Advertisement
Guest User

Crash Debug Disassembly

a guest
Jul 28th, 2011
124
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.11 KB | None | 0 0
  1. nt!KeBugCheckEx:
  2. fffff800`028c3700 48894c2408 mov qword ptr [rsp+8],rcx ss:fffff880`06838210=000000000000001e
  3. fffff800`028c3705 4889542410 mov qword ptr [rsp+10h],rdx
  4. fffff800`028c370a 4c89442418 mov qword ptr [rsp+18h],r8
  5. fffff800`028c370f 4c894c2420 mov qword ptr [rsp+20h],r9
  6. fffff800`028c3714 9c pushfq
  7. fffff800`028c3715 4883ec30 sub rsp,30h
  8. fffff800`028c3719 fa cli
  9. fffff800`028c371a 65488b0c2520000000 mov rcx,qword ptr gs:[20h]
  10. fffff800`028c3723 4881c120010000 add rcx,120h
  11. fffff800`028c372a e841060000 call nt!RtlCaptureContext (fffff800`028c3d70)
  12. fffff800`028c372f 65488b0c2520000000 mov rcx,qword ptr gs:[20h]
  13. fffff800`028c3738 4883c140 add rcx,40h
  14. fffff800`028c373c e8ef020000 call nt!KiSaveProcessorControlState (fffff800`028c3a30)
  15. fffff800`028c3741 654c8b142520000000 mov r10,qword ptr gs:[20h]
  16. fffff800`028c374a 4981c220010000 add r10,120h
  17. fffff800`028c3751 488b442440 mov rax,qword ptr [rsp+40h]
  18. fffff800`028c3756 49898280000000 mov qword ptr [r10+80h],rax
  19. fffff800`028c375d 488b442430 mov rax,qword ptr [rsp+30h]
  20. fffff800`028c3762 49894244 mov qword ptr [r10+44h],rax
  21. fffff800`028c3766 488d056cffffff lea rax,[nt!KiBugCheckReturn+0x5 (fffff800`028c36d9)]
  22. fffff800`028c376d 483b442438 cmp rax,qword ptr [rsp+38h]
  23. fffff800`028c3772 750e jne nt!KeBugCheckEx+0x82 (fffff800`028c3782)
  24. fffff800`028c3774 4c8d442468 lea r8,[rsp+68h]
  25. fffff800`028c3779 4c8d0d50ffffff lea r9,[nt!KeBugCheck (fffff800`028c36d0)]
  26. fffff800`028c3780 eb0c jmp nt!KeBugCheckEx+0x8e (fffff800`028c378e)
  27. fffff800`028c3782 4c8d442438 lea r8,[rsp+38h]
  28. fffff800`028c3787 4c8d0d72ffffff lea r9,[nt!KeBugCheckEx (fffff800`028c3700)]
  29. fffff800`028c378e 4d898298000000 mov qword ptr [r10+98h],r8
  30. fffff800`028c3795 4d898af8000000 mov qword ptr [r10+0F8h],r9
  31. fffff800`028c379c 440f20c0 mov rax,cr8
  32. fffff800`028c37a0 6588042598480000 mov byte ptr gs:[4898h],al
  33. fffff800`028c37a8 3c02 cmp al,2
  34. fffff800`028c37aa 7d09 jge nt!KeBugCheckEx+0xb5 (fffff800`028c37b5)
  35. fffff800`028c37ac b902000000 mov ecx,2
  36. fffff800`028c37b1 440f22c1 mov cr8,rcx
  37. fffff800`028c37b5 488b442430 mov rax,qword ptr [rsp+30h]
  38. fffff800`028c37ba 482500020000 and rax,200h
  39. fffff800`028c37c0 7401 je nt!KeBugCheckEx+0xc3 (fffff800`028c37c3)
  40. fffff800`028c37c2 fb sti
  41. fffff800`028c37c3 f0ff05ce0d1a00 lock inc dword ptr [nt!KiHardwareTrigger (fffff800`02a64598)]
  42. fffff800`028c37ca 488b4c2440 mov rcx,qword ptr [rsp+40h]
  43. fffff800`028c37cf 48c744242800000000 mov qword ptr [rsp+28h],0
  44. fffff800`028c37d8 488d05fafeffff lea rax,[nt!KiBugCheckReturn+0x5 (fffff800`028c36d9)]
  45. fffff800`028c37df 483b442438 cmp rax,qword ptr [rsp+38h]
  46. fffff800`028c37e4 741f je nt!KeBugCheckEx+0x105 (fffff800`028c3805)
  47. fffff800`028c37e6 488b442460 mov rax,qword ptr [rsp+60h]
  48. fffff800`028c37eb 4889442420 mov qword ptr [rsp+20h],rax
  49. fffff800`028c37f0 4c8b4c2458 mov r9,qword ptr [rsp+58h]
  50. fffff800`028c37f5 4c8b442450 mov r8,qword ptr [rsp+50h]
  51. fffff800`028c37fa 488b542448 mov rdx,qword ptr [rsp+48h]
  52. fffff800`028c37ff e88c740f00 call nt!KeBugCheck2 (fffff800`029bac90)
  53. fffff800`028c3804 90 nop
  54. fffff800`028c3805 48c744242000000000 mov qword ptr [rsp+20h],0
  55. fffff800`028c380e 4533c9 xor r9d,r9d
  56. fffff800`028c3811 4533c0 xor r8d,r8d
  57. fffff800`028c3814 33d2 xor edx,edx
  58. fffff800`028c3816 e875740f00 call nt!KeBugCheck2 (fffff800`029bac90)
  59. fffff800`028c381b 90 nop
  60. fffff800`028c381c cc int 3
  61. fffff800`028c381d cc int 3
  62. fffff800`028c381e cc int 3
  63. fffff800`028c381f cc int 3
  64. fffff800`028c3820 cc int 3
  65. fffff800`028c3821 cc int 3
  66. fffff800`028c3822 6666666666660f1f840000000000 nop word ptr [rax+rax]
  67. nt!KeContextToKframes:
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement