约有 3 项符合查询结果, 以下是第 1 - 1项。
费时 < 1 秒。
现场:
kd> !lpc port
Port type Port address Connection port Connected port Name
*** objects of the same type are only linked together if the 4000 flag is set in NtGlobalFlags
*** objects of the same type are only linked together if the 4000 flag is set in NtGlobalFlags
Scanned 254 port objects
kd>!gflag
Current NtGlobalFlag ...
Posted in Windows内核调试
by
Jane1970
on 2009-11-06
环境:XP professional 2002 sp3,windbg 6.11.0001使用kernel debug 到本地的模式,现场:lkd> .sympath SRV*C:\WINDOWS\Symbols*http://msdl.microsoft.com/download/symbolsDBGHELP: Symbol Search Path: srv*c:\windows\symbols*http://msdl.microsoft.com/download/symbolsDBGHELP: Symbol Search Path: ...
Posted in Windows内核调试
by
Jane1970
on 2009-11-05
主机上运行windbg,vmware上运行驱动,通过串口连接成功。希望能够查看vmware目标机上的进程和句柄信息,在windbg的“processes and threads”窗口只能看到ntkrnlpa.exe,通过!process和!handle命令感觉看到的是主机上的进程和句柄信息。敬请高手赐教!
Posted in Windows内核调试
by
Jane1970
on 2009-08-28