Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- kd> uf Kitrap00
- nt!Kei386EoiHelper:
- 8053dea8 fa cli
- 8053dea9 f7457000000200 test dword ptr [ebp+70h],20000h
- 8053deb0 7506 jne nt!KiExceptionExit+0x10 (8053deb8)
- nt!KiExceptionExit+0xa:
- 8053deb2 f6456c01 test byte ptr [ebp+6Ch],1
- 8053deb6 7434 je nt!KiExceptionExit+0x44 (8053deec)
- nt!KiExceptionExit+0x10:
- 8053deb8 8b1d24f1dfff mov ebx,dword ptr ds:[0FFDFF124h]
- 8053debe c6432e00 mov byte ptr [ebx+2Eh],0
- 8053dec2 807b4a00 cmp byte ptr [ebx+4Ah],0
- 8053dec6 7424 je nt!KiExceptionExit+0x44 (8053deec)
- nt!KiExceptionExit+0x20:
- 8053dec8 8bdd mov ebx,ebp
- 8053deca b901000000 mov ecx,1
- 8053decf ff15f4764d80 call dword ptr [nt!_imp_KfRaiseIrql (804d76f4)]
- 8053ded5 50 push eax
- 8053ded6 fb sti
- 8053ded7 53 push ebx
- 8053ded8 6a00 push 0
- 8053deda 6a01 push 1
- 8053dedc e84dfbfbff call nt!KiDeliverApc (804fda2e)
- 8053dee1 59 pop ecx
- 8053dee2 ff151c774d80 call dword ptr [nt!_imp_KfLowerIrql (804d771c)]
- 8053dee8 fa cli
- 8053dee9 ebcd jmp nt!KiExceptionExit+0x10 (8053deb8)
- nt!KiExceptionExit+0x44:
- 8053deec 8b54244c mov edx,dword ptr [esp+4Ch]
- 8053def0 648b1d50000000 mov ebx,dword ptr fs:[50h]
- 8053def7 64891500000000 mov dword ptr fs:[0],edx
- 8053defe f7c3ff000000 test ebx,0FFh
- 8053df04 754e jne nt!KiExceptionExit+0xac (8053df54)
- nt!KiExceptionExit+0x5e:
- 8053df06 f744247000000200 test dword ptr [esp+70h],20000h
- 8053df0e 0f85c0000000 jne nt!KiExceptionExit+0x12c (8053dfd4)
- nt!KiExceptionExit+0x6c:
- 8053df14 66f744246cf8ff test word ptr [esp+6Ch],0FFF8h
- 8053df1b 7477 je nt!KiExceptionExit+0xec (8053df94)
- nt!KiExceptionExit+0x75:
- 8053df1d 8b54243c mov edx,dword ptr [esp+3Ch]
- 8053df21 8b4c2440 mov ecx,dword ptr [esp+40h]
- 8053df25 8b442444 mov eax,dword ptr [esp+44h]
- 8053df29 66837d6c08 cmp word ptr [ebp+6Ch],8
- 8053df2e 740c je nt!KiExceptionExit+0x94 (8053df3c)
- nt!KiExceptionExit+0x88:
- 8053df30 8d6530 lea esp,[ebp+30h]
- 8053df33 0fa9 pop gs
- 8053df35 07 pop es
- 8053df36 1f pop ds
- 8053df37 8d6550 lea esp,[ebp+50h]
- 8053df3a 0fa1 pop fs
- nt!KiExceptionExit+0x94:
- 8053df3c 8d6554 lea esp,[ebp+54h]
- 8053df3f 5f pop edi
- 8053df40 5e pop esi
- 8053df41 5b pop ebx
- 8053df42 5d pop ebp
- 8053df43 66817c24088000 cmp word ptr [esp+8],80h
- 8053df4a 0f87a0000000 ja nt!KiExceptionExit+0x148 (8053dff0)
- nt!KiExceptionExit+0xa8:
- 8053df50 83c404 add esp,4
- 8053df53 cf iretd
- nt!KiExceptionExit+0xac:
- 8053df54 f7457000000200 test dword ptr [ebp+70h],20000h
- 8053df5b 7509 jne nt!KiExceptionExit+0xbe (8053df66)
- nt!KiExceptionExit+0xb5:
- 8053df5d f7456c01000000 test dword ptr [ebp+6Ch],1
- 8053df64 74a0 je nt!KiExceptionExit+0x5e (8053df06)
- nt!KiExceptionExit+0xbe:
- 8053df66 33db xor ebx,ebx
- 8053df68 8b7518 mov esi,dword ptr [ebp+18h]
- 8053df6b 8b7d1c mov edi,dword ptr [ebp+1Ch]
- 8053df6e 0f23fb mov dr7,ebx
- 8053df71 0f23c6 mov dr0,esi
- 8053df74 8b5d20 mov ebx,dword ptr [ebp+20h]
- 8053df77 0f23cf mov dr1,edi
- 8053df7a 0f23d3 mov dr2,ebx
- 8053df7d 8b7524 mov esi,dword ptr [ebp+24h]
- 8053df80 8b7d28 mov edi,dword ptr [ebp+28h]
- 8053df83 8b5d2c mov ebx,dword ptr [ebp+2Ch]
- 8053df86 0f23de mov dr3,esi
- 8053df89 0f23f7 mov dr6,edi
- 8053df8c 0f23fb mov dr7,ebx
- 8053df8f e972ffffff jmp nt!KiExceptionExit+0x5e (8053df06)
- nt!KiExceptionExit+0xec:
- 8053df94 8b5c2410 mov ebx,dword ptr [esp+10h]
- 8053df98 895c246c mov dword ptr [esp+6Ch],ebx
- 8053df9c 8b5c2414 mov ebx,dword ptr [esp+14h]
- 8053dfa0 83eb0c sub ebx,0Ch
- 8053dfa3 895c2464 mov dword ptr [esp+64h],ebx
- 8053dfa7 8b742470 mov esi,dword ptr [esp+70h]
- 8053dfab 897308 mov dword ptr [ebx+8],esi
- 8053dfae 8b74246c mov esi,dword ptr [esp+6Ch]
- 8053dfb2 897304 mov dword ptr [ebx+4],esi
- 8053dfb5 8b742468 mov esi,dword ptr [esp+68h]
- 8053dfb9 8933 mov dword ptr [ebx],esi
- 8053dfbb 8b442444 mov eax,dword ptr [esp+44h]
- 8053dfbf 8b54243c mov edx,dword ptr [esp+3Ch]
- 8053dfc3 8b4c2440 mov ecx,dword ptr [esp+40h]
- 8053dfc7 83c454 add esp,54h
- 8053dfca 5f pop edi
- 8053dfcb 5e pop esi
- 8053dfcc 5b pop ebx
- 8053dfcd 5d pop ebp
- 8053dfce 8b2424 mov esp,dword ptr [esp]
- 8053dfd1 cf iretd
- nt!KiExceptionExit+0x12c:
- 8053dfd4 83c43c add esp,3Ch
- 8053dfd7 5a pop edx
- 8053dfd8 59 pop ecx
- 8053dfd9 58 pop eax
- 8053dfda 8d6554 lea esp,[ebp+54h]
- 8053dfdd 5f pop edi
- 8053dfde 5e pop esi
- 8053dfdf 5b pop ebx
- 8053dfe0 5d pop ebp
- 8053dfe1 66817c24088000 cmp word ptr [esp+8],80h
- 8053dfe8 7706 ja nt!KiExceptionExit+0x148 (8053dff0)
- nt!KiExceptionExit+0x142:
- 8053dfea 83c404 add esp,4
- 8053dfed cf iretd
- nt!KiExceptionExit+0x148:
- 8053dff0 66837c240200 cmp word ptr [esp+2],0
- 8053dff6 74f2 je nt!KiExceptionExit+0x142 (8053dfea)
- nt!KiExceptionExit+0x150:
- 8053dff8 66833c2400 cmp word ptr [esp],0
- 8053dffd 75eb jne nt!KiExceptionExit+0x142 (8053dfea)
- nt!KiExceptionExit+0x157:
- 8053dfff c12c2410 shr dword ptr [esp],10h
- 8053e003 66c7442402f800 mov word ptr [esp+2],0F8h
- 8053e00a 660fb22424 lss sp,dword ptr [esp]
- 8053e00f 0fb7e4 movzx esp,sp
- 8053e012 cf iretd
- nt!KiExceptionExit+0x16b:
- 8053e013 33c9 xor ecx,ecx
- 8053e015 e81a000000 call nt!CommonDispatchException (8053e034)
- 8053e01a 33d2 xor edx,edx
- 8053e01c b901000000 mov ecx,1
- 8053e021 e80e000000 call nt!CommonDispatchException (8053e034)
- 8053e026 33d2 xor edx,edx
- 8053e028 b902000000 mov ecx,2
- 8053e02d e802000000 call nt!CommonDispatchException (8053e034)
- 8053e032 8bff mov edi,edi
- 8053e034 83ec50 sub esp,50h
- 8053e037 890424 mov dword ptr [esp],eax
- 8053e03a 33c0 xor eax,eax
- 8053e03c 89442404 mov dword ptr [esp+4],eax
- 8053e040 89442408 mov dword ptr [esp+8],eax
- 8053e044 895c240c mov dword ptr [esp+0Ch],ebx
- 8053e048 894c2410 mov dword ptr [esp+10h],ecx
- 8053e04c 83f900 cmp ecx,0
- 8053e04f 740c je nt!CommonDispatchException+0x29 (8053e05d)
- nt!CommonDispatchException+0x1d:
- 8053e051 8d5c2414 lea ebx,[esp+14h]
- 8053e055 8913 mov dword ptr [ebx],edx
- 8053e057 897304 mov dword ptr [ebx+4],esi
- 8053e05a 897b08 mov dword ptr [ebx+8],edi
- nt!CommonDispatchException+0x29:
- 8053e05d 8bcc mov ecx,esp
- 8053e05f f7457000000200 test dword ptr [ebp+70h],20000h
- 8053e066 7407 je nt!CommonDispatchException+0x3b (8053e06f)
- nt!CommonDispatchException+0x34:
- 8053e068 b8ffff0000 mov eax,0FFFFh
- 8053e06d eb03 jmp nt!CommonDispatchException+0x3e (8053e072)
- nt!CommonDispatchException+0x3b:
- 8053e06f 8b456c mov eax,dword ptr [ebp+6Ch]
- nt!CommonDispatchException+0x3e:
- 8053e072 83e001 and eax,1
- 8053e075 6a01 push 1
- 8053e077 50 push eax
- 8053e078 55 push ebp
- 8053e079 6a00 push 0
- 8053e07b 51 push ecx
- 8053e07c e8bde8fbff call nt!KiDispatchException (804fc93e)
- 8053e081 8be5 mov esp,ebp
- 8053e083 e920feffff jmp nt!Kei386EoiHelper (8053dea8)
- nt!Dr_kit0_a:
- 8053e0f0 f7457000000200 test dword ptr [ebp+70h],20000h
- 8053e0f7 750d jne nt!Dr_kit0_a+0x16 (8053e106)
- nt!Dr_kit0_a+0x9:
- 8053e0f9 f7456c01000000 test dword ptr [ebp+6Ch],1
- 8053e100 0f84fc000000 je nt!KiTrap00+0x66 (8053e202)
- nt!Dr_kit0_a+0x16:
- 8053e106 0f21c3 mov ebx,dr0
- 8053e109 0f21c9 mov ecx,dr1
- 8053e10c 0f21d7 mov edi,dr2
- 8053e10f 895d18 mov dword ptr [ebp+18h],ebx
- 8053e112 894d1c mov dword ptr [ebp+1Ch],ecx
- 8053e115 897d20 mov dword ptr [ebp+20h],edi
- 8053e118 0f21db mov ebx,dr3
- 8053e11b 0f21f1 mov ecx,dr6
- 8053e11e 0f21ff mov edi,dr7
- 8053e121 895d24 mov dword ptr [ebp+24h],ebx
- 8053e124 894d28 mov dword ptr [ebp+28h],ecx
- 8053e127 33db xor ebx,ebx
- 8053e129 897d2c mov dword ptr [ebp+2Ch],edi
- 8053e12c 0f23fb mov dr7,ebx
- 8053e12f 648b3d20000000 mov edi,dword ptr fs:[20h]
- 8053e136 8b9ff8020000 mov ebx,dword ptr [edi+2F8h]
- 8053e13c 8b8ffc020000 mov ecx,dword ptr [edi+2FCh]
- 8053e142 0f23c3 mov dr0,ebx
- 8053e145 0f23c9 mov dr1,ecx
- 8053e148 8b9f00030000 mov ebx,dword ptr [edi+300h]
- 8053e14e 8b8f04030000 mov ecx,dword ptr [edi+304h]
- 8053e154 0f23d3 mov dr2,ebx
- 8053e157 0f23d9 mov dr3,ecx
- 8053e15a 8b9f08030000 mov ebx,dword ptr [edi+308h]
- 8053e160 8b8f0c030000 mov ecx,dword ptr [edi+30Ch]
- 8053e166 0f23f3 mov dr6,ebx
- 8053e169 0f23f9 mov dr7,ecx
- 8053e16c e991000000 jmp nt!KiTrap00+0x66 (8053e202)
- nt!V86_kit0_a:
- 8053e174 8b8584000000 mov eax,dword ptr [ebp+84h]
- 8053e17a 8b9d88000000 mov ebx,dword ptr [ebp+88h]
- 8053e180 8b4d7c mov ecx,dword ptr [ebp+7Ch]
- 8053e183 8b9580000000 mov edx,dword ptr [ebp+80h]
- 8053e189 66894550 mov word ptr [ebp+50h],ax
- 8053e18d 66895d30 mov word ptr [ebp+30h],bx
- 8053e191 66894d34 mov word ptr [ebp+34h],cx
- 8053e195 66895538 mov word ptr [ebp+38h],dx
- 8053e199 eb43 jmp nt!KiTrap00+0x42 (8053e1de)
- nt!KiTrap00:
- 8053e19c 6a00 push 0
- 8053e19e 66c74424020000 mov word ptr [esp+2],0
- 8053e1a5 55 push ebp
- 8053e1a6 53 push ebx
- 8053e1a7 56 push esi
- 8053e1a8 57 push edi
- 8053e1a9 0fa0 push fs
- 8053e1ab bb30000000 mov ebx,30h
- 8053e1b0 668ee3 mov fs,bx
- 8053e1b3 648b1d00000000 mov ebx,dword ptr fs:[0]
- 8053e1ba 53 push ebx
- 8053e1bb 83ec04 sub esp,4
- 8053e1be 50 push eax
- 8053e1bf 51 push ecx
- 8053e1c0 52 push edx
- 8053e1c1 1e push ds
- 8053e1c2 06 push es
- 8053e1c3 0fa8 push gs
- 8053e1c5 66b82300 mov ax,23h
- 8053e1c9 83ec30 sub esp,30h
- 8053e1cc 668ed8 mov ds,ax
- 8053e1cf 668ec0 mov es,ax
- 8053e1d2 8bec mov ebp,esp
- 8053e1d4 f744247000000200 test dword ptr [esp+70h],20000h
- 8053e1dc 7596 jne nt!V86_kit0_a (8053e174)
- nt!KiTrap00+0x42:
- 8053e1de fc cld
- 8053e1df 8b5d60 mov ebx,dword ptr [ebp+60h]
- 8053e1e2 8b7d68 mov edi,dword ptr [ebp+68h]
- 8053e1e5 89550c mov dword ptr [ebp+0Ch],edx
- 8053e1e8 c74508000ddbba mov dword ptr [ebp+8],0BADB0D00h
- 8053e1ef 895d00 mov dword ptr [ebp],ebx
- 8053e1f2 897d04 mov dword ptr [ebp+4],edi
- 8053e1f5 f60550f0dfffff test byte ptr ds:[0FFDFF050h],0FFh
- 8053e1fc 0f85eefeffff jne nt!Dr_kit0_a (8053e0f0)
- nt!KiTrap00+0x66:
- 8053e202 f7457000000200 test dword ptr [ebp+70h],20000h
- 8053e209 753c jne nt!KiTrap00+0xab (8053e247)
- nt!KiTrap00+0x6f:
- 8053e20b f6456c01 test byte ptr [ebp+6Ch],1
- 8053e20f 7407 je nt!KiTrap00+0x7c (8053e218)
- nt!KiTrap00+0x75:
- 8053e211 66837d6c1b cmp word ptr [ebp+6Ch],1Bh
- 8053e216 751d jne nt!KiTrap00+0x99 (8053e235)
- nt!KiTrap00+0x7c:
- 8053e218 fb sti
- 8053e219 55 push ebp
- 8053e21a e8b5970500 call nt!Ki386CheckDivideByZeroTrap (805979d4)
- 8053e21f 8b5d68 mov ebx,dword ptr [ebp+68h]
- 8053e222 e9ecfdffff jmp nt!KiExceptionExit+0x16b (8053e013)
- nt!KiTrap00+0x8b:
- 8053e227 fb sti
- 8053e228 8b5d68 mov ebx,dword ptr [ebp+68h]
- 8053e22b b8940000c0 mov eax,0C0000094h
- 8053e230 e9defdffff jmp nt!KiExceptionExit+0x16b (8053e013)
- nt!KiTrap00+0x99:
- 8053e235 8b1d24f1dfff mov ebx,dword ptr ds:[0FFDFF124h]
- 8053e23b 8b5b44 mov ebx,dword ptr [ebx+44h]
- 8053e23e 83bb5801000000 cmp dword ptr [ebx+158h],0
- 8053e245 74e0 je nt!KiTrap00+0x8b (8053e227)
- nt!KiTrap00+0xab:
- 8053e247 6a00 push 0
- 8053e249 e83e2c0000 call nt!Ki386VdmReflectException_A (80540e8c)
- 8053e24e 0ac0 or al,al
- 8053e250 74d5 je nt!KiTrap00+0x8b (8053e227)
- nt!KiTrap00+0xb6:
- 8053e252 e951fcffff jmp nt!Kei386EoiHelper (8053dea8)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement