能力值:
( LV2,RANK:10 )
|
-
-
2 楼
关于这个程序,我用IDA学着跟踪运行了下,程序退出后在IDA中有这样的记录,高手帮看下:
Debugger: Process started: D:\目录\程序.EXE
Debugger: Library loaded: C:\WINDOWS\System32\ntdll.dll
Debugger: Library loaded: C:\WINDOWS\system32\kernel32.dll
Debugger: Library loaded: D:\目录\msvbvm60.dll
Debugger: Library loaded: C:\WINDOWS\system32\user32.dll
Debugger: Library loaded: C:\WINDOWS\system32\gdi32.dll
Debugger: Library loaded: C:\WINDOWS\system32\advapi32.dll
Debugger: Library loaded: C:\WINDOWS\system32\rpcrt4.dll
Debugger: Library loaded: C:\WINDOWS\system32\ole32.dll
Debugger: Library loaded: C:\WINDOWS\system32\msvcrt.dll
Debugger: Library loaded: C:\WINDOWS\system32\oleaut32.dll
Debugger: Library loaded: C:\WINDOWS\system32\imm32.dll
Debugger: Library loaded: C:\WINDOWS\system32\lpk.dll
Debugger: Library loaded: C:\WINDOWS\system32\usp10.dll
Debugger: Library loaded: C:\WINDOWS\system32\uxtheme.dll
Debugger: Library loaded: C:\WINDOWS\system32\MSCTF.dll
Debugger: Library loaded: C:\WINDOWS\system32\version.dll
Debugger: Library unloaded.
Debugger: Library loaded: C:\WINDOWS\system32\MSCTFIME.IME
Debugger: Library loaded: D:\目录\MSWINSCK.OCX
Debugger: Library loaded: C:\WINDOWS\system32\wsock32.dll
Debugger: Library loaded: C:\WINDOWS\system32\ws2_32.dll
Debugger: Library loaded: C:\WINDOWS\system32\ws2help.dll
Debugger: Library loaded: C:\WINDOWS\system32\sxs.dll
Debugger: Library loaded: C:\WINDOWS\system32\mswsock.dll
Debugger: Library loaded: C:\WINDOWS\system32\hnetcfg.dll
Debugger: Library loaded: C:\WINDOWS\System32\wshtcpip.dll
Debugger: Thread started: id=00001384, entry=7C810659.(这里是不是在比较时间啊?)
Debugger: Library loaded: C:\WINDOWS\system32\mslbui.dll
Debugger: Library unloaded.
Debugger: Library unloaded.
Debugger: Library unloaded.
Debugger: Library unloaded.
Debugger: Thread terminated: id=00001384 (exit code = 0x0).
Debugger: Process terminated (exit code = 0h).
IDA不会用,自己感觉这里应该记录的是程序退出的过程。
|
|
|