Цитата: хотелось бы взглянуть на лог vmmap.
каг его сделать?
vmmap.exe -p arc.exe vmmap.log
так? тогда вот ён [more]Process: arc.exe
PID: 912
Type Size Committed Total WS Private WS Shareable WS Shared WS Blocks Largest
Total 1 006 920 977 704 714 440 713 520 920 344 241
Image 20 384 20 384 1 188 296 892 320 129 8 300
Private 956 268 951 704 710 724 710 720 4 4 43 656 668
Shareable 6 124 2 160 20 20 16 16 3 072
Mapped File 644 644 5 260
Heap 2 752 308 128 124 4 4 21 1 024
Managed Heap
Stack 18 432 188 64 64 27 2 048
System 2 316 2 316 2 316 2 316
Free 1 092 484 241 116
Address Type Size Committed Total WS Private WS Shareable WS Shared WS Blocks Protection Details
00010000 Private 4 4 1 Read/Write
00020000 Private 4 4 4 4 1 Read/Write
00030000 Thread Stack 2 048 72 12 12 3 Read/Write Thread ID: 3736
00030000 Reserved 1 976
0021E000 Private 4 4 Read/Write/Guard
0021F000 Private 68 68 12 12 Read/Write
00230000 Private 4 4 1 Execute/Read/Write
00240000 Shareable 12 12 8 8 8 1 Read
00250000 Heap (Private) 1 024 40 16 16 4 Read/Write Heap ID: 0 (Default)
00250000 Private 32 32 8 8 Read/Write Heap ID: 0 (Default)
00258000 Reserved 124 Heap ID: 0 (Default)
00277000 Private 8 8 8 8 Read/Write Heap ID: 0 (Default)
00279000 Reserved 860 Heap ID: 0 (Default)
00350000 Heap (Private) 64 24 12 12 2 Read/Write Heap ID: 1
00350000 Private 24 24 12 12 Read/Write Heap ID: 0 (Default)
00356000 Reserved 40 Heap ID: 0 (Default)
00360000 Heap (Mapped) 64 12 4 4 4 2 Read/Write Heap ID: 2
00360000 Mapped 12 12 4 4 4 Read/Write Heap ID: 0 (Default)
00363000 Reserved 52 Heap ID: 0 (Default)
00370000 Mapped File 88 88 1 Read C:\WINDOWS\system32\unicode.nls
00390000 Mapped File 260 260 1 Read C:\WINDOWS\system32\locale.nls
003E0000 Mapped File 24 24 1 Read C:\WINDOWS\system32\sorttbls.nls
003F0000 Image 36 36 4 Execute/Copy on Write C:\WINDOWS\system32\normaliz.dll
003F0000 Image 4 4 Read Header
003F1000 Image 20 20 Execute .text
003F6000 Image 4 4 Read/Write .data
003F7000 Image 4 4 Read .rsrc
003F8000 Image 4 4 Read .reloc
00400000 Image 2 892 2 892 652 80 572 14 Execute/Copy on Write G:\InnoSetup\Toolz\Arc.exe
00400000 Image 4 4 4 4 Read Header
00401000 Image 2 392 2 392 540 540 Execute/Read .text
00657000 Image 100 100 60 60 Read/Write .data
00670000 Image 112 112 28 28 Read .rdata
0068C000 Image 4 4 4 4 Read/Write .bss
0068D000 Image 124 124 Copy on write .bss
006AC000 Image 4 4 Read/Write .bss
006AD000 Image 4 4 Copy on write .bss
006AE000 Image 4 4 Read/Write .bss
006AF000 Image 4 4 Copy on write .bss
006B0000 Image 92 92 Read/Write .bss
006C7000 Image 12 12 Copy on write .bss
006CA000 Image 16 16 16 16 Read/Write .bss
006CE000 Image 8 8 Copy on write .idata
006D0000 Image 12 12 Copy on write .rsrc
006E0000 Mapped File 260 260 1 Read C:\WINDOWS\system32\sortkey.nls
00730000 Shareable 800 56 4 4 4 4 Execute/Read
00730000 Mapped 48 48 Execute/Read
0073C000 Reserved 720
007F0000 Mapped 8 8 4 4 4 Execute/Read
007F2000 Reserved 24
00800000 Shareable 1 036 1 036 1 Read
00910000 Heap (Private) 64 32 4 4 2 Read/Write Heap ID: 3
00910000 Private 32 32 4 4 Read/Write Heap ID: 0 (Default)
00918000 Reserved 32 Heap ID: 0 (Default)
00920000 Shareable 3 072 848 2 Execute/Read
00920000 Mapped 848 848 Execute/Read
009F4000 Reserved 2 224
00C20000 Private 4 4 1 Read/Write
00C30000 Private 4 4 1 Read/Write
00C40000 Heap (Private) 64 64 24 24 1 Read/Write Heap ID: 4
00C50000 Mapped File 12 12 1 Read C:\WINDOWS\system32\ctype.nls
00C60000 Heap (Private) 64 16 4 4 2 Read/Write Heap ID: 5
00C60000 Private 16 16 4 4 Read/Write Heap ID: 0 (Default)
00C64000 Reserved 48 Heap ID: 0 (Default)
00C70000 Shareable 8 8 1 Read
00C80000 Private 4 4 1 Execute/Read/Write
00C90000 Shareable 8 8 1 Read
00CA0000 Heap (Private) 256 12 4 4 2 Read/Write Heap ID: 7
00CA0000 Private 12 12 4 4 Read/Write Heap ID: 0 (Default)
00CA3000 Reserved 244 Heap ID: 0 (Default)
00CE0000 Shareable 4 4 4 4 1 Read
00CF0000 Heap (Private) 64 28 12 12 2 Read/Write Heap ID: 8
00CF0000 Private 28 28 12 12 Read/Write Heap ID: 0 (Default)
00CF7000 Reserved 36 Heap ID: 0 (Default)
00D00000 Private 128 4 2 Read/Write
00D00000 Private 4 4 Read/Write
00D01000 Reserved 124
00D20000 Shareable 8 8 1 Read
00D30000 Heap (Private) 1 024 24 4 4 2 Read/Write Heap ID: 6
00D30000 Private 24 24 4 4 Read/Write Heap ID: 0 (Default)
00D36000 Reserved 1 000 Heap ID: 0 (Default)
00E30000 Thread Stack 2 048 8 3 Read/Write Thread ID: 2524
00E30000 Reserved 2 040
0102E000 Private 4 4 Read/Write/Guard
0102F000 Private 4 4 Read/Write
01030000 Private 2 048 1 024 720 720 5 Read/Write
01030000 Reserved 832
01100000 Private 500 500 196 196 Read/Write
0117D000 Private 4 4 4 4 Execute/Read/Write
0117E000 Private 520 520 520 520 Read/Write
01200000 Reserved 192
01230000 Private 4 4 1 Execute/Read/Write
01240000 Thread Stack 2 048 8 4 4 3 Read/Write Thread ID: 2868
01240000 Reserved 2 040
0143E000 Private 4 4 Read/Write/Guard
0143F000 Private 4 4 4 4 Read/Write
01440000 Heap (Private) 64 56 44 44 2 Read/Write Heap ID: 9
01440000 Private 56 56 44 44 Read/Write Heap ID: 0 (Default)
0144E000 Reserved 8 Heap ID: 0 (Default)
01450000 Private 64 64 64 64 1 Read/Write
01480000 Shareable 8 8 1 Read
01490000 Thread Stack 2 048 16 12 12 3 Read/Write Thread ID: 2460
01490000 Reserved 2 032
0168C000 Private 4 4 Read/Write/Guard
0168D000 Private 12 12 12 12 Read/Write
01690000 Thread Stack 2 048 16 12 12 3 Read/Write Thread ID: 1660
01690000 Reserved 2 032
0188C000 Private 4 4 Read/Write/Guard
0188D000 Private 12 12 12 12 Read/Write
01890000 Private 1 024 528 268 268 4 Read/Write
01890000 Private 260 260 8 8 Read/Write
018D1000 Reserved 252
01910000 Private 268 268 260 260 Read/Write
01953000 Reserved 244
01990000 Private 2 048 1 024 336 336 3 Read/Write
01990000 Reserved 448
01A00000 Private 1 024 1 024 336 336 Read/Write
01B00000 Reserved 576
01B90000 Image 580 580 100 100 11 Execute/Copy on Write C:\Program Files\FreeArc\bin\facompress.dll
01B90000 Image 4 4 Read Header
01B91000 Image 304 304 60 60 Execute .text
01BDD000 Image 4 4 Execute .text1
01BDE000 Image 40 40 8 8 Read .rdata
01BE8000 Image 12 12 4 4 Read/Write .data
01BEB000 Image 124 124 Copy on write .data
01C0A000 Image 4 4 4 4 Read/Write .data
01C0B000 Image 12 12 Copy on write .data
01C0E000 Image 12 12 12 12 Read/Write .data
01C11000 Image 8 8 Copy on write .data
01C13000 Image 16 16 8 8 Read/Write .data
01C17000 Image 8 8 4 4 Read/Write .data1
01C19000 Image 8 8 Read .trace
01C1B000 Image 24 24 Read .reloc
01C30000 Thread Stack 2 048 20 3 Read/Write Thread ID: 2476
01C30000 Reserved 2 028
01E2B000 Private 4 4 Read/Write/Guard
01E2C000 Private 16 16 Read/Write
01E30000 Private 16 388 16 388 1 Read/Write
02E40000 Thread Stack 2 048 24 12 12 3 Read/Write Thread ID: 2992
02E40000 Reserved 2 024
0303A000 Private 4 4 Read/Write/Guard
0303B000 Private 20 20 12 12 Read/Write
03040000 Private 10 240 9 216 20 20 3 Read/Write
03040000 Reserved 768
03100000 Private 9 216 9 216 20 20 Read/Write
03A00000 Reserved 256
03A40000 Private 1 024 212 92 92 2 Read/Write
03A40000 Private 212 212 92 92 Read/Write
03A75000 Reserved 812
03B40000 Thread Stack 2 048 16 12 12 3 Read/Write Thread ID: 3720
03B40000 Reserved 2 032
03D3C000 Private 4 4 Read/Write/Guard
03D3D000 Private 12 12 12 12 Read/Write
03EA0000 Thread Stack 2 048 8 3 Read/Write Thread ID: 3440
03EA0000 Reserved 2 040
0409E000 Private 4 4 Read/Write/Guard
0409F000 Private 4 4 Read/Write
040A0000 Private 4 100 4 100 4 096 4 096 1 Read/Write
10000000 Image 340 340 60 20 40 40 7 Execute/Copy on Write C:\Program Files\Agnitum\Outpost Firewall\wl_hook.dll
10000000 Image 4 4 Read Header
10001000 Image 256 256 36 36 36 Execute/Read .text
10041000 Image 40 40 8 4 4 4 Read .rdata
1004B000 Image 4 4 4 4 Read/Write .data
1004C000 Image 4 4 4 4 Execute/Read/Write .data
1004D000 Image 8 8 8 8 Read/Write .data
1004F000 Image 4 4 Read/Write .IN_HOOK
10050000 Image 4 4 Read .rsrc
10051000 Image 16 16 Read .reloc
1AF40000 Private 656 668 656 668 442 688 442 688 1 Read/Write
43090000 Image 276 276 8 8 5 Execute/Copy on Write C:\WINDOWS\system32\iertutil.dll
43090000 Image 4 4 Read Header
43091000 Image 232 232 4 4 Execute/Read .text
430CB000 Image 4 4 4 4 Read/Write .data
430CC000 Image 4 4 Copy on write .data
430CD000 Image 4 4 Read .rsrc
430CE000 Image 28 28 Read .reloc
43310000 Image 832 832 16 12 4 4 5 Execute/Copy on Write C:\WINDOWS\system32\wininet.dll
43310000 Image 4 4 Read Header
43311000 Image 624 624 4 4 Execute/Read .text
433AD000 Image 12 12 8 8 Read/Write .data
433B0000 Image 20 20 4 4 4 Copy on write .data
433B5000 Image 148 148 Read .rsrc
433DA000 Image 24 24 Read .reloc
4D560000 Private 262 404 262 404 262 404 262 404 1 Read/Write
5D5B0000 Image 616 616 4 Execute/Copy on Write C:\WINDOWS\system32\comctl32.dll
5D5B0000 Image 4 4 Read Header
5D5B1000 Image 452 452 Execute/Read .text
5D622000 Image 12 12 Read/Write .data
5D625000 Image 128 128 Read .rsrc
5D645000 Image 20 20 Read .reloc
62F00000 Image 36 36 4 Execute/Copy on Write C:\WINDOWS\system32\lpk.dll
62F00000 Image 4 4 Read Header
62F01000 Image 20 20 Execute/Read .text
62F06000 Image 4 4 Read/Write .data
62F07000 Image 4 4 Read .rsrc
62F08000 Image 4 4 Read .reloc
71A80000 Image 32 32 4 Execute/Copy on Write C:\WINDOWS\system32\ws2help.dll
71A80000 Image 4 4 Read Header
71A81000 Image 16 16 Execute/Read .text
71A85000 Image 4 4 Read/Write .data
71A86000 Image 4 4 Read .rsrc
71A87000 Image 4 4 Read .reloc
71A90000 Image 92 92 8 8 4 Execute/Copy on Write C:\WINDOWS\system32\ws2_32.dll
71A90000 Image 4 4 Read Header
71A91000 Image 76 76 4 4 Execute/Read .text
71AA4000 Image 4 4 4 4 Read/Write .data
71AA5000 Image 4 4 Read .rsrc
71AA6000 Image 4 4 Read .reloc
71AB0000 Image 40 40 4 Execute/Copy on Write C:\WINDOWS\system32\wsock32.dll
71AB0000 Image 4 4 Read Header
71AB1000 Image 12 12 Execute/Read .text
71AB4000 Image 4 4 Read/Write .data
71AB5000 Image 16 16 Read .rsrc
71AB9000 Image 4 4 Read .reloc
75540000 Image 428 428 7 Execute/Copy on Write C:\WINDOWS\system32\usp10.dll
75540000 Image 4 4 Read Header
75541000 Image 272 272 Execute/Read .text
75585000 Image 40 40 Copy on write .data
7558F000 Image 8 8 Read/Write .data
75591000 Image 12 12 Copy on write .data
75594000 Image 4 4 Read/Write .data
75595000 Image 8 8 Read Shared
75597000 Image 72 72 Read .rsrc
755A9000 Image 8 8 Read .reloc
76360000 Image 116 116 12 4 8 8 4 Execute/Copy on Write C:\WINDOWS\system32\imm32.dll
76360000 Image 4 4 Read Header
76361000 Image 84 84 8 8 8 Execute/Read .text
76376000 Image 4 4 4 4 Read/Write .data
76377000 Image 20 20 Read .rsrc
7637C000 Image 4 4 Read .reloc
773C0000 Image 1 036 1 036 4 Execute/Copy on Write C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
773C0000 Image 4 4 Read Header
773C1000 Image 580 580 Execute/Read .text
77452000 Image 4 4 Read/Write .data
77453000 Image 424 424 Read .rsrc
774BD000 Image 24 24 Read .reloc
77C00000 Image 352 352 92 16 76 76 5 Execute/Copy on Write C:\WINDOWS\system32\msvcrt.dll
77C00000 Image 4 4 Read Header
77C01000 Image 304 304 76 76 76 Execute/Read .text
77C4D000 Image 8 8 Copy on write .data
77C4F000 Image 20 20 16 16 Read/Write .data
77C54000 Image 4 4 Read .rsrc
77C55000 Image 12 12 Read .reloc
77DC0000 Image 688 688 8 4 4 4 5 Execute/Copy on Write C:\WINDOWS\system32\advapi32.dll
77DC0000 Image 4 4 Read Header
77DC1000 Image 468 468 4 4 4 Execute/Read .text
77E36000 Image 4 4 4 4 Read/Write .data
77E37000 Image 16 16 Copy on write .data
77E3B000 Image 176 176 Read .rsrc
77E67000 Image 20 20 Read .reloc
77E70000 Image 584 584 4 4 4 4 Execute/Copy on Write C:\WINDOWS\system32\rpcrt4.dll
77E70000 Image 4 4 Read Header
77E71000 Image 524 524 4 4 4 Execute/Read .text
77EF4000 Image 28 28 Execute/Read .orpc
77EFB000 Image 4 4 Read/Write .data
77EFC000 Image 4 4 Read .rsrc
77EFD000 Image 20 20 Read .reloc
77F10000 Image 292 292 4 Execute/Copy on Write C:\WINDOWS\system32\gdi32.dll
77F10000 Image 4 4 Read Header
77F11000 Image 268 268 Execute/Read .text
77F54000 Image 8 8 Read/Write .data
77F56000 Image 4 4 Read .rsrc
77F57000 Image 8 8 Read .reloc
77F60000 Image 472 472 4 Execute/Copy on Write C:\WINDOWS\system32\shlwapi.dll
77F60000 Image 4 4 Read Header
77F61000 Image 432 432 Execute/Read .text
77FCD000 Image 4 4 Read/Write .data
77FCE000 Image 8 8 Read .rsrc
77FD0000 Image 24 24 Read .reloc
77FE0000 Image 68 68 4 Execute/Copy on Write C:\WINDOWS\system32\secur32.dll
77FE0000 Image 4 4 Read Header
77FE1000 Image 52 52 Execute/Read .text
77FEE000 Image 4 4 Read/Write .data
77FEF000 Image 4 4 Read .rsrc
77FF0000 Image 4 4 Read .reloc
7C800000 Image 992 992 72 12 60 60 5 Execute/Copy on Write C:\WINDOWS\system32\kernel32.dll
7C800000 Image 4 4 4 4 4 Read Header
7C801000 Image 528 528 64 8 56 56 Execute/Read .text
7C885000 Image 12 12 4 4 Read/Write .data
7C888000 Image 8 8 Copy on write .data
7C88A000 Image 416 416 Read .rsrc
7C8F2000 Image 24 24 Read .reloc
7C900000 Image 704 704 144 24 120 120 6 Execute/Copy on Write C:\WINDOWS\system32\ntdll.dll
7C900000 Image 4 4 4 4 4 Read Header
7C901000 Image 488 488 128 12 116 116 Execute/Read .text
7C97B000 Image 12 12 12 12 Read/Write .data
7C97E000 Image 4 4 Copy on write .data
7C97F000 Image 4 4 Read/Write .data
7C980000 Image 180 180 Read .rsrc
7C9AD000 Image 12 12 Read .reloc
7C9C0000 Image 8 300 8 300 12 8 4 4 6 Execute/Copy on Write C:\WINDOWS\system32\shell32.dll
7C9C0000 Image 4 4 Read Header
7C9C1000 Image 2 040 2 040 8 4 4 4 Execute/Read .text
7CBBF000 Image 64 64 Copy on write .data
7CBCF000 Image 24 24 4 4 Read/Write .data
7CBD5000 Image 28 28 Copy on write .data
7CBDC000 Image 6 032 6 032 Read .rsrc
7D1C0000 Image 108 108 Read .reloc
7E360000 Image 580 580 5 Execute/Copy on Write C:\WINDOWS\system32\user32.dll
7E360000 Image 4 4 Read Header
7E361000 Image 384 384 Execute/Read .text
7E3C1000 Image 4 4 Read/Write .data
7E3C2000 Image 4 4 Copy on write .data
7E3C3000 Image 172 172 Read .rsrc
7E3EE000 Image 12 12 Read .reloc
7F6F0000 Shareable 1 024 28 2 Execute/Read
7F6F0000 Mapped 28 28 Execute/Read
7F6F7000 Reserved 996
7FFB0000 Shareable 144 144 4 4 4 1 Read
7FFD5000 Private 4 4 4 4 1 Read/Write
7FFD6000 Private 4 4 1 Read/Write
7FFD8000 Private 4 4 4 4 1 Read/Write
7FFD9000 Private 4 4 4 4 1 Read/Write
7FFDA000 Private 4 4 1 Read/Write
7FFDB000 Private 4 4 4 4 1 Read/Write
7FFDC000 Private 4 4 4 4 1 Read/Write
7FFDD000 Private 4 4 4 4 1 Read/Write
7FFDE000 Private 4 4 1 Read/Write
7FFDF000 Private 4 4 4 4 1 Read/Write
7FFE0000 Private 64 4 4 4 4 2 Read
7FFE0000 Private 4 4 4 4 4 Read
7FFE1000 Reserved 60
[/more]
Цитата: если лень, то устранити причины - сдвиньте базовые адреса dll-ок и будет Вам счастье.
а это как и чем?