Documente Academic
Documente Profesional
Documente Cultură
thread $6f8:
4a68eb98 +30 MADHCNET32.DLL madCodeHook LpcPortThread
75ee3742 +22 KERNEL32.DLL
BaseThreadInitThunk
thread $c58:
76068d03 +93
76068c5d +0d
4a68e81a +12
75ee3742 +22
<priority:1>
KERNELBASE.dll
WaitForSingleObjectEx
KERNELBASE.dll
WaitForSingleObject
MADHCNET32.DLL madCodeHook LpcDispatchThread
KERNEL32.DLL
BaseThreadInitThunk
thread $b5c:
76068d03 +93
76068c5d +0d
4a68e763 +17
75ee3742 +22
KERNELBASE.dll
WaitForSingleObjectEx
KERNELBASE.dll
WaitForSingleObject
MADHCNET32.DLL madCodeHook LpcWorkerThread
KERNEL32.DLL
BaseThreadInitThunk
thread $7b0:
75ee3742 +22 KERNEL32.DLL BaseThreadInitThunk
thread $1390:
74923255 +25 USER32.dll
GetMessageW
75ee3742 +22 KERNEL32.DLL BaseThreadInitThunk
thread $13cc:
74923255 +25 USER32.dll
GetMessageW
75ee3742 +22 KERNEL32.DLL BaseThreadInitThunk
thread $98c:
76068d03 +93 KERNELBASE.dll WaitForSingleObjectEx
76068c5d +0d KERNELBASE.dll WaitForSingleObject
75ee3742 +22 KERNEL32.DLL
BaseThreadInitThunk
thread $e74:
76068d03 +93 KERNELBASE.dll WaitForSingleObjectEx
76068c5d +0d KERNELBASE.dll WaitForSingleObject
75ee3742 +22 KERNEL32.DLL
BaseThreadInitThunk
KeyboardThreadProc ($ef4):
76071280 +130 KERNELBASE.dll
WaitForMultipleObjectsEx
7490a495 +175 USER32.dll
MsgWaitForMultipleObjectsEx
7490a30a +01a USER32.dll
MsgWaitForMultipleObjects
4a45fdb0 +050 madVR.ax
osd.cpp 1462 +7 COsd.KeyboardThreadMethod
4a45fd01 +061 madVR.ax
osd.cpp 1449 +3 KeyboardThreadProc
75ee3742 +022 KERNEL32.DLL
BaseThreadInitThunk
thread $85c: <priority:15>
76071280 +130 KERNELBASE.dll WaitForMultipleObjectsEx
76071133 +013 KERNELBASE.dll WaitForMultipleObjects
75ee3742 +022 KERNEL32.DLL
BaseThreadInitThunk
thread $7a8:
76071133 +13 KERNELBASE.dll WaitForMultipleObjects
76ef725c +8c msvcrt.dll
_endthreadex
75ee3742 +22 KERNEL32.DLL
BaseThreadInitThunk
CheckWindowConnectionThread ($1028):
76068d03 +93 KERNELBASE.dll
WaitForSingleObjectEx
76068c5d +0d KERNELBASE.dll
WaitForSingleObject
4a692d4d +41 MADHCNET32.DLL madNetTools 1143 +6 CheckWindowConnectionThread
BaseThreadInitThunk
<priority:15>
KERNELBASE.dll WaitForMultipleObjectsEx
KERNELBASE.dll WaitForMultipleObjects
KERNEL32.DLL
BaseThreadInitThunk
KERNELBASE.dll
WaitForMultipleObjectsEx
KERNELBASE.dll
WaitForMultipleObjects
madVR.ax
madvr.cpp
3826 +35 CVideoRenderer.Receive
madVR.ax
_freebuf.c
58 +0 CMediaSample.GetProperties
madVR.ax
customren.cpp 1630 +6 CCustomRendererInputPin.Rece
thread $40c:
76068d03 +93
76068c5d +0d
75ee3742 +22
KERNEL32.DLL
BaseThreadInitThunk
<priority:1>
KERNELBASE.dll WaitForSingleObjectEx
KERNELBASE.dll WaitForSingleObject
KERNEL32.DLL
BaseThreadInitThunk
thread $8b4:
760713c2 +92 KERNELBASE.dll SleepEx
7607131a +0a KERNELBASE.dll Sleep
75ee3742 +22 KERNEL32.DLL
BaseThreadInitThunk
thread $128:
773f919a +00a
76071280 +130
76071133 +013
773f8c6a +00a
7607448e +00e
76ef725c +08c
75ee3742 +022
ntdll.dll
KERNELBASE.dll
KERNELBASE.dll
ntdll.dll
KERNELBASE.dll
msvcrt.dll
KERNEL32.DLL
NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjects
NtReleaseSemaphore
ReleaseSemaphore
_endthreadex
BaseThreadInitThunk
thread $c70:
773f919a +00a
76071280 +130
76071133 +013
76ef725c +08c
75ee3742 +022
ntdll.dll
KERNELBASE.dll
KERNELBASE.dll
msvcrt.dll
KERNEL32.DLL
NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjects
_endthreadex
BaseThreadInitThunk
thread $aac:
773f919a +00a
76071280 +130
76071133 +013
76ef725c +08c
75ee3742 +022
ntdll.dll
KERNELBASE.dll
KERNELBASE.dll
msvcrt.dll
KERNEL32.DLL
NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjects
_endthreadex
BaseThreadInitThunk
thread $110c:
773f919a +00a
76071280 +130
76071133 +013
76ef725c +08c
75ee3742 +022
ntdll.dll
KERNELBASE.dll
KERNELBASE.dll
msvcrt.dll
KERNEL32.DLL
NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjects
_endthreadex
BaseThreadInitThunk
thread $131c:
773f919a +00a
76071280 +130
76071133 +013
76ef725c +08c
75ee3742 +022
ntdll.dll
KERNELBASE.dll
KERNELBASE.dll
msvcrt.dll
KERNEL32.DLL
NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjects
_endthreadex
BaseThreadInitThunk
1.7.0.7670
1.0.28.0
11.0.10240.16384
11.0.10240.16384
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Program Files (x86)\NVIDIA
0.86.11.0
1.0.15.0
9.17.10.4229
10.18.13.5384
0.58.2.0
C:\Windows\system32
C:\Windows\SYSTEM32
C:\Program Files (x86)\KCP\LAV
6.12.2.633
6.3.10240.16384
6.3.10240.16384
3.0.0.211
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Program Files (x86)\KCP\xyC:\Program Files (x86)\KCP\LAV
C:\Program Files (x86)\KCP\LAV
6.3.10240.16384
0.58.2.0
C:\Windows\SYSTEM32
C:\Program Files (x86)\KCP\LAV
C:\Program Files (x86)\KCP\LAV
C:\Program Files (x86)\KCP\LAV
C:\Program Files (x86)\KCP\LAV
C:\Program Files (x86)\KCP\LAV
0.58.2.0
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
717b0000 AVRT.dll
6.3.10240.16384
C:\Windows\SYSTEM32
717c0000 ksuser.dll
6.3.10240.16384
C:\Windows\SYSTEM32
717d0000 wdmaud.drv
6.3.10240.16384
C:\Windows\SYSTEM32
71810000 PROPSYS.dll
7.0.10240.16384
C:\Windows\System32
71960000 MMDevApi.dll
6.3.10240.16384
C:\Windows\System32
719c0000 explorerframe.dll
6.3.10240.16384
C:\Windows\system32
71df0000 quartz.dll
6.3.10240.16384
C:\Windows\SYSTEM32
71fa0000 WINSTA.dll
6.3.10240.16384
C:\Windows\SYSTEM32
71ff0000 twinapi.appcore.dll 6.3.10240.16384
C:\Windows\system32
720b0000 dcomp.dll
6.3.10240.16384
C:\Windows\system32
72150000 dxgi.dll
6.3.10240.16384
C:\Windows\system32
721d0000 d3d11.dll
6.3.10240.16384
C:\Windows\system32
723f0000 d2d1.dll
6.3.10240.16384
C:\Windows\system32
72880000 dataexchange.dll
6.3.10240.16384
C:\Windows\system32
728c0000 rsaenh.dll
6.3.10240.16384
C:\Windows\system32
728f0000 WindowsCodecs.dll
6.3.10240.16384
C:\Windows\SYSTEM32
72b00000 dnsapi.dll
6.3.10240.16384
C:\Windows\SYSTEM32
72c40000 nvdxgiwrap.dll
10.18.13.5384
C:\Program Files (x86)\NVIDIA
Corporation\CoProcManager
72c60000 nvd3d9wrap.dll
10.18.13.5384
C:\Program Files (x86)\NVIDIA
Corporation\CoProcManager
72d40000 cryptsp.dll
6.3.10240.16384
C:\Windows\SYSTEM32
72d60000 msdmo.dll
6.3.10240.16384
C:\Windows\SYSTEM32
72d70000 devenum.dll
6.3.10240.16384
C:\Windows\SYSTEM32
72d90000 oledlg.dll
6.3.10240.16384
C:\Windows\SYSTEM32
72db0000 OLEACC.dll
7.2.10240.16384
C:\Windows\SYSTEM32
72e10000 gdiplus.dll
6.3.10240.16384
C:\Windows\WinSxS\x86_microsof
t.windows.gdiplus_6595b64144ccf1df_1.1.10240.16384_none_d15682eeaf714889
72f80000 DSOUND.dll
6.3.10240.16384
C:\Windows\SYSTEM32
73050000 dbgcore.DLL
6.3.10240.16384
C:\Windows\SYSTEM32
73080000 dbghelp.dll
6.3.10240.16384
C:\Windows\SYSTEM32
73200000 netutils.dll
6.3.10240.16384
C:\Windows\SYSTEM32
73210000 WINNSI.DLL
6.3.10240.16384
C:\Windows\SYSTEM32
73220000 WININET.dll
11.0.10240.16384
C:\Windows\SYSTEM32
73450000 COMCTL32.dll
6.10.10240.16384
C:\Windows\WinSxS\x86_microsof
t.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_3bccb1ff6bcd1849
73660000 srvcli.dll
6.3.10240.16384
C:\Windows\SYSTEM32
73680000 wkscli.dll
6.3.10240.16384
C:\Windows\SYSTEM32
73740000 iphlpapi.dll
6.3.10240.16384
C:\Windows\SYSTEM32
73770000 UxTheme.dll
6.3.10240.16384
C:\Windows\SYSTEM32
737f0000 MSIMG32.dll
6.3.10240.16384
C:\Windows\SYSTEM32
73800000 WTSAPI32.dll
6.3.10240.16384
C:\Windows\SYSTEM32
73810000 netapi32.dll
6.3.10240.16384
C:\Windows\SYSTEM32
73d60000 WINMMBASE.dll
6.3.10240.16384
C:\Windows\SYSTEM32
73da0000 dwmapi.dll
6.3.10240.16384
C:\Windows\SYSTEM32
73f00000 WINMM.dll
6.3.10240.16384
C:\Windows\SYSTEM32
74140000 USERENV.dll
6.3.10240.16384
C:\Windows\system32
74160000 wsock32.dll
6.3.10240.16384
C:\Windows\SYSTEM32
74300000 ntmarta.dll
6.3.10240.16384
C:\Windows\SYSTEM32
74330000 DEVOBJ.dll
6.3.10240.16384
C:\Windows\SYSTEM32
74360000 nvinit.dll
10.18.13.5384
C:\Windows\SYSTEM32
74390000 bcrypt.dll
6.3.10240.16384
C:\Windows\SYSTEM32
743b0000 WINSPOOL.DRV
6.3.10240.16384
C:\Windows\SYSTEM32
74420000 VERSION.dll
6.3.10240.16384
C:\Windows\SYSTEM32
74430000 bcryptPrimitives.dll 6.3.10240.16384
C:\Windows\SYSTEM32
74490000 CRYPTBASE.dll
6.3.10240.16384
C:\Windows\SYSTEM32
744a0000 SspiCli.dll
6.3.10240.16384
C:\Windows\SYSTEM32
744c0000 MSCTF.dll
6.3.10240.16384
C:\Windows\SYSTEM32
745e0000 coml2.dll
6.3.10240.16384
C:\Windows\SYSTEM32
74640000 cfgmgr32.dll
6.3.10240.16384
C:\Windows\SYSTEM32
74680000
74800000
748f0000
74a30000
75df0000
75e40000
75ed0000
75fc0000
76140000
761c0000
76250000
76260000
76270000
76310000
76460000
76540000
766a0000
766d0000
76890000
768e0000
76940000
76950000
76e30000
76e80000
76e90000
76f50000
76f60000
771e0000
77390000
CRYPT32.dll
ole32.dll
USER32.dll
SHELL32.dll
WINTRUST.dll
clbcatq.dll
KERNEL32.DLL
KERNELBASE.dll
ADVAPI32.dll
shcore.dll
kernel.appcore.dll
profapi.dll
OLEAUT32.dll
GDI32.dll
COMDLG32.dll
shlwapi.dll
IMM32.dll
combase.dll
sechost.dll
WS2_32.dll
NSI.dll
windows.storage.dll
powrprof.dll
MSASN1.dll
msvcrt.dll
PSAPI.DLL
RPCRT4.dll
SETUPAPI.dll
ntdll.dll
processes:
0000 Idle
0004 System
0170 smss.exe
0200 csrss.exe
025c wininit.exe
026c csrss.exe
02a4 services.exe
02c8 lsass.exe
02d0 winlogon.exe
0344 svchost.exe
0380 svchost.exe
03dc dwm.exe
011c svchost.exe
0258 svchost.exe
0354 svchost.exe
0404 svchost.exe
0424 nvSCPAPISvr.exe
042c nvvsvc.exe
0494 svchost.exe
04d0 nvxdsync.exe
04d8 nvvsvc.exe
0540 svchost.exe
0638 svchost.exe
0730 spoolsv.exe
07ec armsvc.exe
07f4 svchost.exe
07fc ETDService.exe
0584 svchost.exe
0724 mqsvc.exe
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
2001.12.10941.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
7.0.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
6.3.10240.16384
0
0
0
0
0
1
0
0
1
0
0
1
0
0
0
0
0
0
0
1
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
0840 rpcnetp.exe
0 0
0870 svchost.exe
0 0
0898 svchost.exe
0 0
08a4 svchost.exe
0 0
08c4 SMSvcHost.exe
0 0
08d8 vmms.exe
0 0
0978 MsMpEng.exe
0 0
0ad8 SMSvcHost.exe
0 0
09c4 NisSrv.exe
0 0
0c50 sihost.exe
1 4
0c64 taskeng.exe
0 0
0cac GoogleUpdate.exe
0 0
0ce0 ETDCtrl.exe
1 338
0d50 explorer.exe
1 411
0db4 RuntimeBroker.exe
1 4
0ee0 ETDCtrlHelper.exe
1 0
0d9c SearchIndexer.exe
0 0
0e7c ETDGesture.exe
1 40
0280 ShellExperienceHost.exe 1 4
xperienceHost_cw5n1h2txyewy
0e38 SearchUI.exe
1 17
oft.Windows.Cortana_cw5n1h2txyewy
103c taskhostw.exe
1 13
10f4 dllhost.exe
1 4
13d0 nvtray.exe
1 81
oration\Display
0f50 NvBackend.exe
1 4
A Corporation\Update Core
0f18 igfxtray.exe
1 7
10ec hkcmd.exe
1 4
03f4 igfxpers.exe
1 4
1008 WUDFHost.exe
0 0
08cc mpc-hc.exe
1 214
PC-HC
0270 audiodg.exe
0 0
0548 WmiPrvSE.exe
0 0
0694 svchost.exe
1 4
139c madHcCtrl.exe
1 62
adVR
0
0
0
0
0
0
0
0
0
19
0
0
127
378
8
0
0
12
67
normal
C:\Windows\System32
44 normal
C:\Windows\SystemApps\Micros
17 normal
4 normal
4 normal
C:\Windows\System32
C:\Windows\System32
C:\Program Files\NVIDIA Corp
normal
5
17
4
0
279
normal
normal
normal
C:\Windows\System32
C:\Windows\System32
C:\Windows\System32
normal
0
0
1 normal
27 normal
C:\Windows\System32
C:\Program Files (x86)\KCP\m
hardware:
+ {1ed2bbf9-11f0-4084-b21f-ad83a8e6dcdc}
- Fax
- Microsoft Print to PDF
- Microsoft XPS Document Writer
- Root Print Queue
+ {36fc9e60-c465-11cf-8056-444553540000}
- ASMedia USB 3.0 eXtensible Host Controller - 0.96 (Microsoft)
- Generic USB Hub
- Intel(R) 6 Series/C200 Series Chipset Family USB Enhanced Host Controller 1C26
- Intel(R) 6 Series/C200 Series Chipset Family USB Enhanced Host Controller 1C2D
- USB Mass Storage Device
- USB Root Hub
- USB Root Hub (xHCI)
+ {4d36e965-e325-11ce-bfc1-08002be10318}
- HL-DT-ST DVDRAM GT51N
+ {4d36e966-e325-11ce-bfc1-08002be10318}
- ACPI x64-based PC
+ {4d36e967-e325-11ce-bfc1-08002be10318}
- ADATA HD710 USB Device
- Hitachi HTS545050B9A300
+ {4d36e968-e325-11ce-bfc1-08002be10318}
- Intel(R) HD Graphics 3000 (driver 9.17.10.4229)
- NVIDIA GeForce 610M
(driver 10.18.13.5384)
+ {4d36e96a-e325-11ce-bfc1-08002be10318}
- Intel(R) 6 Series/C200 Series Chipset Family 6 Port SATA AHCI Controller - 1
C03 (driver 9.2.0.1011)
+ {4d36e96b-e325-11ce-bfc1-08002be10318}
- Standard PS/2 Keyboard
+ {4d36e96c-e325-11ce-bfc1-08002be10318}
- Intel(R) Display Audio (driver 6.14.0.3097)
- Realtek High Definition Audio (driver 6.0.1.6716)
+ {4d36e96e-e325-11ce-bfc1-08002be10318}
- Generic PnP Monitor
+ {4d36e96f-e325-11ce-bfc1-08002be10318}
- ELAN PS/2 Port Input Device (driver 11.5.2.1)
- HID-compliant mouse
+ {4d36e972-e325-11ce-bfc1-08002be10318}
- Microsoft Kernel Debug Network Adapter
- Microsoft Wi-Fi Direct Virtual Adapter
- Qualcomm Atheros AR8151 PCI-E Gigabit Ethernet Controller (NDIS 6.30)
- Qualcomm Atheros AR9485WB-EG Wireless Network Adapter (driver 10.0.0.321)
+ {4d36e97b-e325-11ce-bfc1-08002be10318}
- Microsoft Storage Spaces Controller
+ {4d36e97d-e325-11ce-bfc1-08002be10318}
- 2nd Generation Intel(R) Core(TM) Processor Family DRAM Controller - 0104 (dr
iver 9.2.0.1026)
- 2nd generation Intel(R) Core(TM) processor family PCI Express Controller - 0
101 (driver 10.1.1.14)
- ACPI Fixed Feature Button
- ACPI Lid
- ACPI Sleep Button
- ACPI Thermal Zone
- Composite Bus Enumerator
- Direct memory access controller
- High Definition Audio Controller
- High precision event timer
- Intel(R) 6 Series/C200 Series Chipset Family PCI Express Root Port 1 - 1C10
(driver 10.1.1.14)
- Intel(R) 6 Series/C200 Series Chipset Family PCI Express Root Port 2 - 1C12
(driver 10.1.1.14)
- Intel(R) 6 Series/C200 Series Chipset Family PCI Express Root Port 4 - 1C16
(driver 10.1.1.14)
- Intel(R) 6 Series/C200 Series Chipset Family PCI Express Root Port 6 - 1C1A
(driver 10.1.1.14)
- Intel(R) 6 Series/C200 Series Chipset Family SMBus Controller - 1C22 (driver
9.2.0.1011)
- Intel(R) HM65 Express Chipset Family LPC Interface Controller - 1C49 (driver
10.1.1.14)
- Intel(R) Management Engine Interface (driver 11.0.0.1157)
- Legacy device
- Microsoft ACPI-Compliant Embedded Controller
- Microsoft ACPI-Compliant System
- Microsoft Basic Display Driver
- Microsoft Basic Render Driver
- Microsoft Hyper-V PCI Server
- Microsoft Hyper-V Virtual Disk Server
- Microsoft Hyper-V Virtual Machine Bus Provider
+
+
+
+
cpu
eax
ebx
ecx
edx
esi
edi
eip
esp
ebp
registers:
= 6ed411b0
= 0125d3d0
= 0dc1ca00
= 0dc1c804
= 0dc1cd80
= 80004005
= 09a50000
= 0dc1bd38
= 0dc1c870
stack dump:
0dc1bd38 0a
0dc1bd48 00
0dc1bd58 00
0dc1bd68 b0
00
00
00
11
2b
00
36
d4
70
00
74
6e
00
00
00
a0
ca
00
00
73
c1
00
00
c6
0d
00
00
72
01
00
a0
00
00
00
00
00
00
00
cf
00
00
00
6f
00
01
00
00
30
00
00
00
56
00
00
c6
c6
00
00
72
72
..+p............
................
..6t.......o...r
...n.s.r....0V.r
0dc1bd78
0dc1bd88
0dc1bd98
0dc1bda8
0dc1bdb8
0dc1bdc8
0dc1bdd8
0dc1bde8
0dc1bdf8
0dc1be08
0dc1be18
0dc1be28
0dc1be38
0dc1be48
0dc1be58
0dc1be68
0e
60
4c
00
20
30
00
00
00
00
00
00
56
36
33
00
00
77
41
00
48
00
00
00
00
00
00
00
45
26
26
00
07
68
59
00
44
00
00
00
00
00
00
00
4e
53
52
00
80
70
31
00
20
00
00
00
00
00
00
00
5f
55
45
00
80
a8
00
00
47
00
00
00
00
00
00
00
38
42
56
00
bd
01
00
00
72
00
00
00
00
00
00
00
30
53
5f
00
c1
00
00
00
61
00
00
00
00
00
00
00
38
59
30
00
0d
00
00
00
70
00
00
00
00
00
00
00
36
53
39
00
01
5c
00
49
68
00
00
00
00
00
00
05
26
5f
00
00
00
5c
00
6e
69
00
00
00
00
00
00
00
44
31
00
00
00
2e
00
74
63
00
00
00
00
00
00
00
45
36
00
00
00
5c
00
65
73
00
00
00
00
00
00
00
56
35
00
00
80
44
00
6c
20
00
00
00
00
00
00
50
5f
32
00
00
4c
49
00
28
33
00
00
00
00
00
00
43
30
31
00
00
00
53
00
52
30
00
00
00
00
00
00
49
31
30
00
00
80
50
00
29
30
00
00
00
00
00
00
5c
31
34
00
00
.............L..
`whp....\\.\DISP
LAY1............
........Intel(R)
HD Graphics 300
0...............
................
................
................
................
................
............PCI\
VEN_8086&DEV_011
6&SUBSYS_1652104
3&REV_09........
................
disassembling:
4a409c20
public direct3d.cpp.CDirect3D.OpenAdapterCallbackMethod: ; functi
on entry point
4a409c20 1550 push
ebp
4a409c21
mov
ebp, esp
4a409c23
sub
esp, 8
4a409c26
mov
[ebp-8], ecx
4a409c29 1551 mov
eax, [ebp+8]
4a409c2c
push
eax
4a409c2d
mov
ecx, [ebp-8]
4a409c30
mov
edx, [ecx+$e38]
4a409c36
> call
edx
4a409c38
mov
[ebp-4], eax
4a409c3b 1553 cmp
dword ptr [ebp-4], 0
4a409c3f
jl
loc_4a409c72
4a409c41
mov
eax, [ebp-8]
4a409c44
cmp
dword ptr [eax+$e3c], 0
4a409c4b
jnz
loc_4a409c72
4a409c4d 1554 push
0
4a409c4f
mov
ecx, [ebp-8]
4a409c52
add
ecx, $e3c
4a409c58
push
ecx
4a409c59
mov
edx, [ebp-8]
4a409c5c
mov
eax, [edx+$e78]
4a409c62
push
eax
4a409c63
mov
ecx, [ebp+8]
4a409c66
mov
edx, [ecx+$10]
4a409c69
mov
eax, [edx+4]
4a409c6c
push
eax
4a409c6d
call
+$d3f1e ($4a4ddb90)
; madvr.cpp.HookCode (madVR.ax)
4a409c72 1556 mov
eax, [ebp-4]
4a409c75 1557 mov
esp, ebp
[...]