Breakpoint
0
hit
ntdll!KiUserApcDispatch:
00007ffe
`
96610a40
488b4c2418
mov rcx,qword ptr [rsp
+
18h
] ss:
00000000
`
010bf438
=
{KERNEL32!LoadLibraryWStub (
00007ffe
`
9623fee0
)}
0
:
000
> kv
Child
-
SP RetAddr : Args to Child : Call Site
00000000
`
010bf420
00007ffe
`
96610534
:
00007ffe
`
965e4f9d
00000000
`
00000000
00000000
`
011d5d20
00000000
`
00000000
: ntdll!KiUserApcDispatch (TrapFrame @
00000000
`
010bf7c8
)
00000000
`
010bf958
00007ffe
`
965e4f9d
:
00000000
`
00000000
00000000
`
011d5d20
00000000
`
00000000
00000000
`
00000001
: ntdll!ZwTestAlert
+
0x14
00000000
`
010bf960
00007ffe
`
965e4b63
:
00000000
`
00000000
00007ffe
`
96570000
00000000
`
00000000
00000000
`
00e4d000
: ntdll!LdrpInitialize
+
0x421
00000000
`
010bfa00
00007ffe
`
965e4b0e
:
00000000
`
010bfa80
00000000
`
00000000
00000000
`
00000000
00000000
`
00000000
: ntdll!LdrpInitialize
+
0x3b
00000000
`
010bfa30
00000000
`
00000000
:
00000000
`
00000000
00000000
`
00000000
00000000
`
00000000
00000000
`
00000000
: ntdll!LdrInitializeThunk
+
0xe
0
:
000
> r
rax
=
0000000000000000
rbx
=
0000000000000000
rcx
=
00007ffe96610a40
rdx
=
0000000000000000
rsi
=
0000000000000001
rdi
=
0000000000000000
rip
=
00007ffe96610a40
rsp
=
00000000010bf420
rbp
=
0000000000000000
r8
=
00000000010bf420
r9
=
0000000000000000
r10
=
0000000000000000
r11
=
0000000000000246
r12
=
0000000000e4c050
r13
=
00000000010bfa80
r14
=
0000000000002000
r15
=
0000000000e4d000
iopl
=
0
nv up ei pl zr na po nc
cs
=
0033
ss
=
002b
ds
=
002b
es
=
002b
fs
=
0053
gs
=
002b
efl
=
00000246
ntdll!KiUserApcDispatch:
00007ffe
`
96610a40
488b4c2418
mov rcx,qword ptr [rsp
+
18h
] ss:
00000000
`
010bf438
=
{KERNEL32!LoadLibraryWStub (
00007ffe
`
9623fee0
)}
0
:
000
> t
Breakpoint
0
hit
ntdll!KiUserApcDispatch:
00007ffe
`
96610a40
488b4c2418
mov rcx,qword ptr [rsp
+
18h
] ss:
00000000
`
010bf438
=
{KERNEL32!LoadLibraryWStub (
00007ffe
`
9623fee0
)}
0
:
000
> t
ntdll!KiUserApcDispatcher
+
0x5
:
00007ffe
`
96610a45
488bc1
mov rax,rcx
0
:
000
> t
ntdll!KiUserApcDispatcher
+
0x8
:
00007ffe
`
96610a48
4c8bcc
mov r9,rsp
0
:
000
> t
ntdll!KiUserApcDispatcher
+
0xb
:
00007ffe
`
96610a4b
48c1f902
sar rcx,
2
0
:
000
> t
ntdll!KiUserApcDispatcher
+
0xf
:
00007ffe
`
96610a4f
488b542408
mov rdx,qword ptr [rsp
+
8
] ss:
00000000
`
010bf428
=
0000000000000001
0
:
000
> t
ntdll!KiUserApcDispatcher
+
0x14
:
00007ffe
`
96610a54
48f7d9
neg rcx
0
:
000
> t
ntdll!KiUserApcDispatcher
+
0x17
:
00007ffe
`
96610a57
4c8b442410
mov r8,qword ptr [rsp
+
10h
] ss:
00000000
`
010bf430
=
0000000000000000
0
:
000
> t
ntdll!KiUserApcDispatcher
+
0x1c
:
00007ffe
`
96610a5c
480fa4c920
shld rcx,rcx,
20h
0
:
000
> t
ntdll!KiUserApcDispatcher
+
0x21
:
00007ffe
`
96610a61
85c9
test ecx,ecx
0
:
000
> t
ntdll!KiUserApcDispatcher
+
0x23
:
00007ffe
`
96610a63
7438
je ntdll!KiUserApcDispatcher
+
0x5d
(
00007ffe
`
96610a9d
) [br
=
0
]
0
:
000
> t
ntdll!KiUserApcDispatcher
+
0x25
:
00007ffe
`
96610a65
488b0c24
mov rcx,qword ptr [rsp] ss:
00000000
`
010bf420
=
00000000010c0044
0
:
000
> t
ntdll!KiUserApcDispatcher
+
0x29
:
00007ffe
`
96610a69
e882ffffff call ntdll!KiUserCallForwarder (
00007ffe
`
966109f0
)
0
:
000
> t
ntdll!KiUserCallForwarder:
00007ffe
`
966109f0
4883ec48
sub rsp,
48h
0
:
000
> p
ntdll!KiUserCallForwarder
+
0x4
:
00007ffe
`
966109f4
48894c2420
mov qword ptr [rsp
+
20h
],rcx ss:
00000000
`
010bf3f0
=
0000000000000000
0
:
000
> p
ntdll!KiUserCallForwarder
+
0x9
:
00007ffe
`
966109f9
4889542428
mov qword ptr [rsp
+
28h
],rdx ss:
00000000
`
010bf3f8
=
00000000010bf404
0
:
000
> p
ntdll!KiUserCallForwarder
+
0xe
:
00007ffe
`
966109fe
4c89442430
mov qword ptr [rsp
+
30h
],r8 ss:
00000000
`
010bf400
=
00000004010f0000
0
:
000
> p
ntdll!KiUserCallForwarder
+
0x13
:
00007ffe
`
96610a03
4c894c2438
mov qword ptr [rsp
+
38h
],r9 ss:
00000000
`
010bf408
=
{ntdll!`string' (
00007ffe
`
966948f0
)}
0
:
000
> p
ntdll!KiUserCallForwarder
+
0x18
:
00007ffe
`
96610a08
488bc8
mov rcx,rax
0
:
000
> p
ntdll!KiUserCallForwarder
+
0x1b
:
00007ffe
`
96610a0b
488b05cee70d00
mov rax,qword ptr [ntdll!_guard_check_icall_fptr (
00007ffe
`
966ef1e0
)] ds:
00007ffe
`
966ef1e0
=
{ntdll!LdrpValidateUserCallTarget (
00007ffe
`
965fc580
)}
0
:
000
> p
ntdll!KiUserCallForwarder
+
0x22
:
00007ffe
`
96610a12
ffd0 call rax {ntdll!LdrpValidateUserCallTarget (
00007ffe
`
965fc580
)}
0
:
000
> p
ntdll!KiUserCallForwarder
+
0x24
:
00007ffe
`
96610a14
488bc1
mov rax,rcx
0
:
000
> p
ntdll!KiUserCallForwarder
+
0x27
:
00007ffe
`
96610a17
488b4c2420
mov rcx,qword ptr [rsp
+
20h
] ss:
00000000
`
010bf3f0
=
00000000010c0044
0
:
000
> p
ntdll!KiUserCallForwarder
+
0x2c
:
00007ffe
`
96610a1c
488b542428
mov rdx,qword ptr [rsp
+
28h
] ss:
00000000
`
010bf3f8
=
0000000000000001
0
:
000
> p
ntdll!KiUserCallForwarder
+
0x31
:
00007ffe
`
96610a21
4c8b442430
mov r8,qword ptr [rsp
+
30h
] ss:
00000000
`
010bf400
=
0000000000000000
0
:
000
> p
ntdll!KiUserCallForwarder
+
0x36
:
00007ffe
`
96610a26
4c8b4c2438
mov r9,qword ptr [rsp
+
38h
] ss:
00000000
`
010bf408
=
00000000010bf420
0
:
000
> p
ntdll!KiUserCallForwarder
+
0x3b
:
00007ffe
`
96610a2b
4883c448
add rsp,
48h
0
:
000
> p
ntdll!KiUserCallForwarder
+
0x3f
:
00007ffe
`
96610a2f
48ffe0
jmp rax {KERNEL32!LoadLibraryWStub (
00007ffe
`
9623fee0
)}
0
:
000
> t
KERNEL32!LoadLibraryWStub:
00007ffe
`
9623fee0
48ff2589160600
jmp qword ptr [KERNEL32!_imp_LoadLibraryW (
00007ffe
`
962a1570
)] ds:
00007ffe
`
962a1570
=
{KERNELBASE!LoadLibraryW (
00007ffe
`
93e99bc0
)}
0
:
000
> t
KERNELBASE!LoadLibraryW:
00007ffe
`
93e99bc0
4533c0
xor r8d,r8d
0
:
000
> r rcx
rcx
=
00000000010c0044
0
:
000
> dU
00000000010c0044
00000000
`
010c0044
"C:\Program Files (x86)\iOAEnt\10"
00000000
`
010c0084
"7.5.18939.62005\qmipcmt64.dll"
0
:
000
> !address
00000000010c0044