建议注入精确一点,最好别注入剪映了。
0:211> kb
# RetAddr : Args to Child : Call Site
00 000007fe`fd211203 : 00000000`225beb48 ffffffff`fffffffe 00000000`00000014 ffffffff`fffffffe : ntdll!NtDelayExecution+0xa
01 000007fe`e4bbf629 : 00000000`225bedb0 00000000`00000000 00000000`00000000 00000000`00000000 : KERNELBASE!SleepEx+0xab
02 00000000`770ab9b0 : 00000000`00000001 00000000`00000000 00000000`00000001 00000000`00000001 : parfait!AlogWrite+0x24ad9
03 00000000`772a8f95 : 00000000`225bedb0 00000000`00000006 00000000`00000000 00000000`00000001 : kernel32!UnhandledExceptionFilter+0x160
04 00000000`77287258 : 00000000`00000000 00000000`37e9d580 00000000`00000000 00000000`77288c37 : ntdll! ?? ::FNODOBFM::`string'+0x2025
05 00000000`7729be9d : 00000000`225c0000 00000000`225bfdf0 00000000`225bfdf0 00000000`77368908 : ntdll!_C_specific_handler+0x8c
06 00000000`7727040a : 00000000`225c0000 00000000`7711dd58 00000000`0000dde8 00000000`06e4ef60 : ntdll!RtlpExecuteHandlerForException+0xd
07 00000000`7729b53e : 00000000`225bf9f0 00000000`225bf500 00000000`00000000 000007fe`00000000 : ntdll!RtlDispatchException+0x45a
08 000007fe`c0a6d0c4 : 00000000`7726be24 000007fe`f461a980 00000000`00000000 00000000`00000000 : ntdll!KiUserExceptionDispatcher+0x2e
09 00000000`7726be24 : 000007fe`f461a980 00000000`00000000 00000000`00000000 00000000`00000041 : 360ZipExt64+0x6d0c4
0a 00000000`7726867b : 00000000`00000000 00000000`00000000 000007ff`fffda000 000007ff`ffd6e000 : ntdll!RtlProcessFlsData+0x84
0b 00000000`77273ed8 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!LdrShutdownThread+0x4b
0c 00000000`77025575 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlExitUserThread+0x38
0d 00000000`7728372d : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x15
0e 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x1d
STACK_TEXT:
00000000`225bfc38 00000000`7726be24 : 000007fe`f461a980 00000000`00000000 00000000`00000000 00000000`00000041 : 360ZipExt64+0x6d0c4
00000000`225bfc40 00000000`7726867b : 00000000`00000000 00000000`00000000 000007ff`fffda000 000007ff`ffd6e000 : ntdll!RtlProcessFlsData+0x84
00000000`225bfc80 00000000`77273ed8 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!LdrShutdownThread+0x4b
00000000`225bfd80 00000000`77025575 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlExitUserThread+0x38
00000000`225bfdc0 00000000`7728372d : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x15
00000000`225bfdf0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x1d
MODULE_NAME: 360ZipExt64
IMAGE_NAME: 360ZipExt64.dll
参考:https://learn.microsoft.com/en-u ... d-exit-fls-callback |
|
|
|
评论
直达楼层