• 博客访问: 32586
  • 博文数量: 41
  • 用 户 组: 普通用户
  • 注册时间: 1970-01-01 08:00
个人简介

鏆傛棤浠嬬粛

ITPUB论坛APP

ITPUB论坛APP



APP发帖 享双倍积分

文章分类

全部博文(41)

文章存档

2007年(6)

2006年(22)

2005年(13)

我的朋友
最近访客
微信关注

IT168企业级官微



微信号:IT168qiye



系统架构师大会



微信号:SACC2013

发布时间:2006-10-30 14:34:58

http://bible.younet.com/files/2006/05/27/346282.shtml[@more@]......【阅读全文】

阅读(429) | 评论(0) | 转发(0)

发布时间:2006-10-27 16:28:50

http://support.microsoft.com/kb/238956/[@more@]......【阅读全文】

阅读(487) | 评论(0) | 转发(0)

发布时间:2006-10-25 14:58:54

fs:124 ETHREAD At the operating-system level, a Windows thread is represented by an executive thread (ETHREAD) block, which is illustrated in Figure 6-7. The ETHREAD block and the structures it points to exist in the system address space, with the exception of the thread environment block (TEB), which exists in the process address space. In addition, the Windows subsystem process (Csrss) maintains a parallel structure for each thread created in a Windows process. Also, for threads that have call......【阅读全文】

阅读(561) | 评论(0) | 转发(0)

发布时间:2006-10-11 18:25:20

PE ChecksumKiTrap0E[@more@]PE ChecksumKiTrap0E......【阅读全文】

阅读(397) | 评论(0) | 转发(0)

发布时间:2006-08-15 07:45:30

0:000> dt ntdll!_PEB 7ffdf000 +0x000 InheritedAddressSpace : 0 '' +0x001 ReadImageFileExecOptions : 0 '' +0x002 BeingDebugged : 0x1 '' +0x003 SpareBool : 0 '' +0x004 Mutant : 0xffffffff +0x008 ImageBaseAddress : 0x00400000 +0x00c Ldr : 0x00241ea0 _PEB_LDR_DATA +0x010 ProcessParameters : 0x00020000 _RTL_USER_PROCESS_PARAMETERS +0x014 SubSystemData : (null) +0x018 ProcessHeap : 0x00140000 +0x01c FastPebLock ......【阅读全文】

阅读(413) | 评论(0) | 转发(0)
给主人留下些什么吧!~~
留言热议
请登录后留言。

登录 注册