data String 4b797a6b79724b6a784f4e5063555949c7102e99bdf73b4b11732ca323bc6ec9d1bd741a879d5675286139db959b8b5f7e928e412007f5270161a89213628b4f2d541a83c9a3a504d18fc62380dc8bdab4a756ecba21a00377a3d21779ce5c5def79b933e1238237a567405ede8d609a051a9960b668bb7bec...
bFill+0x3d9:fffff961`218c90fd c1e104 shl ecx,4 // ecx = ecx * 2^4 = ecx * 0x10 = eax * 0x301: kd> r ecxecx=100000051: kd> pwin32kfull!bFill+0x3dc:fffff961`218c9100 4533c0 xor r8d,r8d1: kd> r rcx // 此时rcx已经溢出为0x50rcx...