操作步驟如下:
首先確認已經安裝好 WinDbg , VMware , 虛擬作業系統,我這裡以 WinDbg 6.12.0002.633 X86 ,
VMware 6.5 , Windows XP Professional SP3 為例說明。
下載 DriverMonitor 這個工具軟體,方便載入驅動程式到系統。
為虛擬作業系統添加一個 Serial Port ,序列埠選擇 “輸出到具名管道”,模式選擇
//./pipe/com_1
This end is the server
The other end is an application
將編譯好的工程檔案,整個檔案夾拷貝到真實機器,包括 .cpp .h objchk_wxp_x86/i386/ 檔案夾下的 .pdb .sys 檔案。
修改虛擬機器的 boot.ini 檔案:
“我的電腦” -> "系統屬性" -> “進階” ->"啟動和故障恢複 " -> "設定" ->"系統啟動" -> "要手動編輯啟動選項,請單擊“編輯”" ->
開啟編輯,在 [operating systems] 段後加入新的一行
multi(0)disk(0)rdisk(0)partition(1)/WINDOWS="Microsoft Windows XP Professional" /fastdetect /debugport=com1 /baudrate=115200
在真實機器上找到 WinDbg 安裝目錄下的 windbg.exe 右鍵一個捷徑,增加參數,完整目標名如下 :
C:/WinDDK/7600.16385.1/Debuggers/windbg.exe -b -k com:pipe,port=//./pipe/com_1,resets=0
現在啟動虛擬作業系統,如下
選擇 [啟用偵錯工具].
現在執行剛才建立的 WinDbg捷徑,WinDbg 會與 虛擬作業系統通過串口進行通訊。
WinDbg 的 Command 視窗顯示連通成功:
Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Opened //./pipe/com_1
Waiting to reconnect...
Connected to Windows XP 2600 x86 compatible target at (Thu Jan 27 17:17:55.656 2011 (UTC + 8:00)), ptr64 FALSE
Kernel Debugger connection established. (Initial Breakpoint requested)
Symbol search path is: SRV*c:/symcache*http://msdl.microsoft.com/download/symbols;D:/Test7/NT_Driver/objchk_wxp_x86/i386
Executable search path is:
Windows XP Kernel Version 2600 MP (1 procs) Free x86 compatible
Built by: 2600.xpsp.080413-2111
Machine Name:
Kernel base = 0x804d8000 PsLoadedModuleList = 0x8055e720
System Uptime: not available
WARNING: Inaccessible path: 'C:/Documents and Settings/Administrator/案頭/Test2/NT_Driver'
Break instruction exception - code 80000003 (first chance)
*******************************************************************************
* *
* You are seeing this message because you pressed either *
* CTRL+C (if you run kd.exe) or, *
* CTRL+BREAK (if you run WinDBG), *
* on your debugger machine's keyboard. *
* *
* THIS IS NOT A BUG OR A SYSTEM CRASH *
* *
* If you did not intend to break into the debugger, press the "g" key, then *
* press the "Enter" key now. This message might immediately reappear. If it *
* does, press "g" and "Enter" again. *
* *
*******************************************************************************
nt!RtlpBreakWithStatusInstruction:
8052c5dc cc int 3
現在添加 源檔案 和 符號檔案 目錄
File -> Symbol Search Path -> Browse
"D:/Test7/NT_Driver/objchk_wxp_x86/i386" 把 Reload 勾上
File -> Open Source File ->Driver.cpp
現在以 DriverEntry 和 HelloDDKUnload 函數為例,設定斷點,在 command 中輸入 " bu HelloDDK!DriverEntry "
bu HelloDDK!HelloDDKUnload
好了,現在輸入 g 斷行符號,讓作業系統載入起來。
現在在虛擬作業系統裡面運行 DriverMonitor ,選擇編譯好的 sys 檔案
點擊 Go 按鈕,這時候 真實機器 的 WinDbg 收到訊息,轉到 DriverEntry 入口函數停止下來。注意粉紅色的標記
command 視窗顯示函數資訊:
--GetMcast: 6501a8c0 81f29e00
Breakpoint 0 hit
helloddk!DriverEntry:
f8bb2e90 8bff mov edi,edi
這個時候就可以 按 F10 一步一步執行函數,或按 F11 跳進函數內部查看執行過程。或者按 F5 直接執行到下一個斷點處。
下面點擊 DriverMonitor 的 stop 按鈕。
執行的代碼會以高亮顯示,command 視窗會列印 KdPrint 的字串
Enter DriverUnload // <-------------
helloddk!HelloDDKUnload+0x15:
f8bb2725 8b4508 mov eax,dword ptr [ebp+8]