1: kd> r cr3 cr3=0000000000187000 1: kd> dq 0000000000187000 00000000`00187000 ????????`???????? ????????`???????? 00000000`00187010 ????????`???????? ????????`???????? 00000000`00187020 ????????`???????? ????????`???????? 00000000`00187030 ????????`???????? ????????`???????? 00000000`00187040 ????????`???????? ????????`???????? 00000000`00187050 ????????`???????? ????????`???????? 00000000`00187060 ????????`???????? ????????`???????? 00000000`00187070 ????????`???????? ????????`???????? 1: kd> !process 0 0 **** NT ACTIVE PROCESS DUMP **** ........ PROCESS fffffa8019801890 SessionId: 1 Cid: 06c4 Peb: 7fffffd8000 ParentCid: 0688 DirBase: 6ba7f000 ObjectTable: fffff8a0012cc330 HandleCount: 76. Image: calc.exe ........ 1: kd> dq 6ba7f000 00000000`6ba7f000 ????????`???????? ????????`???????? 00000000`6ba7f010 ????????`???????? ????????`???????? 00000000`6ba7f020 ????????`???????? ????????`???????? 00000000`6ba7f030 ????????`???????? ????????`???????? 00000000`6ba7f040 ????????`???????? ????????`???????? 00000000`6ba7f050 ????????`???????? ????????`???????? 00000000`6ba7f060 ????????`???????? ????????`???????? 00000000`6ba7f070 ????????`???????? ????????`????????
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课
0000000000187000不是物理地址,谢谢记得物理地址要cr3的值右移12位来着的
hzqst 0000000000187000不是物理地址,谢谢记得物理地址要cr3的值右移12位来着的
ugvjewxf !dq
空白即是正义 请使用!dq 另外187000记得好像是system?