|
1: kd> uf NtCreateDebugObject
nt!NtCreateDebugObject:
fffff800`042697a0 48895c2408 mov qword ptr [rsp+8],rbx
''''省略''''
fffff800`04269813 488364242000 and qword ptr [rsp+20h],0
fffff800`04269819 458aca mov r9b,r10b
'''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''计算DbgkDebugObjectType'
fffff800`0426981c 488b158dd3daff mov rdx,qword ptr [nt!DbgkDebugObjectType (fffff800`04016bb0)]
我用 fffff800`0426981c + 7 + ffdad38d = FFFFF80104016BB0
与正确的地址出入 100000000
求助过路的师兄
|
|