Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- CPU Stack
- Address Value ASCII Comments
- 04BAFE20 /7739B6E3 9w ; RETURN to USER32.7739B6E3
- 04BAFE24 |00160056 V..
- 04BAFE28 |0000001E ...
- 04BAFE2C |00000000 ....
- 04BAFE30 |00000000 ....
- 04BAFE34 |4BC4CEE9 K
- 04BAFE38 |DCBAABCD ?
- 04BAFE3C |00000000 ....
- 04BAFE40 |04BAFE94
- 04BAFE44 |4BC4CEE9 K
- 04BAFE48 |04BAFEC0
- 04BAFE4C \7739B874 t9w ; RETURN from USER32.7739B6BB to USER32.7739B874
- 04BAFE50 /4BC4CEE9 K
- 04BAFE54 |00160056 V..
- 04BAFE58 |0000001E ...
- 04BAFE5C |00000000 ....
- 04BAFE60 |00000000 ....
- 04BAFE64 |04BAFF58 X
- 04BAFE68 |04BAFF50 P
- 04BAFE6C |005F2C30 0,_.
- 04BAFE70 |00000024 $...
- 04BAFE74 |00000001 ...
- 04BAFE78 |00000000 ....
- 04BAFE7C |00000000 ....
- 04BAFE80 |00000030 0...
- 04BAFE84 |FFFFFFFF
- 04BAFE88 |FFFFFFFF
- 04BAFE8C |7739B82A *9w ; RETURN from ntdll.RtlActivateActivationContextUnsafeFast to USER32.7739B82A
- 04BAFE90 |00000000 ....
- 04BAFE94 |00000000 ....
- 04BAFE98 |7739C819 9w ; USER32.GetMessageW
- 04BAFE9C |00000000 ....
- 04BAFEA0 |00000000 ....
- 04BAFEA4 |00000000 ....
- 04BAFEA8 |04BAFE64 d
- 04BAFEAC |00000000 ....
- 04BAFEB0 |04BAFF18 ; Pointer to next SEH record
- 04BAFEB4 |773AAF18 :w ; SE handler
- 04BAFEB8 |7739B890 9w
- 04BAFEBC |00000000 ....
- 04BAFEC0 |04BAFF28 (
- 04BAFEC4 \7739BA92 9w ; RETURN from USER32.7739B7D2 to USER32.7739BA92
- 04BAFEC8 /00000000 ....
- 04BAFECC |4BC4CEE9 K
- 04BAFED0 |00160056 V..
- 04BAFED4 |0000001E ...
- 04BAFED8 |00000000 ....
- 04BAFEDC |00000000 ....
- 04BAFEE0 |005F2C44 D,_.
- 04BAFEE4 |00000001 ...
- 04BAFEE8 |00000000 ....
- 04BAFEEC |7739C819 9w ; USER32.GetMessageW
- 04BAFEF0 |000B00BE ..
- 04BAFEF4 |016A4899 Hj
- 04BAFEF8 |00000000 ....
- 04BAFEFC |00000000 ....
- 04BAFF00 |161CAE56 V
- 04BAFF04 |00690076 v.i.
- 04BAFF08 |00000000 ....
- 04BAFF0C |00000000 ....
- 04BAFF10 |04BAFEE8
- 04BAFF14 |7739C844 D9w ; RETURN from USER32.7739C805 to USER32.7739C844
- 04BAFF18 |04BAFFDC ; Pointer to next SEH record
- 04BAFF1C |773AAF18 :w ; SE handler
- 04BAFF20 |7739BAB0 9w
- 04BAFF24 |FFFFFFFF
- 04BAFF28 |04BAFF38 8
- 04BAFF2C \7739BAD0 ?9w ; RETURN from USER32.7739B9CA to USER32.7739BAD0
- 04BAFF30 /04BAFF50 P
- 04BAFF34 |00000000 ....
- 04BAFF38 |04BAFF6C l
- 04BAFF3C \7768FFDC hw ; RETURN from USER32.DispatchMessageW to ole32.7768FFDC
- 04BAFF40 /04BAFF50 P ; pMsg = 04BAFF50 -> MSGW {hWnd=00160056, Msg=WM_TIMECHANGE, wParam=0, lParam=0, time=371123953., pt_X=400., pt_Y=300.}
- 04BAFF44 |00000000 ....
- 04BAFF48 |77792C30 0,yw
- 04BAFF4C |00000000 ....
- 04BAFF50 |00160056 V..
- 04BAFF54 |0000001E ...
- 04BAFF58 |00000000 ....
- 04BAFF5C |00000000 ....
- 04BAFF60 |161EE6F1
- 04BAFF64 |00000190 ..
- 04BAFF68 |0000012C ,..
- 04BAFF6C |04BAFF88
- 04BAFF70 \7768F366 fhw ; RETURN from ole32.7768FF71 to ole32.7768F366
- 04BAFF74 /00007530 0u..
- 04BAFF78 |77E61C96 w ; KERNEL32.WaitForSingleObjectEx
- 04BAFF7C |001F6E20 n.
- 04BAFF80 |00000434 4..
- 04BAFF84 |001EA980 .
- 04BAFF88 |04BAFF90
- 04BAFF8C \7768F2A2 hw ; RETURN from ole32.7768F2AB to ole32.7768F2A2
- 04BAFF90 /04BAFFAC
- 04BAFF94 \776BBAD4 ?kw ; RETURN to ole32.776BBAD4
- 04BAFF98 /77792C30 0,yw
- 04BAFF9C |00000000 ....
- 04BAFFA0 |001F6E20 n.
- 04BAFFA4 |77670000 ..gw
- 04BAFFA8 |001F6E20 n.
- 04BAFFAC |04BAFFB8
- 04BAFFB0 \776B1724 $kw ; RETURN from ole32.776BBAAE to ole32.776B1724
- 04BAFFB4 /00000000 ....
- 04BAFFB8 |04BAFFEC
- 04BAFFBC \77E6482F /Hw ; RETURN to KERNEL32.77E6482F
- 04BAFFC0 001F6E20 n.
- 04BAFFC4 00000000 ....
- 04BAFFC8 00000000 ....
- 04BAFFCC 001F6E20 n.
- 04BAFFD0 00000000 ....
- 04BAFFD4 04BAFFC4
- 04BAFFD8 8083318C 1
- 04BAFFDC FFFFFFFF ; End of SEH chain
- 04BAFFE0 77E61A60 `w ; SE handler
- 04BAFFE4 77E64838 8Hw
- 04BAFFE8 00000000 ....
- 04BAFFEC 00000000 ....
- 04BAFFF0 00000000 ....
- 04BAFFF4 776B1704 kw
- 04BAFFF8 001F6E20 n.
- 04BAFFFC 00000000 ....
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement