authui!CLogonFrame::Create中的USER32!LoadImageW可以作为有效起始断点
authui!CLogonFrame::Create中的USER32!LoadImageW
kd> kc
#
WARNING: Stack unwind information not available. Following frames may be wrong.
00 USER32!LoadImageW
01 DUI70!DirectUI::Value::CreateGraphic
02 DUI70!DirectUI::DUIXmlParser::ParseGraphicHelper
03 DUI70!DirectUI::DUIXmlParser::ParseGraphicGraphic
04 DUI70!DirectUI::DUIXmlParser::DispatchFuncall<unsigned long>
05 DUI70!DirectUI::DUIXmlParser::ParseGraphicValue
06 DUI70!DirectUI::DUIXmlParser::GetPropValPairInfo
07 DUI70!DirectUI::DUIXmlParser::AddRulesToStyleSheet
08 DUI70!DirectUI::DUIXmlParser::AddRulesToStyleSheet
09 DUI70!DirectUI::DUIXmlParser::CreateStyleSheet
0a DUI70!DirectUI::DUIXmlParser::ParseStyleSheets
0b DUI70!DirectUI::DUIXmlParser::InitializeParserFromXmlLiteReader
0c DUI70!DirectUI::DUIXmlParser::SetPreprocessedXML
0d DUI70!DirectUI::DUIXmlParser::SetXML
0e DUI70!DirectUI::DUIXmlParser::SetXMLFromResource
0f DUI70!DirectUI::DUIXmlParser::SetXMLFromResource
10 authui!CLogonFrame::CreateStyleParser
11 authui!CLogonFrame::_Initialize
12 authui!CLogonFrame::Create
13 authui!CLogonUI_CreateThenDoModalThenDestroy
14 authui!CLogonUI::DoModal
15 LogonUI!wWinMain
16 LogonUI!_initterm_e
17 kernel32!BaseThreadInitThunk
18 ntdll!__RtlUserThreadStart
19 ntdll!_RtlUserThreadStart
kd> g
Breakpoint 35 hit
eax=00000000 ebx=00000000 ecx=00000007 edx=00000007 esi=73b87df0 edi=00002fb5
eip=77489987 esp=001ff544 ebp=001ff568 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206
USER32!LoadImageW:
001b:77489987 8bff mov edi,edi
kd> dd 001ff4f0
001ff4f0 00000000 0000007f 000dfdb0 00000000
001ff500 00000000 000dfdb0 000dfdb0 00000060
001ff510 00000000 000dfdb0 001ff558 001ff530
001ff520 73bd8e51 00115c40 001ff5b0 00115f30
001ff530 001ff550 73bd8f00 00115c40 001ff5b0
001ff540 001ff5b0 73bb85fa 72690000 00002fb5
001ff550 00000000 00000000 00000000 00002000
001ff560 73b87df0 72690000 001ff5b8 73bd9890
kd> dd 001ff544
001ff544 73bb85fa 72690000 00002fb5 00000000
001ff554 00000000 00000000 00002000 73b87df0
001ff564 72690000 001ff5b8 73bd9890 00002fb5
001ff574 00000002 ffffffff 00000000 00000000
001ff584 72690000 00000000 00000000 00115f40
001ff594 000dfdb0 00002fb5 00000002 ffffffff
001ff5a4 00000000 00000000 00000000 00000001
001ff5b4 72690000 001ff5cc 73bd98c0 00000001
kd> ?00002fb5
Evaluate expression: 12213 = 00002fb5