卡饭论坛's Archiver



wyyhhh 发表于 2008-8-24 13:22

中毒了////传个日志

SREfedaad3f caused an Access Violation (0xc0000005)
in module KERNEL32.dll at 001b:77e8d94d.
Exception handler called in System Repair Engineer Exception Handler.
Error occurred at 8/24/2008 13:11:18.
F:\工具\sreng2\SREfedaad3f.EXE, run by wu.
Operating system:  Windows 2000 Professional Service Pack 4 (Build 2195).
1 processor(s), type 586.
59% memory in use.
256 MBytes physical memory.
103 MBytes physical memory free.
1257 MBytes paging file.
1036 MBytes paging file free.
2048 MBytes user address space.
1998 MBytes user address space free.
Read from location 00000000 caused an access violation.
Context:
EDI:    0x00000034  ESI: 0x00000000  EAX:   0x00000000
EBX:    0x00000000  ECX: 0x80000008  EDX:   0x00000000
EIP:    0x77e8d94d  EBP: 0x0164f390  SegCs: 0x0000001b
EFlags: 0x00010202  ESP: 0x0164f330  SegSs: 0x00000023
Bytes at CS:EIP:
8b 00 8b d0 89 45 ec 69 d2 28 04 00 00 03 fa 6a
Stack:
0x0164f330: 0078ab38 00000434 0078ab38 00000000 8.x.4...8.x.....
0x0164f340: 01c50000 00000014 0164f394 77e8d844 ..........d.D..w
0x0164f350: 00000434 00000001 0000004c 0078ab38 4.......L...8.x.
0x0164f360: 00000434 0078ab38 77e87104 00130000 4...8.x..q.w....
0x0164f370: 00010000 00204318 00000000 00000000 .....C .........
0x0164f380: 00000000 0164fb00 00000000 00000000 ......d.........
0x0164f390: 0164f3c0 77e8cc52 0164f3cc 80000008 ..d.R..w..d.....
0x0164f3a0: 00000434 00000000 07460000 00000000 4.........F.....
0x0164f3b0: 0164fc70 00000000 07460000 00000000 p.d.......F.....
0x0164f3c0: 00000000 00426276 80000008 00000434 ....vbB.....4...
0x0164f3d0: d5e64c1e 0000027c 0164fc70 00000000 .L..|...p.d.....
0x0164f3e0: 00000000 0078ab38 0078ab38 0166fbd8 ....8.x.8.x...f.
0x0164f3f0: 0164f3c8 0078ab38 0078ab38 00000001 ..d.8.x.8.x.....
0x0164f400: 0164fc70 00000564 0078ab38 0164f3cc p.d.d...8.x...d.
0x0164f410: 016f0a88 01126560 0164f3c4 0166fbd8 ..o.`e....d...f.
0x0164f420: 011270d8 016f0628 00000000 00000000 .p..(.o.........
0x0164f430: 00000000 00000000 00000000 00000000 ................
0x0164f440: 00000000 00000000 00000000 00000000 ................
0x0164f450: 00000000 00000000 00000000 00000000 ................
0x0164f460: 00000000 00000000 00000000 00000000 ................
0x0164f470: 00000000 00000000 00000000 00000000 ................
0x0164f480: 00000000 00000000 00000000 49444e49 ............INDI
0x0164f490: 4c4c4443 00000000 00000000 00000000 CDLL............
0x0164f4a0: 00000000 00000000 00000000 00000000 ................
0x0164f4b0: 00000000 00000000 00000000 00000000 ................
0x0164f4c0: 00000000 00000000 00000000 00000000 ................
0x0164f4d0: 00000000 00000000 00000000 00000000 ................
0x0164f4e0: 00000000 00000000 00000000 00000000 ................
0x0164f4f0: 7263694d 666f736f 29522874 6e695720 Microsoft(R) Win
0x0164f500: 73776f64 29522820 30303220 704f2030 dows (R) 2000 Op
0x0164f510: 74617265 20676e69 74737953 00006d65 erating System..
0x0164f520: 00000000 00000000 00000000 00000000 ................
0x0164f530: 00000000 00000000 00000000 00000000 ................
0x0164f540: 00000000 00000000 00000000 00000000 ................
0x0164f550: 00000000 7263694d 666f736f 6f432074 ....Microsoft Co
0x0164f560: 726f7072 6f697461 0000006e 00000000 rporation.......
0x0164f570: 00000000 00000000 00000000 00000000 ................
0x0164f580: 00000000 00000000 00000000 00000000 ................
0x0164f590: 00000000 00000000 00000000 00000000 ................
0x0164f5a0: 00000000 00000000 00000000 00000000 ................
0x0164f5b0: 00000000 00000000 79706f43 68676972 ........Copyrigh
0x0164f5c0: 43282074 694d2029 736f7263 2074666f t (C) Microsoft
0x0164f5d0: 70726f43 3931202e 312d3439 00393939 Corp. 1994-1999.
0x0164f5e0: 00000000 00000000 00000000 00000000 ................
0x0164f5f0: 00000000 00000000 00000000 00000000 ................
0x0164f600: 00000000 00000000 00000000 00000000 ................
0x0164f610: 00000000 00000000 00000000 30302e35 ............5.00
0x0164f620: 3239322e 30302e30 00003030 00000000 .2920.0000......
0x0164f630: 00000000 00000000 00000000 00000000 ................
0x0164f640: 00000000 00000000 00000000 00000000 ................
0x0164f650: 00000000 00000000 00000000 00000000 ................
0x0164f660: 00000000 00000000 00000000 00000000 ................
0x0164f670: 00000000 00000000 00000000 00000000 ................
0x0164f680: 6279654b 6472616f 6e614c20 67617567 Keyboard Languag
0x0164f690: 6e492065 61636964 20726f74 6c656853 e Indicator Shel
0x0164f6a0: 6f48206c 45206b6f 6e657478 6e6f6973 l Hook Extension
0x0164f6b0: 00000000 00000000 00000000 00000000 ................
0x0164f6c0: 00000000 00000000 00000000 00000000 ................
0x0164f6d0: 00000000 00000000 00000000 00000000 ................
0x0164f6e0: 00000000 00000000 00000000 00000000 ................
0x0164f6f0: 00000000 00000000 00000000 00000000 ................
0x0164f700: 00000000 00000000 00000000 00000000 ................
0x0164f710: 00000000 00000000 00000000 00000000 ................
0x0164f720: 00000000 00000000 00000000 00000000 ................
0x0164f730: 00000000 00000000 00000000 00000000 ................
0x0164f740: 00000000 00000000 00000000 00000000 ................
0x0164f750: 00000000 00000000 00000000 00000000 ................
0x0164f760: 00000000 00000000 00000000 00000000 ................
0x0164f770: 00000000 00000000 00000000 00000000 ................
0x0164f780: 00000000 00000000 00000000 00000000 ................
0x0164f790: 00000000 00000000 00000000 00000000 ................
0x0164f7a0: 00000000 00000000 00000000 30302e35 ............5.00
0x0164f7b0: 3239322e 30302e30 00003030 00000000 .2920.0000......
0x0164f7c0: 00000000 00000000 00000000 00000000 ................
0x0164f7d0: 00000000 00000000 00000000 00000000 ................
0x0164f7e0: 00000000 00000000 00000000 00000000 ................
0x0164f7f0: 00000000 00000000 00000000 00000000 ................
0x0164f800: 00000000 00000000 00000000 00000000 ................
0x0164f810: 49444e49 4c4c4443 4c4c442e 00000000 INDICDLL.DLL....
0x0164f820: 00000000 00000000 00000000 00000000 ................
0x0164f830: 00000000 00000000 00000000 00000000 ................
0x0164f840: 00000000 00000000 00000000 00000000 ................
0x0164f850: 00000000 00000000 00000000 00000000 ................
0x0164f860: 00000000 00000001 0164f912 00134330 ..........d.0C..
0x0164f870: 00000001 7ffb0022 0000000b 0164f8a8 ....".........d.
0x0164f880: 77ea959f 00134330 0164f8fc 0164f912 ...w0C....d...d.
0x0164f890: 0164fb40 0164fc44 00000000 0000027c @.d.D.d.....|...
0x0164f8a0: 0164fb1c 00000001 0164fb04 77e8d2ba ..d.......d....w
0x0164f8b0: 00000000 00000000 0164f8fc 00000000 ..........d.....
0x0164f8c0: 0164fb40 00000104 00000000 00000000 @.d.............
0x0164f8d0: 0164fc70 00000000 0000022c 00000000 p.d.....,.......
0x0164f8e0: 00000434 00000000 00000000 00000005 4...............
0x0164f8f0: 00000338 00000008 00000000 00530053 8...........S.S.
0x0164f900: 0043004c 0074006e 0065002e 00650078 L.C.n.t...e.x.e.
0x0164f910: 00000000 00000000 00000000 00000000 ................
0x0164f920: 00000000 00000000 00000000 00000000 ................
0x0164f930: 00000000 00000000 00000000 00000000 ................
0x0164f940: 00000000 00000000 00000000 00000000 ................
0x0164f950: 00000000 00000000 00000000 00000000 ................
0x0164f960: 00000000 00000000 00000000 00000000 ................
0x0164f970: 00000000 00000000 00000000 00000000 ................
0x0164f980: 00000000 00000000 00000000 00000000 ................
0x0164f990: 00000000 00000000 00000000 00000000 ................
0x0164f9a0: 00000000 00000000 00000000 00000000 ................
0x0164f9b0: 00000000 00000000 00000000 00000000 ................
0x0164f9c0: 00000000 00000000 00000000 00000000 ................
0x0164f9d0: 00000000 00000000 00000000 00000000 ................
0x0164f9e0: 00000000 00000000 00000000 00000000 ................
0x0164f9f0: 00000000 00000000 00000000 00000000 ................
0x0164fa00: 00000000 00000000 00000000 00000000 ................
0x0164fa10: 00000000 00000000 00000000 00000000 ................
0x0164fa20: 00000000 00000000 00000000 00000000 ................
0x0164fa30: 00000000 00000000 00000000 00000000 ................
0x0164fa40: 00000000 00000000 00000000 00000000 ................
0x0164fa50: 00000000 00000000 00000000 00000000 ................
0x0164fa60: 00000000 00000000 00000000 00000000 ................
0x0164fa70: 00000000 00000000 00000000 00000000 ................
0x0164fa80: 00000000 00000000 00000000 00000000 ................
0x0164fa90: 00000000 00000000 00000000 00000000 ................
0x0164faa0: 00000000 00000000 00000000 00000000 ................
0x0164fab0: 00000000 00000000 00000000 00000000 ................
0x0164fac0: 00000000 00000000 00000000 00000000 ................
0x0164fad0: 00000000 00000000 00000000 00000000 ................
0x0164fae0: 00000000 00000000 00000000 00000000 ................
0x0164faf0: 00000000 00000000 00000000 d5e64c2e .............L..
0x0164fb00: 0164ffac 004f0305 00000005 00426b8c ..d...O......kB.
0x0164fb10: 00000434 77ebafec 0164fc70 00000128 4......wp.d.(...
0x0164fb20: 00000000 00000434 00000000 00000000 ....4...........
0x0164fb30: 00000005 00000338 00000008 00000000 ....8...........
0x0164fb40: 434c5353 652e746e 65006578 00657800 SSLCnt.exe.e.xe.
0x0164fb50: 0164fa00 7ffd9000 0164fbe8 77fb7e64 ..d.......d.d~.w
0x0164fb60: 77f81678 0016c810 0016c820 77e80803 x..w.... ......w
0x0164fb70: 0164fb84 00000475 00134c28 00000000 ..d.u...(L......
0x0164fb80: 0016c810 61430000 64656863 55746547 ......CachedGetU
0x0164fb90: 46726573 536d6f72 69006469 00000064 serFromSid.id...
0x0164fba0: 00100100 00130000 01120000 0164fbf8 ..............d.
0x0164fbb0: 7ffd9bf8 00000000 00d800d6 00134c28 ............(L..
0x0164fbc0: 65d10000 00000016 65d133fb 65d14bd0 ...e.....3.e.K.e
0x0164fbd0: 0164fb84 0164fb40 00000014 0164ffac [email=..d.@.d.......d]..d.@.d.......d[/email].
0x0164fbe0: 77fb7e64 77f81370 ffffffff 0164fc2c d~.wp..w....,.d.
0x0164fbf0: 77f8d985 65d10000 0164fc24 00000000 ...w...e$.d.....
0x0164fc00: 0164fc38 00000001 77e80d38 0164fc2c 8.d.....8..w,.d.
0x0164fc10: 77e80d46 65d10000 00000000 77ebafec F..w...e.......w
0x0164fc20: 00000000 00150014 00501e24 00000000 ........$.P.....
0x0164fc30: bea3fed9 65d10000 65d133fb 0164fc70 .......e.3.ep.d.
0x0164fc40: 00426c26 d5e644d6 00426c32 0164fdda &lB..D..2lB...d.
0x0164fc50: 00727487 01125e18 0046efce d5e643aa .tr..^....F..C..
0x0164fc60: 0012ae10 787023c8 0164ffec 00000001 .....#px..d.....
0x0164fc70: 445c3a43 4d55434f 5c317e45 4c5c7577 C:\DOCUME~1\wu\L
0x0164fc80: 4c41434f 5c317e53 706d6554 4138365c OCALS~1\Temp\68A
0x0164fc90: 42313130 37353338 35373444 33384233 011B8357D4753B83
0x0164fca0: 33393639 42353831 34463145 4d542e30 9693185BE1F40.TM
0x0164fcb0: 00000050 00000000 00000000 00000000 P...............
0x0164fcc0: 00000000 00000000 00000000 00000000 ................
0x0164fcd0: 00000000 00000000 00000000 00000000 ................
0x0164fce0: 00000000 00000000 00000000 00000000 ................
0x0164fcf0: 00000000 00000000 00000000 00000000 ................
0x0164fd00: 00000000 00000000 00000000 00000000 ................
0x0164fd10: 00000000 00000000 00000000 00000000 ................
0x0164fd20: 00000000 00000000 00000000 00000000 ................
0x0164fd30: 00000000 00000000 00000000 00000000 ................
0x0164fd40: 00000000 00000000 00000000 00000000 ................
0x0164fd50: 00000000 00000000 00000000 00000000 ................
0x0164fd60: 00000000 00000000 00000000 00000000 ................
0x0164fd70: 00000000 00000001 00000001 00000001 ................
0x0164fd80: 64e20000 65d10000 0046dce0 00000000 ...d...e..F.....
0x0164fd90: 01126418 000000c3 445c3a43 4d55434f .d......C:\DOCUM
0x0164fda0: 5c317e45 4c5c7577 4c41434f 5c317e53 E~1\wu\LOCALS~1\
0x0164fdb0: 706d6554 4138365c 42313130 37353338 Temp\68A011B8357
0x0164fdc0: 35373444 33384233 33393639 42353831 D4753B839693185B
0x0164fdd0: 34463145 4d542e30 00000050 00000000 E1F40.TMP.......
0x0164fde0: 00000000 00000000 00000000 00000000 ................
0x0164fdf0: 00000000 00000000 00000000 00000000 ................
0x0164fe00: 00000000 00000000 00000000 00000000 ................
0x0164fe10: 00000000 00000000 00000000 00000000 ................
0x0164fe20: 00000000 00000000 00000000 00000000 ................
0x0164fe30: 00000000 00000000 00000000 00000000 ................
0x0164fe40: 00000000 00000000 00000000 00000000 ................
0x0164fe50: 00000000 00000000 00000000 00000000 ................
0x0164fe60: 00000000 00000000 00000000 00000000 ................
0x0164fe70: 00000000 00000000 00000000 00000000 ................
0x0164fe80: 00000000 00000000 00000000 00000000 ................
0x0164fe90: 00000000 00000000 00000000 00000000 ................
0x0164fea0: 445c3a43 4d55434f 5c317e45 4c5c7577 C:\DOCUME~1\wu\L
0x0164feb0: 4c41434f 5c317e53 706d6554 0000005c OCALS~1\Temp\...
0x0164fec0: 00000000 00000000 00000000 00000000 ................
0x0164fed0: 00000000 00000000 00000000 00000000 ................
0x0164fee0: 00000000 00000000 00000000 00000000 ................
0x0164fef0: 00000000 00000000 00000000 00000000 ................
0x0164ff00: 00000000 00000000 00000000 00000000 ................
0x0164ff10: 00000000 00000000 00000000 00000000 ................
0x0164ff20: 00000000 00000000 00000000 00000000 ................
0x0164ff30: 00000000 00000000 00000000 00000000 ................
0x0164ff40: 00000000 00000000 00000000 00000000 ................
0x0164ff50: 00000000 00000000 00000000 00000000 ................
0x0164ff60: 00000000 00000000 00000000 00000000 ................
0x0164ff70: 00000000 00000000 00000000 00000000 ................
0x0164ff80: 00000000 00000000 00000000 00000000 ................
0x0164ff90: 00000000 00000000 00000000 00000000 ................
0x0164ffa0: 00000000 00000000 d5e643a6 0164ffdc .........C....d.
0x0164ffb0: 004f67ab 00000000 77e6b3bc 01125e18 .gO........w.^..
0x0164ffc0: 0012ae10 787023c8 01125e18 7ffd9000 .....#px.^......
0x0164ffd0: c0000005 0164ffc0 0164ef7c ffffffff ......d.|.d.....
0x0164ffe0: 77eb2160 77e62b08 00000000 00000000 `!.w.+.w........
0x0164fff0: 00000000 0046ede0 01125e18 00000000 ......F..^......
Module 1
F:\工具\sreng2\SREfedaad3f.EXE
Image Base: 0x00400000  Image Size: 0x00403000
Checksum:   0x001e3efb  Time Stamp: 0x48707aae
File Size:  1953792     File Time:  8/24/2008 13:07:26
Version Information:
   Company:    Smallfrogs Studio
   Product:    System Repair Engineer
   FileDesc:   System Repair Engineer
   FileVer:    2.6.12.1018
   ProdVer:    2.6.0.0
Module 2
C:\WINNT\system32\WINHTTP.dll
Image Base: 0x4ff90000  Image Size: 0x00054000
Checksum:   0x00055cc9  Time Stamp: 0x40c7a9b9
File Size:  331776      File Time:  10/11/2004 15:04:32
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft? Windows? Operating System
   FileDesc:   Windows HTTP Services
   FileVer:    5.1.2600.1557
   ProdVer:    5.1.2600.1557
Module 3
C:\WINNT\system32\WININET.dll
Image Base: 0x63000000  Image Size: 0x00095000
Checksum:   0x00095f63  Time Stamp: 0x47b5e529
File Size:  575488      File Time:  2/15/2008 16:12:24
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Internet Extensions for Win32
   FileVer:    6.0.2800.1609
   ProdVer:    6.0.2800.1609
Module 4
C:\WINNT\system32\Winsta.dll
Image Base: 0x64e20000  Image Size: 0x0000d000
Checksum:   0x00012836  Time Stamp: 0x3ef31d88
File Size:  39184       File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Winstation Library
   FileVer:    5.0.2195.6701
   ProdVer:    5.0.2195.6701
Module 5
C:\WINNT\system32\utildll.dll
Image Base: 0x65d10000  Image Size: 0x0000a000
Checksum:   0x00007512  Time Stamp: 0x3ef31d80
File Size:  29456       File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   WinStation utility support DLL
   FileVer:    5.0.2195.6701
   ProdVer:    5.0.2195.6701
Module 6
C:\WINNT\system32\USP10.dll
Image Base: 0x65d20000  Image Size: 0x00054000
Checksum:   0x000531d3  Time Stamp: 0x3ef31d80
File Size:  315664      File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Uniscribe Unicode script processor
   FileDesc:   Uniscribe Unicode script processor
   FileVer:    1.325.2195.6692
   ProdVer:    1.325.2195.6692
Module 7
C:\WINNT\system32\PSAPI.DLL
Image Base: 0x687e0000  Image Size: 0x0000b000
Checksum:   0x00013abf  Time Stamp: 0x385135b7
File Size:  28944       File Time:  3/17/2000 06:40:12
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Process Status Helper
   FileVer:    5.0.2134.1
   ProdVer:    5.0.2134.1
Module 8
C:\WINNT\system32\NTMARTA.DLL
Image Base: 0x694b0000  Image Size: 0x0001d000
Checksum:   0x0001fbe2  Time Stamp: 0x3ef31d67
File Size:  102672      File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Windows NT MARTA provider
   FileVer:    5.0.2195.6666
   ProdVer:    5.0.2195.6666
Module 9
C:\WINNT\system32\LPK.DLL
Image Base: 0x6c330000  Image Size: 0x00008000
Checksum:   0x0000d9f6  Time Stamp: 0x3ef31d54
File Size:  20240       File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Language Pack
   FileVer:    5.0.2195.6692
   ProdVer:    5.0.2195.6692
Module 10
C:\WINNT\system32\SETUPAPI.dll
Image Base: 0x6d990000  Image Size: 0x000ac000
Checksum:   0x000b7b95  Time Stamp: 0x3ef31d14
File Size:  692496      File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Windows Setup API
   FileVer:    5.0.2195.6622
   ProdVer:    5.0.2195.6622

wyyhhh 发表于 2008-8-24 13:23

Module 11
C:\WINNT\system32\INDICDLL.dll
Image Base: 0x6dd30000  Image Size: 0x00006000
Checksum:   0x00011cf8  Time Stamp: 0x38513577
File Size:  11536       File Time:  1/10/2000 12:00:00
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Keyboard Language Indicator Shell Hook Extension
   FileVer:    5.0.2920.0
   ProdVer:    5.0.2920.0

Module 12
C:\WINNT\system32\SHLWAPI.DLL
Image Base: 0x70a70000  Image Size: 0x00066000
Checksum:   0x00064419  Time Stamp: 0x47b61835
File Size:  402944      File Time:  2/15/2008 16:12:18
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows(R) Operating System
   FileDesc:   Shell Light-weight Utility Library
   FileVer:    6.0.2800.1923
   ProdVer:    6.0.2800.1923

Module 13
C:\WINNT\system32\COMCTL32.DLL
Image Base: 0x71710000  Image Size: 0x00084000
Checksum:   0x000842e7  Time Stamp: 0x44ef1374
File Size:  530192      File Time:  8/28/2006 14:14:10
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Common Controls Library
   FileVer:    5.81.4968.2500
   ProdVer:    5.50.4968.2500

Module 14
C:\WINNT\system32\CLBCATQ.DLL
Image Base: 0x72c50000  Image Size: 0x0008f000
Checksum:   0x0009502e  Time Stamp: 0x431bff1e
File Size:  551184      File Time:  9/5/2005 13:47:36
Version Information:
   Company:    Microsoft Corporation
   Product:    COM Services
   FileDesc:   
   FileVer:    2000.2.3529.0
   ProdVer:    3.0.0.3529

Module 15
C:\WINNT\system32\WS2HELP.DLL
Image Base: 0x74fa0000  Image Size: 0x00008000
Checksum:   0x00009768  Time Stamp: 0x38513525
File Size:  18192       File Time:  1/10/2000 12:00:00
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Windows Socket 2.0 Helper for Windows NT
   FileVer:    5.0.2134.1
   ProdVer:    5.0.2134.1

Module 16
C:\WINNT\system32\WS2_32.dll
Image Base: 0x74fb0000  Image Size: 0x00014000
Checksum:   0x0001cfd7  Time Stamp: 0x3ef31d89
File Size:  69904       File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Windows Socket 2.0 32-Bit DLL
   FileVer:    5.0.2195.6601
   ProdVer:    5.0.2195.6601

Module 17
C:\WINNT\system32\WSOCK32.dll
Image Base: 0x74fd0000  Image Size: 0x0000a000
Checksum:   0x0000bfc5  Time Stamp: 0x3ef31d8a
File Size:  27920       File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Windows Socket 32-Bit DLL
   FileVer:    5.0.2195.6603
   ProdVer:    5.0.2195.6603

Module 18
C:\WINNT\system32\SAMLIB.dll
Image Base: 0x750e0000  Image Size: 0x00010000
Checksum:   0x000112d1  Time Stamp: 0x42a066af
File Size:  51984       File Time:  6/3/2005 07:18:24
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   SAM Library DLL
   FileVer:    5.0.2195.6944
   ProdVer:    5.0.2195.6944

Module 19
C:\WINNT\system32\NETRAP.dll
Image Base: 0x75150000  Image Size: 0x00006000
Checksum:   0x000053d4  Time Stamp: 0x38513523
File Size:  11536       File Time:  1/10/2000 12:00:00
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Net Remote Admin Protocol DLL
   FileVer:    5.0.2134.1
   ProdVer:    5.0.2134.1

Module 20
C:\WINNT\system32\oledlg.dll
Image Base: 0x75280000  Image Size: 0x0001f000
Checksum:   0x00022645  Time Stamp: 0x453730f2
File Size:  115472      File Time:  10/19/2006 13:31:56
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft Windows(TM) OLE 2.0 User Interface Support
   FileDesc:   Microsoft Windows(TM) OLE 2.0 User Interface Support
   FileVer:    5.0.2195.7114
   ProdVer:    5.0.2195.7114

Module 21
C:\WINNT\system32\LZ32.DLL
Image Base: 0x75950000  Image Size: 0x00006000
Checksum:   0x0000bb71  Time Stamp: 0x3ef31d24
File Size:  10000       File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   LZ Expand/Compress API DLL
   FileVer:    5.0.2195.6611
   ProdVer:    5.0.2195.6611

Module 22
C:\WINNT\system32\SensApi.dll
Image Base: 0x75a50000  Image Size: 0x00005000
Checksum:   0x0000d035  Time Stamp: 0x3ef31d23
File Size:  7440        File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   SENS Connectivity API DLL
   FileVer:    5.0.2195.6627
   ProdVer:    5.0.2195.6627

Module 23
C:\WINNT\system32\IMM32.DLL
Image Base: 0x75e00000  Image Size: 0x0001a000
Checksum:   0x00020c35  Time Stamp: 0x3ef31d22
File Size:  96528       File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Windows 2000 IMM32 API Client DLL
   FileVer:    5.0.2195.6655
   ProdVer:    5.0.2195.6655

Module 24
C:\WINNT\system32\LINKINFO.DLL
Image Base: 0x766b0000  Image Size: 0x00009000
Checksum:   0x0000f5ff  Time Stamp: 0x4333e0cf
File Size:  17680       File Time:  9/23/2005 19:02:40
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Windows Volume Tracking
   FileVer:    5.0.2195.7069
   ProdVer:    5.0.2195.7069

Module 25
C:\WINNT\system32\wintrust.dll
Image Base: 0x768d0000  Image Size: 0x0002b000
Checksum:   0x00036728  Time Stamp: 0x42a066a1
File Size:  167184      File Time:  6/3/2005 07:18:10
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Microsoft Trust Verification APIs
   FileVer:    5.131.2195.6824
   ProdVer:    5.131.2195.6824

Module 26
C:\WINNT\system32\comdlg32.dll
Image Base: 0x76af0000  Image Size: 0x0003e000
Checksum:   0x000467c0  Time Stamp: 0x3ef31d1c
File Size:  241424      File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Common Dialogs DLL
   FileVer:    5.0.3700.6693
   ProdVer:    5.0.3700.6693

Module 27
C:\WINNT\system32\ntshrui.dll
Image Base: 0x76f60000  Image Size: 0x0000f000
Checksum:   0x00010e47  Time Stamp: 0x3851350a
File Size:  47888       File Time:  1/10/2000 12:00:00
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Shell extensions for sharing
   FileVer:    5.0.2134.1
   ProdVer:    5.0.2134.1

Module 28
C:\WINNT\system32\CSCDLL.DLL
Image Base: 0x77080000  Image Size: 0x00023000
Checksum:   0x0001fa3b  Time Stamp: 0x3ef31d19
File Size:  101136      File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Offline Network Agent
   FileVer:    5.0.2195.6713
   ProdVer:    5.0.2195.6713

Module 29
C:\WINNT\system32\ATL.DLL
Image Base: 0x773a0000  Image Size: 0x00015000
Checksum:   0x00015800  Time Stamp: 0x3ef31d18
File Size:  74810       File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft (R) Visual C++
   FileDesc:   ATL Module for Windows NT (Unicode)
   FileVer:    3.0.9435.0
   ProdVer:    6.0.0.9435

Module 30
C:\WINNT\system32\MSASN1.dll
Image Base: 0x773f0000  Image Size: 0x00011000
Checksum:   0x0001020a  Time Stamp: 0x42a0669f
File Size:  56592       File Time:  6/3/2005 07:18:08
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   ASN.1 Runtime APIs
   FileVer:    5.0.2195.6905
   ProdVer:    5.0.2195.6905

Module 31
C:\WINNT\system32\TAPI32.dll
Image Base: 0x774f0000  Image Size: 0x00022000
Checksum:   0x0002485f  Time Stamp: 0x3ef31d17
File Size:  126736      File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Microsoft? Windows(TM) Telephony API Client DLL
   FileVer:    5.0.2195.6664
   ProdVer:    5.0.2195.6664

Module 32
C:\WINNT\system32\WINMM.dll
Image Base: 0x77530000  Image Size: 0x00030000
Checksum:   0x00036949  Time Stamp: 0x38513506
File Size:  189200      File Time:  1/10/2000 12:00:00
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   MCI API DLL
   FileVer:    5.0.2161.1
   ProdVer:    5.0.2161.1

Module 33
C:\WINNT\system32\WINSPOOL.DRV
Image Base: 0x777c0000  Image Size: 0x0001e000
Checksum:   0x00025df3  Time Stamp: 0x3ef31d14
File Size:  113936      File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Windows Spooler Driver
   FileVer:    5.0.2195.6659
   ProdVer:    5.0.2195.6659

Module 34
C:\WINNT\system32\VERSION.dll
Image Base: 0x777e0000  Image Size: 0x00007000
Checksum:   0x000067ad  Time Stamp: 0x3ef31d14
File Size:  16144       File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Version Checking and File Installation Libraries
   FileVer:    5.0.2195.6623
   ProdVer:    5.0.2195.6623

Module 35
C:\WINNT\system32\cscui.dll
Image Base: 0x77810000  Image Size: 0x0003e000
Checksum:   0x00043a19  Time Stamp: 0x3ef31d14
File Size:  242960      File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Client Side Caching UI
   FileVer:    5.0.2195.6705
   ProdVer:    5.0.2195.6705

Module 36
C:\WINNT\system32\IMAGEHLP.dll
Image Base: 0x77900000  Image Size: 0x00023000
Checksum:   0x0002c758  Time Stamp: 0x3ef31d13
File Size:  128784      File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Windows NT Image Helper
   FileVer:    5.0.2195.6613
   ProdVer:    5.0.2195.6613

Module 37
C:\WINNT\system32\WLDAP32.dll
Image Base: 0x77930000  Image Size: 0x0002b000
Checksum:   0x0002f924  Time Stamp: 0x42a0669d
File Size:  146192      File Time:  6/3/2005 07:18:08
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Win32 LDAP API DLL
   FileVer:    5.0.2195.7017
   ProdVer:    5.0.2195.7017

Module 38
C:\WINNT\system32\DNSAPI.DLL
Image Base: 0x77960000  Image Size: 0x00024000
Checksum:   0x000259c6  Time Stamp: 0x47b59262
File Size:  137488      File Time:  2/15/2008 18:53:48
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   DNS Client API DLL
   FileVer:    5.0.2195.7151
   ProdVer:    5.0.2195.7151

Module 39
C:\WINNT\system32\OLEAUT32.dll
Image Base: 0x77990000  Image Size: 0x0009c000
Checksum:   0x000a63ba  Time Stamp: 0x44b350ea
File Size:  631056      File Time:  7/11/2006 12:49:08
Version Information:
   Company:    Microsoft Corporation
   Product:   
   FileDesc:   
   FileVer:    2.40.4531.0
   ProdVer:    2.40.4531.0

Module 40
C:\WINNT\system32\NTDSAPI.dll
Image Base: 0x77bd0000  Image Size: 0x00011000
Checksum:   0x00010513  Time Stamp: 0x3ef31d12
File Size:  57616       File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   NT5DS
   FileVer:    5.0.2195.6666
   ProdVer:    5.0.2195.6666

Module 41
C:\WINNT\system32\USER32.dll
Image Base: 0x77df0000  Image Size: 0x0005f000
Checksum:   0x000610f9  Time Stamp: 0x45ed4dbc
File Size:  381200      File Time:  3/6/2007 16:47:18
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Windows 2000 USER API Client DLL
   FileVer:    5.0.2195.7133
   ProdVer:    5.0.2195.7133

Module 42
C:\WINNT\system32\KERNEL32.dll
Image Base: 0x77e60000  Image Size: 0x000d3000
Checksum:   0x000d1072  Time Stamp: 0x46236f7f
File Size:  841488      File Time:  4/16/2007 20:43:42
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Windows NT BASE API Client DLL
   FileVer:    5.0.2195.7135
   ProdVer:    5.0.2195.7135

Module 43
C:\WINNT\system32\GDI32.dll
Image Base: 0x77f40000  Image Size: 0x0003c000
Checksum:   0x0004424c  Time Stamp: 0x4680e2dd
File Size:  235280      File Time:  6/26/2007 15:26:46
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   GDI Client DLL
   FileVer:    5.0.2195.7138
   ProdVer:    5.0.2195.7138

Module 44
C:\WINNT\system32\ntdll.dll
Image Base: 0x77f80000  Image Size: 0x0007c000
Checksum:   0x00078ff9  Time Stamp: 0x41e648e0
File Size:  483600      File Time:  8/16/2005 03:56:12
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   NT Layer DLL
   FileVer:    5.0.2195.7006
   ProdVer:    5.0.2195.7006

Module 45
C:\WINNT\system32\msvcrt.dll
Image Base: 0x78000000  Image Size: 0x00045000
Checksum:   0x00054d71  Time Stamp: 0x3e6e3115
File Size:  286773      File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft (R) Visual C++
   FileDesc:   Microsoft (R) C Runtime Library
   FileVer:    6.1.9844.0
   ProdVer:    6.1.9844.0

Module 46
C:\WINNT\system32\RPCRT4.dll
Image Base: 0x786f0000  Image Size: 0x0006f000
Checksum:   0x0006e05d  Time Stamp: 0x469c64ce
File Size:  439056      File Time:  7/17/2007 12:12:24
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Remote Procedure Call Runtime
   FileVer:    5.0.2195.7090
   ProdVer:    5.0.2195.7090

Module 47
C:\WINNT\system32\SHELL32.DLL
Image Base: 0x78f90000  Image Size: 0x00246000
Checksum:   0x00243159  Time Stamp: 0x44b5f185
File Size:  2362640     File Time:  7/13/2006 12:38:54
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Windows Shell Common Dll
   FileVer:    5.0.3900.7105
   ProdVer:    5.0.3900.7105

Module 48
C:\WINNT\system32\USERENV.DLL
Image Base: 0x794d0000  Image Size: 0x00064000
Checksum:   0x00063006  Time Stamp: 0x42a0669c
File Size:  399120      File Time:  6/3/2005 07:18:06
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Userenv
   FileVer:    5.0.2195.7002
   ProdVer:    5.0.2195.7002

Module 49
C:\WINNT\system32\ADVAPI32.dll
Image Base: 0x796d0000  Image Size: 0x00065000
Checksum:   0x00068bf1  Time Stamp: 0x42a0669c
File Size:  401168      File Time:  6/3/2005 07:18:06
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Advanced Windows 32 Base API
   FileVer:    5.0.2195.7038
   ProdVer:    5.0.2195.7038

Module 50
C:\WINNT\system32\Secur32.dll
Image Base: 0x797b0000  Image Size: 0x0000f000
Checksum:   0x0001b6d4  Time Stamp: 0x3ef31d12
File Size:  48912       File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Security Support Provider Interface
   FileVer:    5.0.2195.6695
   ProdVer:    5.0.2195.6695

Module 51
C:\WINNT\system32\MPR.DLL
Image Base: 0x79b20000  Image Size: 0x00011000
Checksum:   0x0000fa17  Time Stamp: 0x46236f7e
File Size:  54032       File Time:  4/16/2007 20:43:42
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Multiple Provider Router DLL
   FileVer:    5.0.2195.7134
   ProdVer:    5.0.2195.7134

Module 52
C:\WINNT\system32\cryptnet.dll
Image Base: 0x79c00000  Image Size: 0x00013000
Checksum:   0x0000fe7f  Time Stamp: 0x42a066a4
File Size:  63760       File Time:  6/3/2005 07:18:14
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Crypto Network Related API
   FileVer:    5.131.2195.6926
   ProdVer:    5.131.2195.6926

Module 53
C:\WINNT\system32\CRYPT32.dll
Image Base: 0x79c40000  Image Size: 0x0008c000
Checksum:   0x0008c667  Time Stamp: 0x42a0669f
File Size:  563984      File Time:  6/3/2005 07:18:08
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Crypto API32
   FileVer:    5.131.2195.6926
   ProdVer:    5.131.2195.6926

Module 54
C:\WINNT\system32\rsaenh.dll
Image Base: 0x7ca00000  Image Size: 0x00023000
Checksum:   0x0002b2c2  Time Stamp: 0x3dafa75e
File Size:  134928      File Time:  6/20/2003 03:05:04
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Microsoft Enhanced Cryptographic Provider (US/Canada Only, Not for Export)
   FileVer:    5.0.2195.6611
   ProdVer:    5.0.2195.6611

Module 55
C:\WINNT\system32\NETAPI32.DLL
Image Base: 0x7cea0000  Image Size: 0x00050000
Checksum:   0x0004c4bd  Time Stamp: 0x44e46ba0
File Size:  309520      File Time:  8/17/2006 18:44:10
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Net Win32 API DLL
   FileVer:    5.0.2195.7108
   ProdVer:    5.0.2195.7108

Module 56
C:\WINNT\system32\ole32.dll
Image Base: 0x7cf00000  Image Size: 0x000ef000
Checksum:   0x000eb6a6  Time Stamp: 0x431bff1f
File Size:  957712      File Time:  9/5/2005 13:47:36
Version Information:
   Company:    Microsoft Corporation
   Product:    Microsoft(R) Windows (R) 2000 Operating System
   FileDesc:   Microsoft OLE for Windows
   FileVer:    5.0.2195.7059
   ProdVer:    5.0.2195.7059


===== [end of KZTechsAppErr.TXT] =====

kcoo 发表于 2008-8-24 14:14

请问LZ:这个日志是用什么分析的?怎么导出的?[:11:]

ts2884664 发表于 2008-8-24 16:40

用这个SRE导出的  不过技术不够 帮不上忙 等牛人吧

秋叶濛濛 发表于 2008-8-24 16:45

有问题请按版规操作

具体看置顶

页: [1]

Powered by Discuz! Archiver 6.1.0  © 2001-2007 Comsenz Inc.