windbg 备忘录 - 2

  • vertarget

 

0:020> vertarget
Windows XP Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
Product: WinNt, suite: SingleUserTS
kernel32.dll version: 
Debug session time: Sun Jul 13 17:04:47.593 2008 (GMT+8)
System Uptime: 0 days 7:25:03.283
Process Uptime: 0 days 0:00:40.156
  Kernel time: 0 days 0:00:01.015
  User time: 0 days 0:00:00.531

 

  • !peb

 

0:020> !peb
PEB at 7ffd8000
    InheritedAddressSpace:    No
    ReadImageFileExecOptions: No
    BeingDebugged:            Yes
    ImageBaseAddress:         00400000
    Ldr                       00241e90
    Ldr.Initialized:          Yes
    Ldr.InInitializationOrderModuleList: 00241f28 . 00247840
    Ldr.InLoadOrderModuleList:           00241ec0 . 00247830
    Ldr.InMemoryOrderModuleList:         00241ec8 . 00247838
            Base TimeStamp                     Module
          400000 48057626 Apr 16 11:44:38 2008 C:\Program Files\Internet Explorer\iexplore.exe
        7c920000 411095a0 Aug 04 15:52:00 2004 C:\WINDOWS\system32\ntdll.dll
 
  • lmvm
0:020> lmvm msvcrt
start    end        module name
77be0000 77c38000   msvcrt     (pdb symbols)          C:\symserver\msvcrt.pdb\A678F3C30DED426B839032B996987E381\msvcrt.pdb
    Loaded symbol image file: C:\WINDOWS\system32\msvcrt.dll
    Image path: C:\WINDOWS\system32\msvcrt.dll
    Image name: msvcrt.dll
    Timestamp:        Wed Aug 04 15:54:19 2004 (4110962B)
    CheckSum:         0005B1BC
    ImageSize:        00058000
    File version:     7.0.2600.2180
    Product version:  6.1.8638.2180
    File flags:       0 (Mask 3F)
    File OS:          40004 NT Win32
    File type:        1.0 App
    File date:        00000000.00000000
    Translations:     0409.04b0
    CompanyName:      Microsoft Corporation
    ProductName:      Microsoft® Windows® Operating System
    InternalName:     msvcrt.dll
    OriginalFilename: msvcrt.dll
    ProductVersion:   7.0.2600.2180
    FileVersion:      7.0.2600.2180 (xpsp_sp2_rtm.040803-2158)
    FileDescription:  Windows NT CRT DLL
    LegalCopyright:   © Microsoft Corporation. All rights reserved.
 

 

  • lm
0:020> lm
start    end        module name
00400000 0049b000   iexplore   (pdb symbols)          C:\symserver\iexplore.pdb\D30DD314266F4A0FB8DD6828D163AFDB2\iexplore.pdb
00eb0000 00f6a000   GOOGLEPINYIN C (export symbols)       C:\WINDOWS\system32\GOOGLEPINYIN.IME
 

 

  • r dd dw db ed
  • s -u 0012ff40 L?80000000 "haibao.cn"
0:029> s -u 0012ff40 L?80000000 "haibao.cn"
0018d982  0068 0061 0069 0062 0061 006f 002e 0063  h.a.i.b.a.o...c.
00190656  0068 0061 0069 0062 0061 006f 002e 0063  h.a.i.b.a.o...c.
0019c478  0068 0061 0069 0062 0061 006f 002e 0063  h.a.i.b.a.o...c.
0019c498  0068 0061 0069 0062 0061 006f 002e 0063  h.a.i.b.a.o...c.
0019c598  0068 0061 0069 0062 0061 006f 002e 0063  h.a.i.b.a.o...c.
0019c5f8  0068 0061 0069 0062 0061 006f 002e 0063  h.a.i.b.a.o...c.
 

你可能感兴趣的:(C++,c,windows,C#,Microsoft)