date/time         : 2012-03-07 23:08
computer name     : HNXXXX
user name         : Administrator
admin/terminal    : TRUE / TRUE
operating system  : Windows 2003 Service Pack 2 build 3790
system language   : Chinese
system up time    : 12 hours 35 minutes 
program up time   : 36 minutes 48 seconds 
processors        : 2x AMD Athlon(tm) 64 X2 Dual Core CPU3800+
physical memory   : 2055/3071 MB (/ܼ)
display mode      : 1, 1440x900, 32 bit
allocated memory  : 21.73 MB
executable        : flashfxp.exe
exec. date/time   : 2008-11-21 11:53
version           : 3.7.6.1308
executable size   : 3985920
executable hash   : 9FDCFFCDC62D63BF512B8D41273E7CC6
madExcept version : 2.7k
exception class   : EAccessViolation
exception message : ȡڵַ 7C93ED80 ģ 'ntdll.dll'ȡ ַ 00000000.

main thread ($25c):
7c93ed80 ntdll.dll                        RtlFreeHeap
77e3b7ff user32.dll                       LoadIconA
006a7b99 flashfxp.exe FrmMain1  7680  +32 TFrmMain.SetTrayState
006a34f5 flashfxp.exe FrmMain1  6013 +878 TFrmMain.Transfer1Click
0069c037 flashfxp.exe FrmMain1  2923   +9 TFrmMain.WMTRANS
0046bca1 flashfxp.exe Controls  4233  +37 TControl.WndProc
0046e4d6 flashfxp.exe Controls  5698  +42 TWinControl.WndProc
0046af90 flashfxp.exe Controls  3726   +1 TControl.Update
0046b08d flashfxp.exe Controls  3753  +16 TControl.Repaint
004cd82f flashfxp.exe ComCtrls 14522   +6 TToolButton.CMEnabledChanged
0046bca1 flashfxp.exe Controls  4233  +37 TControl.WndProc
0046bad0 flashfxp.exe Controls  4158   +5 TControl.Perform
0046aa19 flashfxp.exe Controls  3415   +3 TControl.SetEnabled
006cf2d3 flashfxp.exe FrmMain1 21258  +36 TFrmMain.ToggleState
004d695a flashfxp.exe ThemeMgr   591  +10 TWindowProcList.DispatchMessage
004d72e1 flashfxp.exe ThemeMgr  1157  +46 TThemeManager.FormWindowProc
004d87d4 flashfxp.exe ThemeMgr  2064   +2 TThemeManager.PreFormWindowProc
0046e160 flashfxp.exe Controls  5571   +3 TWinControl.MainWndProc
0047f1c0 flashfxp.exe Forms     1484   +8 StdWndProc
77e316e0 user32.dll                       DispatchMessageA
00487d37 flashfxp.exe Forms     6901  +34 TApplication.ProcessMessage
00487d6e flashfxp.exe Forms     6939   +1 TApplication.HandleMessage
00487f8e flashfxp.exe Forms     7029  +21 TApplication.Run
006ec68d flashfxp.exe FlashFXP   682 +509 initialization

thread $12f0 (TChangeHandlerThread):
7c95845c ntdll.dll                              KiFastSystemCallRet
7c957b67 ntdll.dll                              NtWaitForMultipleObjects
7c822026 kernel32.dll                           WaitForMultipleObjectsEx
7c822fb9 kernel32.dll                           WaitForMultipleObjects
005ffbd1 flashfxp.exe UPTShellControls 4038 +11 TChangeHandlerThread.Execute
0044d1be flashfxp.exe madExcept                 HookedTThreadExecute
0041b210 flashfxp.exe Classes          6905  +1 ThreadProc
00403fbc flashfxp.exe System                    ThreadWrapper
0044d0f1 flashfxp.exe madExcept                 CallThreadProc
0044d133 flashfxp.exe madExcept                 ThreadExceptFrame
>> created by main thread ($25c) at:
005ff897 flashfxp.exe UPTShellControls 3934  +2 TChangeHandlerThread.Create

thread $18d4:
7c95845c ntdll.dll              KiFastSystemCallRet
7c957b77 ntdll.dll              NtWaitForSingleObject
7c821d18 kernel32.dll           WaitForSingleObjectEx
7c821c88 kernel32.dll           WaitForSingleObject
0044d0f1 flashfxp.exe madExcept CallThreadProc
0044d133 flashfxp.exe madExcept ThreadExceptFrame
>> created by main thread ($25c) at:
71b6d254 WS2_32.dll             

thread $1428: <priority:1>
7c95845c ntdll.dll  KiFastSystemCallRet
7c957647 ntdll.dll  NtRemoveIoCompletion

thread $1994:
7c95845c ntdll.dll              KiFastSystemCallRet
7c9576a7 ntdll.dll              NtReplyWaitReceivePortEx
0044d0f1 flashfxp.exe madExcept CallThreadProc
0044d133 flashfxp.exe madExcept ThreadExceptFrame
>> created by thread $1c98 at:
77c442ba RPCRT4.dll             

thread $16e0:
7c95845c ntdll.dll  KiFastSystemCallRet
7c957b67 ntdll.dll  NtWaitForMultipleObjects

thread $1914:
7c95845c ntdll.dll              KiFastSystemCallRet
7c9576a7 ntdll.dll              NtReplyWaitReceivePortEx
0044d0f1 flashfxp.exe madExcept CallThreadProc
0044d133 flashfxp.exe madExcept ThreadExceptFrame
>> created by thread $1994 at:
77c442ba RPCRT4.dll             

thread $1918 (THttpPostThread):
7c95845c ntdll.dll                       KiFastSystemCallRet
7c957b77 ntdll.dll                       NtWaitForSingleObject
7c96d0f2 ntdll.dll                       RtlEnterCriticalSection
76d920e3 rtutils.dll                     TraceRegisterExA
76df40bc RASAPI32.dll                    RasEnumEntriesW
40297585 WININET.dll                     #101
7c95cb30 ntdll.dll                       bsearch
00437ae4 flashfxp.exe EnhFunc    3515 +7 GetHttpProxyServer
004417b8 flashfxp.exe FDhttpPost  130 +4 HTTPPostBugReport
00441469 flashfxp.exe FDhttpPost   45 +1 THttpPostThread.Execute
0044d1be flashfxp.exe madExcept          HookedTThreadExecute
0041b210 flashfxp.exe Classes    6905 +1 ThreadProc
00403fbc flashfxp.exe System             ThreadWrapper
0044d0f1 flashfxp.exe madExcept          CallThreadProc
0044d133 flashfxp.exe madExcept          ThreadExceptFrame
>> created by thread $1eb0 at:
00441412 flashfxp.exe FDhttpPost   35 +1 THttpPostThread.Create

thread $17e8:
7c95845c ntdll.dll  KiFastSystemCallRet
7c956db7 ntdll.dll  NtDelayExecution

thread $1fa0:
7c95845c ntdll.dll  KiFastSystemCallRet
7c9575c7 ntdll.dll  NtRaiseHardError
7c9583c9 ntdll.dll  KiUserExceptionDispatcher

:
00400000 flashfxp.exe      3.7.6.1308        D:\Program Files\FlashFXP
01600000 safemon.dll       7.3.0.1020        C:\Program Files\360\360Safe\safemon
01690000 MSVCP60.dll       7.0.3790.3959     C:\WINDOWS\system32
01700000 Normaliz.dll      6.0.5441.0        C:\WINDOWS\system32
01ce0000 xpsp2res.dll      5.2.3790.3959     C:\WINDOWS\system32
02840000 ssleay32.dll      0.9.8.9           D:\Program Files\FlashFXP
028b0000 libeay32.dll      0.9.8.9           D:\Program Files\FlashFXP
02ad0000 idle.dll                            C:\Program Files\Yuguo
10000000 360UDiskGuard.dll 2.0.0.1013        C:\Program Files\360\360Safe\safemon
40270000 WININET.dll       8.0.6001.19190    C:\WINDOWS\system32
40910000 iertutil.dll      8.0.6001.19190    C:\WINDOWS\system32
439b0000 urlmon.dll        8.0.6001.19190    C:\WINDOWS\system32
4c510000 msctfime.ime      5.2.3790.3959     C:\WINDOWS\system32
4c620000 gdiplus.dll       5.2.6002.22507    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22507_x-ww_C7DAD021
4d090000 WMVCore.DLL       10.0.0.4007       C:\WINDOWS\system32
4f010000 audiodev.dll      5.2.3810.3997     C:\WINDOWS\system32
589e0000 WMASF.DLL         10.0.0.4000       C:\WINDOWS\system32
5a0c0000 wiashext.dll      5.2.3790.3959     C:\WINDOWS\system32
5f500000 ntlanman.dll      5.2.3790.3959     C:\WINDOWS\System32
5fbe0000 NETUI1.dll        5.2.3790.0        C:\WINDOWS\System32
5fc20000 NETUI0.dll        5.2.3790.0        C:\WINDOWS\System32
60f80000 SnacNp.dll        11.0.3001.155     C:\Program Files\Symantec\Symantec Endpoint Protection
69660000 hnetcfg.dll       5.2.3790.3959     C:\WINDOWS\system32
71a40000 wshtcpip.dll      5.2.3790.3959     C:\WINDOWS\System32
71a80000 mswsock.dll       5.2.3790.4318     C:\WINDOWS\System32
71ad0000 UxTheme.dll       6.0.3790.3959     C:\WINDOWS\system32
71b10000 wsock32.dll       5.2.3790.0        C:\WINDOWS\system32
71b30000 MPR.dll           5.2.3790.3959     C:\WINDOWS\system32
71b50000 WS2HELP.dll       5.2.3790.3959     C:\WINDOWS\system32
71b60000 WS2_32.dll        5.2.3790.3959     C:\WINDOWS\system32
71ba0000 netapi32.dll      5.2.3790.4392     C:\WINDOWS\system32
72f40000 winspool.drv      5.2.3790.3959     C:\WINDOWS\system32
74430000 MSCTF.dll         5.2.3790.3959     C:\WINDOWS\system32
74ae0000 USP10.dll         1.422.3790.4695   C:\WINDOWS\system32
75870000 USERENV.dll       5.2.3790.3959     C:\WINDOWS\system32
75d60000 apphelp.dll       5.2.3790.3959     C:\WINDOWS\system32
75d90000 drprov.dll        5.2.3790.3959     C:\WINDOWS\System32
75da0000 davclnt.dll       5.2.3790.3959     C:\WINDOWS\System32
76080000 MSASN1.dll        5.2.3790.4584     C:\WINDOWS\system32
760a0000 crypt32.dll       5.131.3790.4933   C:\WINDOWS\system32
76180000 IMM32.DLL         5.2.3790.3959     C:\WINDOWS\system32
761a0000 comdlg32.dll      6.0.3790.3959     C:\WINDOWS\system32
76410000 CSCDLL.dll        5.2.3790.3959     C:\WINDOWS\System32
76430000 cscui.dll         5.2.3790.3959     C:\WINDOWS\System32
76820000 LINKINFO.dll      5.2.3790.3959     C:\WINDOWS\system32
76830000 ntshrui.dll       6.0.3790.3959     C:\WINDOWS\system32
769e0000 winmm.dll         5.2.3790.4916     C:\WINDOWS\system32
76ab0000 PSAPI.DLL         5.2.3790.3959     C:\WINDOWS\system32
76b10000 WINTRUST.dll      5.131.3790.4642   C:\WINDOWS\system32
76b70000 imagehlp.dll      5.2.3790.3959     C:\WINDOWS\system32
76d90000 rtutils.dll       5.2.3790.3959     C:\WINDOWS\system32
76da0000 rasman.dll        5.2.3790.3959     C:\WINDOWS\system32
76dc0000 TAPI32.dll        5.2.3790.3959     C:\WINDOWS\system32
76df0000 RASAPI32.dll      5.2.3790.3959     C:\WINDOWS\system32
76e30000 DNSAPI.dll        5.2.3790.4840     C:\WINDOWS\system32
76e70000 WLDAP32.dll       5.2.3790.3959     C:\WINDOWS\system32
76eb0000 Secur32.dll       5.2.3790.4530     C:\WINDOWS\system32
76ed0000 winrnr.dll        5.2.3790.3959     C:\WINDOWS\System32
76ee0000 rasadhlp.dll      5.2.3790.3959     C:\WINDOWS\system32
76f70000 COMRes.dll        2001.12.4720.3959 C:\WINDOWS\system32
770d0000 SETUPAPI.dll      5.2.3790.3959     C:\WINDOWS\system32
774b0000 ole32.dll         5.2.3790.4926     C:\WINDOWS\system32
775f0000 oleaut32.dll      5.2.3790.4807     C:\WINDOWS\system32
77680000 CLBCatQ.DLL       2001.12.4720.3959 C:\WINDOWS\system32
77b60000 version.dll       5.2.3790.3959     C:\WINDOWS\system32
77b70000 msvcrt.dll        7.0.3790.3959     C:\WINDOWS\system32
77bd0000 GDI32.dll         5.2.3790.4396     C:\WINDOWS\system32
77c20000 RPCRT4.dll        5.2.3790.4759     C:\WINDOWS\system32
77cd0000 comctl32.dll      6.0.3790.4770     C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.3790.4770_x-ww_05FDF087
77e10000 user32.dll        5.2.3790.4033     C:\WINDOWS\system32
77eb0000 SHLWAPI.dll       6.0.3790.4603     C:\WINDOWS\system32
77f30000 ADVAPI32.dll      5.2.3790.4455     C:\WINDOWS\system32
7c800000 kernel32.dll      5.2.3790.4480     C:\WINDOWS\system32
7c930000 ntdll.dll         5.2.3790.4937     C:\WINDOWS\system32
7ca10000 shell32.dll       6.0.3790.4822     C:\WINDOWS\system32
7e020000 SAMLIB.dll        5.2.3790.3959     C:\WINDOWS\System32
7f000000 LPK.DLL           5.2.3790.3959     C:\WINDOWS\system32

disassembling:
7c938e3b   cmp     [esi+2], bx
7c938e3f   jz      loc_7c95b4ae
7c938e45   test    byte ptr [esi+5], $10
7c938e49   jz      loc_7c95a7a2
7c938e4f   jmp     loc_7c95b4ae
7c93c282   push    $7f
7c93c284   pop     eax
7c93c285   jmp     loc_7c95a734
7c93ed63   add     esi, -$18
7c93ed66   mov     [ebp-$60], esi
7c93ed69   mov     [ebp-$8c], esi
7c93ed6f   mov     eax, [esi]
7c93ed71   mov     [ebp-$94], eax
7c93ed77   mov     ecx, [esi+4]
7c93ed7a   mov     [ebp-$9c], ecx
7c93ed80 > mov     edx, [ecx]
7c93ed82   cmp     edx, [eax+4]
7c93ed85   jnz     loc_7c970b9f
7c93ed8b   cmp     edx, esi
7c93ed8d   jnz     loc_7c970b9f
7c93ed93   mov     [ecx], eax
7c93ed95   mov     [eax+4], ecx
7c93ed98   cmp     byte ptr [ebp-$19], 0
7c93ed9c   jz      loc_7c93edad
7c93ed9e   push    dword ptr [edi+$578]
7c93eda4   call    +$b44a ($7c94a1f3)     ; RtlLeaveCriticalSection (ntdll.dll)
7c93eda9   mov     byte ptr [ebp-$19], 0
7c93edad   mov     [ebp-$20], ebx
7c93edb0   push    $8000
7c93edb5   lea     eax, [ebp-$20]
7c93edb8   push    eax
7c93edb9   lea     eax, [ebp-$60]
7c93edbc   push    eax
7c93edbd   push    $ffffffff
7c93edbf   call    +$4ff0 ($7c943db4)
7c93edc4   mov     [ebp-$a4], eax
[...]

