Windbg
+ -

Windbg 模块列表命令lm

2021-07-01 86 0

lm,显示当前加系统(内核)或进程加载的模块

如x64记事本下:

0:001> lm
start             end                 module name
00000000`77410000 00000000`7750a000   USER32     (deferred)             
00000000`77510000 00000000`7762f000   kernel32   (deferred)             
00000000`77630000 00000000`777cf000   ntdll      (pdb symbols)          c:\symbolslocal\ntdll.pdb\4E2FE9F5853741CE92B4B76674057EEE1\ntdll.pdb
00000000`ff800000 00000000`ff835000   notepad    (deferred)             
000007fe`f7ee0000 000007fe`f7f51000   WINSPOOL   (deferred)             
000007fe`fa5d0000 000007fe`fa5e8000   dwmapi     (deferred)             
000007fe`fab30000 000007fe`fab86000   uxtheme    (deferred)             
000007fe`fba50000 000007fe`fbc45000   COMCTL32   (deferred)             
000007fe`fc670000 000007fe`fc67c000   VERSION    (deferred)             
000007fe`fd450000 000007fe`fd45f000   CRYPTBASE   (deferred)             
000007fe`fd8c0000 000007fe`fd92a000   KERNELBASE   (deferred)             
000007fe`fd930000 000007fe`fdb2f000   ole32      (deferred)             
000007fe`fdb30000 000007fe`fdb4f000   sechost    (deferred)             
000007fe`fde20000 000007fe`fdefb000   OLEAUT32   (deferred)             
000007fe`fdf00000 000007fe`fdf2e000   IMM32      (deferred)             
000007fe`fe030000 000007fe`fedbb000   SHELL32    (deferred)             
000007fe`ff2f0000 000007fe`ff387000   COMDLG32   (deferred)             
000007fe`ff390000 000007fe`ff42f000   msvcrt     (deferred)             
000007fe`ff430000 000007fe`ff497000   GDI32      (deferred)             
000007fe`ff4a0000 000007fe`ff5cc000   RPCRT4     (deferred)             
000007fe`ff5d0000 000007fe`ff69b000   USP10      (deferred)             
000007fe`ff6a0000 000007fe`ff7a9000   MSCTF      (deferred)             
000007fe`ff7b0000 000007fe`ff821000   SHLWAPI    (deferred)             
000007fe`ff830000 000007fe`ff83e000   LPK        (deferred)             
000007fe`ff840000 000007fe`ff91b000   ADVAPI32   (deferred)

0 篇笔记 写笔记

作者信息
我爱内核
Windows驱动开发,网站开发
好好学习,天天向上。
取消
感谢您的支持,我会继续努力的!
扫码支持
扫码打赏,你说多少就多少

打开支付宝扫一扫,即可进行扫码打赏哦

您的支持,是我们前进的动力!