rge: 0xbc
peakpagefileusage: 0xc0
peakvirtualsize: 0xc4
virtualsize: 0xc8
vm: 0xd0
debugport: 0x120
exceptionport: 0x124
objecttable: 0x128
token: 0x12c
workingsetlock: 0x130
workingsetpage: 0x150
processoutswapenabled: 0x154
processoutswapped: 0x155
addressspaceinitialized: 0x156
addressspacedeleted: 0x157
addresscreationlock: 0x158
forkinprogress: 0x17c
vmoperation: 0x180
vmoperationevent: 0x184
pagedirectorypte: 0x1f0
lastfaultcount: 0x18c
vadroot: 0x194
vadhint: 0x198
cloneroot: 0x19c
numberofprivatepages: 0x1a0
numberoflockedpages: 0x1a4
forkwassuccessful: 0x182
exitprocesscalled: 0x1aa
createprocessreported: 0x1ab
sectionhandle: 0x1ac
peb: 0x1b0
sectionbaseaddress: 0x1b4
quotablock: 0x1b8
lastthreadexitstatus: 0x1bc
workingsetwatch: 0x1c0
inheritedfromuniqueprocessid: 0x1c8
grantedaccess: 0x1cc
defaultharderrorprocessing 0x1d0
ldtinformation: 0x1d4
vadfreehint: 0x1d8
vdmobjects: 0x1dc
devicemap: 0x1e0
imagefilename[0]: 0x1fc
vmtrimfaultvalue: 0x20c
win32process: 0x214
win32windowstation: 0x1c4
3. 什么是活动进程链表
eprocess块中有一个activeprocesslinks成员,它是一个plist_entry机构的双向链表。当一个新进程建立的时候父进程负责完成eprocess块,然后把activeprocesslinks链接到一个全局内核变量psactiveprocesshead链表中。
在pspcreateprocess内核api中能清晰的找到:
insertta
上一页 [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] ... 下一页 >>