Wed, 31 Dec 2014 06:09:35 +0100
Cloned upstream origin tor-browser at tor-browser-31.3.0esr-4.5-1-build1
revision ID fc1c9ff7c1b2defdbc039f12214767608f46423f for hacking purpose.
michael@0 | 1 | MDRawHeader |
michael@0 | 2 | signature = 0x504d444d |
michael@0 | 3 | version = 0x5128a793 |
michael@0 | 4 | stream_count = 9 |
michael@0 | 5 | stream_directory_rva = 0x20 |
michael@0 | 6 | checksum = 0x0 |
michael@0 | 7 | time_date_stamp = 0x45d35f73 2007-02-14 19:13:55 |
michael@0 | 8 | flags = 0x0 |
michael@0 | 9 | |
michael@0 | 10 | mDirectory[0] |
michael@0 | 11 | MDRawDirectory |
michael@0 | 12 | stream_type = 3 |
michael@0 | 13 | location.data_size = 100 |
michael@0 | 14 | location.rva = 0x184 |
michael@0 | 15 | |
michael@0 | 16 | mDirectory[1] |
michael@0 | 17 | MDRawDirectory |
michael@0 | 18 | stream_type = 4 |
michael@0 | 19 | location.data_size = 1408 |
michael@0 | 20 | location.rva = 0x1e8 |
michael@0 | 21 | |
michael@0 | 22 | mDirectory[2] |
michael@0 | 23 | MDRawDirectory |
michael@0 | 24 | stream_type = 5 |
michael@0 | 25 | location.data_size = 52 |
michael@0 | 26 | location.rva = 0x1505 |
michael@0 | 27 | |
michael@0 | 28 | mDirectory[3] |
michael@0 | 29 | MDRawDirectory |
michael@0 | 30 | stream_type = 6 |
michael@0 | 31 | location.data_size = 168 |
michael@0 | 32 | location.rva = 0xdc |
michael@0 | 33 | |
michael@0 | 34 | mDirectory[4] |
michael@0 | 35 | MDRawDirectory |
michael@0 | 36 | stream_type = 7 |
michael@0 | 37 | location.data_size = 56 |
michael@0 | 38 | location.rva = 0x8c |
michael@0 | 39 | |
michael@0 | 40 | mDirectory[5] |
michael@0 | 41 | MDRawDirectory |
michael@0 | 42 | stream_type = 15 |
michael@0 | 43 | location.data_size = 24 |
michael@0 | 44 | location.rva = 0xc4 |
michael@0 | 45 | |
michael@0 | 46 | mDirectory[6] |
michael@0 | 47 | MDRawDirectory |
michael@0 | 48 | stream_type = 1197932545 |
michael@0 | 49 | location.data_size = 12 |
michael@0 | 50 | location.rva = 0x14f9 |
michael@0 | 51 | |
michael@0 | 52 | mDirectory[7] |
michael@0 | 53 | MDRawDirectory |
michael@0 | 54 | stream_type = 0 |
michael@0 | 55 | location.data_size = 0 |
michael@0 | 56 | location.rva = 0x0 |
michael@0 | 57 | |
michael@0 | 58 | mDirectory[8] |
michael@0 | 59 | MDRawDirectory |
michael@0 | 60 | stream_type = 0 |
michael@0 | 61 | location.data_size = 0 |
michael@0 | 62 | location.rva = 0x0 |
michael@0 | 63 | |
michael@0 | 64 | Streams: |
michael@0 | 65 | stream type 0x0 at index 8 |
michael@0 | 66 | stream type 0x3 at index 0 |
michael@0 | 67 | stream type 0x4 at index 1 |
michael@0 | 68 | stream type 0x5 at index 2 |
michael@0 | 69 | stream type 0x6 at index 3 |
michael@0 | 70 | stream type 0x7 at index 4 |
michael@0 | 71 | stream type 0xf at index 5 |
michael@0 | 72 | stream type 0x47670001 at index 6 |
michael@0 | 73 | |
michael@0 | 74 | MinidumpThreadList |
michael@0 | 75 | thread_count = 2 |
michael@0 | 76 | |
michael@0 | 77 | thread[0] |
michael@0 | 78 | MDRawThread |
michael@0 | 79 | thread_id = 0xbf4 |
michael@0 | 80 | suspend_count = 0 |
michael@0 | 81 | priority_class = 0x0 |
michael@0 | 82 | priority = 0x0 |
michael@0 | 83 | teb = 0x7ffdf000 |
michael@0 | 84 | stack.start_of_memory_range = 0x12f31c |
michael@0 | 85 | stack.memory.data_size = 0xce4 |
michael@0 | 86 | stack.memory.rva = 0x1639 |
michael@0 | 87 | thread_context.data_size = 0x2cc |
michael@0 | 88 | thread_context.rva = 0xd94 |
michael@0 | 89 | |
michael@0 | 90 | MDRawContextX86 |
michael@0 | 91 | context_flags = 0x1003f |
michael@0 | 92 | dr0 = 0x0 |
michael@0 | 93 | dr1 = 0x0 |
michael@0 | 94 | dr2 = 0x0 |
michael@0 | 95 | dr3 = 0x0 |
michael@0 | 96 | dr6 = 0x0 |
michael@0 | 97 | dr7 = 0x0 |
michael@0 | 98 | float_save.control_word = 0xffff027f |
michael@0 | 99 | float_save.status_word = 0xffff0000 |
michael@0 | 100 | float_save.tag_word = 0xffffffff |
michael@0 | 101 | float_save.error_offset = 0x0 |
michael@0 | 102 | float_save.error_selector = 0x220000 |
michael@0 | 103 | float_save.data_offset = 0x0 |
michael@0 | 104 | float_save.data_selector = 0xffff0000 |
michael@0 | 105 | float_save.register_area[80] = 0x0000000018b72200000118b72200000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 |
michael@0 | 106 | float_save.cr0_npx_state = 0x0 |
michael@0 | 107 | gs = 0x0 |
michael@0 | 108 | fs = 0x3b |
michael@0 | 109 | es = 0x23 |
michael@0 | 110 | ds = 0x23 |
michael@0 | 111 | edi = 0x0 |
michael@0 | 112 | esi = 0x7b8 |
michael@0 | 113 | ebx = 0x7c883780 |
michael@0 | 114 | edx = 0x7c97c0d8 |
michael@0 | 115 | ecx = 0x7c80b46e |
michael@0 | 116 | eax = 0x400000 |
michael@0 | 117 | ebp = 0x12f384 |
michael@0 | 118 | eip = 0x7c90eb94 |
michael@0 | 119 | cs = 0x1b |
michael@0 | 120 | eflags = 0x246 |
michael@0 | 121 | esp = 0x12f320 |
michael@0 | 122 | ss = 0x23 |
michael@0 | 123 | extended_registers[512] = 0x7f0200000000220000000000000000000000000000000000801f0000ffff00000000000018b72200000100000000000018b72200000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000004509917c4e09917c38b622002400020024b42200020000009041917c0070fd7f0510907cccb22200000000009cb3220018ee907c7009917cc0e4977c6f3e917c623e917c08020000dcb62200b4b622001e000000000000000000000000000000000000002eb42200000000000f000000020000001e00200000fcfd7f2f63796764726976652f632f444f43554d457e312f4d4d454e544f7e312f4c4f43414c537e312f54656d7000000000000000000130b422000000004300000000000000001efcfd7f4509917c4e09917c5ad9000008b32200b4b62200 |
michael@0 | 124 | |
michael@0 | 125 | Stack |
michael@0 | 126 | 0x00000000c0e9907ccb25807cb8070000000000000000000034ff1200b0fe12008037887c140000000100000000000000000000001000000027e0907c2e39917c0050fd7f00f0fd7f000000000400000034f312006947c788d4f31200a89a837cf825807c0000000098f312003225807cb8070000ffffffff00000000e4f31200ff1d4000b8070000ffffffffa8fa12008037887c0e1c4000a8fa120000000000ff792a0f64f91200b01b400000004000b0fe12000040020070fa1200084042000000000080fa120080fa12004e30867ca8fa12000000000000000000000000000018000002100000e3ef907c0000000079d900000000000048f41200000014003207917c0500000078071400000014000000000020f412003207917ca05f140018ee907cfa00000074f61200000000009615917ceb06917cf00298000100000000000000384f14009615917ceb06917c7801140008000000404f14000000a659985f1400080000000000000018ee907c90fea700400698003815917c184f1400eb06917c00000000800000000000a65988f69f0090f51200a569917cf8f41200d95c878880f5120043ef907c480485000500000090f5120088fea700a8212400000000000000000080f512002469917cf8fbfd7fa821240008000000f500000000000000384d850078019800a8fa120004000000a05f140096d4917c00000000b0d4917c0000000008069800184f140000000000104f140000000000184f140000004000000000010040020063003a005c0074006500730074005f006100700070002e006500780065000000000000002f00000028000000184f1400780185007801140028000000000000000000140084f3120010000000d8f5120018ee907cf006917cffffffffeb06917ce619917c88e6a7003003000001030000ff1b917c0000980080e6a70080069800400698000000980080e6a70000000000000000000000000080e6a7000818000088e6a700d759927c78019800081800000210000000009800f8f31200280a0000dcf6120018ee907cf006917cffffffffeb06917c0859927c00009800080000005859927c00000000000001000000a659000000005a6202000010000068fe030001000000dffe03000000010000000100fffffe7f0100000001c0c27700008500000000002dc0c27700000000684aaf590000a659241a917c80c0977c0000000000000000cd5c927c0050fd7f0000a65900000100080000004550fd7f0000000000000000000000000050fd7fcd5c927c05000000d4f61200f45c927c80e4977c05000000010000000050fd7f18f712007009917cc0e4977c172e817cff2d817c000000000000a6590000a6590210000000f0fd7f05000000e8f612000806980064f81200a89a837c002e817cffffffffff2d817cc8242400dd8ea75901000000000000004cf712003608a9590000a65901000000000000000100000060f71200e407a9596cf7120000004000000000010040020063003a005c0074006500730074005f006100700070002e0065007800650000006d05917c905f140000000000440d020000000000604f14000c0000007801140000000000a04e1400d84d8700400687004509917c0800000000000000000000004000000078011400a8038700404f14000510907c000000000000000078011400980387000800000008000000c0e4977cd04d8700f835887c7801140010000000a0e7ae591600000030fd1200d39b917c44000000620000000000a65950e9ae59d8eaae59a80387000100000014040000000000000100000002000000f800a659c003870001000000780114009508917c0000a659091b917c020000000900000040000000a2fd12009cfd1200404f1400a2fd1200d04d8700640187000000000000000000d04d870010000000d84d8700384f1400a803870010000000c00300000000870074fb1200404f14006cfe120018ee907cf006917cffffffffeb06917ca09d400000008700000000000400000000000000ffffff3fc04d8700ccfd12009c4d400004000000fa19917cb84d870064018700c04d8700063440000400000018000000c04d870079d90000c0038700fa31400000000000c04d8700c04d87000000000001000000b0fe120082294000c04d87000000000000000000c04d870048fe12008cfe120000000000e224400040fe12008cfe1200c04d8700d84d8700b0fe12008600817c54fa1200d8f9120000000000160018005479420079d90000000000000757917c00000200a4f91200a4f91200a4f91200020000000200000000000000c4f912000000000079d9000014fb12004cfa120014fb1200005a917c00fa1200a0fb120001000000655a917ca405817c74c1977ce705817c00000000f4fd120098fb120000000000a0fb12000000000090fb12000000800070fa120000000000000000000000000016001800547942000000000001000000000000000000000000000000000000003308917ca89a837c0000807c0000807ce800807c2cfa12001fe2907c11fa877cffffffffe06f817c000000006cfa12001c0000000f000000e06f817c8fc60000f0f312000060817cc8fa1200a89a837c7039867cfffffffff0ff1200da36847ca8fa1200099b837cb0fa120000000000b0fa12000000000000000000000000009cfb1200b8fb1200d4fa1200bf37907c9cfb1200e0ff1200b8fb120070fb1200b0ff1200d837907ce0ff120084fb12008b37907c9cfb1200e0ff1200b8fb120070fb1200a89a837c010000009cfb1200e0ff12006078937c9cfb1200e0ff1200b8fb120070fb1200a89a837c280a00009cfb12000200000018ee907c9032917cffffffff8832917c3364917c68fb1200000087003207917c02000000dc31917c1232917c8132917c8832917c1e000000c01e2400080200003807917c54fb12003207917cc4fb120018ee907c9032917c0000130000d01200beb4800088fe1200faea907c00000000b8fb12009cfb1200b8fb1200050000c000000000000000009e4240000200000001000000450000003f0001000000000000000000000000000000000000000000000000007f02ffff0000ffffffffffff0000000000002200000000000000ffff0000000018b72200000118b7220000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000003b0000002300000023000000280a000002000000c1ab807c58bc420094fe12004500000088fe12009e4240001b0000004602010084fe1200230000007f0200000000220000000000000000000000000000000000801f0000ffff00000000000018b72200000100000000000018b72200000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000004509917c4e09917c38b622002400020024b42200020000009041917c0070fd7f0510907cccb22200000000009cb3220018ee907c7009917cc0e4977c6f3e917c623e917c08020000dcb62200b4b622001e000000000000000000000000000000000000002eb42200000000000f000000020000001e00200000fcfd7f2f63796764726976652f632f444f43554d457e312f4d4d454e544f7e312f4c4f43414c537e312f54656d7000000000000000000130b422000000004300000000000000001efcfd7f4509917c4e09917c5ad9000008b32200b4b622004500000070ff120000424000b8278700dc31917c00000000004c870000000020040000000000000007000000000000004042400000000000000000002e000000000000000cff12007b434100010000000700000084434100004d87002e39917cffffffff24000000240000002700000000000000584d870004000000b1944000244c87002a0000002f000000c0fe1200004d8700584d87000000a659b0b9a859015d400015aa400000000000b4070000784e14000000000001000000f40b00000000000000000000bc070000b8070000f40b0000a8fa120000000000009c4000599c400094b240004f752a0fc0ff1200ec534000010000003039870050398700ff752a0f00002400a02024000050fd7f050000c00100000005000000000000000000240084ff1200acfa1200e0ff1200d06f4000a70b7a0f00000000f0ff1200d76f817c00002400a02024000050fd7f050000c0c8ff1200a8fa1200ffffffffa89a837ce06f817c0000000000000000000000004354400000000000 |
michael@0 | 127 | |
michael@0 | 128 | thread[1] |
michael@0 | 129 | MDRawThread |
michael@0 | 130 | thread_id = 0x11c0 |
michael@0 | 131 | suspend_count = 0 |
michael@0 | 132 | priority_class = 0x0 |
michael@0 | 133 | priority = 0x0 |
michael@0 | 134 | teb = 0x7ffde000 |
michael@0 | 135 | stack.start_of_memory_range = 0x97f6e8 |
michael@0 | 136 | stack.memory.data_size = 0x918 |
michael@0 | 137 | stack.memory.rva = 0x231d |
michael@0 | 138 | thread_context.data_size = 0x2cc |
michael@0 | 139 | thread_context.rva = 0x1060 |
michael@0 | 140 | |
michael@0 | 141 | MDRawContextX86 |
michael@0 | 142 | context_flags = 0x1003f |
michael@0 | 143 | dr0 = 0x0 |
michael@0 | 144 | dr1 = 0x0 |
michael@0 | 145 | dr2 = 0x0 |
michael@0 | 146 | dr3 = 0x0 |
michael@0 | 147 | dr6 = 0x0 |
michael@0 | 148 | dr7 = 0x0 |
michael@0 | 149 | float_save.control_word = 0xffff027f |
michael@0 | 150 | float_save.status_word = 0xffff0000 |
michael@0 | 151 | float_save.tag_word = 0xffffffff |
michael@0 | 152 | float_save.error_offset = 0x0 |
michael@0 | 153 | float_save.error_selector = 0x870000 |
michael@0 | 154 | float_save.data_offset = 0x0 |
michael@0 | 155 | float_save.data_selector = 0xffff0000 |
michael@0 | 156 | float_save.register_area[80] = 0x84fb120000001400320778071400000014000000f4fe1200a0fd120018eeb0fd12003815917c961534ff120034ff12000000e7712a0f2a0000005400ccfb120068514000584d540000002a000000f4fe |
michael@0 | 157 | float_save.cr0_npx_state = 0x0 |
michael@0 | 158 | gs = 0x0 |
michael@0 | 159 | fs = 0x3b |
michael@0 | 160 | es = 0x23 |
michael@0 | 161 | ds = 0x23 |
michael@0 | 162 | edi = 0x145b00 |
michael@0 | 163 | esi = 0x145aa8 |
michael@0 | 164 | ebx = 0x145ad0 |
michael@0 | 165 | edx = 0x7c90eb94 |
michael@0 | 166 | ecx = 0x7 |
michael@0 | 167 | eax = 0xa80000 |
michael@0 | 168 | ebp = 0x97f6fc |
michael@0 | 169 | eip = 0x7c90eb94 |
michael@0 | 170 | cs = 0x1b |
michael@0 | 171 | eflags = 0x246 |
michael@0 | 172 | esp = 0x97f6ec |
michael@0 | 173 | ss = 0x23 |
michael@0 | 174 | extended_registers[512] = 0x7f0200000000870000000000000000000000000000000000801f0000ccfb120084fb1200000014003207917c050000007807140000001400000000005cfb1200f4fe1200a0fd120018ee907c2d020000b0fd12003815917c9615917ceb06917c34ff120034ff12000000000060000000e7712a0f2a0000005400000000000000ccfb120068514000584d870034fc1200540000002a000000f4fe1200f8fe12002c2f4000584d87005e00000034fc12005400000000000000b0fe1200f4fe1200c0fe12005f21400034fc12002a0000003b762a0f91214000303132330000870038393a3b3c3d3e3f4041424300000000070000003bd11e2340061400b858101e5e03e0652e005c00320033003100650064003100780114002d0066003300380034002d0000000000390034002d0062003800350038002d0031003000984e1400350065003000330065003000360035002e0064006d0070000000907c08000000ffffffff8832917cbeb4807c780114001d00f40b784e14000401000044fd120050fd1200c01e240078011400bdb9807ca04e14007c80c2770000000008fd120078011400ecfc1200f0fc1200e6b9807cffffffff7c80c27708fd12001c00000024fd1200e92a867c7c80c277b45a887c8037887c2d0200000080c2770000c17780000000005003000010000020000000780114005cff12001648847c091b917c |
michael@0 | 175 | |
michael@0 | 176 | Stack |
michael@0 | 177 | 0x8000108020fa97009fd7907c0000000048f7970005000f0040061400000000004cf7970037b9807c00000000000000003103917c780114000000000061dc907cf1b8807c00000000ffffffff70f79700000000000000000054f797003082140001000000000000000200000000000000000000007cf7970020b9807c0e00000004000000006000000000a80078011400000000000882140092d5907c8b9b807c9c070000d0f89700780114009c07000038821400807f140020dea85910fa9700780114009807000088fb9700e07f14009c0700000000000078011400000000000882140000000000000000000000000078011400ba0300000000000000000000000000000000000000000000000000007801140000000000000000000000000000000000c0030000000000000000000000000000088214005c0057000600000078011400000000005c00730079007300740065006d0033000082140068011400000000000000000000821400d47f1400807f140070f8970061eea859e000a8000000a8001c4e000084f89700bdeea859e000a8000000a8001c4e0000a4f897005fefa8590000a8000000000006000000c4f89700e000a80060fe9700c8f897005abfa8590000a80000000000060000001c000000d47f1400807f1400380000006ce9907c88b9807cffffffff0000a80000000000807f140030fa97007fc3a859a0c4a859b0fb970060fe9700684f1400504500004c010400ca9610410000000000000000e0000e210b01070a00400000003a000000000000f1100000001000000000bf760000000000100000000200000500010005000100040000000000000000b00000000400009ba2000000001400285214000000000034fa97007801140034fa9700910e917c080614006d05917cc84d85005c4e8500684f140000000000b04800002852140078011400e00300003052140000000000000000000000000078011400c403000030821400380000000000000000000000000000000000000000000000000000003882140048050000780200003800000000100000ec000000b8470000400000000000000000000000000000000000140000000000807f140000000000000000000000000000000101a900000060fe9700dcff9700dcff97000050fd7f78fa970054fa9700ad9d917c8cfa9700c2066f7f0e000000000000001c01000078fa9700c84d850068fa970085ae807c78fc970024fc970083dba85978fc97008cfa9700800000008edba85914010000050000000100000096020000b8fc97003815917c9615917ceb06917c60fe970060fe9700c4fd9700d8fa9700000014003207917c21000000b80c14000000140030521400b0fa9700fffffffff4fc970018ee907c3807917cffffffff3207917cab06917ceb06917ccc4f140060fe9700684f1400e0004000e4fa9700a863917c74fb970018ee907c3808917cffffffff3308917c5b2c817c872c817c00000000f4fb9700000000000000000054fd970018ee907c4006140064fd97003815917c00e0fd7feb06917c684f140038821400780114000050fd7facfb970000000000000004000000000090fe97000000000018fb970050531400508b1400a89a837cffe9907cf60d817ca807000000000000ffe9907cf60d817c08000000000000000000000000000000585314003cfc97003882140000000000160e817cc4fd970060fe970058531400208f1400588b1400460f917c50531400208f1400780114003082140000000000b8fc970078011400b8fc9700910e917c080614006d05917c3882140060fe97000000000000000000960200003082140078011400ffe9907c38821400a807000000000000780114005853140058fc9700505314001000000000000000160e817c784e8500c4fd9700388214000000000024010000f00c00001000000044fc970000000000c7e2907ce721807cffffffffe8f69700388214001809000098fc9700acfc9700d2e2a859ffffffffe8f697003882140018090000c4fc97003882140060fe9700c4fd9700ccfc97004ee3a859ffffffffe8f69700000000003882140018090000e0fc9700f4fc970093b2a859ffffffffe8f69700000000003882140018090000c4fd970060fe9700a85a140078fd9700a5b3a85960fe9700c4fd9700684f1400e8f697000000000018090000000000000200000080fd9700c4fd970060fe970000000000f40b000000000000000000000000000000f0fd7f000000001cf3120000000000e40c000039160000cc020000940d00000000000000000000000000000000000002000000ac4f14006010000098fd97005eb7a8593916000000000000684f1400784e85000000000084ff9700d4fe97007bb9a85960fe9700c4fd9700684f14003849140084ff9700010000000000000008ff9700f40b0000090000000000000020000000200000006c0000008c000000380000001e000000c4000000dc000000a80000008401000064000000b801000030000000e801000080050000e8010000680700000000000068070000680700000000000005150000340000002915000039150000fc1600001d23000068070000600300008a070000c80a0000310a00002c130000f91400000c000000352c000000000000ffffffff5c0f0000c84d8500784e8500884e85000000000000000000000000004c010000fc39a6590000000002000000050000000100000000008500280a000001000001cc0200009c0000000b00000050000000040000000010000000000000000000000001000000000000000000000000000034ff970078baa859384914005c0f0000c84d850001000000884e8500684f140008ff970064ff970000000000a8070000b0fe1200f40b00009cfb120000000000b8fb12000000000000000000ae20140000000000884e8500784e8500c84d8500a8fa120011204000ffffffff5c0f0000a80700000000000078ff970064ff970000000000adbf807c2025807cecff97000100000084ff970003000000c0110000f40b0000f40b0000a8fa120000000000010067470c0000006cff9700bc070000ffffffff000000006c1a4000f40b000000fa12000000000000004000a09d4000b0fe120083b6807cb0fe120000004000a09d4000b0fe120000e0fd7f00069c86c0ff9700d8863f86ffffffffa89a837c90b6807c000000000000000000000000301a4000b0fe120000000000 |
michael@0 | 178 | |
michael@0 | 179 | MinidumpModuleList |
michael@0 | 180 | module_count = 13 |
michael@0 | 181 | |
michael@0 | 182 | module[0] |
michael@0 | 183 | MDRawModule |
michael@0 | 184 | base_of_image = 0x400000 |
michael@0 | 185 | size_of_image = 0x2d000 |
michael@0 | 186 | checksum = 0x0 |
michael@0 | 187 | time_date_stamp = 0x45d35f6c |
michael@0 | 188 | module_name_rva = 0x78a |
michael@0 | 189 | version_info.signature = 0x0 |
michael@0 | 190 | version_info.struct_version = 0x0 |
michael@0 | 191 | version_info.file_version = 0x0:0x0 |
michael@0 | 192 | version_info.product_version = 0x0:0x0 |
michael@0 | 193 | version_info.file_flags_mask = 0x0 |
michael@0 | 194 | version_info.file_flags = 0x0 |
michael@0 | 195 | version_info.file_os = 0x0 |
michael@0 | 196 | version_info.file_type = 0x0 |
michael@0 | 197 | version_info.file_subtype = 0x0 |
michael@0 | 198 | version_info.file_date = 0x0:0x0 |
michael@0 | 199 | cv_record.data_size = 40 |
michael@0 | 200 | cv_record.rva = 0x132c |
michael@0 | 201 | misc_record.data_size = 0 |
michael@0 | 202 | misc_record.rva = 0x0 |
michael@0 | 203 | (code_file) = "c:\test_app.exe" |
michael@0 | 204 | (code_identifier) = "45D35F6C2d000" |
michael@0 | 205 | (cv_record).cv_signature = 0x53445352 |
michael@0 | 206 | (cv_record).signature = 5a9832e5-2872-41c1-838e-d98914e9b7ff |
michael@0 | 207 | (cv_record).age = 1 |
michael@0 | 208 | (cv_record).pdb_file_name = "c:\test_app.pdb" |
michael@0 | 209 | (misc_record) = (null) |
michael@0 | 210 | (debug_file) = "c:\test_app.pdb" |
michael@0 | 211 | (debug_identifier) = "5A9832E5287241C1838ED98914E9B7FF1" |
michael@0 | 212 | (version) = "" |
michael@0 | 213 | |
michael@0 | 214 | module[1] |
michael@0 | 215 | MDRawModule |
michael@0 | 216 | base_of_image = 0x7c900000 |
michael@0 | 217 | size_of_image = 0xb0000 |
michael@0 | 218 | checksum = 0xaf2f7 |
michael@0 | 219 | time_date_stamp = 0x411096b4 |
michael@0 | 220 | module_name_rva = 0x7ae |
michael@0 | 221 | version_info.signature = 0xfeef04bd |
michael@0 | 222 | version_info.struct_version = 0x10000 |
michael@0 | 223 | version_info.file_version = 0x50001:0xa280884 |
michael@0 | 224 | version_info.product_version = 0x50001:0xa280884 |
michael@0 | 225 | version_info.file_flags_mask = 0x3f |
michael@0 | 226 | version_info.file_flags = 0x0 |
michael@0 | 227 | version_info.file_os = 0x40004 |
michael@0 | 228 | version_info.file_type = 0x2 |
michael@0 | 229 | version_info.file_subtype = 0x0 |
michael@0 | 230 | version_info.file_date = 0x0:0x0 |
michael@0 | 231 | cv_record.data_size = 34 |
michael@0 | 232 | cv_record.rva = 0x1354 |
michael@0 | 233 | misc_record.data_size = 0 |
michael@0 | 234 | misc_record.rva = 0x0 |
michael@0 | 235 | (code_file) = "C:\WINDOWS\system32\ntdll.dll" |
michael@0 | 236 | (code_identifier) = "411096B4b0000" |
michael@0 | 237 | (cv_record).cv_signature = 0x53445352 |
michael@0 | 238 | (cv_record).signature = 36515fb5-d043-45e4-91f6-72fa2e2878c0 |
michael@0 | 239 | (cv_record).age = 2 |
michael@0 | 240 | (cv_record).pdb_file_name = "ntdll.pdb" |
michael@0 | 241 | (misc_record) = (null) |
michael@0 | 242 | (debug_file) = "ntdll.pdb" |
michael@0 | 243 | (debug_identifier) = "36515FB5D04345E491F672FA2E2878C02" |
michael@0 | 244 | (version) = "5.1.2600.2180" |
michael@0 | 245 | |
michael@0 | 246 | module[2] |
michael@0 | 247 | MDRawModule |
michael@0 | 248 | base_of_image = 0x7c800000 |
michael@0 | 249 | size_of_image = 0xf4000 |
michael@0 | 250 | checksum = 0xf724d |
michael@0 | 251 | time_date_stamp = 0x44ab9a84 |
michael@0 | 252 | module_name_rva = 0x7ee |
michael@0 | 253 | version_info.signature = 0xfeef04bd |
michael@0 | 254 | version_info.struct_version = 0x10000 |
michael@0 | 255 | version_info.file_version = 0x50001:0xa280b81 |
michael@0 | 256 | version_info.product_version = 0x50001:0xa280b81 |
michael@0 | 257 | version_info.file_flags_mask = 0x3f |
michael@0 | 258 | version_info.file_flags = 0x0 |
michael@0 | 259 | version_info.file_os = 0x40004 |
michael@0 | 260 | version_info.file_type = 0x2 |
michael@0 | 261 | version_info.file_subtype = 0x0 |
michael@0 | 262 | version_info.file_date = 0x0:0x0 |
michael@0 | 263 | cv_record.data_size = 37 |
michael@0 | 264 | cv_record.rva = 0x1376 |
michael@0 | 265 | misc_record.data_size = 0 |
michael@0 | 266 | misc_record.rva = 0x0 |
michael@0 | 267 | (code_file) = "C:\WINDOWS\system32\kernel32.dll" |
michael@0 | 268 | (code_identifier) = "44AB9A84f4000" |
michael@0 | 269 | (cv_record).cv_signature = 0x53445352 |
michael@0 | 270 | (cv_record).signature = bce8785c-57b4-4245-a669-896b6a19b954 |
michael@0 | 271 | (cv_record).age = 2 |
michael@0 | 272 | (cv_record).pdb_file_name = "kernel32.pdb" |
michael@0 | 273 | (misc_record) = (null) |
michael@0 | 274 | (debug_file) = "kernel32.pdb" |
michael@0 | 275 | (debug_identifier) = "BCE8785C57B44245A669896B6A19B9542" |
michael@0 | 276 | (version) = "5.1.2600.2945" |
michael@0 | 277 | |
michael@0 | 278 | module[3] |
michael@0 | 279 | MDRawModule |
michael@0 | 280 | base_of_image = 0x774e0000 |
michael@0 | 281 | size_of_image = 0x13d000 |
michael@0 | 282 | checksum = 0x13dc6b |
michael@0 | 283 | time_date_stamp = 0x42e5be93 |
michael@0 | 284 | module_name_rva = 0x834 |
michael@0 | 285 | version_info.signature = 0xfeef04bd |
michael@0 | 286 | version_info.struct_version = 0x10000 |
michael@0 | 287 | version_info.file_version = 0x50001:0xa280aa6 |
michael@0 | 288 | version_info.product_version = 0x50001:0xa280aa6 |
michael@0 | 289 | version_info.file_flags_mask = 0x3f |
michael@0 | 290 | version_info.file_flags = 0x0 |
michael@0 | 291 | version_info.file_os = 0x40004 |
michael@0 | 292 | version_info.file_type = 0x2 |
michael@0 | 293 | version_info.file_subtype = 0x0 |
michael@0 | 294 | version_info.file_date = 0x0:0x0 |
michael@0 | 295 | cv_record.data_size = 34 |
michael@0 | 296 | cv_record.rva = 0x139b |
michael@0 | 297 | misc_record.data_size = 0 |
michael@0 | 298 | misc_record.rva = 0x0 |
michael@0 | 299 | (code_file) = "C:\WINDOWS\system32\ole32.dll" |
michael@0 | 300 | (code_identifier) = "42E5BE9313d000" |
michael@0 | 301 | (cv_record).cv_signature = 0x53445352 |
michael@0 | 302 | (cv_record).signature = 683b65b2-46f4-4187-96d2-ee6d4c55eb11 |
michael@0 | 303 | (cv_record).age = 2 |
michael@0 | 304 | (cv_record).pdb_file_name = "ole32.pdb" |
michael@0 | 305 | (misc_record) = (null) |
michael@0 | 306 | (debug_file) = "ole32.pdb" |
michael@0 | 307 | (debug_identifier) = "683B65B246F4418796D2EE6D4C55EB112" |
michael@0 | 308 | (version) = "5.1.2600.2726" |
michael@0 | 309 | |
michael@0 | 310 | module[4] |
michael@0 | 311 | MDRawModule |
michael@0 | 312 | base_of_image = 0x77dd0000 |
michael@0 | 313 | size_of_image = 0x9b000 |
michael@0 | 314 | checksum = 0xa0de4 |
michael@0 | 315 | time_date_stamp = 0x411096a7 |
michael@0 | 316 | module_name_rva = 0x874 |
michael@0 | 317 | version_info.signature = 0xfeef04bd |
michael@0 | 318 | version_info.struct_version = 0x10000 |
michael@0 | 319 | version_info.file_version = 0x50001:0xa280884 |
michael@0 | 320 | version_info.product_version = 0x50001:0xa280884 |
michael@0 | 321 | version_info.file_flags_mask = 0x3f |
michael@0 | 322 | version_info.file_flags = 0x0 |
michael@0 | 323 | version_info.file_os = 0x40004 |
michael@0 | 324 | version_info.file_type = 0x2 |
michael@0 | 325 | version_info.file_subtype = 0x0 |
michael@0 | 326 | version_info.file_date = 0x0:0x0 |
michael@0 | 327 | cv_record.data_size = 37 |
michael@0 | 328 | cv_record.rva = 0x13bd |
michael@0 | 329 | misc_record.data_size = 0 |
michael@0 | 330 | misc_record.rva = 0x0 |
michael@0 | 331 | (code_file) = "C:\WINDOWS\system32\advapi32.dll" |
michael@0 | 332 | (code_identifier) = "411096A79b000" |
michael@0 | 333 | (cv_record).cv_signature = 0x53445352 |
michael@0 | 334 | (cv_record).signature = 455d6c5f-184d-45bb-b5c5-f30f82975114 |
michael@0 | 335 | (cv_record).age = 2 |
michael@0 | 336 | (cv_record).pdb_file_name = "advapi32.pdb" |
michael@0 | 337 | (misc_record) = (null) |
michael@0 | 338 | (debug_file) = "advapi32.pdb" |
michael@0 | 339 | (debug_identifier) = "455D6C5F184D45BBB5C5F30F829751142" |
michael@0 | 340 | (version) = "5.1.2600.2180" |
michael@0 | 341 | |
michael@0 | 342 | module[5] |
michael@0 | 343 | MDRawModule |
michael@0 | 344 | base_of_image = 0x77e70000 |
michael@0 | 345 | size_of_image = 0x91000 |
michael@0 | 346 | checksum = 0x9c482 |
michael@0 | 347 | time_date_stamp = 0x411096ae |
michael@0 | 348 | module_name_rva = 0x8ba |
michael@0 | 349 | version_info.signature = 0xfeef04bd |
michael@0 | 350 | version_info.struct_version = 0x10000 |
michael@0 | 351 | version_info.file_version = 0x50001:0xa280884 |
michael@0 | 352 | version_info.product_version = 0x50001:0xa280884 |
michael@0 | 353 | version_info.file_flags_mask = 0x3f |
michael@0 | 354 | version_info.file_flags = 0x0 |
michael@0 | 355 | version_info.file_os = 0x40004 |
michael@0 | 356 | version_info.file_type = 0x2 |
michael@0 | 357 | version_info.file_subtype = 0x0 |
michael@0 | 358 | version_info.file_date = 0x0:0x0 |
michael@0 | 359 | cv_record.data_size = 35 |
michael@0 | 360 | cv_record.rva = 0x13e2 |
michael@0 | 361 | misc_record.data_size = 0 |
michael@0 | 362 | misc_record.rva = 0x0 |
michael@0 | 363 | (code_file) = "C:\WINDOWS\system32\rpcrt4.dll" |
michael@0 | 364 | (code_identifier) = "411096AE91000" |
michael@0 | 365 | (cv_record).cv_signature = 0x53445352 |
michael@0 | 366 | (cv_record).signature = bea45a72-1da1-41da-a3ba-86b3a2031153 |
michael@0 | 367 | (cv_record).age = 2 |
michael@0 | 368 | (cv_record).pdb_file_name = "rpcrt4.pdb" |
michael@0 | 369 | (misc_record) = (null) |
michael@0 | 370 | (debug_file) = "rpcrt4.pdb" |
michael@0 | 371 | (debug_identifier) = "BEA45A721DA141DAA3BA86B3A20311532" |
michael@0 | 372 | (version) = "5.1.2600.2180" |
michael@0 | 373 | |
michael@0 | 374 | module[6] |
michael@0 | 375 | MDRawModule |
michael@0 | 376 | base_of_image = 0x77f10000 |
michael@0 | 377 | size_of_image = 0x47000 |
michael@0 | 378 | checksum = 0x4d0d0 |
michael@0 | 379 | time_date_stamp = 0x43b34feb |
michael@0 | 380 | module_name_rva = 0x8fc |
michael@0 | 381 | version_info.signature = 0xfeef04bd |
michael@0 | 382 | version_info.struct_version = 0x10000 |
michael@0 | 383 | version_info.file_version = 0x50001:0xa280b02 |
michael@0 | 384 | version_info.product_version = 0x50001:0xa280b02 |
michael@0 | 385 | version_info.file_flags_mask = 0x3f |
michael@0 | 386 | version_info.file_flags = 0x0 |
michael@0 | 387 | version_info.file_os = 0x40004 |
michael@0 | 388 | version_info.file_type = 0x2 |
michael@0 | 389 | version_info.file_subtype = 0x0 |
michael@0 | 390 | version_info.file_date = 0x0:0x0 |
michael@0 | 391 | cv_record.data_size = 34 |
michael@0 | 392 | cv_record.rva = 0x1405 |
michael@0 | 393 | misc_record.data_size = 0 |
michael@0 | 394 | misc_record.rva = 0x0 |
michael@0 | 395 | (code_file) = "C:\WINDOWS\system32\gdi32.dll" |
michael@0 | 396 | (code_identifier) = "43B34FEB47000" |
michael@0 | 397 | (cv_record).cv_signature = 0x53445352 |
michael@0 | 398 | (cv_record).signature = c0ea66be-00a6-4bd7-aef7-9e443a91869c |
michael@0 | 399 | (cv_record).age = 2 |
michael@0 | 400 | (cv_record).pdb_file_name = "gdi32.pdb" |
michael@0 | 401 | (misc_record) = (null) |
michael@0 | 402 | (debug_file) = "gdi32.pdb" |
michael@0 | 403 | (debug_identifier) = "C0EA66BE00A64BD7AEF79E443A91869C2" |
michael@0 | 404 | (version) = "5.1.2600.2818" |
michael@0 | 405 | |
michael@0 | 406 | module[7] |
michael@0 | 407 | MDRawModule |
michael@0 | 408 | base_of_image = 0x77d40000 |
michael@0 | 409 | size_of_image = 0x90000 |
michael@0 | 410 | checksum = 0x9505c |
michael@0 | 411 | time_date_stamp = 0x42260159 |
michael@0 | 412 | module_name_rva = 0x93c |
michael@0 | 413 | version_info.signature = 0xfeef04bd |
michael@0 | 414 | version_info.struct_version = 0x10000 |
michael@0 | 415 | version_info.file_version = 0x50001:0xa280a3e |
michael@0 | 416 | version_info.product_version = 0x50001:0xa280a3e |
michael@0 | 417 | version_info.file_flags_mask = 0x3f |
michael@0 | 418 | version_info.file_flags = 0x0 |
michael@0 | 419 | version_info.file_os = 0x40004 |
michael@0 | 420 | version_info.file_type = 0x2 |
michael@0 | 421 | version_info.file_subtype = 0x0 |
michael@0 | 422 | version_info.file_date = 0x0:0x0 |
michael@0 | 423 | cv_record.data_size = 35 |
michael@0 | 424 | cv_record.rva = 0x1427 |
michael@0 | 425 | misc_record.data_size = 0 |
michael@0 | 426 | misc_record.rva = 0x0 |
michael@0 | 427 | (code_file) = "C:\WINDOWS\system32\user32.dll" |
michael@0 | 428 | (code_identifier) = "4226015990000" |
michael@0 | 429 | (cv_record).cv_signature = 0x53445352 |
michael@0 | 430 | (cv_record).signature = ee2b714d-83a3-4c9d-8802-7621272f8326 |
michael@0 | 431 | (cv_record).age = 2 |
michael@0 | 432 | (cv_record).pdb_file_name = "user32.pdb" |
michael@0 | 433 | (misc_record) = (null) |
michael@0 | 434 | (debug_file) = "user32.pdb" |
michael@0 | 435 | (debug_identifier) = "EE2B714D83A34C9D88027621272F83262" |
michael@0 | 436 | (version) = "5.1.2600.2622" |
michael@0 | 437 | |
michael@0 | 438 | module[8] |
michael@0 | 439 | MDRawModule |
michael@0 | 440 | base_of_image = 0x77c10000 |
michael@0 | 441 | size_of_image = 0x58000 |
michael@0 | 442 | checksum = 0x57cd3 |
michael@0 | 443 | time_date_stamp = 0x41109752 |
michael@0 | 444 | module_name_rva = 0x97e |
michael@0 | 445 | version_info.signature = 0xfeef04bd |
michael@0 | 446 | version_info.struct_version = 0x10000 |
michael@0 | 447 | version_info.file_version = 0x70000:0xa280884 |
michael@0 | 448 | version_info.product_version = 0x60001:0x21be0884 |
michael@0 | 449 | version_info.file_flags_mask = 0x3f |
michael@0 | 450 | version_info.file_flags = 0x0 |
michael@0 | 451 | version_info.file_os = 0x40004 |
michael@0 | 452 | version_info.file_type = 0x1 |
michael@0 | 453 | version_info.file_subtype = 0x0 |
michael@0 | 454 | version_info.file_date = 0x0:0x0 |
michael@0 | 455 | cv_record.data_size = 35 |
michael@0 | 456 | cv_record.rva = 0x144a |
michael@0 | 457 | misc_record.data_size = 0 |
michael@0 | 458 | misc_record.rva = 0x0 |
michael@0 | 459 | (code_file) = "C:\WINDOWS\system32\msvcrt.dll" |
michael@0 | 460 | (code_identifier) = "4110975258000" |
michael@0 | 461 | (cv_record).cv_signature = 0x53445352 |
michael@0 | 462 | (cv_record).signature = a678f3c3-0ded-426b-8390-32b996987e38 |
michael@0 | 463 | (cv_record).age = 1 |
michael@0 | 464 | (cv_record).pdb_file_name = "msvcrt.pdb" |
michael@0 | 465 | (misc_record) = (null) |
michael@0 | 466 | (debug_file) = "msvcrt.pdb" |
michael@0 | 467 | (debug_identifier) = "A678F3C30DED426B839032B996987E381" |
michael@0 | 468 | (version) = "7.0.2600.2180" |
michael@0 | 469 | |
michael@0 | 470 | module[9] |
michael@0 | 471 | MDRawModule |
michael@0 | 472 | base_of_image = 0x76390000 |
michael@0 | 473 | size_of_image = 0x1d000 |
michael@0 | 474 | checksum = 0x2a024 |
michael@0 | 475 | time_date_stamp = 0x411096ae |
michael@0 | 476 | module_name_rva = 0x9c0 |
michael@0 | 477 | version_info.signature = 0xfeef04bd |
michael@0 | 478 | version_info.struct_version = 0x10000 |
michael@0 | 479 | version_info.file_version = 0x50001:0xa280884 |
michael@0 | 480 | version_info.product_version = 0x50001:0xa280884 |
michael@0 | 481 | version_info.file_flags_mask = 0x3f |
michael@0 | 482 | version_info.file_flags = 0x0 |
michael@0 | 483 | version_info.file_os = 0x40004 |
michael@0 | 484 | version_info.file_type = 0x2 |
michael@0 | 485 | version_info.file_subtype = 0x0 |
michael@0 | 486 | version_info.file_date = 0x0:0x0 |
michael@0 | 487 | cv_record.data_size = 34 |
michael@0 | 488 | cv_record.rva = 0x146d |
michael@0 | 489 | misc_record.data_size = 0 |
michael@0 | 490 | misc_record.rva = 0x0 |
michael@0 | 491 | (code_file) = "C:\WINDOWS\system32\imm32.dll" |
michael@0 | 492 | (code_identifier) = "411096AE1d000" |
michael@0 | 493 | (cv_record).cv_signature = 0x53445352 |
michael@0 | 494 | (cv_record).signature = 2c17a49c-251b-4c8e-b9e2-ad13d7d9ea16 |
michael@0 | 495 | (cv_record).age = 2 |
michael@0 | 496 | (cv_record).pdb_file_name = "imm32.pdb" |
michael@0 | 497 | (misc_record) = (null) |
michael@0 | 498 | (debug_file) = "imm32.pdb" |
michael@0 | 499 | (debug_identifier) = "2C17A49C251B4C8EB9E2AD13D7D9EA162" |
michael@0 | 500 | (version) = "5.1.2600.2180" |
michael@0 | 501 | |
michael@0 | 502 | module[10] |
michael@0 | 503 | MDRawModule |
michael@0 | 504 | base_of_image = 0x59a60000 |
michael@0 | 505 | size_of_image = 0xa1000 |
michael@0 | 506 | checksum = 0xa8824 |
michael@0 | 507 | time_date_stamp = 0x4110969a |
michael@0 | 508 | module_name_rva = 0xa00 |
michael@0 | 509 | version_info.signature = 0xfeef04bd |
michael@0 | 510 | version_info.struct_version = 0x10000 |
michael@0 | 511 | version_info.file_version = 0x50001:0xa280884 |
michael@0 | 512 | version_info.product_version = 0x50001:0xa280884 |
michael@0 | 513 | version_info.file_flags_mask = 0x3f |
michael@0 | 514 | version_info.file_flags = 0x0 |
michael@0 | 515 | version_info.file_os = 0x40004 |
michael@0 | 516 | version_info.file_type = 0x2 |
michael@0 | 517 | version_info.file_subtype = 0x0 |
michael@0 | 518 | version_info.file_date = 0x0:0x0 |
michael@0 | 519 | cv_record.data_size = 36 |
michael@0 | 520 | cv_record.rva = 0x148f |
michael@0 | 521 | misc_record.data_size = 0 |
michael@0 | 522 | misc_record.rva = 0x0 |
michael@0 | 523 | (code_file) = "C:\WINDOWS\system32\dbghelp.dll" |
michael@0 | 524 | (code_identifier) = "4110969Aa1000" |
michael@0 | 525 | (cv_record).cv_signature = 0x53445352 |
michael@0 | 526 | (cv_record).signature = 39559573-e21b-46f2-8e28-6923be9e6a76 |
michael@0 | 527 | (cv_record).age = 1 |
michael@0 | 528 | (cv_record).pdb_file_name = "dbghelp.pdb" |
michael@0 | 529 | (misc_record) = (null) |
michael@0 | 530 | (debug_file) = "dbghelp.pdb" |
michael@0 | 531 | (debug_identifier) = "39559573E21B46F28E286923BE9E6A761" |
michael@0 | 532 | (version) = "5.1.2600.2180" |
michael@0 | 533 | |
michael@0 | 534 | module[11] |
michael@0 | 535 | MDRawModule |
michael@0 | 536 | base_of_image = 0x77c00000 |
michael@0 | 537 | size_of_image = 0x8000 |
michael@0 | 538 | checksum = 0x11d78 |
michael@0 | 539 | time_date_stamp = 0x411096b7 |
michael@0 | 540 | module_name_rva = 0xa44 |
michael@0 | 541 | version_info.signature = 0xfeef04bd |
michael@0 | 542 | version_info.struct_version = 0x10000 |
michael@0 | 543 | version_info.file_version = 0x50001:0xa280884 |
michael@0 | 544 | version_info.product_version = 0x50001:0xa280884 |
michael@0 | 545 | version_info.file_flags_mask = 0x3f |
michael@0 | 546 | version_info.file_flags = 0x0 |
michael@0 | 547 | version_info.file_os = 0x40004 |
michael@0 | 548 | version_info.file_type = 0x2 |
michael@0 | 549 | version_info.file_subtype = 0x0 |
michael@0 | 550 | version_info.file_date = 0x0:0x0 |
michael@0 | 551 | cv_record.data_size = 36 |
michael@0 | 552 | cv_record.rva = 0x14b3 |
michael@0 | 553 | misc_record.data_size = 0 |
michael@0 | 554 | misc_record.rva = 0x0 |
michael@0 | 555 | (code_file) = "C:\WINDOWS\system32\version.dll" |
michael@0 | 556 | (code_identifier) = "411096B78000" |
michael@0 | 557 | (cv_record).cv_signature = 0x53445352 |
michael@0 | 558 | (cv_record).signature = 180a90c4-0384-463e-82dd-c45b2c8ab76e |
michael@0 | 559 | (cv_record).age = 2 |
michael@0 | 560 | (cv_record).pdb_file_name = "version.pdb" |
michael@0 | 561 | (misc_record) = (null) |
michael@0 | 562 | (debug_file) = "version.pdb" |
michael@0 | 563 | (debug_identifier) = "180A90C40384463E82DDC45B2C8AB76E2" |
michael@0 | 564 | (version) = "5.1.2600.2180" |
michael@0 | 565 | |
michael@0 | 566 | module[12] |
michael@0 | 567 | MDRawModule |
michael@0 | 568 | base_of_image = 0x76bf0000 |
michael@0 | 569 | size_of_image = 0xb000 |
michael@0 | 570 | checksum = 0xa29b |
michael@0 | 571 | time_date_stamp = 0x411096ca |
michael@0 | 572 | module_name_rva = 0xa88 |
michael@0 | 573 | version_info.signature = 0xfeef04bd |
michael@0 | 574 | version_info.struct_version = 0x10000 |
michael@0 | 575 | version_info.file_version = 0x50001:0xa280884 |
michael@0 | 576 | version_info.product_version = 0x50001:0xa280884 |
michael@0 | 577 | version_info.file_flags_mask = 0x3f |
michael@0 | 578 | version_info.file_flags = 0x0 |
michael@0 | 579 | version_info.file_os = 0x40004 |
michael@0 | 580 | version_info.file_type = 0x2 |
michael@0 | 581 | version_info.file_subtype = 0x0 |
michael@0 | 582 | version_info.file_date = 0x0:0x0 |
michael@0 | 583 | cv_record.data_size = 34 |
michael@0 | 584 | cv_record.rva = 0x14d7 |
michael@0 | 585 | misc_record.data_size = 0 |
michael@0 | 586 | misc_record.rva = 0x0 |
michael@0 | 587 | (code_file) = "C:\WINDOWS\system32\psapi.dll" |
michael@0 | 588 | (code_identifier) = "411096CAb000" |
michael@0 | 589 | (cv_record).cv_signature = 0x53445352 |
michael@0 | 590 | (cv_record).signature = a5c3a1f9-689f-43d8-ad22-8a0929388970 |
michael@0 | 591 | (cv_record).age = 2 |
michael@0 | 592 | (cv_record).pdb_file_name = "psapi.pdb" |
michael@0 | 593 | (misc_record) = (null) |
michael@0 | 594 | (debug_file) = "psapi.pdb" |
michael@0 | 595 | (debug_identifier) = "A5C3A1F9689F43D8AD228A09293889702" |
michael@0 | 596 | (version) = "5.1.2600.2180" |
michael@0 | 597 | |
michael@0 | 598 | MinidumpMemoryList |
michael@0 | 599 | region_count = 3 |
michael@0 | 600 | |
michael@0 | 601 | region[0] |
michael@0 | 602 | MDMemoryDescriptor |
michael@0 | 603 | start_of_memory_range = 0x7c90eb14 |
michael@0 | 604 | memory.data_size = 0x100 |
michael@0 | 605 | memory.rva = 0x1539 |
michael@0 | 606 | Memory |
michael@0 | 607 | 0xff83c4ec890424c744240401000000895c2408c74424100000000054e877000000c208009090909090558bec83ec508944240c64a1180000008b80a4010000890424c744240400000000c744240800000000c74424100000000054e8380000008b04248be55dc3908da424000000008d490090909090908bd40f349090909090c38da424000000008d64240090909090908d542408cd2ec3558bec9c81ecd00200008985dcfdffff898dd8fdffff8b45088b4d0489480c8d852cfdffff8988b80000008998a40000008990a800000089b0a000000089b89c0000008d4d0c8988c40000008b4d008988b40000008b4dfc8988c00000008c88bc0000008c989800 |
michael@0 | 608 | |
michael@0 | 609 | region[1] |
michael@0 | 610 | MDMemoryDescriptor |
michael@0 | 611 | start_of_memory_range = 0x12f31c |
michael@0 | 612 | memory.data_size = 0xce4 |
michael@0 | 613 | memory.rva = 0x1639 |
michael@0 | 614 | Memory |
michael@0 | 615 | 0x00000000c0e9907ccb25807cb8070000000000000000000034ff1200b0fe12008037887c140000000100000000000000000000001000000027e0907c2e39917c0050fd7f00f0fd7f000000000400000034f312006947c788d4f31200a89a837cf825807c0000000098f312003225807cb8070000ffffffff00000000e4f31200ff1d4000b8070000ffffffffa8fa12008037887c0e1c4000a8fa120000000000ff792a0f64f91200b01b400000004000b0fe12000040020070fa1200084042000000000080fa120080fa12004e30867ca8fa12000000000000000000000000000018000002100000e3ef907c0000000079d900000000000048f41200000014003207917c0500000078071400000014000000000020f412003207917ca05f140018ee907cfa00000074f61200000000009615917ceb06917cf00298000100000000000000384f14009615917ceb06917c7801140008000000404f14000000a659985f1400080000000000000018ee907c90fea700400698003815917c184f1400eb06917c00000000800000000000a65988f69f0090f51200a569917cf8f41200d95c878880f5120043ef907c480485000500000090f5120088fea700a8212400000000000000000080f512002469917cf8fbfd7fa821240008000000f500000000000000384d850078019800a8fa120004000000a05f140096d4917c00000000b0d4917c0000000008069800184f140000000000104f140000000000184f140000004000000000010040020063003a005c0074006500730074005f006100700070002e006500780065000000000000002f00000028000000184f1400780185007801140028000000000000000000140084f3120010000000d8f5120018ee907cf006917cffffffffeb06917ce619917c88e6a7003003000001030000ff1b917c0000980080e6a70080069800400698000000980080e6a70000000000000000000000000080e6a7000818000088e6a700d759927c78019800081800000210000000009800f8f31200280a0000dcf6120018ee907cf006917cffffffffeb06917c0859927c00009800080000005859927c00000000000001000000a659000000005a6202000010000068fe030001000000dffe03000000010000000100fffffe7f0100000001c0c27700008500000000002dc0c27700000000684aaf590000a659241a917c80c0977c0000000000000000cd5c927c0050fd7f0000a65900000100080000004550fd7f0000000000000000000000000050fd7fcd5c927c05000000d4f61200f45c927c80e4977c05000000010000000050fd7f18f712007009917cc0e4977c172e817cff2d817c000000000000a6590000a6590210000000f0fd7f05000000e8f612000806980064f81200a89a837c002e817cffffffffff2d817cc8242400dd8ea75901000000000000004cf712003608a9590000a65901000000000000000100000060f71200e407a9596cf7120000004000000000010040020063003a005c0074006500730074005f006100700070002e0065007800650000006d05917c905f140000000000440d020000000000604f14000c0000007801140000000000a04e1400d84d8700400687004509917c0800000000000000000000004000000078011400a8038700404f14000510907c000000000000000078011400980387000800000008000000c0e4977cd04d8700f835887c7801140010000000a0e7ae591600000030fd1200d39b917c44000000620000000000a65950e9ae59d8eaae59a80387000100000014040000000000000100000002000000f800a659c003870001000000780114009508917c0000a659091b917c020000000900000040000000a2fd12009cfd1200404f1400a2fd1200d04d8700640187000000000000000000d04d870010000000d84d8700384f1400a803870010000000c00300000000870074fb1200404f14006cfe120018ee907cf006917cffffffffeb06917ca09d400000008700000000000400000000000000ffffff3fc04d8700ccfd12009c4d400004000000fa19917cb84d870064018700c04d8700063440000400000018000000c04d870079d90000c0038700fa31400000000000c04d8700c04d87000000000001000000b0fe120082294000c04d87000000000000000000c04d870048fe12008cfe120000000000e224400040fe12008cfe1200c04d8700d84d8700b0fe12008600817c54fa1200d8f9120000000000160018005479420079d90000000000000757917c00000200a4f91200a4f91200a4f91200020000000200000000000000c4f912000000000079d9000014fb12004cfa120014fb1200005a917c00fa1200a0fb120001000000655a917ca405817c74c1977ce705817c00000000f4fd120098fb120000000000a0fb12000000000090fb12000000800070fa120000000000000000000000000016001800547942000000000001000000000000000000000000000000000000003308917ca89a837c0000807c0000807ce800807c2cfa12001fe2907c11fa877cffffffffe06f817c000000006cfa12001c0000000f000000e06f817c8fc60000f0f312000060817cc8fa1200a89a837c7039867cfffffffff0ff1200da36847ca8fa1200099b837cb0fa120000000000b0fa12000000000000000000000000009cfb1200b8fb1200d4fa1200bf37907c9cfb1200e0ff1200b8fb120070fb1200b0ff1200d837907ce0ff120084fb12008b37907c9cfb1200e0ff1200b8fb120070fb1200a89a837c010000009cfb1200e0ff12006078937c9cfb1200e0ff1200b8fb120070fb1200a89a837c280a00009cfb12000200000018ee907c9032917cffffffff8832917c3364917c68fb1200000087003207917c02000000dc31917c1232917c8132917c8832917c1e000000c01e2400080200003807917c54fb12003207917cc4fb120018ee907c9032917c0000130000d01200beb4800088fe1200faea907c00000000b8fb12009cfb1200b8fb1200050000c000000000000000009e4240000200000001000000450000003f0001000000000000000000000000000000000000000000000000007f02ffff0000ffffffffffff0000000000002200000000000000ffff0000000018b72200000118b7220000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000003b0000002300000023000000280a000002000000c1ab807c58bc420094fe12004500000088fe12009e4240001b0000004602010084fe1200230000007f0200000000220000000000000000000000000000000000801f0000ffff00000000000018b72200000100000000000018b72200000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000004509917c4e09917c38b622002400020024b42200020000009041917c0070fd7f0510907cccb22200000000009cb3220018ee907c7009917cc0e4977c6f3e917c623e917c08020000dcb62200b4b622001e000000000000000000000000000000000000002eb42200000000000f000000020000001e00200000fcfd7f2f63796764726976652f632f444f43554d457e312f4d4d454e544f7e312f4c4f43414c537e312f54656d7000000000000000000130b422000000004300000000000000001efcfd7f4509917c4e09917c5ad9000008b32200b4b622004500000070ff120000424000b8278700dc31917c00000000004c870000000020040000000000000007000000000000004042400000000000000000002e000000000000000cff12007b434100010000000700000084434100004d87002e39917cffffffff24000000240000002700000000000000584d870004000000b1944000244c87002a0000002f000000c0fe1200004d8700584d87000000a659b0b9a859015d400015aa400000000000b4070000784e14000000000001000000f40b00000000000000000000bc070000b8070000f40b0000a8fa120000000000009c4000599c400094b240004f752a0fc0ff1200ec534000010000003039870050398700ff752a0f00002400a02024000050fd7f050000c00100000005000000000000000000240084ff1200acfa1200e0ff1200d06f4000a70b7a0f00000000f0ff1200d76f817c00002400a02024000050fd7f050000c0c8ff1200a8fa1200ffffffffa89a837ce06f817c0000000000000000000000004354400000000000 |
michael@0 | 616 | |
michael@0 | 617 | region[2] |
michael@0 | 618 | MDMemoryDescriptor |
michael@0 | 619 | start_of_memory_range = 0x97f6e8 |
michael@0 | 620 | memory.data_size = 0x918 |
michael@0 | 621 | memory.rva = 0x231d |
michael@0 | 622 | Memory |
michael@0 | 623 | 0x8000108020fa97009fd7907c0000000048f7970005000f0040061400000000004cf7970037b9807c00000000000000003103917c780114000000000061dc907cf1b8807c00000000ffffffff70f79700000000000000000054f797003082140001000000000000000200000000000000000000007cf7970020b9807c0e00000004000000006000000000a80078011400000000000882140092d5907c8b9b807c9c070000d0f89700780114009c07000038821400807f140020dea85910fa9700780114009807000088fb9700e07f14009c0700000000000078011400000000000882140000000000000000000000000078011400ba0300000000000000000000000000000000000000000000000000007801140000000000000000000000000000000000c0030000000000000000000000000000088214005c0057000600000078011400000000005c00730079007300740065006d0033000082140068011400000000000000000000821400d47f1400807f140070f8970061eea859e000a8000000a8001c4e000084f89700bdeea859e000a8000000a8001c4e0000a4f897005fefa8590000a8000000000006000000c4f89700e000a80060fe9700c8f897005abfa8590000a80000000000060000001c000000d47f1400807f1400380000006ce9907c88b9807cffffffff0000a80000000000807f140030fa97007fc3a859a0c4a859b0fb970060fe9700684f1400504500004c010400ca9610410000000000000000e0000e210b01070a00400000003a000000000000f1100000001000000000bf760000000000100000000200000500010005000100040000000000000000b00000000400009ba2000000001400285214000000000034fa97007801140034fa9700910e917c080614006d05917cc84d85005c4e8500684f140000000000b04800002852140078011400e00300003052140000000000000000000000000078011400c403000030821400380000000000000000000000000000000000000000000000000000003882140048050000780200003800000000100000ec000000b8470000400000000000000000000000000000000000140000000000807f140000000000000000000000000000000101a900000060fe9700dcff9700dcff97000050fd7f78fa970054fa9700ad9d917c8cfa9700c2066f7f0e000000000000001c01000078fa9700c84d850068fa970085ae807c78fc970024fc970083dba85978fc97008cfa9700800000008edba85914010000050000000100000096020000b8fc97003815917c9615917ceb06917c60fe970060fe9700c4fd9700d8fa9700000014003207917c21000000b80c14000000140030521400b0fa9700fffffffff4fc970018ee907c3807917cffffffff3207917cab06917ceb06917ccc4f140060fe9700684f1400e0004000e4fa9700a863917c74fb970018ee907c3808917cffffffff3308917c5b2c817c872c817c00000000f4fb9700000000000000000054fd970018ee907c4006140064fd97003815917c00e0fd7feb06917c684f140038821400780114000050fd7facfb970000000000000004000000000090fe97000000000018fb970050531400508b1400a89a837cffe9907cf60d817ca807000000000000ffe9907cf60d817c08000000000000000000000000000000585314003cfc97003882140000000000160e817cc4fd970060fe970058531400208f1400588b1400460f917c50531400208f1400780114003082140000000000b8fc970078011400b8fc9700910e917c080614006d05917c3882140060fe97000000000000000000960200003082140078011400ffe9907c38821400a807000000000000780114005853140058fc9700505314001000000000000000160e817c784e8500c4fd9700388214000000000024010000f00c00001000000044fc970000000000c7e2907ce721807cffffffffe8f69700388214001809000098fc9700acfc9700d2e2a859ffffffffe8f697003882140018090000c4fc97003882140060fe9700c4fd9700ccfc97004ee3a859ffffffffe8f69700000000003882140018090000e0fc9700f4fc970093b2a859ffffffffe8f69700000000003882140018090000c4fd970060fe9700a85a140078fd9700a5b3a85960fe9700c4fd9700684f1400e8f697000000000018090000000000000200000080fd9700c4fd970060fe970000000000f40b000000000000000000000000000000f0fd7f000000001cf3120000000000e40c000039160000cc020000940d00000000000000000000000000000000000002000000ac4f14006010000098fd97005eb7a8593916000000000000684f1400784e85000000000084ff9700d4fe97007bb9a85960fe9700c4fd9700684f14003849140084ff9700010000000000000008ff9700f40b0000090000000000000020000000200000006c0000008c000000380000001e000000c4000000dc000000a80000008401000064000000b801000030000000e801000080050000e8010000680700000000000068070000680700000000000005150000340000002915000039150000fc1600001d23000068070000600300008a070000c80a0000310a00002c130000f91400000c000000352c000000000000ffffffff5c0f0000c84d8500784e8500884e85000000000000000000000000004c010000fc39a6590000000002000000050000000100000000008500280a000001000001cc0200009c0000000b00000050000000040000000010000000000000000000000001000000000000000000000000000034ff970078baa859384914005c0f0000c84d850001000000884e8500684f140008ff970064ff970000000000a8070000b0fe1200f40b00009cfb120000000000b8fb12000000000000000000ae20140000000000884e8500784e8500c84d8500a8fa120011204000ffffffff5c0f0000a80700000000000078ff970064ff970000000000adbf807c2025807cecff97000100000084ff970003000000c0110000f40b0000f40b0000a8fa120000000000010067470c0000006cff9700bc070000ffffffff000000006c1a4000f40b000000fa12000000000000004000a09d4000b0fe120083b6807cb0fe120000004000a09d4000b0fe120000e0fd7f00069c86c0ff9700d8863f86ffffffffa89a837c90b6807c000000000000000000000000301a4000b0fe120000000000 |
michael@0 | 624 | |
michael@0 | 625 | MDException |
michael@0 | 626 | thread_id = 0xbf4 |
michael@0 | 627 | exception_record.exception_code = 0xc0000005 |
michael@0 | 628 | exception_record.exception_flags = 0x0 |
michael@0 | 629 | exception_record.exception_record = 0x0 |
michael@0 | 630 | exception_record.exception_address = 0x40429e |
michael@0 | 631 | exception_record.number_parameters = 2 |
michael@0 | 632 | exception_record.exception_information[ 0] = 0x1 |
michael@0 | 633 | exception_record.exception_information[ 1] = 0x45 |
michael@0 | 634 | thread_context.data_size = 716 |
michael@0 | 635 | thread_context.rva = 0xac8 |
michael@0 | 636 | |
michael@0 | 637 | MDRawContextX86 |
michael@0 | 638 | context_flags = 0x1003f |
michael@0 | 639 | dr0 = 0x0 |
michael@0 | 640 | dr1 = 0x0 |
michael@0 | 641 | dr2 = 0x0 |
michael@0 | 642 | dr3 = 0x0 |
michael@0 | 643 | dr6 = 0x0 |
michael@0 | 644 | dr7 = 0x0 |
michael@0 | 645 | float_save.control_word = 0xffff027f |
michael@0 | 646 | float_save.status_word = 0xffff0000 |
michael@0 | 647 | float_save.tag_word = 0xffffffff |
michael@0 | 648 | float_save.error_offset = 0x0 |
michael@0 | 649 | float_save.error_selector = 0x220000 |
michael@0 | 650 | float_save.data_offset = 0x0 |
michael@0 | 651 | float_save.data_selector = 0xffff0000 |
michael@0 | 652 | float_save.register_area[80] = 0x0000000018b72200000118b72200000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 |
michael@0 | 653 | float_save.cr0_npx_state = 0x0 |
michael@0 | 654 | gs = 0x0 |
michael@0 | 655 | fs = 0x3b |
michael@0 | 656 | es = 0x23 |
michael@0 | 657 | ds = 0x23 |
michael@0 | 658 | edi = 0xa28 |
michael@0 | 659 | esi = 0x2 |
michael@0 | 660 | ebx = 0x7c80abc1 |
michael@0 | 661 | edx = 0x42bc58 |
michael@0 | 662 | ecx = 0x12fe94 |
michael@0 | 663 | eax = 0x45 |
michael@0 | 664 | ebp = 0x12fe88 |
michael@0 | 665 | eip = 0x40429e |
michael@0 | 666 | cs = 0x1b |
michael@0 | 667 | eflags = 0x10246 |
michael@0 | 668 | esp = 0x12fe84 |
michael@0 | 669 | ss = 0x23 |
michael@0 | 670 | extended_registers[512] = 0x7f0200000000220000000000000000000000000000000000801f0000ffff00000000000018b72200000100000000000018b72200000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000004509917c4e09917c38b622002400020024b42200020000009041917c0070fd7f0510907cccb22200000000009cb3220018ee907c7009917cc0e4977c6f3e917c623e917c08020000dcb62200b4b622001e000000000000000000000000000000000000002eb42200000000000f000000020000001e00200000fcfd7f2f63796764726976652f632f444f43554d457e312f4d4d454e544f7e312f4c4f43414c537e312f54656d7000000000000000000130b422000000004300000000000000001efcfd7f4509917c4e09917c5ad9000008b32200b4b62200 |
michael@0 | 671 | |
michael@0 | 672 | MDRawSystemInfo |
michael@0 | 673 | processor_architecture = 0 |
michael@0 | 674 | processor_level = 6 |
michael@0 | 675 | processor_revision = 0xd08 |
michael@0 | 676 | number_of_processors = 1 |
michael@0 | 677 | product_type = 1 |
michael@0 | 678 | major_version = 5 |
michael@0 | 679 | minor_version = 1 |
michael@0 | 680 | build_number = 2600 |
michael@0 | 681 | platform_id = 2 |
michael@0 | 682 | csd_version_rva = 0x768 |
michael@0 | 683 | suite_mask = 0x100 |
michael@0 | 684 | cpu.x86_cpu_info.vendor_id[0] = 0x756e6547 |
michael@0 | 685 | cpu.x86_cpu_info.vendor_id[1] = 0x49656e69 |
michael@0 | 686 | cpu.x86_cpu_info.vendor_id[2] = 0x6c65746e |
michael@0 | 687 | cpu.x86_cpu_info.version_information = 0x6d8 |
michael@0 | 688 | cpu.x86_cpu_info.feature_information = 0xafe9fbff |
michael@0 | 689 | cpu.x86_cpu_info.amd_extended_cpu_features = 0xffffffff |
michael@0 | 690 | (csd_version) = "Service Pack 2" |
michael@0 | 691 | (cpu_vendor) = "GenuineIntel" |
michael@0 | 692 | |
michael@0 | 693 | MDRawMiscInfo |
michael@0 | 694 | size_of_info = 24 |
michael@0 | 695 | flags1 = 0x3 |
michael@0 | 696 | process_id = 0xf5c |
michael@0 | 697 | process_create_time = 0x45d35f73 |
michael@0 | 698 | process_user_time = 0x0 |
michael@0 | 699 | process_kernel_time = 0x0 |
michael@0 | 700 | |
michael@0 | 701 | MDRawBreakpadInfo |
michael@0 | 702 | validity = 0x3 |
michael@0 | 703 | dump_thread_id = 0x11c0 |
michael@0 | 704 | requesting_thread_id = 0xbf4 |
michael@0 | 705 |