kd> r
eax=00000001 ebx=ffdff980 ecx=8054bd4c edx=000002f8 esi=00000000 edi=1aa78a2c
eip=80528bdc esp=8054abd0 ebp=8054abe0 iopl=0 nv up ei pl nz na po nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000202
eax=00000001 ebx=ffdff980 ecx=8054bd4c edx=000002f8 esi=00000000 edi=1aa78a2c
eip=80528bdc esp=8054abd0 ebp=8054abe0 iopl=0 nv up ei pl nz na po nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000202
rM num则是根据num的值转储指定的寄存器值,num是8位掩码值。
kd> rM 1
eax=00000001 ebx=ffdff980 ecx=8054bd4c edx=000002f8 esi=00000000 edi=1aa78a2c
eip=80528bdc esp=8054abd0 ebp=8054abe0 iopl=0 nv up ei pl nz na po nc
eax=00000001 ebx=ffdff980 ecx=8054bd4c edx=000002f8 esi=00000000 edi=1aa78a2c
eip=80528bdc esp=8054abd0 ebp=8054abe0 iopl=0 nv up ei pl nz na po nc
可以看到1转储的寄存器和r指令差不多,只是减少了段寄存器和efl标志寄存器,而rM 2也是一样的结果