記一次看DUMP的實戰

weixin_34279184發表於2010-03-15

命令:

.sympath srv*d:\symcache*\\symbols\symbols

解釋:

The .sympath command changes the default path of the host debugger for symbol search.

 

命令:

.reload /f ntdll.dll

解釋:

The .reload command deletes all symbol information for the specified module and reloads these symbols as needed. In some cases, this command also reloads or unloads the module itself.

這個帶有/f開關的.reload命令和ld(LoadSymbols)命令都會強制指定的symbol被立即載入, 儘管其他的symbol還是被推遲的. 如果symbol path更換了, symbols是不會自動載入的.

 

命令:

!address –summary

解釋:

The !address extension displays information about the memory that the target process or target computer uses.

這裡的-summary開關指定直顯示summary資訊.

 

命令:

.chain

解釋:

The .chain command lists all loaded debugger extensions in their default search order. List Debugger Extensions.

 

命令:

!eeheap –gc

 

命令:

.loadby sos mscorwks

 

命令:

!clrstack

未完.....

相關文章