본문 바로가기
디버그

[windbg] CodeMachine extension dll

by WeZZ 2013. 2. 22.

 

 

 

kd> !stack -p -t
.
.
.
48 fffffa600171b5c0 fffffa60009751e8 NDIS!ndisMIndicateNetBufferListsToOpen+ac (perf)
Parameter[0] = fffffa8007877680 : rcx setup in parent frame by mov instruction @ fffffa60009751db from NvReg rdi which is saved by current frame
Parameter[1] = fffffa8007877c00 : rdx saved in current frame into NvReg rsi which is saved by child frames
Parameter[2] = 0000000000000000 : r8  saved in current frame into NvReg r13 which is saved by child frames
Parameter[3] = 0000000000000000 : r9  saved in current frame into NvReg r12 which is saved by child frames

 

이기능은 유용한듯.ㅎㅎ

 

출처 : http://www.codemachine.com/tool_cmkd.html