6a +0010 kernel32.dll

Classes
UnitCodeInspector 780 +387
UnitCodeInspector 380 +6
UnitfrmMain
1820 +13

TStringList.Get
UpdateCI_Pawn
UpdateCI
TfrmMain.sciEditorMou

Controls
Controls
Controls

TControl.MouseDown
TControl.DoMouseDown
TControl.WMLButtonDow

Controls
Controls
Controls

TControl.WndProc
TWinControl.WndProc
TWinControl.MainWndPr

Classes
Forms

StdWndProc
DispatchMessageA
TApplication.ProcessM

Forms

TApplication.HandleMe

Forms
AMXX_Studio

TApplication.Run
163 +101 initialization
BaseThreadInitThunk

thread $1448:
77a270b4 +00 ntdll.dll
KiFastSystemCallRet
77a26a02 +0a ntdll.dll
NtWaitForMultipleObjects
7738ed6a +10 kernel32.dll BaseThreadInitThunk
thread $fa8:
77a270b4 +000
t
77a257d2 +00a
75de1870 +04f
75de1813 +00a
0066e794 +3bc

ntdll.dll

KiFastSystemCallRe

ntdll.dll
KERNELBASE.dll
KERNELBASE.dll
AMXX_Studio.exe UnitCodeExplorerUpdater 106 +53

NtDelayExecution
SleepEx
Sleep
TCodeExplorerUpdat

er.Execute
00470888 +034 AMXX_Studio.exe Classes
00404cf8 +028 AMXX_Studio.exe System
7738ed6a +010 kernel32.dll
k
thread $1444: <priority:2>
77a270b4 +00 ntdll.dll
772318d4 +3b USER32.dll
0044d59d +0d AMXX_Studio.exe madExcept
0044d607 +37 AMXX_Studio.exe madExcept
7738ed6a +10 kernel32.dll
>> created by main thread ($16d8) at:
74006c8b +00 winmm.dll

ThreadProc
ThreadWrapper
BaseThreadInitThun

KiFastSystemCallRet
GetMessageA
CallThreadProcSafe
ThreadExceptFrame
BaseThreadInitThunk

thread $c20:
77a270b4 +00 ntdll.dll
KiFastSystemCallRet
77a26a32 +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
7738ed6a +10 kernel32.dll BaseThreadInitThunk
modules:
00400000 AMXX_Studio.exe 1.4.3.3
C:\Users\Rui\Documents\Amxx
10000000 scilexer.dll
1.6.6.0
C:\Users\Rui\Documents\Amxx
19600000 tv_w32.dll
6.0.10511.0
C:\Program Files\TeamViewer\Version6
6add0000 RICHED20.dll
5.31.23.1230
C:\Windows\system32
6c240000 CRTDLL.dll
4.0.1183.1
C:\Windows\system32
6efb0000 olepro32.dll
6.1.7601.17514 C:\Windows\system32
70220000 winspool.drv
6.1.7601.17514 C:\Windows\system32
704e0000 comctl32.dll
5.82.7601.17514 C:\Windows\WinSxS\x86_microsoft.window
s.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af
706e0000 RICHED32.DLL
6.1.7601.17514 C:\Windows\system32
716e0000 wsock32.dll
6.1.7600.16385 C:\Windows\system32
74000000 winmm.dll
6.1.7601.17514 C:\Windows\system32
74350000 msimg32.dll
6.1.7600.16385 C:\Windows\system32
74900000 uxtheme.dll
6.1.7600.16385 C:\Windows\system32
75020000 version.dll
6.1.7600.16385 C:\Windows\system32
75380000 rsaenh.dll
6.1.7600.16385 C:\Windows\system32
755e0000 CRYPTSP.dll
6.1.7600.16385 C:\Windows\system32
75a40000 SspiCli.dll
6.1.7601.17514 C:\Windows\system32
75ab0000 CRYPTBASE.dll 6.1.7600.16385 C:\Windows\system32
75ac0000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\system32
75de0000 KERNELBASE.dll 6.1.7601.17651 C:\Windows\system32
75e30000 comdlg32.dll
6.1.7601.17514 C:\Windows\system32
76060000 GDI32.dll
6.1.7601.17514 C:\Windows\system32
760b0000 LPK.dll
6.1.7600.16385 C:\Windows\system32
760c0000 SHLWAPI.dll
6.1.7601.17514 C:\Windows\system32
76120000 USP10.dll
1.626.7601.17514 C:\Windows\system32
76250000 SHELL32.dll
6.1.7601.17514 C:\Windows\system32
771e0000 WS2_32.dll
6.1.7601.17514 C:\Windows\system32
77220000 USER32.dll
6.1.7601.17514 C:\Windows\system32
77340000 kernel32.dll
6.1.7601.17651 C:\Windows\system32
77420000 RPCRT4.dll
6.1.7601.17514 C:\Windows\system32
774d0000 oleaut32.dll
6.1.7601.17676 C:\Windows\system32
77560000 ole32.dll
6.1.7601.17514 C:\Windows\system32
776c0000 MSCTF.dll
6.1.7600.16385 C:\Windows\system32
77790000 advapi32.dll
6.1.7601.17514 C:\Windows\system32
77830000 msvcrt.dll
7.0.7600.16385 C:\Windows\system32
779e0000 ntdll.dll
6.1.7601.17514 C:\Windows\SYSTEM32
77b20000 imm32.dll
6.1.7601.17514 C:\Windows\system32
77b70000 sechost.dll
6.1.7600.16385 C:\Windows\SYSTEM32

77c00000 NSI.dll

6.1.7600.16385

processes:
0000 Idle
0004 System
013c smss.exe
01b8 csrss.exe
0200 wininit.exe
0210 csrss.exe
0240 services.exe
0250 lsass.exe
0258 lsm.exe
02c4 svchost.exe
0308 winlogon.exe
0330 svchost.exe
036c atiesrxx.exe
03b8 svchost.exe
03ec svchost.exe
0414 svchost.exe
0470 audiodg.exe
04bc svchost.exe
0538 atieclxx.exe
0584 svchost.exe
05ec AsLdrSrv.exe
066c spoolsv.exe
0688 svchost.exe
0718 svchost.exe
07a4 svchost.exe
089c Dwm.exe
08a4 taskhost.exe
08b8 Explorer.EXE
09b4 HControl.exe
09d0 SynTPEnh.exe
09d8 sm56hlpr.exe
09e4 RtHDVCpl.exe
0a08 SynTPHelper.exe
0a10 MOM.exe
ATI.ACE\Core-Static
0a24 HControlUser.exe
0a34 ATKOSD.exe
0a74 WDC.exe
0ab0 wmdc.exe
0c5c svchost.exe
0c8c WUDFHost.exe
0cd0 Steam.exe
0e28 SearchIndexer.exe
0854 PresentationFontCache.exe
00c8 CCC.exe
ATI.ACE\Core-Static
0aec wuauclt.exe
0d64 svchost.exe
07f0 wmpnetwk.exe
0d04 hlsw.exe
02d4 msnmsgr.exe
enger
0bbc wlcomm.exe
acts
1624 ts3client_win32.exe
t
0f98 firefox.exe

0
0
0
0
0
1
0
0
0
0
1
0
0
0
0
0
0
0
1
0
0
0
0
0
0
1
1
1
1
1
1
1
1
1
1
1
1
1
0
0
1
0
0
1

C:\Windows\system32

high
normal
normal

C:\Windows\system32
C:\Windows\system32
C:\Windows

above normal
normal
normal
above normal
normal

C:\Program
C:\Program
C:\Windows
C:\Program
C:\Program

normal

C:\Program Files\ASUS\ATK Hotkey

normal

C:\Windows\WindowsMobile

normal

C:\Program Files\Steam

normal

C:\Program Files\ATI Technologies\

Files\Synaptics\SynTP
Files\Motorola\SMSERIAL
Files\Synaptics\SynTP
Files\ATI Technologies\

1 normal
0
0
1 normal
1 normal

C:\Windows\system32

1 normal

C:\Program Files\Windows Live\Cont

1 normal

C:\Program Files\TeamSpeak 3 Clien

1 normal

C:\Program Files\Mozilla Firefox

C:\Program Files\HLSW
C:\Program Files\Windows Live\Mess

07f8
16f8
n6
0d94
0ad8
13a8
0cc8

plugin-container.exe
TeamViewer.exe

1 normal
1 normal

C:\Program Files\Mozilla Firefox


C:\Program Files\TeamViewer\Versio

Skype.exe
TeamViewer_Desktop.exe
tv_w32.exe
AMXX_Studio.exe

1 normal
1
1
1 normal

C:\Program Files\Skype\Phone
C:\Users\Rui\Documents\Amxx

hardware:
+ Batteries
- Bateria Composta da Microsoft
- Microsoft ACPI-Mtodo de controlo de bateria em conformidade
- Transformador Microsoft
+ Computer
- PC com base em X86 ACPI
+ Disk drives
- Generic- xD/SDMMC/MS/Pro USB Device
- ST9250827AS ATA Device
- WD Ext HDD 1021 USB Device
+ Display adapters
- ATI Mobility Radeon HD 3400 Series (driver 8.821.0.0)
+ DVD/CD-ROM drives
- HL-DT-ST DVDRAM GSA-T40N ATA Device
+ Human Interface Devices
- Dispositivo USB de Introduo de Texto
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 0
- ATA Channel 1
- Controlador Dual Channel PCI IDE padro
- Controlador SiS PCI IDE
+ Imaging devices
- USB 2.0 Camera
+ Keyboards
- Teclado Padro PS/2
+ Mice and other pointing devices
- Rato compatvel com HID
- Synaptics PS/2 Port TouchPad (driver 10.1.8.0)
+ Modems
- Motorola SM56 Speakerphone Modem (driver 6.12.25.6)
+ Monitors
- Monitor PnP Genrico
+ Network adapters
- Atheros AR5007EG Wireless Network Adapter (driver 8.0.0.238)
- Controlador Ethernet SiS191
- TAP-Win32 Adapter V9 (driver 9.0.0.6)
+ Portable Devices
- E:\
+ Processors
- Intel(R) Core(TM)2 Duo CPU
T5800 @ 2.00GHz
- Intel(R) Core(TM)2 Duo CPU
T5800 @ 2.00GHz
+ Sound, video and game controllers
- Dispositivo de udio half duplex Unimodem
- Realtek High Definition Audio (driver 6.0.1.5543)
+ Storage volume shadow copies
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico

- Cpia sombra de volume genrico


- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
+ System devices
- Altifalante do sistema
- ATK0100 ACPI UTILITY (driver 1043.2.31.100)
- Barramento de PCI
- Boto de alimentao ACPI
- Boto de funcionalidade fixa ACPI
- Boto de suspenso ACPI
- Bridge de CPU de sistemas PCI padro
- Bridge PCI ISA padro
- Controlador BIOS Microsoft System Management
- Controlador de acesso directo memria (DMA)
- Controlador de Enumerador de Unidades Virtuais da Microsoft
- Controlador de High Definition Audio
- Controlador de rato do servidor de terminais
- Controlador do teclado do servidor de terminais
- Controlador PIC
- Enumerador de Barramento Para Dispositivos Compostos
- Enumerador de Barramento Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Enumerador UMBus
- Enumerador UMBus
- Ficheiro como Controlador de Volume
- Gestor de volumes
- Microsoft ACPI-Controlador incorporado em conformidade
- Placa de sistema
- Porta Raiz SiS PCI Express x16
- Porta SiS PCI Express x1
- Porta SiS PCI Express x1
- Processador de dados numricos (NDP)
- Recursos da placa principal
- Recursos da placa principal
- Recursos da placa principal
- Relgio CMOS de sistema/tempo real
- Remote Desktop Device Redirector Bus
- Sistema compatvel com Microsoft ACPI
- Tampa ACPI
- Temporizador do sistema
- Zona trmica ACPI
+ Universal Serial Bus controllers
- Concentrador raiz USB (usbport)
- Concentrador raiz USB (usbport)
- Concentrador raiz USB (usbport)
- Controlador Anfitrio PCI para USB Avanado
- Controlador Anfitrio SiS 7001 PCI para USB Aberto
- Controlador Anfitrio SiS 7001 PCI para USB Aberto
- Dispositivo composto USB
- Dispositivo de armazenamento de massa USB
- Dispositivo de armazenamento de massa USB
cpu
eax
ebx
ecx
edx
esi
edi

registers:
= 045035dc
= 042d41dc
= 00000000
= 00468159
= 0000050c
= 0000050c

eip = 00468159
esp = 0012f6b8
ebp = 0012f718
stack dump:
0012f6b8 59
0012f6c8 cc
0012f6d8 0c
0012f6e8 0c
0012f6f8 96
0012f708 54
0012f718 78
0012f728 0c
0012f738 78
0012f748 00
0012f758 00
0012f768 00
0012f778 00
0012f788 00
0012f798 00
0012f7a8 00
0012f7b8 00
0012f7c8 00
0012f7d8 00
0012f7e8 00

81
f6
05
05
6f
f8
fb
05
fb
00
00
00
00
00
00
00
00
00
00
00

disassembling:
[...]
00667beb
00667bed
00667bed
00667bef
00667bf0
00667bf3
00667bf5 780
00667bfb
00667bfd
00667c00
00667c02
>
00667c02
00667c05
00667c0b
00667c0d
00667c10
00667c10
00667c15
00667c17
00667c17
00667c19 781
[...]

46
12
00
00
46
12
12
00
12
00
00
00
00
00
00
00
00
00
00
00

00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00

de
59
0c
00
30
0c
59
05
c0
00
00
00
00
00
00
00
00
00
00
00

fa
81
05
00
f7
05
81
7c
7b
00
00
00
00
00
00
00
00
00
00
00

ed
46
00
00
12
00
46
66
6a
00
00
00
00
00
00
00
00
00
00
00

0e
00
00
00
00
00
00
00
01
00
00
00
00
00
00
00
00
00
00
00

01
dc
18
f0
dc
f4
14
34
e4
00
00
00
00
00
00
00
00
00
00
00

00
35
f7
10
45
4a
df
fd
ce
00
00
00
00
00
00
00
00
00
00
00

test
jl

eax, eax
loc_667c3a

inc
mov
xor
lea
mov
mov
mov
call

eax
[ebp-$2c], eax
ebx, ebx
ecx, [ebp-$324]
edx, ebx
eax, [ebp-$30]
edi, [eax]
dword ptr [edi+$c]

mov
mov
mov
call

edx, [ebp-$324]
cl, 1
eax, [ebp-$14]
-$33de5 ($633e30)

test
jz

al, al
loc_667c28

lea

ecx, [ebp-$1c]

date/time
computer name
user name
operating system
system language
system up time
program up time
processors
physical memory

:
:
:
:
:
:
:
:
:

00
50
12
46
40
6d
4d
12
4b
00
00
00
00
00
00
00
00
00
00
00

00
04
00
00
00
01
00
00
00
00
00
00
00
00
00
00
00
00
00
00

07
dc
e8
f4
18
00
ac
dc
14
00
00
00
00
00
00
00
00
00
00
00

00
41
f6
4a
f7
00
3f
45
00
00
00
00
00
00
00
00
00
00
00
00

00
2d
12
6d
12
00
55
40
00
00
00
00
00
00
00
00
00
00
00
00

00
04
00
01
00
00
04
00
00
00
00
00
00
00
00
00
00
00
00
00

Y.F.............
....Y.F..5P..A-.
................
..........F..Jm.
.oF.0....E@.....
T........Jm.....
x...Y.F...M..?U.
.....|f.4....E@.
x....{j...K.....
................
................
................
................
................
................
................
................
................
................
................

; UnitCodeUtils.IsAtStart

2012-03-18, 03:46:29, 981ms


PC-ALT
Rui
Windows NT New Service Pack 1 build 7601
Portuguese
9 hours 24 minutes
9 hours 9 minutes
2x Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
900/3071 MB (free/total)

free disk space : (C:) 201,03 GB


display mode
: 1280x800, 32 bit
process id
: $1114
allocated memory : 66,75 MB
command line
: "C:\Users\Rui\Documents\Amxx\AMXX_Studio.exe" "F:\Format 022012\Ambiente-Trabalho\PFM\Scrypting\Novo JB\jailbreakballfootball.sma"
executable
: AMXX_Studio.exe
exec. date/time : 2006-12-19 13:34
version
: 1.4.3.3
madExcept version : 3.0b
callstack crc
: $1a6e0b1b, $a5c27919, $ab08b075
exception number : 2
exception class : EStringListError
exception message : Listenindex berschreitet das Maximum (1433).
main thread ($1340):
00468154 +001c AMXX_Studio.exe
00667c02 +2076 AMXX_Studio.exe
00665b38 +0074 AMXX_Studio.exe
00684636 +0336 AMXX_Studio.exe
Up
004c1037 +001f AMXX_Studio.exe
004c108f +004f AMXX_Studio.exe
004c10b2 +000a AMXX_Studio.exe
004bcd24 +0188 AMXX_Studio.exe
004bfc6f +0157 AMXX_Studio.exe
004bf8ec +002c AMXX_Studio.exe
oc
00471ef0 +0014 AMXX_Studio.exe
76e42e3c +000a USER32.dll
004dc0c7 +0083 AMXX_Studio.exe
essage
004dc0fe +000a AMXX_Studio.exe
ssage
004dc32e +0096 AMXX_Studio.exe
0068f336 +081e AMXX_Studio.exe
76ffed6a +0010 kernel32.dll
thread $1678:
77a37094 +000
t
77a357d2 +00a
75bc1870 +04f
75bc1813 +00a
0066e794 +3bc
er.Execute
00470888 +034
00404cf8 +028
76ffed6a +010
k

Classes
UnitCodeInspector 780 +387
UnitCodeInspector 380 +6
UnitfrmMain
1033 +25

TStringList.Get
UpdateCI_Pawn
UpdateCI
TfrmMain.sciEditorKey

Controls
Controls
Controls
Controls
Controls
Controls

TWinControl.KeyUp
TWinControl.DoKeyUp
TWinControl.WMKeyUp
TControl.WndProc
TWinControl.WndProc
TWinControl.MainWndPr

Classes
Forms

StdWndProc
DispatchMessageA
TApplication.ProcessM

Forms

TApplication.HandleMe

Forms
AMXX_Studio

TApplication.Run
163 +101 initialization
BaseThreadInitThunk

ntdll.dll

KiFastSystemCallRe

ntdll.dll
KERNELBASE.dll
KERNELBASE.dll
AMXX_Studio.exe UnitCodeExplorerUpdater 106 +53

NtDelayExecution
SleepEx
Sleep
TCodeExplorerUpdat

AMXX_Studio.exe Classes
AMXX_Studio.exe System
kernel32.dll

ThreadProc
ThreadWrapper
BaseThreadInitThun

thread $f90:
77a37094 +00 ntdll.dll
KiFastSystemCallRet
77a36a02 +0a ntdll.dll
NtWaitForMultipleObjects
76ffed6a +10 kernel32.dll BaseThreadInitThunk
thread $4b4:
77a37094 +00
76e418d4 +3b
0044d59d +0d

<priority:2>
ntdll.dll
KiFastSystemCallRet
USER32.dll
GetMessageA
AMXX_Studio.exe madExcept CallThreadProcSafe

0044d607 +37 AMXX_Studio.exe madExcept ThreadExceptFrame


76ffed6a +10 kernel32.dll
BaseThreadInitThunk
>> created by main thread ($1340) at:
74046c8b +00 winmm.dll
thread $1494:
77a37094 +00 ntdll.dll
KiFastSystemCallRet
77a36a32 +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
76ffed6a +10 kernel32.dll BaseThreadInitThunk
modules:
00400000 AMXX_Studio.exe
1.4.3.3
C:\Users\Rui\Documents\Amxx
10000000 scilexer.dll
1.6.6.0
C:\Users\Rui\Documents\Amxx
5cc70000 SearchFolder.dll
6.1.7601.17514
C:\Windows\system32
5d340000 StructuredQuery.dll 7.0.7601.17514
C:\Windows\System32
5e360000 RICHED32.DLL
6.1.7601.17514
C:\Windows\system32
5e770000 ieproxy.dll
8.0.7601.17744
C:\Program Files\Internet Explor
er
6d1c0000 ieframe.DLL
8.0.7601.17744
C:\Windows\system32
6e840000 RICHED20.dll
5.31.23.1230
C:\Windows\system32
6e960000 olepro32.dll
6.1.7601.17514
C:\Windows\system32
6ea20000 NetworkExplorer.dll 6.1.7601.17514
C:\Windows\system32
6ebe0000 tiptsf.dll
6.1.7600.16385
C:\Program Files\Common Files\mi
crosoft shared\ink
6ec80000 thumbcache.dll
6.1.7601.17514
C:\Windows\system32
6f030000 SHDOCVW.dll
6.1.7601.17514
C:\Windows\system32
6f060000 actxprxy.dll
6.1.7601.17514
C:\Windows\system32
6f880000 ntshrui.dll
6.1.7601.17514
C:\Windows\system32
6f930000 CSCAPI.dll
6.1.7601.17514
C:\Windows\system32
6f940000 CSCDLL.dll
6.1.7601.17514
C:\Windows\System32
6f950000 cscui.dll
6.1.7601.17514
C:\Windows\System32
6f9c0000 EhStorShell.dll
6.1.7600.16385
C:\Windows\system32
6fb00000 winspool.drv
6.1.7601.17514
C:\Windows\system32
71890000 comctl32.dll
5.82.7601.17514
C:\Windows\WinSxS\x86_microsoft.
windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af
73cf0000 slc.dll
6.1.7600.16385
C:\Windows\system32
74040000 winmm.dll
6.1.7601.17514
C:\Windows\system32
74080000 ntmarta.dll
6.1.7600.16385
C:\Windows\system32
740b0000 msimg32.dll
6.1.7600.16385
C:\Windows\system32
742c0000 samcli.dll
6.1.7601.17514
C:\Windows\system32
74300000 netutils.dll
6.1.7601.17514
C:\Windows\system32
74350000 OLEACC.dll
7.0.0.0
C:\Windows\system32
74410000 wsock32.dll
6.1.7600.16385
C:\Windows\system32
744b0000 WindowsCodecs.dll 6.1.7601.17514
C:\Windows\system32
745e0000 dwmapi.dll
6.1.7600.16385
C:\Windows\system32
74a20000 uxtheme.dll
6.1.7600.16385
C:\Windows\system32
74a60000 propsys.dll
7.0.7601.17514
C:\Windows\system32
74b60000 SAMLIB.dll
6.1.7600.16385
C:\Windows\system32
74ba0000 comctl32.DLL
6.10.7601.17514
C:\Windows\WinSxS\x86_microsoft.
windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2
75000000 version.dll
6.1.7600.16385
C:\Windows\system32
75390000 rsaenh.dll
6.1.7600.16385
C:\Windows\system32
755f0000 CRYPTSP.dll
6.1.7600.16385
C:\Windows\system32
759c0000 srvcli.dll
6.1.7601.17514
C:\Windows\system32
75a30000 Secur32.dll
6.1.7601.17725
C:\Windows\System32
75a50000 SspiCli.dll
6.1.7601.17725
C:\Windows\system32
75a70000 apphelp.dll
6.1.7601.17514
C:\Windows\system32
75ac0000 CRYPTBASE.dll
6.1.7600.16385
C:\Windows\system32
75b30000 RpcRtRemote.dll
6.1.7601.17514
C:\Windows\system32
75b40000 profapi.dll
6.1.7600.16385
C:\Windows\system32

75bb0000
75bc0000
75c10000
75c40000
75c60000
75d80000
75e40000
76a90000
76af0000
76ba0000
76c30000
76c50000
76d20000
76da0000
76e30000
76f00000
76fb0000
77090000
770a0000
770c0000
77260000
77300000
77460000
774d0000
77700000
77840000
77940000
779f0000
77b30000
77b80000
77b90000
77bd0000

MSASN1.dll
KERNELBASE.dll
WINTRUST.dll
DEVOBJ.dll
CRYPT32.dll
CFGMGR32.dll
SHELL32.dll
SHLWAPI.dll
advapi32.dll
oleaut32.dll
sechost.dll
MSCTF.dll
comdlg32.dll
CLBCatQ.DLL
USER32.dll
msvcrt.dll
kernel32.dll
psapi.dll
imm32.dll
SETUPAPI.dll
USP10.dll
ole32.dll
NSI.dll
iertutil.dll
urlmon.dll
WININET.dll
RPCRT4.dll
ntdll.dll
WLDAP32.dll
LPK.dll
WS2_32.dll
GDI32.dll

processes:
0000 Idle
0004 System
0160 smss.exe
01dc csrss.exe
0230 wininit.exe
023c csrss.exe
0268 services.exe
0278 lsass.exe
0280 lsm.exe
02f0 svchost.exe
0318 winlogon.exe
0368 svchost.exe
0398 atiesrxx.exe
03e4 svchost.exe
0418 svchost.exe
0438 svchost.exe
04ec svchost.exe
0524 atieclxx.exe
05b0 svchost.exe
0620 ASLDRSrv.exe
066c spoolsv.exe
0688 svchost.exe
06dc WVSScheduler.exe
072c armsvc.exe
0750 avp.exe
0780 svchost.exe

6.1.7601.17514
6.1.7601.17651
6.1.7601.17514
6.1.7600.16385
6.1.7601.17514
6.1.7601.17514
6.1.7601.17678
6.1.7601.17514
6.1.7601.17514
6.1.7601.17676
6.1.7600.16385
6.1.7600.16385
6.1.7601.17514
2001.12.8530.16385
6.1.7601.17514
7.0.7601.17744
6.1.7601.17651
6.1.7600.16385
6.1.7601.17514
6.1.7601.17514
1.626.7601.17514
6.1.7601.17514
6.1.7600.16385
8.0.7601.17744
8.0.7601.17744
8.0.7601.17744
6.1.7601.17514
6.1.7601.17725
6.1.7601.17514
6.1.7600.16385
6.1.7601.17514
6.1.7601.17514
0
0
0
0
0
1
0
0
0
0
1
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0

C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\SYSTEM32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\SYSTEM32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32

0240 TeamViewer_Service.exe
0868 Dwm.exe
0880 Explorer.EXE
088c taskhost.exe
0a68 sm56hlpr.exe
0a70 avp.exe
Internet Security 2012
0a78 DMedia.exe
0a80 RtHDVCpl.exe
0b08 MOM.exe
E\Core-Static
0b10 PlusService.exe
Plus!
0b18 Steam.exe
0b54 msnmsgr.exe
0bec HControl.exe
0bf4 WUDFHost.exe
0c44 SearchIndexer.exe
0d3c SteamService.exe
0dec CCC.exe
E\Core-Static
0e64 ATKOSD.exe
02a4 wmpnetwk.exe
051c PresentationFontCache.exe
08a4 svchost.exe
0d98 wlcomm.exe
0e58 filezilla.exe
0de0 ts3client_win32.exe
0e6c audiodg.exe
0c98 firefox.exe
1114 AMXX_Studio.exe
10f8 plugin-container.exe
134c Travian Babysitter.exe
1248 JetAudio.exe
1458 hlsw.exe
0ec8 Skype.exe
1590 hl.exe
counter-strike
04c0 GameOverlayUI.exe

0
1
1
1
1
1

high
normal
normal
normal
normal

C:\Windows\system32
C:\Windows
C:\Windows\system32
C:\Program Files\Motorola\SMSERIAL
C:\Program Files\Kaspersky Lab\Kaspersky

1 normal C:\Program Files\ASUS\ATK Media


1 normal C:\Program Files\Realtek\Audio\HDA
1 normal C:\Program Files\ATI Technologies\ATI.AC
1 normal C:\Program Files\Yuna Software\Messenger
1 normal C:\Program Files\Steam
1 normal C:\Program Files\Windows Live\Messenger
1
0
0
0
1 normal C:\Program Files\ATI Technologies\ATI.AC
1
0
0
0
1
1
1
0
1
1
1
1
1
1
1
1

normal C:\Program Files\Windows Live\Contacts


normal C:\Program Files\FileZilla FTP Client
normal
normal
normal
normal
normal
normal
normal
normal

C:\Program Files\Mozilla Firefox


C:\Users\Rui\Documents\Amxx
C:\Program Files\Mozilla Firefox
C:\Program Files\Travian Babysitter
C:\Program Files\JetAudio
C:\Program Files\HLSW
C:\Program Files\Skype\Phone
c:\program files\steam\steamapps\rui_bd\

1 normal C:\Program Files\Steam

hardware:
+ Batteries
- Bateria Composta da Microsoft
- Microsoft ACPI-Mtodo de controlo de bateria em conformidade
- Transformador Microsoft
+ Computer
- PC com base em X86 ACPI
+ Disk drives
- Generic- xD/SDMMC/MS/Pro USB Device
- ST9250827AS ATA Device
- WD Ext HDD 1021 USB Device
+ Display adapters
- ATI Mobility Radeon HD 3400 Series (driver 8.930.0.0)
+ DVD/CD-ROM drives
- HL-DT-ST DVDRAM GSA-T40N ATA Device
+ Human Interface Devices
- Dispositivo de controlo para consumidores compatvel com HID
- Dispositivo USB de Introduo de Texto
- Dispositivo USB de Introduo de Texto
+ IDE ATA/ATAPI controllers

+
+
+
+
+
+

+
+
+

- ATA Channel 0
- ATA Channel 0
- ATA Channel 1
- Controlador Dual Channel PCI IDE padro
- Controlador SiS PCI IDE
Imaging devices
- USB 2.0 Camera
Keyboards
- Teclado Padro PS/2
Mice and other pointing devices
- Rato compatvel com HID
- Rato PS/2 Microsoft
Modems
- Motorola SM56 Speakerphone Modem (driver 6.12.25.6)
Monitors
- Monitor PnP Genrico
Network adapters
- Atheros AR5007EG Wireless Network Adapter (driver 8.0.0.238)
- Controlador Ethernet SiS191
- TAP-Win32 Adapter V9 (driver 9.0.0.8)
Portable Devices
- E:\
Processors
- Intel(R) Core(TM)2 Duo CPU
T5800 @ 2.00GHz
- Intel(R) Core(TM)2 Duo CPU
T5800 @ 2.00GHz
Sound, video and game controllers
- Dispositivo de udio half duplex Unimodem
- Realtek High Definition Audio (driver 6.0.1.5817)
- Sennheiser USB headset
Storage volume shadow copies
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
System devices
- Altifalante do sistema
- ATK0100 ACPI UTILITY (driver 1043.2.31.100)
- Barramento de PCI
- Boto de alimentao ACPI
- Boto de funcionalidade fixa ACPI
- Boto de suspenso ACPI
- Bridge de CPU de sistemas PCI padro
- Bridge PCI ISA padro
- Controlador BIOS Microsoft System Management
- Controlador de acesso directo memria (DMA)
- Controlador de Enumerador de Unidades Virtuais da Microsoft
- Controlador de High Definition Audio
- Controlador de rato do servidor de terminais
- Controlador do teclado do servidor de terminais
- Controlador PIC
- Enumerador de Barramento Para Dispositivos Compostos
- Enumerador de Barramento Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Enumerador UMBus
- Ficheiro como Controlador de Volume

- Gestor de volumes
- Microsoft ACPI-Controlador incorporado em conformidade
- Placa de sistema
- Porta Raiz SiS PCI Express x16
- Porta SiS PCI Express x1
- Porta SiS PCI Express x1
- Processador de dados numricos (NDP)
- Recursos da placa principal
- Recursos da placa principal
- Recursos da placa principal
- Relgio CMOS de sistema/tempo real
- Remote Desktop Device Redirector Bus
- Sistema compatvel com Microsoft ACPI
- Tampa ACPI
- Temporizador do sistema
- Zona trmica ACPI
+ Universal Serial Bus controllers
- Concentrador raiz USB (usbport)
- Concentrador raiz USB (usbport)
- Concentrador raiz USB (usbport)
- Controlador Anfitrio PCI para USB Avanado
- Controlador Anfitrio SiS 7001 PCI para USB Aberto
- Controlador Anfitrio SiS 7001 PCI para USB Aberto
- Dispositivo composto USB
- Dispositivo composto USB
- Dispositivo de armazenamento de massa USB
- Dispositivo de armazenamento de massa USB
cpu
eax
ebx
ecx
edx
esi
edi
eip
esp
ebp

registers:
= 07bb5e38
= 07bb5e08
= 00000000
= 00468159
= 00000599
= 00000599
= 00468159
= 0012f680
= 0012f6e0

stack dump:
0012f680 59
0012f690 94
0012f6a0 99
0012f6b0 99
0012f6c0 96
0012f6d0 1c
0012f6e0 40
0012f6f0 99
0012f700 40
0012f710 00
0012f720 00
0012f730 00
0012f740 00
0012f750 00
0012f760 00
0012f770 00
0012f780 00
0012f790 00
0012f7a0 00
0012f7b0 00

81
f6
05
05
6f
f8
fb
05
fb
00
00
00
00
00
00
00
00
00
00
00

46
12
00
00
46
12
12
00
12
00
00
00
00
00
00
00
00
00
00
00

00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00

de
59
99
00
f8
99
59
05
64
00
00
00
00
00
00
00
00
00
00
00

fa
81
05
00
f6
05
81
7c
fd
00
00
00
00
00
00
00
00
00
00
00

ed
46
00
00
12
00
46
66
12
00
00
00
00
00
00
00
00
00
00
00

0e
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00

01
38
e0
f0
dc
28
14
50
a8
00
00
00
00
00
00
00
00
00
00
00

00
5e
f6
10
45
58
df
fb
4c
00
00
00
00
00
00
00
00
00
00
00

00
bb
12
46
40
7b
4d
12
4e
00
00
00
00
00
00
00
00
00
00
00

00
07
00
00
00
01
00
00
00
00
00
00
00
00
00
00
00
00
00
00

07
08
b0
28
e0
00
38
dc
be
00
00
00
00
00
00
00
00
00
00
00

00
5e
f6
58
f6
00
5a
45
03
00
00
00
00
00
00
00
00
00
00
00

00
bb
12
7b
12
00
d6
40
00
00
00
00
00
00
00
00
00
00
00
00

00
07
00
01
00
00
07
00
00
00
00
00
00
00
00
00
00
00
00
00

Y.F.............
....Y.F.8^...^..
................
..........F.(X{.
.oF......E@.....
........(X{.....
@...Y.F...M.8Z..
.....|f.P....E@.
@...d....LN.....
................
................
................
................
................
................
................
................
................
................
................

disassembling:
[...]
00667beb
00667bed
00667bed
00667bef
00667bf0
00667bf3
00667bf5 780
00667bfb
00667bfd
00667c00
00667c02
>
00667c02
00667c05
00667c0b
00667c0d
00667c10
00667c10
00667c15
00667c17
00667c17
00667c19 781
[...]

test
jl

eax, eax
loc_667c3a

inc
mov
xor
lea
mov
mov
mov
call

eax
[ebp-$2c], eax
ebx, ebx
ecx, [ebp-$324]
edx, ebx
eax, [ebp-$30]
edi, [eax]
dword ptr [edi+$c]

mov
mov
mov
call

edx, [ebp-$324]
cl, 1
eax, [ebp-$14]
-$33de5 ($633e30)

test
jz

al, al
loc_667c28

lea

ecx, [ebp-$1c]

; UnitCodeUtils.IsAtStart

date/time
: 2012-03-21, 13:56:52, 958ms
computer name
: PC-ALT
user name
: Rui
operating system : Windows NT New Service Pack 1 build 7601
system language : Portuguese
system up time
: 3 hours 6 minutes
program up time : 57 minutes 18 seconds
processors
: 2x Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
physical memory : 1505/3071 MB (free/total)
free disk space : (C:) 201,63 GB
display mode
: 1280x800, 32 bit
process id
: $17dc
allocated memory : 39,13 MB
command line
: "C:\Users\Rui\Documents\Amxx\AMXX_Studio.exe" "C:\Users\Rui\
Downloads\[Zombie-Mod.ru]health_bar\health_bar\addons\amxmodx\scripting\zp_addon
_zbhealthbar.sma"
executable
: AMXX_Studio.exe
exec. date/time : 2006-12-19 13:34
version
: 1.4.3.3
madExcept version : 3.0b
callstack crc
: $b1954426, $9cfc0943, $bd2037d8
count
: 145
exception number : 1
exception class : EFCreateError
exception message : Datei "C:\Users\Rui\AppData\Local\Temp\health_bar.sma" kann
nicht erstellt werden. Acesso negado.
main thread ($100c):
00468afc +0a4 AMXX_Studio.exe
00468a34 +020 AMXX_Studio.exe
004679f5 +015 AMXX_Studio.exe
0066a966 +0f6 AMXX_Studio.exe
00687c67 +0e7 AMXX_Studio.exe
00513b29 +095 AMXX_Studio.exe

Classes
Classes
Classes
UnitCompile 48 +12
UnitfrmMain 1741 +7
TB2Item
1499 +22

TFileStream.Create
TFileStream.Create
TStrings.SaveToFile
DoCompilePAWN
TfrmMain.mnuDoCompileClick
TTBCustomItem.Click

00554f7d
00683057
00513b29
00513a1b
00471ef0
75832e3c
004dc0c7
004dc0fe
004dc32e
0068f336
767fed6a

+015
+00b
+095
+0b3
+014
+00a
+083
+00a
+096
+81e
+010

thread $f34:
77067094 +000
et
770657d2 +00a
751f1870 +04f
751f1813 +00a
0066fd2d +1c9
006702ca +766
0066e647 +26f
ter.Execute
00470888 +034
00404cf8 +028
767fed6a +010
nk

AMXX_Studio.exe
AMXX_Studio.exe
AMXX_Studio.exe
AMXX_Studio.exe
AMXX_Studio.exe
USER32.dll
AMXX_Studio.exe
AMXX_Studio.exe
AMXX_Studio.exe
AMXX_Studio.exe
kernel32.dll

SpTBXItem
UnitfrmMain
TB2Item
TB2Item
Classes

4155 +2 TSpTBXCustomItem.Click
692 +1 TfrmMain.mnuTCompileClick
1499 +22 TTBCustomItem.Click
1449 +27 TTBCustomItem.ClickWndProc
StdWndProc
DispatchMessageA
Forms
TApplication.ProcessMessage
Forms
TApplication.HandleMessage
Forms
TApplication.Run
AMXX_Studio 163 +101 initialization
BaseThreadInitThunk

ntdll.dll

KiFastSystemCallR

ntdll.dll
NtDelayExecution
KERNELBASE.dll
SleepEx
KERNELBASE.dll
Sleep
AMXX_Studio.exe UnitTextAnalyze
100 +33 ParseCodePawn
AMXX_Studio.exe UnitTextAnalyze
167 +100 ParseCodePawn
AMXX_Studio.exe UnitCodeExplorerUpdater 79 +26 TCodeExplorerUpda
AMXX_Studio.exe Classes
AMXX_Studio.exe System
kernel32.dll

thread $cf8: <priority:2>


77067094 +00 ntdll.dll
758318d4 +3b USER32.dll
0044d59d +0d AMXX_Studio.exe madExcept
0044d607 +37 AMXX_Studio.exe madExcept
767fed6a +10 kernel32.dll
>> created by main thread ($100c) at:
73636c8b +00 winmm.dll

ThreadProc
ThreadWrapper
BaseThreadInitThu

KiFastSystemCallRet
GetMessageA
CallThreadProcSafe
ThreadExceptFrame
BaseThreadInitThunk

thread $17f4:
77067094 +00 ntdll.dll
KiFastSystemCallRet
77066a02 +0a ntdll.dll
NtWaitForMultipleObjects
767fed6a +10 kernel32.dll BaseThreadInitThunk
thread $1658:
77067094 +00 ntdll.dll
KiFastSystemCallRet
77066a32 +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
767fed6a +10 kernel32.dll BaseThreadInitThunk
modules:
00400000 AMXX_Studio.exe 1.4.3.3
C:\Users\Rui\Documents\Amxx
10000000 scilexer.dll
1.6.6.0
C:\Users\Rui\Documents\Amxx
6c330000 RICHED20.dll
5.31.23.1230
C:\Windows\system32
6c430000 olepro32.dll
6.1.7601.17514 C:\Windows\system32
6eb60000 wsock32.dll
6.1.7600.16385 C:\Windows\system32
6eb70000 winspool.drv
6.1.7601.17514 C:\Windows\system32
70ec0000 comctl32.dll
5.82.7601.17514 C:\Windows\WinSxS\x86_microsoft.window
s.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af
73630000 winmm.dll
6.1.7601.17514 C:\Windows\system32
736e0000 msimg32.dll
6.1.7600.16385 C:\Windows\system32
736f0000 RICHED32.DLL
6.1.7601.17514 C:\Windows\system32
73c10000 dwmapi.dll
6.1.7600.16385 C:\Windows\system32
73f40000 uxtheme.dll
6.1.7600.16385 C:\Windows\system32

740c0000 comctl32.DLL
6.10.7601.17514 C:\Windows\WinSxS\x86_microsoft.window
s.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2
74630000 version.dll
6.1.7600.16385 C:\Windows\system32
749c0000 rsaenh.dll
6.1.7600.16385 C:\Windows\system32
74c20000 CRYPTSP.dll
6.1.7600.16385 C:\Windows\system32
75080000 SspiCli.dll
6.1.7601.17725 C:\Windows\system32
750a0000 apphelp.dll
6.1.7601.17514 C:\Windows\system32
750f0000 CRYPTBASE.dll 6.1.7600.16385 C:\Windows\system32
75160000 RpcRtRemote.dll 6.1.7601.17514 C:\Windows\system32
751f0000 KERNELBASE.dll 6.1.7601.17651 C:\Windows\system32
75610000 MSCTF.dll
6.1.7600.16385 C:\Windows\system32
75770000 USP10.dll
1.626.7601.17514 C:\Windows\system32
75810000 LPK.dll
6.1.7600.16385 C:\Windows\system32
75820000 USER32.dll
6.1.7601.17514 C:\Windows\system32
758f0000 WS2_32.dll
6.1.7601.17514 C:\Windows\system32
75930000 SHELL32.dll
6.1.7601.17678 C:\Windows\system32
76580000 comdlg32.dll
6.1.7601.17514 C:\Windows\system32
76600000 msvcrt.dll
7.0.7601.17744 C:\Windows\system32
766b0000 oleaut32.dll
6.1.7601.17676 C:\Windows\system32
76740000 GDI32.dll
6.1.7601.17514 C:\Windows\system32
76790000 imm32.dll
6.1.7601.17514 C:\Windows\system32
767b0000 kernel32.dll
6.1.7601.17651 C:\Windows\system32
76890000 advapi32.dll
6.1.7601.17514 C:\Windows\system32
76ad0000 RPCRT4.dll
6.1.7601.17514 C:\Windows\system32
76ec0000 ole32.dll
6.1.7601.17514 C:\Windows\system32
77020000 ntdll.dll
6.1.7601.17725 C:\Windows\SYSTEM32
77160000 NSI.dll
6.1.7600.16385 C:\Windows\system32
771d0000 SHLWAPI.dll
6.1.7601.17514 C:\Windows\system32
77230000 sechost.dll
6.1.7600.16385 C:\Windows\SYSTEM32
processes:
0000 Idle
0004 System
0160 smss.exe
01e4 csrss.exe
0234 wininit.exe
023c csrss.exe
026c services.exe
027c lsass.exe
0284 lsm.exe
02f0 svchost.exe
0334 winlogon.exe
0368 svchost.exe
0398 atiesrxx.exe
03e4 svchost.exe
041c svchost.exe
0438 svchost.exe
04dc svchost.exe
0508 atieclxx.exe
05b0 svchost.exe
061c ASLDRSrv.exe
0668 spoolsv.exe
0684 svchost.exe
06d8 WVSScheduler.exe
06fc armsvc.exe
0714 avp.exe
0748 svchost.exe
07a8 TeamViewer_Service.exe
08b4 WUDFHost.exe
0a74 SearchIndexer.exe

0
0
0
0
0
1
0
0
0
0
1
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0

0dc4 taskhost.exe
0e28 Dwm.exe
0e74 Explorer.EXE
0f48 sm56hlpr.exe
0f94 avp.exe
Internet Security 2012
0fe4 DMedia.exe
0604 RtHDVCpl.exe
09cc PlusService.exe
Plus!
0364 MOM.exe
E\Core-Static
0c58 HControl.exe
051c ATKOSD.exe
0fa4 CCC.exe
E\Core-Static
08a0 svchost.exe
0960 PresentationFontCache.exe
0c44 wmpnetwk.exe
0a44 firefox.exe
0fd8 plugin-container.exe
0724 Travian Babysitter.exe
11d4 ts3client_win32.exe
12e0 audiodg.exe
1424 JetAudio.exe
17dc AMXX_Studio.exe
1718 hlsw.exe
1198 Steam.exe
0ed0 SteamService.exe
0fbc filezilla.exe
0870 calc.exe

1
1
1
1
1

normal
high
normal
normal
normal

C:\Windows\system32
C:\Windows\system32
C:\Windows
C:\Program Files\Motorola\SMSERIAL
C:\Program Files\Kaspersky Lab\Kaspersky

1 normal C:\Program Files\ASUS\ATK Media


1 normal C:\Program Files\Realtek\Audio\HDA
1 normal C:\Program Files\Yuna Software\Messenger
1 normal C:\Program Files\ATI Technologies\ATI.AC
1
1
1 normal C:\Program Files\ATI Technologies\ATI.AC
0
0
0
1
1
1
1
0
1
1
1
1
0
1
1

normal C:\Program Files\Mozilla Firefox


normal C:\Program Files\Mozilla Firefox
normal C:\Program Files\Travian Babysitter
normal
normal
normal
normal

C:\Program Files\JetAudio
C:\Users\Rui\Documents\Amxx
C:\Program Files\HLSW
C:\Program Files\Steam

normal C:\Program Files\FileZilla FTP Client


normal C:\Windows\system32

hardware:
+ Batteries
- Bateria Composta da Microsoft
- Microsoft ACPI-Mtodo de controlo de bateria em conformidade
- Transformador Microsoft
+ Computer
- PC com base em X86 ACPI
+ Disk drives
- Generic- xD/SDMMC/MS/Pro USB Device
- ST9250827AS ATA Device
- WD Ext HDD 1021 USB Device
+ Display adapters
- ATI Mobility Radeon HD 3400 Series (driver 8.930.0.0)
+ DVD/CD-ROM drives
- HL-DT-ST DVDRAM GSA-T40N ATA Device
+ Human Interface Devices
- Dispositivo de controlo para consumidores compatvel com HID
- Dispositivo USB de Introduo de Texto
- Dispositivo USB de Introduo de Texto
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 0
- ATA Channel 1
- Controlador Dual Channel PCI IDE padro
- Controlador SiS PCI IDE
+ Imaging devices
- USB 2.0 Camera
+ Keyboards

- Teclado Padro PS/2


+ Mice and other pointing devices
- Rato compatvel com HID
- Rato PS/2 Microsoft
+ Modems
- Motorola SM56 Speakerphone Modem (driver 6.12.25.6)
+ Monitors
- Monitor PnP Genrico
+ Network adapters
- Atheros AR5007EG Wireless Network Adapter (driver 8.0.0.238)
- Controlador Ethernet SiS191
- TAP-Win32 Adapter V9 (driver 9.0.0.8)
+ Portable Devices
- E:\
+ Processors
- Intel(R) Core(TM)2 Duo CPU
T5800 @ 2.00GHz
- Intel(R) Core(TM)2 Duo CPU
T5800 @ 2.00GHz
+ Sound, video and game controllers
- Dispositivo de udio half duplex Unimodem
- Realtek High Definition Audio (driver 6.0.1.5817)
- Sennheiser USB headset
+ Storage volume shadow copies
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
+ System devices
- Altifalante do sistema
- ATK0100 ACPI UTILITY (driver 1043.2.31.100)
- Barramento de PCI
- Boto de alimentao ACPI
- Boto de funcionalidade fixa ACPI
- Boto de suspenso ACPI
- Bridge de CPU de sistemas PCI padro
- Bridge PCI ISA padro
- Controlador BIOS Microsoft System Management
- Controlador de acesso directo memria (DMA)
- Controlador de Enumerador de Unidades Virtuais da Microsoft
- Controlador de High Definition Audio
- Controlador de rato do servidor de terminais
- Controlador do teclado do servidor de terminais
- Controlador PIC
- Enumerador de Barramento Para Dispositivos Compostos
- Enumerador de Barramento Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Enumerador UMBus
- Ficheiro como Controlador de Volume
- Gestor de volumes
- Microsoft ACPI-Controlador incorporado em conformidade
- Placa de sistema
- Porta Raiz SiS PCI Express x16
- Porta SiS PCI Express x1
- Porta SiS PCI Express x1
- Processador de dados numricos (NDP)
- Recursos da placa principal
- Recursos da placa principal

- Recursos da placa principal


- Relgio CMOS de sistema/tempo real
- Remote Desktop Device Redirector Bus
- Sistema compatvel com Microsoft ACPI
- Tampa ACPI
- Temporizador do sistema
- Zona trmica ACPI
+ Universal Serial Bus controllers
- Concentrador raiz USB (usbport)
- Concentrador raiz USB (usbport)
- Concentrador raiz USB (usbport)
- Controlador Anfitrio PCI para USB Avanado
- Controlador Anfitrio SiS 7001 PCI para USB Aberto
- Controlador Anfitrio SiS 7001 PCI para USB Aberto
- Dispositivo composto USB
- Dispositivo composto USB
- Dispositivo de armazenamento de massa USB
- Dispositivo de armazenamento de massa USB
cpu
eax
ebx
ecx
edx
esi
edi
eip
esp
ebp

registers:
= 046c415c
= 047e1104
= 00000000
= 00468b01
= 0370400c
= 047effff
= 00468b01
= 0012fbc8
= 0012fc34

stack dump:
0012fbc8 01
0012fbd8 dc
0012fbe8 0c
0012fbf8 44
0012fc08 04
0012fc18 00
0012fc28 20
0012fc38 39
0012fc48 1b
0012fc58 00
0012fc68 00
0012fc78 cc
0012fc88 00
0012fc98 00
0012fca8 00
0012fcb8 00
0012fcc8 6c
0012fcd8 30
0012fce8 00
0012fcf8 00

8b
fb
40
fc
11
00
9d
8a
47
00
00
fc
00
00
00
00
7c
1b
00
00

46
12
70
12
7e
00
3e
46
40
00
00
12
00
00
00
00
68
71
00
00

00
00
03
00
04
00
05
00
00
00
00
00
00
00
00
00
00
01
00
00

de
01
ff
dc
01
00
0b
00
5c
70
a8
dc
c8
00
00
00
40
00
00
00

fa
8b
ff
45
40
00
00
00
fc
fc
4c
45
7b
00
00
00
fd
00
00
00

ed
46
7e
40
70
00
00
00
12
12
4e
40
70
00
00
00
12
00
00
00

0e
00
04
00
03
00
00
00
00
00
00
00
01
00
00
00
00
00
00
00

01
5c
34
34
00
78
86
ff
04
fa
c4
c4
00
00
00
00
dc
00
00
00

00
41
fc
fc
00
b2
41
ff
11
79
fc
fc
00
00
00
00
45
00
00
00

disassembling:
[...]
0066a946
mov
edx, [edx+$14]
0066a949
call
-$265b62 ($404dec)
0066a949
0066a94e
loc_66a94e:
0066a94e 48 mov
eax, [$698714]
0066a953
mov
eax, [eax]

00
6c
12
12
00
3e
40
7e
7e
46
12
12
00
00
00
00
40
00
00
00

00
04
00
00
00
05
00
04
04
00
00
00
00
00
00
00
00
00
00
00

07
04
f8
8c
00
0b
5c
78
bc
ff
69
8c
00
00
00
08
08
00
00
00

00
11
fb
b5
00
35
fc
fc
65
ff
a9
b5
00
00
00
fd
fd
00
00
00

00
7e
12
71
00
46
12
12
72
00
66
71
00
00
00
12
12
00
00
00

00
04
00
04
00
00
00
00
01
00
00
04
00
00
00
00
00
00
00
00

..F.............
......F.\Al...~.
.@p...~.4.......
D....E@.4.....q.
..~..@p.........
........x.>..5F.
..>......A@.\...
9.F.......~.x...
.G@.\.....~..er.
....p....yF.....
.....LN.....i.f.
.....E@.......q.
.....{p.........
................
................
................
l|h.@....E@.....
0.q.............
................
................

; System.@LStrLAsg

0066a955
mov
0066a95b
mov
0066a961
mov
0066a964
mov
0066a966
> call
0066a966
0066a969 50 mov
0066a96b
xor
0066a96d
call
Change
0066a96d
0066a972
test
0066a974
jz
0066a974
0066a976 51 mov
0066a97b
mov
[...]

eax, [eax+$614]
eax, [eax+$2e0]
edx, [ebp-4]
ecx, [eax]
dword ptr [ecx+$74]
dl, 1
eax, eax
+$26e6 ($66d058)

; UnitPlugins.Plugin_VisibleControl

al, al
loc_66a9b8
eax, [$698714]
eax, [eax]

date/time
: 2012-04-10, 23:32:35, 625ms
computer name
: PC-ALT
user name
: Rui
operating system : Windows NT New Service Pack 1 build 7601
system language : Portuguese
system up time
: 10 hours
program up time : 5 minutes 43 seconds
processors
: 2x Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
physical memory : 1196/3071 MB (free/total)
free disk space : (C:) 198,92 GB
display mode
: 1280x800, 32 bit
process id
: $19f4
allocated memory : 33,18 MB
command line
: "C:\Users\Rui\Documents\Amxx\AMXX_Studio.exe" "F:\PFM\PFM 20
12\statsx_shell.sma"
executable
: AMXX_Studio.exe
exec. date/time : 2006-12-19 14:34
version
: 1.4.3.3
madExcept version : 3.0b
callstack crc
: $1a6e0b1b, $82ea7f44, $6eb50079
count
: 4
exception number : 1
exception class : EStringListError
exception message : Listenindex berschreitet das Maximum (1).
main thread ($1880):
00468154 +001c AMXX_Studio.exe
00667c02 +2076 AMXX_Studio.exe
00665b38 +0074 AMXX_Studio.exe
00684636 +0336 AMXX_Studio.exe
Up
004c1037 +001f AMXX_Studio.exe
004c108f +004f AMXX_Studio.exe
004c10d2 +000a AMXX_Studio.exe
p
004bcd24 +0188 AMXX_Studio.exe
004bfc6f +0157 AMXX_Studio.exe
004bf8ec +002c AMXX_Studio.exe
oc
00471ef0 +0014 AMXX_Studio.exe
753f2e3c +000a USER32.dll
004dc0c7 +0083 AMXX_Studio.exe

Classes
UnitCodeInspector 780 +387
UnitCodeInspector 380 +6
UnitfrmMain
1033 +25

TStringList.Get
UpdateCI_Pawn
UpdateCI
TfrmMain.sciEditorKey

Controls
Controls
Controls

TWinControl.KeyUp
TWinControl.DoKeyUp
TWinControl.WMSysKeyU

Controls
Controls
Controls

TControl.WndProc
TWinControl.WndProc
TWinControl.MainWndPr

Classes

StdWndProc
DispatchMessageA
TApplication.ProcessM

Forms

essage
004dc0fe
ssage
004dc32e
0068f336
766bed6a

+000a AMXX_Studio.exe Forms

TApplication.HandleMe

+0096 AMXX_Studio.exe Forms


+081e AMXX_Studio.exe AMXX_Studio
+0010 kernel32.dll

thread $1fac:
76fc7094 +000
t
76fc57d2 +00a
752f1870 +04f
752f1813 +00a
0066e794 +3bc
er.Execute
00470888 +034
00404cf8 +028
766bed6a +010
k

TApplication.Run
163 +101 initialization
BaseThreadInitThunk

ntdll.dll

KiFastSystemCallRe

ntdll.dll
KERNELBASE.dll
KERNELBASE.dll
AMXX_Studio.exe UnitCodeExplorerUpdater 106 +53

NtDelayExecution
SleepEx
Sleep
TCodeExplorerUpdat

AMXX_Studio.exe Classes
AMXX_Studio.exe System
kernel32.dll

ThreadProc
ThreadWrapper
BaseThreadInitThun

thread $1d50: <priority:2>


76fc7094 +00 ntdll.dll
753f18d4 +3b USER32.dll
0044d59d +0d AMXX_Studio.exe madExcept
0044d607 +37 AMXX_Studio.exe madExcept
766bed6a +10 kernel32.dll
>> created by main thread ($1880) at:
735d6c8b +00 winmm.dll

KiFastSystemCallRet
GetMessageA
CallThreadProcSafe
ThreadExceptFrame
BaseThreadInitThunk

modules:
00400000 AMXX_Studio.exe
1.4.3.3
C:\Users\Rui\Docume
nts\Amxx
10000000 scilexer.dll
1.6.6.0
C:\Users\Rui\Docume
nts\Amxx
6c930000 olepro32.dll
6.1.7601.17514 C:\Windows\system32
6dd30000 winspool.drv
6.1.7601.17514 C:\Windows\system32
70520000 wsock32.dll
6.1.7600.16385 C:\Windows\system32
70c30000 MSVCR90.dll
9.0.30729.6161 C:\Windows\WinSxS\x
86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57
70e20000 comctl32.dll
5.82.7601.17514 C:\Windows\WinSxS\x
86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83d
ffa859149af
712c0000 rpchrome150browserrecordhelper.dll 15.0.2.72
C:\ProgramData\Real
\RealPlayer\BrowserRecordPlugin\Chrome\Hook
72fa0000 RICHED32.DLL
6.1.7601.17514 C:\Windows\system32
735d0000 winmm.dll
6.1.7601.17514 C:\Windows\system32
73640000 msimg32.dll
6.1.7600.16385 C:\Windows\system32
737d0000 RICHED20.dll
5.31.23.1230
C:\Windows\system32
73b70000 dwmapi.dll
6.1.7600.16385 C:\Windows\system32
73ea0000 uxtheme.dll
6.1.7600.16385 C:\Windows\system32
74020000 comctl32.DLL
6.10.7601.17514 C:\Windows\WinSxS\x
86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e697
5e2bd6f2b2
74590000 version.dll
6.1.7600.16385 C:\Windows\system32
74fe0000 SspiCli.dll
6.1.7601.17725 C:\Windows\system32
75000000 apphelp.dll
6.1.7601.17514 C:\Windows\system32
75050000 CRYPTBASE.dll
6.1.7600.16385 C:\Windows\system32
752f0000 KERNELBASE.dll
6.1.7601.17651 C:\Windows\system32
753d0000 NSI.dll
6.1.7600.16385 C:\Windows\system32
753e0000 USER32.dll
6.1.7601.17514 C:\Windows\system32

754b0000
75920000
759c0000
75a20000
76670000
76750000
768f0000
76980000
76bd0000
76ca0000
76cc0000
76e20000
76ed0000
76f80000
770d0000
77100000
77110000

WS2_32.dll
advapi32.dll
SHLWAPI.dll
SHELL32.dll
kernel32.dll
USP10.dll
oleaut32.dll
comdlg32.dll
MSCTF.dll
sechost.dll
ole32.dll
msvcrt.dll
RPCRT4.dll
ntdll.dll
imm32.dll
LPK.dll
GDI32.dll

processes:
0000 Idle
0004 System
0160 smss.exe
01d8 csrss.exe
022c wininit.exe
0234 csrss.exe
0264 services.exe
0278 lsass.exe
0280 lsm.exe
02a4 winlogon.exe
0320 svchost.exe
036c svchost.exe
039c atiesrxx.exe
03e4 svchost.exe
0420 svchost.exe
0440 svchost.exe
04e0 svchost.exe
055c atieclxx.exe
05b4 svchost.exe
0628 ASLDRSrv.exe
0674 spoolsv.exe
0694 svchost.exe
06dc WVSScheduler.exe
0710 armsvc.exe
072c avp.exe
0760 svchost.exe
0798 openvpnas.exe
07c0 hsssrv.exe
0170 hsswd.exe
025c TeamViewer_Service.exe
0938 Dwm.exe
0a18 taskhost.exe
0a54 WUDFHost.exe
0b3c HControl.exe
0b44 Explorer.EXE
0c58 ATKOSD.exe
0d38 sm56hlpr.exe
0d40 avp.exe
persky Internet Security 2012
0d48 DMedia.exe
0df0 RtHDVCpl.exe

6.1.7601.17514
6.1.7601.17514
6.1.7601.17514
6.1.7601.17678
6.1.7601.17651
1.626.7601.17514
6.1.7601.17676
6.1.7601.17514
6.1.7600.16385
6.1.7600.16385
6.1.7601.17514
7.0.7601.17744
6.1.7601.17514
6.1.7601.17725
6.1.7601.17514
6.1.7600.16385
6.1.7601.17514
0
0
0
0
0
1
0
0
0
1
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
1
1
0
1
1
1
1
1

C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\SYSTEM32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\SYSTEM32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32

high
normal

C:\Windows\system32
C:\Windows\system32

normal

C:\Windows

normal
normal

C:\Program Files\Motorola\SMSERIAL
C:\Program Files\Kaspersky Lab\Kas

1 normal
1 normal

C:\Program Files\ASUS\ATK Media


C:\Program Files\Realtek\Audio\HDA

0e30 PlusService.exe
senger Plus!
0e3c realsched.exe
pdate
0e94 MOM.exe
ATI.ACE\Core-Static
0dd0 SearchIndexer.exe
0d1c wmpnetwk.exe
11d4 CCC.exe
ATI.ACE\Core-Static
175c firefox.exe
0cd4 PresentationFontCache.exe
124c svchost.exe
1264 plugin-container.exe
1014 hlsw.exe
1638 ts3client_win32.exe
0f18 audiodg.exe
1424 Skype.exe
19f0 msnmsgr.exe
enger
0994 wlcomm.exe
acts
1ef4 Steam.exe
0258 SteamService.exe
02fc hl.exe
ui_bd\counter-strike
1bcc GameOverlayUI.exe
1f88 filezilla.exe
ent
19f4 AMXX_Studio.exe

1 normal

C:\Program Files\Yuna Software\Mes

1 normal

C:\Program Files\Real\RealPlayer\U

1 normal

C:\Program Files\ATI Technologies\

0
0
1 normal

C:\Program Files\ATI Technologies\

1
0
0
1
1
1
0
1
1

normal

C:\Program Files\Mozilla Firefox

normal
C:\Program Files\Mozilla Firefox
below normal C:\Program Files\HLSW
normal
normal

C:\Program Files\Skype\Phone
C:\Program Files\Windows Live\Mess

1 normal

C:\Program Files\Windows Live\Cont

1 normal
0
1 normal

C:\Program Files\Steam

1 normal
1 normal

C:\Program Files\Steam
C:\Program Files\FileZilla FTP Cli

1 normal

C:\Users\Rui\Documents\Amxx

c:\program files\steam\steamapps\r

hardware:
+ Batteries
- Bateria Composta da Microsoft
- Microsoft ACPI-Mtodo de controlo de bateria em conformidade
- Transformador Microsoft
+ Computer
- PC com base em X86 ACPI
+ Disk drives
- Generic- xD/SDMMC/MS/Pro USB Device
- ST9250827AS ATA Device
- WD Ext HDD 1021 USB Device
+ Display adapters
- ATI Mobility Radeon HD 3400 Series (driver 8.930.0.0)
+ DVD/CD-ROM drives
- HL-DT-ST DVDRAM GSA-T40N ATA Device
+ Human Interface Devices
- Dispositivo de controlo para consumidores compatvel com HID
- Dispositivo USB de Introduo de Texto
- Dispositivo USB de Introduo de Texto
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 0
- ATA Channel 1
- Controlador Dual Channel PCI IDE padro
- Controlador SiS PCI IDE
+ Imaging devices
- USB 2.0 Camera
+ Keyboards
- Teclado Padro PS/2

+ Mice and other pointing devices


- Rato compatvel com HID
- Rato PS/2 Microsoft
+ Modems
- Motorola SM56 Speakerphone Modem (driver 6.12.25.6)
+ Monitors
- Monitor PnP Genrico
+ Network adapters
- Atheros AR5007EG Wireless Network Adapter (driver 8.0.0.238)
- Controlador Ethernet SiS191
- TAP-Win32 Adapter V9 (driver 9.0.0.8)
+ Portable Devices
- E:\
+ Processors
- Intel(R) Core(TM)2 Duo CPU
T5800 @ 2.00GHz
- Intel(R) Core(TM)2 Duo CPU
T5800 @ 2.00GHz
+ Sound, video and game controllers
- Dispositivo de udio half duplex Unimodem
- ManyCam Virtual Microphone (driver 3.0.0.0)
- ManyCam Virtual Webcam (driver 3.0.0.0)
- Realtek High Definition Audio (driver 6.0.1.5817)
- Sennheiser USB headset
+ Storage volume shadow copies
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
- Cpia sombra de volume genrico
+ System devices
- Altifalante do sistema
- ATK0100 ACPI UTILITY (driver 1043.2.31.100)
- Barramento de PCI
- Boto de alimentao ACPI
- Boto de funcionalidade fixa ACPI
- Boto de suspenso ACPI
- Bridge de CPU de sistemas PCI padro
- Bridge PCI ISA padro
- Controlador BIOS Microsoft System Management
- Controlador de acesso directo memria (DMA)
- Controlador de Enumerador de Unidades Virtuais da Microsoft
- Controlador de High Definition Audio
- Controlador de rato do servidor de terminais
- Controlador do teclado do servidor de terminais
- Controlador PIC
- Enumerador de Barramento Para Dispositivos Compostos
- Enumerador de Barramento Raiz UMBus
- Enumerador de dispositivos de software Plug and Play
- Enumerador UMBus
- Enumerador UMBus
- Ficheiro como Controlador de Volume
- Gestor de volumes
- Microsoft ACPI-Controlador incorporado em conformidade
- Placa de sistema
- Porta Raiz SiS PCI Express x16
- Porta SiS PCI Express x1
- Porta SiS PCI Express x1
- Processador de dados numricos (NDP)
- Recursos da placa principal

- Recursos da placa principal


- Recursos da placa principal
- Relgio CMOS de sistema/tempo real
- Remote Desktop Device Redirector Bus
- Sistema compatvel com Microsoft ACPI
- Tampa ACPI
- Temporizador do sistema
- Zona trmica ACPI
+ Universal Serial Bus controllers
- Concentrador raiz USB (usbport)
- Concentrador raiz USB (usbport)
- Concentrador raiz USB (usbport)
- Controlador Anfitrio PCI para USB Avanado
- Controlador Anfitrio SiS 7001 PCI para USB Aberto
- Controlador Anfitrio SiS 7001 PCI para USB Aberto
- Dispositivo composto USB
- Dispositivo composto USB
- Dispositivo de armazenamento de massa USB
- Dispositivo de armazenamento de massa USB
cpu
eax
ebx
ecx
edx
esi
edi
eip
esp
ebp

registers:
= 008d7cec
= 0469e5ac
= 00000000
= 00468159
= 00000001
= 00000001
= 00468159
= 0012f680
= 0012f6e0

stack dump:
0012f680 59
0012f690 94
0012f6a0 01
0012f6b0 01
0012f6c0 96
0012f6d0 1c
0012f6e0 40
0012f6f0 01
0012f700 40
0012f710 00
0012f720 00
0012f730 00
0012f740 00
0012f750 00
0012f760 00
0012f770 00
0012f780 00
0012f790 00
0012f7a0 00
0012f7b0 00

81
f6
00
00
6f
f8
fb
00
fb
00
00
00
00
00
00
00
00
00
00
00

disassembling:
[...]
00667beb
00667bed
00667bed
00667bef
00667bf0

46
12
00
00
46
12
12
00
12
00
00
00
00
00
00
00
00
00
00
00

00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00

de
59
01
00
f8
01
59
05
64
00
00
00
00
00
00
00
00
00
00
00

fa
81
00
00
f6
00
81
7c
fd
00
00
00
00
00
00
00
00
00
00
00

ed
46
00
00
12
00
46
66
12
00
00
00
00
00
00
00
00
00
00
00

0e
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00

01
ec
e0
f0
dc
28
14
50
18
00
00
00
00
00
00
00
00
00
00
00

test
jl

eax, eax
loc_667c3a

inc
mov

eax
[ebp-$2c], eax

00
7c
f6
10
45
58
df
fb
10
00
00
00
00
00
00
00
00
00
00
00

00
8d
12
46
40
83
4d
12
4c
00
00
00
00
00
00
00
00
00
00
00

00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00

07
ac
b0
28
e0
00
18
dc
e6
00
00
00
00
00
00
00
00
00
00
00

00
e5
f6
58
f6
00
7e
45
0d
00
00
00
00
00
00
00
00
00
00
00

00
69
12
83
12
00
8d
40
00
00
00
00
00
00
00
00
00
00
00
00

00
04
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00

Y.F.............
....Y.F..|....i.
................
..........F.(X..
.oF......E@.....
........(X......
@...Y.F...M..~..
.....|f.P....E@.
@...d.....L.....
................
................
................
................
................
................
................
................
................
................
................

00667bf3
xor
00667bf5 780 lea
00667bfb
mov
00667bfd
mov
00667c00
mov
00667c02
> call
00667c02
00667c05
mov
00667c0b
mov
00667c0d
mov
00667c10
call
00667c10
00667c15
test
00667c17
jz
00667c17
00667c19 781 lea
[...]

ebx, ebx
ecx, [ebp-$324]
edx, ebx
eax, [ebp-$30]
edi, [eax]
dword ptr [edi+$c]
edx, [ebp-$324]
cl, 1
eax, [ebp-$14]
-$33de5 ($633e30)
al, al
loc_667c28
ecx, [ebp-$1c]

; UnitCodeUtils.IsAtStart

Вам также может понравиться