Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- fffff800`028c3b87 c20001 ret 100h
- fffff800`028c3b8a 7403 je nt!KiRestoreDebugRegisterState+0x4f (fffff800`028c3b8f)
- fffff800`028c3b8c 83c801 or eax,1
- fffff800`028c3b8f 85c0 test eax,eax
- fffff800`028c3b91 7412 je nt!KiRestoreDebugRegisterState+0x65 (fffff800`028c3ba5)
- fffff800`028c3b93 448bc0 mov r8d,eax
- fffff800`028c3b96 b9d9010000 mov ecx,1D9h
- fffff800`028c3b9b 0f32 rdmsr
- fffff800`028c3b9d 83e0fc and eax,0FFFFFFFCh
- fffff800`028c3ba0 410bc0 or eax,r8d
- fffff800`028c3ba3 0f30 wrmsr
- fffff800`028c3ba5 c20000 ret 0
- fffff800`028c3ba8 cc int 3
- fffff800`028c3ba9 cc int 3
- fffff800`028c3baa cc int 3
- fffff800`028c3bab cc int 3
- fffff800`028c3bac cc int 3
- fffff800`028c3bad cc int 3
- fffff800`028c3bae 6690 xchg ax,ax
- nt!KiSaveDebugRegisterState:
- fffff800`028c3bb0 654c8b0c2518000000 mov r9,qword ptr gs:[18h]
- fffff800`028c3bb9 0f21c0 mov rax,dr0
- fffff800`028c3bbc 0f21ca mov rdx,dr1
- fffff800`028c3bbf 48894558 mov qword ptr [rbp+58h],rax
- fffff800`028c3bc3 48895560 mov qword ptr [rbp+60h],rdx
- fffff800`028c3bc7 0f21d0 mov rax,dr2
- fffff800`028c3bca 0f21da mov rdx,dr3
- fffff800`028c3bcd 48894568 mov qword ptr [rbp+68h],rax
- fffff800`028c3bd1 48895570 mov qword ptr [rbp+70h],rdx
- fffff800`028c3bd5 0f21f0 mov rax,dr6
- fffff800`028c3bd8 0f21fa mov rdx,dr7
- fffff800`028c3bdb 48894578 mov qword ptr [rbp+78h],rax
- fffff800`028c3bdf 48899580000000 mov qword ptr [rbp+80h],rdx
- fffff800`028c3be6 33c0 xor eax,eax
- fffff800`028c3be8 0f23f8 mov dr7,rax
- fffff800`028c3beb 65f604254a4d000002 test byte ptr gs:[4D4Ah],2
- fffff800`028c3bf4 747d je nt!KiSaveDebugRegisterState+0xc3 (fffff800`028c3c73)
- fffff800`028c3bf6 66f7c20003 test dx,300h
- fffff800`028c3bfb 7476 je nt!KiSaveDebugRegisterState+0xc3 (fffff800`028c3c73)
- fffff800`028c3bfd 448b05b07a2300 mov r8d,dword ptr [nt!KiLastBranchTOSMSR (fffff800`02afb6b4)]
- fffff800`028c3c04 450bc0 or r8d,r8d
- fffff800`028c3c07 7408 je nt!KiSaveDebugRegisterState+0x61 (fffff800`028c3c11)
- fffff800`028c3c09 418bc8 mov ecx,r8d
- fffff800`028c3c0c 0f32 rdmsr
- fffff800`028c3c0e 448bc0 mov r8d,eax
- fffff800`028c3c11 8b0d91762300 mov ecx,dword ptr [nt!KiLastBranchFromBaseMSR (fffff800`02afb2a8)]
- fffff800`028c3c17 4103c8 add ecx,r8d
- fffff800`028c3c1a 0f32 rdmsr
- fffff800`028c3c1c 898598000000 mov dword ptr [rbp+98h],eax
- fffff800`028c3c22 8b0d28772300 mov ecx,dword ptr [nt!KiLastBranchToBaseMSR (fffff800`02afb350)]
- fffff800`028c3c28 89959c000000 mov dword ptr [rbp+9Ch],edx
- fffff800`028c3c2e 4103c8 add ecx,r8d
- fffff800`028c3c31 0f32 rdmsr
- fffff800`028c3c33 898590000000 mov dword ptr [rbp+90h],eax
- fffff800`028c3c39 899594000000 mov dword ptr [rbp+94h],edx
- fffff800`028c3c3f 8b0d37782300 mov ecx,dword ptr [nt!KiLastExceptionFromBaseMSR (fffff800`02afb47c)]
- fffff800`028c3c45 0f32 rdmsr
- fffff800`028c3c47 8985a8000000 mov dword ptr [rbp+0A8h],eax
- fffff800`028c3c4d 8995ac000000 mov dword ptr [rbp+0ACh],edx
- fffff800`028c3c53 8b0d1f782300 mov ecx,dword ptr [nt!KiLastExceptionToBaseMSR (fffff800`02afb478)]
- fffff800`028c3c59 0f32 rdmsr
- fffff800`028c3c5b 8985a0000000 mov dword ptr [rbp+0A0h],eax
- fffff800`028c3c61 8995a4000000 mov dword ptr [rbp+0A4h],edx
- fffff800`028c3c67 b9d9010000 mov ecx,1D9h
- fffff800`028c3c6c 0f32 rdmsr
- fffff800`028c3c6e 83e0fc and eax,0FFFFFFFCh
- fffff800`028c3c71 0f30 wrmsr
- fffff800`028c3c73 6641f781080200005503 test word ptr [r9+208h],355h
- fffff800`028c3c7d 746c je nt!KiSaveDebugRegisterState+0x13b (fffff800`028c3ceb)
- fffff800`028c3c7f 498b81e0010000 mov rax,qword ptr [r9+1E0h]
- fffff800`028c3c86 498b91e8010000 mov rdx,qword ptr [r9+1E8h]
- fffff800`028c3c8d 0f23c0 mov dr0,rax
- fffff800`028c3c90 0f23ca mov dr1,rdx
- fffff800`028c3c93 498b81f0010000 mov rax,qword ptr [r9+1F0h]
- fffff800`028c3c9a 498b91f8010000 mov rdx,qword ptr [r9+1F8h]
- fffff800`028c3ca1 0f23d0 mov dr2,rax
- fffff800`028c3ca4 0f23da mov dr3,rdx
- fffff800`028c3ca7 498b9108020000 mov rdx,qword ptr [r9+208h]
- fffff800`028c3cae 33c0 xor eax,eax
- fffff800`028c3cb0 0f23f0 mov dr6,rax
- fffff800`028c3cb3 0f23fa mov dr7,rdx
- fffff800`028c3cb6 65f604254a4d000002 test byte ptr gs:[4D4Ah],2
- fffff800`028c3cbf 742a je nt!KiSaveDebugRegisterState+0x13b (fffff800`028c3ceb)
- fffff800`028c3cc1 66f7c20002 test dx,200h
- fffff800`028c3cc6 7403 je nt!KiSaveDebugRegisterState+0x11b (fffff800`028c3ccb)
- fffff800`028c3cc8 83c802 or eax,2
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement