State.xml 2.5 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889
  1. <?xml version="1.0"?>
  2. <State>
  3. <Threads>
  4. <!-- One Thread element for each thread -->
  5. <Thread Id="XXXXXXXX" StartAddr="XXXXXXXX" StartModule="abcdefgh.ijk" StartSym="&lt;nosymbols&gt;">
  6. <Registers
  7. EAX="01234567" EBX="89ABCDEF" ECX="01234567" EDX="89ABCDEF" ESI="01234567"
  8. EDI="89ABCDEF" EBP="01234567" ESP="89ABCDEF" EIP="01234567" FLG="89ABCDEF"
  9. CS="0123" DS="4567" SS="89AB" ES="CDEF" FS="0123" GS="4567"
  10. /> <!-- TODO: include floating-point registers -->
  11. <Stack Dump="0000000018431300d261360100000000ffffffff383f13003038130063007300630072006900700074002e006500780065000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000">
  12. <!-- One Frm element for each stack frame of thread -->
  13. <Frm
  14. ProgCnt="XXXXXXXX"
  15. FramePtr="XXXXXXXX"
  16. RetAddr="XXXXXXXX"
  17. Params="XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX"
  18. Module="abcdefjh.ijk"
  19. SymName="">
  20. <!-- If a function table entry exists for the stack frame -->
  21. <FPO
  22. OffStart="XXXXXXXX"
  23. ProcSize="XXXXXXXX"
  24. Locals="XXXXXXXX"
  25. Params="XXXX"
  26. Prolog="XX"
  27. RegsSaved="XX"
  28. HasSEH="1"
  29. UseBP="1"
  30. Frame="NONFPO"
  31. />
  32. </Frm>
  33. </Stack>
  34. </Thread>
  35. </Threads>
  36. <Modules>
  37. <Module
  38. Name="F:\WINNT\system32\ADVAPI32.DLL"
  39. LoadAddr="77DB0000"
  40. LoadSize="0005A000"
  41. FileSize="00057510"
  42. FileDate="19991202"
  43. FileTime="073000"
  44. FileVer="5.0.2191.1"
  45. ProdVer="5.0.2191.1"
  46. IsDebug="0"
  47. Company="Microsoft Corporation"
  48. Desc="Advanced Windows 32 Base API"
  49. ProdName="Microsoft(R) Windows (R) 2000 Operating System"
  50. Copy="Copyright (C) Microsoft Corp. 1981-1999"
  51. />
  52. <!-- One Module element for each loaded module -->
  53. </Modules>
  54. <Processes>
  55. <Process
  56. Name="F:\WINNT\system32\notepad.exe"
  57. FileSize="0000C710"
  58. FileDate="19991130"
  59. FileTime="154000"
  60. FileVer="5.0.2140.1"
  61. ProdVer="5.0.2140.1"
  62. IsDebug="0"
  63. Company="Microsoft Corporation"
  64. Desc="Notepad"
  65. ProdName="Microsoft(R) Windows (R) 2000 Operating System"
  66. Copy="Copyright (C) Microsoft Corp. 1981-1999"
  67. />
  68. <!-- One Process element for each loaded module (except for debuggee) -->
  69. </Processes>
  70. </State>