EAX=00E1FDDC EBX=BFF7427F ECX=0000000D EDX=78037174 ESI=8162595B |
EDI=00000000 EBP=00E1FE38 ESP=00E1FDAC EIP=00F62C60 o d I s Z a P c |
CS=0167 DS=016F SS=016F ES=016F FS=0F67 GS=0F7E |
-------------------------------------------------------------------------PROT32- |
0167:00F62B6F 00FF ADD BH,BH ^ |
0167:00F62B71 25B029F600 AND EAX,KERNEL32!GetPrivateProfileStri^ |
0167:00F62B76 FF25B429F600 JMP [KERNEL32!GlobalUnlock] |
0167:00F62B7C FF25B829F600 JMP [KERNEL32!GetPrivateProfileIntA] |
0167:00F62B82 FF25BC29F600 JMP [KERNEL32!GetLocalTime] |
0167:00F62B88 FF25C029F600 JMP [KERNEL32!FindResourceA] |
0167:00F62B8E FF25C429F600 JMP [KERNEL32!GetComputerNameA] |
0167:00F62B94 FF25C829F600 JMP [KERNEL32!GlobalLock] |
0167:00F62B9A FF25CC29F600 JMP [KERNEL32!GlobalFree] v |
0167:00F62BA0 FF25D029F600 JMP [KERNEL32!LoadResource] < > v |
-------------------------------------------------------------------------------- |
WINICE: Load32 Obj=0005 Add=016F:794E2000 Len=00002000 Mod=MSWSOCK |
WINICE: Load32 Obj=0006 Add=016F:794E4000 Len=00001000 Mod=MSWSOCK |
Break due to BPX #0167:004F5E60 (ET=511.06 milliseconds) |
:bc* |
:codeon |
:pagein n |
Screen dumper set to mode 2 |
:pagein n c:\apitable |
|
PAGEIN address Wa |