[COLOR=Blue]
//
查看400000地址信息,类似!vprot[
/COLOR
]
0:000> [COLOR=Red]!address 400000[
/COLOR
]
Usage: Image
Allocation Base: 00400000
Base Address: 00400000
End Address: 00401000
Region Size: 00001000
Type: 01000000 MEM_IMAGE
State: 00001000 MEM_COMMIT
Protect: 00000002 PAGE_READONLY
More info: lmv m PEViewer
More info: !lmi PEViewer
More info:
ln
0x400000
[COLOR=Blue]
//
查看属于Image,Heap,Stack 性质的内存信息[
/COLOR
]
0:000> [COLOR=Red]!address
/f
:Image,Heap,Stack [
/COLOR
]
BaseAddr EndAddr+1 RgnSize Type State Protect Usage
-------------------------------------------------------------------------------------------
30000 12d000 fd000 MEM_PRIVATE MEM_RESERVE Stack [a38.d98; ~0]
12d000 12e000 1000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE|PAGE_GUARD Stack [a38.d98; ~0]
12e000 130000 2000 MEM_PRIVATE MEM_COMMIT PAGE_READWRITE Stack [a38.d98; ~0]
400000 401000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"PEViewer.exe"
401000 411000 10000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_WRITECOPY Image
"PEViewer.exe"
411000 434000 23000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"PEViewer.exe"
434000 43c000 8000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"PEViewer.exe"
43c000 43d000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"PEViewer.exe"
43d000 43e000 1000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image
"PEViewer.exe"
43e000 43f000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"PEViewer.exe"
43f000 449000 a000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"PEViewer.exe"
10200000 10201000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\MSVCR100D.dll"
10201000 1035e000 15d000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"C:\WINDOWS\system32\MSVCR100D.dll"
1035e000 10364000 6000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"C:\WINDOWS\system32\MSVCR100D.dll"
10364000 10372000 e000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\MSVCR100D.dll"
10480000 10481000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\MSVCP100D.dll"
10481000 1052c000 ab000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"C:\WINDOWS\system32\MSVCP100D.dll"
1052c000 10530000 4000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"C:\WINDOWS\system32\MSVCP100D.dll"
10530000 10537000 7000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\MSVCP100D.dll"
5d170000 5d171000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\COMCTL32.dll"
5d171000 5d1e2000 71000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"C:\WINDOWS\system32\COMCTL32.dll"
5d1e2000 5d1e5000 3000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"C:\WINDOWS\system32\COMCTL32.dll"
5d1e5000 5d20a000 25000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\COMCTL32.dll"
762f0000 762f1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\MSIMG32.dll"
762f1000 762f2000 1000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"C:\WINDOWS\system32\MSIMG32.dll"
762f2000 762f3000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"C:\WINDOWS\system32\MSIMG32.dll"
762f3000 762f5000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\MSIMG32.dll"
76990000 76991000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\ole32.dll"
76991000 76ab6000 125000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"C:\WINDOWS\system32\ole32.dll"
76ab6000 76abd000 7000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"C:\WINDOWS\system32\ole32.dll"
76abd000 76acd000 10000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\ole32.dll"
770f0000 770f1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\OLEAUT32.dll"
770f1000 77171000 80000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"C:\WINDOWS\system32\OLEAUT32.dll"
77171000 77174000 3000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"C:\WINDOWS\system32\OLEAUT32.dll"
77174000 7717b000 7000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\OLEAUT32.dll"
77be0000 77be1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\msvcrt.dll"
77be1000 77c2d000 4c000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"C:\WINDOWS\system32\msvcrt.dll"
77c2d000 77c34000 7000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"C:\WINDOWS\system32\msvcrt.dll"
77c34000 77c38000 4000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\msvcrt.dll"
77d10000 77d11000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\USER32.dll"
77d11000 77d71000 60000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"C:\WINDOWS\system32\USER32.dll"
77d71000 77d73000 2000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"C:\WINDOWS\system32\USER32.dll"
77d73000 77da0000 2d000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\USER32.dll"
77da0000 77da1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\ADVAPI32.dll"
77da1000 77e16000 75000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"C:\WINDOWS\system32\ADVAPI32.dll"
77e16000 77e1b000 5000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"C:\WINDOWS\system32\ADVAPI32.dll"
77e1b000 77e49000 2e000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\ADVAPI32.dll"
77e50000 77e51000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\RPCRT4.dll"
77e51000 77edb000 8a000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"C:\WINDOWS\system32\RPCRT4.dll"
77edb000 77edc000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"C:\WINDOWS\system32\RPCRT4.dll"
77edc000 77ee2000 6000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\RPCRT4.dll"
77ef0000 77ef1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\GDI32.dll"
77ef1000 77f34000 43000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"C:\WINDOWS\system32\GDI32.dll"
77f34000 77f36000 2000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"C:\WINDOWS\system32\GDI32.dll"
77f36000 77f39000 3000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\GDI32.dll"
77f40000 77f41000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\SHLWAPI.dll"
77f41000 77fad000 6c000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"C:\WINDOWS\system32\SHLWAPI.dll"
77fad000 77fae000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"C:\WINDOWS\system32\SHLWAPI.dll"
77fae000 77fb6000 8000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\SHLWAPI.dll"
77fc0000 77fc1000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\Secur32.dll"
77fc1000 77fce000 d000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"C:\WINDOWS\system32\Secur32.dll"
77fce000 77fcf000 1000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"C:\WINDOWS\system32\Secur32.dll"
77fcf000 77fd1000 2000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\Secur32.dll"
78b60000 78b61000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\mfc100d.dll"
78b61000 79070000 50f000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"C:\WINDOWS\system32\mfc100d.dll"
79070000 79080000 10000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"C:\WINDOWS\system32\mfc100d.dll"
79080000 79203000 183000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\mfc100d.dll"
7c800000 7c801000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\kernel32.dll"
7c801000 7c885000 84000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"C:\WINDOWS\system32\kernel32.dll"
7c885000 7c888000 3000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image
"C:\WINDOWS\system32\kernel32.dll"
7c888000 7c88a000 2000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"C:\WINDOWS\system32\kernel32.dll"
7c88a000 7c91e000 94000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"C:\WINDOWS\system32\kernel32.dll"
7c920000 7c921000 1000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"ntdll.dll"
7c921000 7c99b000 7a000 MEM_IMAGE MEM_COMMIT PAGE_EXECUTE_READ Image
"ntdll.dll"
7c99b000 7c99e000 3000 MEM_IMAGE MEM_COMMIT PAGE_READWRITE Image
"ntdll.dll"
7c99e000 7c9a0000 2000 MEM_IMAGE MEM_COMMIT PAGE_WRITECOPY Image
"ntdll.dll"
7c9a0000 7c9b3000 13000 MEM_IMAGE MEM_COMMIT PAGE_READONLY Image
"ntdll.dll"