Code: Select all
Log data
Address Message
OllyDbg v2.01 (preliminary version - under development!)
File 'H:\dls\vegastrike\svn\win32\bin\Vegastrike-13222.exe'
New process (ID 00000880) created
009EEA15 Main thread (ID 00001750) created
76E80000 Unload hidden module 76E80000
764A0000 Unload hidden module 764A0000
76E80000 Unload hidden module 76E80000
76D80000 Unload hidden module 76D80000
00240000 Module H:\dls\vegastrike\svn\win32\bin\glut32.dll
00300000 Module H:\dls\vegastrike\svn\win32\bin\xmlparse.dll
00370000 Module H:\dls\vegastrike\svn\win32\bin\SDL.dll
00400000 Module H:\dls\vegastrike\svn\win32\bin\Vegastrike-13222.exe
Different PE Data Directory in file and in memory (antivirus?)
Import table: file (00769BCC,000000F0), memory (010132EC,000000F0)
10000000 Module H:\dls\vegastrike\svn\win32\bin\OpenAL32.dll
1E000000 Module H:\dls\vegastrike\svn\win32\bin\python26.dll
67B10000 Module C:\Windows\system32\DDRAW.dll
67C00000 Module C:\Windows\system32\OPENGL32.dll
67D70000 Module C:\Windows\system32\GLU32.dll
6B3F0000 Module C:\Windows\system32\DCIMAN32.dll
73920000 Module C:\Windows\system32\WSOCK32.dll
73960000 Module C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCP90.dll
739F0000 Module C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll
74070000 Module C:\Windows\system32\dwmapi.dll
74360000 Module C:\Windows\system32\WINMM.dll
74610000 Module C:\Program Files\Alwil Software\Avast5\snxhk.dll
74FA0000 Module C:\Windows\syswow64\CRYPTBASE.dll
74FB0000 Module C:\Windows\syswow64\SspiCli.dll
75010000 Module C:\Windows\syswow64\RPCRT4.dll
75100000 Module C:\Windows\syswow64\CFGMGR32.dll
75130000 Module C:\Windows\syswow64\msvcrt.dll
75370000 Module C:\Windows\syswow64\ole32.dll
Code sections '.text' and '.orpc' will be merged to a single memory block
754D0000 Module C:\Windows\syswow64\SHLWAPI.dll
75530000 Module C:\Windows\syswow64\USP10.dll
755D0000 Module C:\Windows\syswow64\WS2_32.dll
75620000 Module C:\Windows\syswow64\SHELL32.dll
762C0000 Module C:\Windows\syswow64\NSI.dll
76450000 Module C:\Windows\syswow64\DEVOBJ.dll
764A0000 Module C:\Windows\syswow64\kernel32.dll
765B0000 Module C:\Windows\syswow64\SETUPAPI.dll
76AB0000 Module C:\Windows\syswow64\USER32.dll
76CF0000 Module C:\Windows\syswow64\GDI32.dll
76FB0000 Module C:\Windows\SysWOW64\sechost.dll
76FD0000 Module C:\Windows\syswow64\OLEAUT32.dll
77060000 Module C:\Windows\syswow64\KERNELBASE.dll
771D0000 Module C:\Windows\syswow64\ADVAPI32.dll
77420000 Module C:\Windows\syswow64\LPK.dll
77450000 Module C:\Windows\SysWOW64\ntdll.dll
Analysing ntdll
6091 fuzzy procedures
5553 calls to known, 4344 calls to guessed functions
211 switches, 1354 loops
Analysing kernel32
4405 fuzzy procedures
4282 calls to known, 2665 calls to guessed functions
106 switches, 680 loops
Analysing USER32
3708 fuzzy procedures
3421 calls to known, 4263 calls to guessed functions
158 switches, 427 loops
Analysing GDI32
2499 fuzzy procedures
2400 calls to known, 2806 calls to guessed functions
70 switches, 300 loops
Analysing SHELL32
36701 fuzzy procedures
15854 calls to known, 39812 calls to guessed functions
671 switches, 2558 loops
Analysing ADVAPI32
3024 fuzzy procedures
3682 calls to known, 2762 calls to guessed functions
72 switches, 638 loops
Analysing WINMM
1070 fuzzy procedures
1077 calls to known, 1933 calls to guessed functions
59 switches, 223 loops
Analysing dwmapi
321 fuzzy procedures
227 calls to known, 345 calls to guessed functions
4 switches, 13 loops
Analysing WSOCK32
46 fuzzy procedures
16 calls to known, 10 calls to guessed functions
1 switch, 3 loops
Analysing DCIMAN32
68 fuzzy procedures
48 calls to known, 19 calls to guessed functions
1 switch, 7 loops
Analysing DDRAW
2089 fuzzy procedures
1694 calls to known, 3343 calls to guessed functions
93 switches, 851 loops
Analysing OPENGL32
3083 fuzzy procedures
1014 calls to known, 2364 calls to guessed functions
273 switches, 1528 loops
Analysing GLU32
815 fuzzy procedures
79 calls to known, 1444 calls to guessed functions
60 switches, 408 loops
Analysing KERNELBASE
1096 fuzzy procedures
2073 calls to known, 1538 calls to guessed functions
80 switches, 401 loops
Analysing NSI
51 fuzzy procedures
25 calls to known, 31 calls to guessed functions
1 switch, 1 loop
Analysing msvcrt
3768 fuzzy procedures
4276 calls to known, 2874 calls to guessed functions
213 switches, 1087 loops
Analysing USP10
876 fuzzy procedures
945 calls to known, 2285 calls to guessed functions
232 switches, 1055 loops
Analysing LPK
55 fuzzy procedures
200 calls to known, 78 calls to guessed functions
10 switches, 49 loops
Analysing SHLWAPI
2693 fuzzy procedures
1826 calls to known, 2257 calls to guessed functions
62 switches, 304 loops
Analysing ole32
13418 fuzzy procedures
5575 calls to known, 14785 calls to guessed functions
201 switches, 1167 loops
Analysing CRYPTBASE
122 fuzzy procedures
71 calls to known, 62 calls to guessed functions
2 switches, 20 loops
Analysing SspiCli
364 fuzzy procedures
758 calls to known, 740 calls to guessed functions
15 switches, 194 loops
Analysing RPCRT4
5328 fuzzy procedures
2794 calls to known, 8691 calls to guessed functions
181 switches, 849 loops
Analysing OLEAUT32
4046 fuzzy procedures
2135 calls to known, 4826 calls to guessed functions
192 switches, 751 loops
Analysing sechost
367 fuzzy procedures
762 calls to known, 393 calls to guessed functions
19 switches, 168 loops
Analysing WS2_32
1258 fuzzy procedures
1112 calls to known, 1720 calls to guessed functions
16 switches, 261 loops
Analysing CFGMGR32
1137 fuzzy procedures
570 calls to known, 1492 calls to guessed functions
34 switches, 86 loops
Analysing DEVOBJ
464 fuzzy procedures
269 calls to known, 711 calls to guessed functions
11 switches, 35 loops
Analysing SETUPAPI
3442 fuzzy procedures
5912 calls to known, 7062 calls to guessed functions
107 switches, 469 loops
Analysing snxhk
627 fuzzy procedures
512 calls to known, 1139 calls to guessed functions
38 switches, 309 loops
Analysing MSVCR90
2583 fuzzy procedures
4819 calls to known, 2165 calls to guessed functions
227 switches, 965 loops
Analysing MSVCP90
3348 fuzzy procedures
3525 calls to known, 1758 calls to guessed functions
24 switches, 305 loops
Analysing python26
5770 fuzzy procedures
11276 calls to known, 4546 calls to guessed functions
224 switches, 1889 loops
Analysing OpenAL32
405 fuzzy procedures
349 calls to known, 791 calls to guessed functions
33 switches, 273 loops
Analysing SDL
952 fuzzy procedures
1337 calls to known, 356 calls to guessed functions
23 switches, 552 loops
Analysing xmlparse
1711 fuzzy procedures
209 calls to known, 814 calls to guessed functions
6 switches, 321 loops
Analysing glut32
460 fuzzy procedures
333 calls to known, 175 calls to guessed functions
67 loops
Analysing Vegastrike-13222
80248 fuzzy procedures
31940 calls to known, 45921 calls to guessed functions
480 switches, 7758 loops
73B40000 Module <Mod_73B4> (anonymous)
Not an 80x86 executable
73B50000 Module <Mod_73B5> (anonymous)
Not an 80x86 executable
73BB0000 Module <Mod_73BB> (anonymous)
Not an 80x86 executable
77270000 Module <Mod_7727> (anonymous)
Not an 80x86 executable
763C0000 Module C:\Windows\system32\IMM32.DLL
76750000 Module C:\Windows\syswow64\MSCTF.dll
Analysing IMM32
504 fuzzy procedures
1228 calls to known, 863 calls to guessed functions
32 switches, 190 loops
Analysing Mod_7727
0 fuzzy procedures
Analysing MSCTF
4920 fuzzy procedures
1716 calls to known, 6897 calls to guessed functions
70 switches, 545 loops
Analysing Mod_73BB
0 fuzzy procedures
Analysing Mod_73B5
0 fuzzy procedures
Analysing Mod_73B4
0 fuzzy procedures
009EEA15 Entry point of main module
72D70000 Module C:\Windows\system32\DINPUT.DLL
Analysing DINPUT
662 fuzzy procedures
753 calls to known, 1571 calls to guessed functions
29 switches, 188 loops
74240000 Module C:\Windows\system32\HID.DLL
Analysing HID
110 fuzzy procedures
45 calls to known, 49 calls to guessed functions
21 switches, 50 loops
75360000 Module C:\Windows\syswow64\MSASN1.dll
770B0000 Module C:\Windows\syswow64\CRYPT32.dll
Analysing MSASN1
283 fuzzy procedures
226 calls to known, 183 calls to guessed functions
15 switches, 58 loops
Analysing CRYPT32
4969 fuzzy procedures
6846 calls to known, 8378 calls to guessed functions
223 switches, 1515 loops
76420000 Module C:\Windows\syswow64\WINTRUST.dll
Analysing WINTRUST
1113 fuzzy procedures
1409 calls to known, 1319 calls to guessed functions
25 switches, 251 loops
74371EBA New thread 2. (ID 00001740) created
774941F3 New thread 3. (ID 000017DC) created
73F70000 Module C:\Windows\system32\PROPSYS.dll
Analysing PROPSYS
4139 fuzzy procedures
1753 calls to known, 5120 calls to guessed functions
142 switches, 447 loops
733F0000 Module C:\Windows\system32\MMDevAPI.DLL
Analysing MMDevAPI
2068 fuzzy procedures
855 calls to known, 1943 calls to guessed functions
19 switches, 196 loops
742A0000 Module C:\Windows\system32\ksuser.dll
Analysing ksuser
13 fuzzy procedures
7 calls to known, 8 calls to guessed functions
2 loops
74110000 Module C:\Windows\system32\AVRT.dll
Analysing AVRT
63 fuzzy procedures
103 calls to known, 57 calls to guessed functions
3 switches, 13 loops
72EA0000 Module C:\Windows\system32\wdmaud.drv
Code sections '.text' and 'RT_CODE' will be merged to a single memory block
Analysing wdmaud_drv
1304 fuzzy procedures
497 calls to known, 1806 calls to guessed functions
38 switches, 276 loops
72DD0000 Module C:\Windows\system32\AUDIOSES.DLL
Code size in header is 00029800, extended to end of section 'RT_CODE'
Code sections '.text' and '.orpc' will be merged to a single memory block
Code sections '.orpc' and 'RT_CODE' will be merged to a single memory block
Analysing AUDIOSES
1770 fuzzy procedures
687 calls to known, 1666 calls to guessed functions
7 switches, 100 loops
73310000 Module C:\Windows\system32\MSACM32.dll
743A0000 Module C:\Windows\system32\msacm32.drv
Analysing MSACM32
358 fuzzy procedures
665 calls to known, 804 calls to guessed functions
32 switches, 97 loops
Analysing msacm32_drv
89 fuzzy procedures
150 calls to known, 121 calls to guessed functions
12 switches, 21 loops
73200000 Module C:\Windows\system32\midimap.dll
Analysing midimap
82 fuzzy procedures
103 calls to known, 45 calls to guessed functions
3 switches, 26 loops
04910000 Module H:\dls\vegastrike\svn\win32\bin\wrap_oal.dll
Analysing wrap_oal
949 fuzzy procedures
321 calls to known, 2819 calls to guessed functions
174 switches, 544 loops
6F850000 Module C:\Windows\system32\POWRPROF.dll
Analysing POWRPROF
329 fuzzy procedures
428 calls to known, 541 calls to guessed functions
8 switches, 60 loops
6D600000 Module C:\Windows\system32\dsound.dll
Analysing dsound
2724 fuzzy procedures
554 calls to known, 2547 calls to guessed functions
54 switches, 509 loops
76820000 Module C:\Windows\syswow64\CLBCatQ.DLL
Analysing CLBCatQ
2421 fuzzy procedures
1410 calls to known, 2979 calls to guessed functions
87 switches, 599 loops
6D62E4A1 New thread 4. (ID 00001720) created
733F27E1 New thread 5. (ID 00000B20) created
77496679 New thread 6. (ID 000017EC) created
77496679 New thread 7. (ID 00000F48) created
6D62E4A1 New thread 8. (ID 0000085C) created
77496679 New thread 9. (ID 000016E4) created
Thread 6. (ID 000017EC) terminated, exit code 0
77496679 New thread 10. (ID 000013E8) created
Thread 2. (ID 00001740) terminated, exit code 0
Thread 5. (ID 00000B20) terminated, exit code 0
Thread 4. (ID 00001720) terminated, exit code 0
Thread 8. (ID 0000085C) terminated, exit code 0
6D62E4A1 New thread 11. (ID 0000160C) created
733F27E1 New thread 12. (ID 000000B8) created
6D62E4A1 New thread 13. (ID 00000BD4) created
Thread 12. (ID 000000B8) terminated, exit code 0
Thread 11. (ID 0000160C) terminated, exit code 0
Thread 13. (ID 00000BD4) terminated, exit code 0
04910000 Unload H:\dls\vegastrike\svn\win32\bin\wrap_oal.dll
04910000 Module H:\dls\vegastrike\svn\win32\bin\wrap_oal.dll
6D62E4A1 New thread 14. (ID 000010F0) created
733F27E1 New thread 15. (ID 000011FC) created
6D62E4A1 New thread 16. (ID 000009F0) created
6D604F9D New thread 17. (ID 00000BD8) created
774B14F1 New thread 18. (ID 00000E50) created
7436A3E0 New thread 19. (ID 000010BC) created
74250000 Module C:\Windows\SysWOW64\KBDUS.DLL - failed to initialize
73460000 Module C:\Windows\SysWOW64\KBDUS.DLL - failed to initialize
05B50000 Module C:\Windows\SysWOW64\ole32.dll - failed to initialize
74250000 Module C:\Windows\system32\atiglpxx.dll
Analysing atiglpxx
64 fuzzy procedures
41 calls to known, 10 calls to guessed functions
10 loops
73910000 Module C:\Windows\system32\VERSION.dll
Analysing VERSION
123 fuzzy procedures
188 calls to known, 79 calls to guessed functions
3 switches, 30 loops
69030000 Module C:\Windows\system32\atioglxx.dll
Code sections '.text' and '.text4' will be merged to a single memory block
Code sections '.text4' and '.text3' will be merged to a single memory block
Code sections '.text3' and '.text2' will be merged to a single memory block
Analysing atioglxx
40201 fuzzy procedures
3614 calls to known, 159675 calls to guessed functions
6067 switches, 37775 loops
77496679 New thread 20. (ID 0000059C) created
733C0000 Module C:\Windows\system32\WTSAPI32.dll
738D0000 Module C:\Windows\system32\profapi.dll
Invalid Image Export Directory, or system update is pending
Analysing profapi
208 fuzzy procedures
136 calls to known, 336 calls to guessed functions
2 switches, 26 loops
Analysing WTSAPI32
237 fuzzy procedures
280 calls to known, 153 calls to guessed functions
9 switches, 62 loops
75610000 Module C:\Windows\syswow64\PSAPI.DLL
Analysing PSAPI
40 fuzzy procedures
5 calls to known functions
Thread 9. (ID 000016E4) terminated, exit code 0
77496679 New thread 21. (ID 00000E10) created
73460000 Module C:\Windows\system32\atigktxx.dll
Analysing atigktxx
242 fuzzy procedures
78 calls to known, 67 calls to guessed functions
5 switches, 27 loops
Thread 10. (ID 000013E8) terminated, exit code 0
6C940000 Module C:\Windows\system32\aticfx32.dll
Analysing aticfx32
2622 fuzzy procedures
1693 calls to known, 3353 calls to guessed functions
108 switches, 702 loops
6C99067D New thread 22. (ID 00001604) created
69296450 New thread 23. (ID 00000B28) created
69296450 New thread 24. (ID 00001068) created
69296450 New thread 25. (ID 0000141C) created
005D3470 New thread 26. (ID 000009BC) created
05A50000 Module C:\Windows\system32\atiadlxy.dll
738E0000 Module C:\Windows\system32\USERENV.dll
Analysing USERENV
421 fuzzy procedures
381 calls to known, 708 calls to guessed functions
3 switches, 54 loops
Analysing atiadlxy
878 fuzzy procedures
1596 calls to known, 1209 calls to guessed functions
73 switches, 482 loops
7706B9BC Exception E06D7363 - exception is non-continuable