Confirmed users
25
edits
(Starting dump of some notes) |
mNo edit summary |
||
| Line 1: | Line 1: | ||
== WinDbg Command == | |||
This might be useful for windbg debugging. | |||
!htrace -enable;gh;bp /1 ADVAPI32!RegOpenKeyExW "$$ print args info;!handle rcx;!htrace rcx;du rdx;r r8;r r9;dp rsp+28h;dp poi(rsp+28h);r rsp;bp /1 ADVAPI32!LocalBaseRegOpenKey+0x25"; | |||
== Crash Stack == | == Crash Stack == | ||
# Child-SP RetAddr Call Site | # Child-SP RetAddr Call Site | ||