GrayFace - 2015-09-23

AdvOR frequently crashes when I stop intercept of plugin-container.exe
by unchecking the check box in Intercept->Processes. Today I was lucky
and it actually generated a crash log.

BIG FUCKING ERROR C0000005
AdvOR version: 0.3.0.20
Exception code: EXCEPTION_ACCESS_VIOLATION
Address: 00000000
Cause: Write to address: 00000000
EAX=00000414 EBX=00001230 ECX=0022F410 EDX=7C90E514
ESI=00000000 EDI=000C082C EBP=0022F4C4 ESP=0022F498
DR0=00000000 DR1=00000000 DR2=00000000 DR3=00000000
DR6=00000000 DR7=00000000 FS =0000003B GS =00000000
CS =0000001B DS =00000023 ES =00000023 SS =00000023
EIP=00000000 EFlags=00210206

 [EAX]: FREE: 00000000, len: 00010000
 [EBX]: FREE: 00001000, len: 0000F000
 [ECX]: [RW]: 0022F000, len: 00001000 [ C0 FB 22 00 00 00 00 00 00

00 00 00 BC 7A 85 B3 01 00 00 00 00 80 85 B3 64 7D 85 B3 00 00 00 00 ]
[EDX]: [RWX]: 7C90E000, len: 00070000 [ C3 8D A4 24 00 00 00 00 8D
64 24 00 8D 54 24 08 CD 2E C3 90 55 8B EC 9C 81 EC D0 02 00 00 89 85 ]

[ESI]: FREE: 00000000, len: 00010000
[EDI]: RESERVED: 000C0000, len: 0016B000
[EBP]: [RW]: 0022F000, len: 00001000 [ F4 F4 22 00 0B 6D 47 00 30
12 00 00 70 30 00 00 05 10 00 00 00 00 00 00 58 29 B8 00 00 00 00 00 ]

[ESP]: [RW]: 0022F000, len: 00001000 [ 82 5F 00 10 14 04 00 00 00
00 00 00 00 40 00 00 00 30 00 00 40 00 00 00 30 12 00 00 2C 08 0C 00 ]

[EIP]: FREE: 00000000, len: 00010000

 Module: unknown

[unknown] [Virtual] PC=00000000, Return = 10005F82, SP=0022F498, Params:
00000414, 00000000, 00004000, 00003000
[AdvOR.dll] [Virtual] PC=10005F82, Return = 00476D0B, SP=0022F498,
Params: 00001230, 00003070, 00001005, 00000000
[AdvOR.exe] [Virtual] PC=00476D0B, Return = 7E368734, SP=0022F498,
Params: 000C082C, 0000004E, 00003070, 0022F82C
[USER32.dll] [Virtual] PC=7E368734, Return = 7E373CE4, SP=0022F498,
Params: 00476A20, 000C082C, 0000004E, 00003070
[USER32.dll] [Virtual] PC=7E373CE4, Return = 7E373B30, SP=0022F498,
Params: 00000000, 00476A20, 000C082C, 0000004E
[USER32.dll] [Virtual] PC=7E373B30, Return = 7E373D5C, SP=0022F498,
Params: 00000000, 0000004E, 00003070, 0022F82C
[USER32.dll] [Virtual] PC=7E373D5C, Return = 7E368734, SP=0022F498,
Params: 000C082C, 0000004E, 00003070, 0022F82C
[USER32.dll] [Virtual] PC=7E368734, Return = 7E368816, SP=0022F498,
Params: 7E373D3A, 000C082C, 0000004E, 00003070
[USER32.dll] [Virtual] PC=7E368816, Return = 7E378EA0, SP=0022F498,
Params: 00000000, 7E373D3A, 000C082C, 0000004E
[USER32.dll] [Virtual] PC=7E378EA0, Return = 7E378EEC, SP=0022F498,
Params: 00ED5560, 0000004E, 00003070, 0022F82C
[USER32.dll] [Virtual] PC=7E378EEC, Return = 7C90E473, SP=0022F498,
Params: 0022F710, 00000018, 00ED5560, 0000004E
[ntdll.dll] [Virtual] PC=7C90E473, Return = 7E3792E3, SP=0022F498,
Params: 00ED5560, 0000004E, 00003070, 0022F82C
[USER32.dll] [Virtual] PC=7E3792E3, Return = 5D5B682C, SP=0022F498,
Params: 000C082C, 0000004E, 00003070, 0022F82C
[COMCTL32.DLL] [Virtual] PC=5D5B682C, Return = 5D5CCFF4, SP=0022F498,
Params: 002519E0, FFFFFF9B, 0022F82C, 000608AA
[COMCTL32.DLL] [Virtual] PC=5D5CCFF4, Return = 5D5CCF59, SP=0022F498,
Params: 002519E0, 0000002D, 00000000, FFFFFF9B
[COMCTL32.DLL] [Virtual] PC=5D5CCF59, Return = 5D5CCD7E, SP=0022F498,
Params: 00000008, 0022F8DC, 0000F000, 00000002
[COMCTL32.DLL] [Virtual] PC=5D5CCD7E, Return = 5D6108B3, SP=0022F498,
Params: 002519E0, 0000002D, 00001000, 0000F000
[COMCTL32.DLL] [Virtual] PC=5D6108B3, Return = 5D61104E, SP=0022F498,
Params: 002519E0, 0000002D, 01800004, 002519E0
[COMCTL32.DLL] [Virtual] PC=5D61104E, Return = 5D61116F, SP=0022F498,
Params: 000608AA, 00000000, 00000004, 00000180
[COMCTL32.DLL] [Virtual] PC=5D61116F, Return = 5D5B90A8, SP=0022F498,
Params: 002519E0, 00000000, 00000004, 00000180
[COMCTL32.DLL] [Virtual] PC=5D5B90A8, Return = 7E368734, SP=0022F498,
Params: 000608AA, 00000201, 00000001, 01800004
[USER32.dll] [Virtual] PC=7E368734, Return = 7E368816, SP=0022F498,
Params: 5D5B6E16, 000608AA, 00000201, 00000001
[USER32.dll] [Virtual] PC=7E368816, Return = 7E3689CD, SP=0022F498,
Params: 00000000, 5D5B6E16, 000608AA, 00000201
[USER32.dll] [Virtual] PC=7E3689CD, Return = 7E368A10, SP=0022F498,
Params: 0022FC8C, 00000000, 0022FC70, 7E3774FF
[USER32.dll] [Virtual] PC=7E368A10, Return = 7E3774FF, SP=0022F498,
Params: 0022FC8C, 00000000, 00EAFA78, 00000001
[USER32.dll] [Virtual] PC=7E3774FF, Return = 7E37763C, SP=0022F498,
Params: 000F08F6, 00ED5758, 00000000, 00000000
[USER32.dll] [Virtual] PC=7E37763C, Return = 7E3749C4, SP=0022F498,
Params: 000F08F6, 00000000, 00000010, 00000000
[USER32.dll] [Virtual] PC=7E3749C4, Return = 7E374A06, SP=0022F498,
Params: 00400000, 00B90C08, 00000000, 0047B480
[USER32.dll] [Virtual] PC=7E374A06, Return = 7E3747EA, SP=0022F498,
Params: 00400000, 00B90C08, 00000000, 0047B480
[USER32.dll] [Virtual] PC=7E3747EA, Return = 0092F10E, SP=0022F498,
Params: 00400000, 000003E8, 00000000, 0047B480
[AdvOR.exe] [Virtual] PC=0092F10E, Return = 0099194A, SP=0022F498,
Params: 00000001, 010F2C78, 00AC24A0, 00991933
[AdvOR.exe] [Virtual] PC=0099194A, Return = 004010B6, SP=0022F498,
Params: 00000001, 010F2C78, 010F2EC0, 00B7C004
[AdvOR.exe] [Virtual] PC=004010B6, Return = 00401128, SP=0022F498,
Params: 00000002, 806214CE, 7C90DCBA, 7C816034
[AdvOR.exe] [Virtual] PC=00401128, Return = 7C816037, SP=0022F498,
Params: 00300036, 00320036, 7FFDE000, C0000005
[kernel32.dll] [Virtual] PC=7C816037, Return = 00000000, SP=0022F498,
Params: 00401110, 00000000, 78746341, 00000020


--

Best regards,
Sergey "GrayFace" Rozhenko, mailto:sergroj@mail.ru