´òÓ¡

[ÇóÖú] ΢ÈíÒ»¸öº±ÎªÈËÖªµÄÎÞµÐÃüÁîntsd

΢ÈíÒ»¸öº±ÎªÈËÖªµÄÎÞµÐÃüÁîntsd

ÎÊ:Ôõô²ÅÄܹصôÒ»¸öÓÃÈÎÎñ¹ÜÀíÆ÷¹Ø²»Á˵Ľø³Ì£¿ÎÒǰ¶Îʱ¼ä·¢ÏÖÎҵĻú×ÓÀï¶àÁËÒ»¸ö½ø³Ì£¬Ö»Òª¿ª»ú¾ÍÔÚ£¬ÎÒÓÃÈÎÎñ¹ÜÀíÆ÷È´Ôõô¹ØÒ²¹Ø²»ÁË¡£ ¡¡

¡¡¡¡´ð1:ɱ½ø³ÌºÜÈÝÒ×£¬Ëæ±ãÕÒ¸ö¹¤¾ß¶¼ÐС£±ÈÈçIceSword¡£¹Ø¼üÊÇÕÒµ½Õâ¸ö½ø³ÌµÄÆô¶¯·½Ê½£¬²»È»Ï´ÎÖØÆôËüÓÖ³öÀ´ÁË¡£Ë³±ã½Ì´ó¼ÒÒ»Õкݵġ£ÆäʵÓÃWindows×Ô´øµÄ¹¤¾ß¾ÍÄÜɱ´ó²¿·Ö½ø³Ì£º
¡¡¡¡c:\> ntsd -c q -p PID ¡¡

¡¡¡¡Ö»ÓÐSystem¡¢SMSS.EXEºÍCSRSS.EXE²»ÄÜɱ¡£Ç°Á½¸öÊÇ´¿ÄÚºË̬µÄ£¬×îºóÄǸöÊÇWin32×Óϵͳ£¬ntsd±¾ÉíÐèÒªËü¡£ntsd´Ó2000¿ªÊ¼¾ÍÊÇϵͳ×Ô´øµÄÓû§Ì¬µ÷ÊÔ¹¤¾ß¡£±»µ÷ÊÔÆ÷¸½×Å(attach)µÄ½ø³Ì»áËæµ÷ÊÔÆ÷Ò»ÆðÍ˳ö£¬ËùÒÔ¿ÉÒÔÓÃÀ´ÔÚÃüÁîÐÐÏ*ÕÖ¹½ø³Ì¡£Ê¹ÓÃntsd×Ô¶¯¾Í»ñµÃÁËdebugȨÏÞ£¬´Ó¶øÄÜɱµô´ó²¿·ÖµÄ½ø³Ì¡£ntsd»áпªÒ»¸öµ÷ÊÔ´°¿Ú£¬±¾À´ÔÚ´¿ÃüÁîÐÐÏÂÎÞ·¨¿ØÖÆ£¬µ«Èç¹ûÖ»ÊǼòµ¥µÄÃüÁ±ÈÈçÍ˳ö(q)£¬ÓÃ-c²ÎÊý´ÓÃüÁîÐд«µÝ¾ÍÐÐÁË¡£Ntsd °´ÕÕ¹ßÀýÒ²ÏòÈí¼þ¿ª·¢ÈËÔ±Ìṩ¡£Ö»ÓÐϵͳ¿ª·¢ÈËԱʹÓôËÃüÁî¡£Ó÷¨:¿ª¸öcmd.exe´°¿Ú£¬ÊäÈ룺 ¡¡

¡¡¡¡ntsd -c q -p PID ¡¡

¡¡¡¡°Ñ×îºóÄǸöPID£¬¸Ä³ÉÄãÒªÖÕÖ¹µÄ½ø³ÌµÄID¡£Èç¹ûÄã²»ÖªµÀ½ø³ÌµÄID£¬ÈÎÎñ¹ÜÀíÆ÷-> ½ø³ÌÑ¡Ï-> ²é¿´-> Ñ¡ÔñÁÐ-> ¹´ÉÏ"PID(½ø³Ì±êʶ·û)"£¬È»ºó¾ÍÄÜ¿´¼ûÁË¡£

¡¡¡¡´ð2£ºxpÏ»¹ÓÐÁ½¸öºÃ¶«¶«tasklistºÍtskill¡£tasklistÄÜÁгöËùÓеĽø³Ì£¬ºÍÏàÓ¦µÄÐÅÏ¢¡£tskillÄܲéɱ½ø³Ì£¬Óï·¨ºÜ¼òµ¥£ºtskill ³ÌÐòÃû¡£

TOP

ȷʵº±¼û лл·ÖÏí ^_^

»¶Ó­´ó¼Ò¹âÁÙ:¾Õ»¨ÂÛ̳ ö¦Í¼¹²ÉÍ

TOP

Ò²Êղر¸Óã¬Ð»ÁË£¡
Ò»¸öŬÁ¦ÇÚ±¸µÄ²ËÄñ£¬ÓÀÔ¶·É²»¸ßµÄ²ËÄñ¡£
»¶Ó­´ó¼Ò¹âÁÙ:Ó²¼þ¼¼ÊõºÍ·þÎñÆ÷°æÃ棬ÎÒ»áŬÁ¦Óë´ó¼ÒÒ»ÆðÌÖÂÛÎÊÌâµÄ£¬Ï£ÍûÓë´ó¼Ò¹²Í¬Ñ§Ï°¡¢»¥Ïà°ïÖú¡¢¹²Í¬½ø²½¡£

TOP

Êղأ¬Ð»LZÁË

TOP

¸ü¶àNTSDµÄ²ÎÊý¡£

Ö±½ÓÊäÈë½ø³ÌÃû£¬¼´¿É½áÊø
¸½¼þ: ÄúËùÔÚµÄÓû§×éÎÞ·¨ÏÂÔØ»ò²é¿´¸½¼þ
-------------
Do it,just.С^@^´ó^@^
-------------------------------------
Ò»²½Ò»¸ö½ÅÓ¡£¬Ì¤Ì¤ÊµÊµ

TOP

²»´í£¬ÓÖѧÁËÒ»ÕУ¬

TOP

ºÃÌû£¬ÊÕÏÂÁË£¬THANK YOU£¡£¡£¡

TOP

TSKILL processid | processname [/SERVER:servername] [/ID:sessionid | /A] [/V]

processid Òª½áÊøµÄ½ø³ÌµÄ Process ID¡£
processname Òª½áÊøµÄ½ø³ÌÃû³Æ¡£
/SERVER:servername º¬ÓÐ processID µÄ·þÎñÆ÷(Ĭ
ʹÓýø³ÌÃûºÍ /SERVER ʱ
/ID »ò /A
/ID:sessionid ½áÊøÔÚÖ¸¶¨»á»°ÏÂÔËÐеĽø³Ì
/A ½áÊøÔÚËùÓлỰÏÂÔËÐеĽø³Ì
/V ÏÔʾÕýÔÚÖ´ÐеÄ*×÷µÄÐÅÏ¢¡£

TOP

Windows XP/2000µÄÈÎÎñ¹ÜÀíÆ÷ÊÇÒ»¸ö·Ç³£ÓÐÓõŤ¾ß£¬ÄÜÈÃÄã¿´µ½ÏµÍ³ÖÐÕýÔÚÔËÐÐÄÄЩ³ÌÐò(½ø³Ì)£¬Ö»ÒªÄãÆ½Ê±¶à¿´ÈÎÎñ¹ÜÀíÆ÷ÖеĽø³ÌÁÐ±í£¬ÊìϤϵͳµÄ»ù±¾½ø³Ì£¬¾Í¿ÉÒÔËæÊ±·¢ÏÖ¿ÉÒɽø³Ì£¬Õâ¶Ô·À·¶Ä¾ÂíºÍ²¡¶¾´óÓÐñÔÒæ!

¡¡¡¡Ò»¡¢ÄÄЩϵͳ½ø³Ì²»Äܹصô

¡¡¡¡WindowsÔËÐеÄʱºò£¬»áÆô¶¯¶à¸ö½ø³Ì¡£Ö»ÒªÄã°´Ï¡°Ctrl+Alt+Del¡±¼ü´ò¿ªÈÎÎñ¹ÜÀíÆ÷£¬µã»÷¡°²é¿´¡±/Ñ¡ÔñÁУ¬¹´Ñ¡¡°PIO(½ø³Ì±êʶ·û)¡±£¬È»ºóµ¥»÷¡°½ø³Ì¡±±êÇ©£¬¼´¿É¿´µ½ÕâЩ½ø³Ì¡£²»¹ýÓÐһЩ½ø³Ì¸öÈËÓû§¸ù±¾Óò»µ½£¬ÀýÈçSystray.exe(ÏÔʾϵͳÍÐÅÌСÀ®°Èͼ±ê)¡¢Ctfmon.exe(΢ÈíOfficeÊäÈë·¨)¡¢Winampa.exeµÈ£¬ÎÒÃÇÍêÈ«¿ÉÒÔ½ûÖ¹ËüÃÇ£¬ÕâÑù×ö²¢²»»áÓ°ÏìϵͳµÄÕý³£ÔËÐС£

¡¡¡¡¶þ¡¢ÈçºÎ¹Ø±ÕÈÎÎñ¹ÜÀíÆ÷ɱ²»Á˵Ľø³Ì

¡¡¡¡Èç¹ûÄãÔÚÈÎÎñ¹ÜÀíÆ÷ÖÐÎÞ·¨¹Ø±Õij¸ö¿ÉÒɽø³Ì£¬¿ÉÒÔʹÓÃÏÂÃæµÄ·½·¨Ç¿Ðйرգ¬×¢ÒⲻҪɱµô½ø³Ì±íÖеÄϵͳºËÐĽø³Ì:

¡¡¡¡1.ʹÓÃWindows XP/2000×Ô´øµÄ¹¤¾ß

¡¡¡¡´ÓWindows 2000¿ªÊ¼£¬Windowsϵͳ¾Í×Ô´øÁËÒ»¸öÓû§Ì¬µ÷ÊÔ¹¤¾ßNtsd£¬ËüÄܹ»É±µô´ó²¿·Ö½ø³Ì£¬ÒòΪ±»µ÷ÊÔÆ÷¸½×ŵĽø³Ì»áËæµ÷ÊÔÆ÷Ò»ÆðÍ˳ö£¬ËùÒÔÖ»ÒªÄãÔÚÃüÁîÐÐÏÂʹÓÃNtsdµ÷³öij½ø³Ì£¬È»ºóÍ˳öNtsd¼´¿ÉÖÕÖ¹¸Ã½ø³Ì£¬¶øÇÒʹÓÃNtsd»á×Ô¶¯»ñµÃDebugȨÏÞ£¬Òò´ËNtsdÄÜɱµô´ó²¿·ÖµÄ½ø³Ì¡£

¡¡¡¡*×÷·½·¨:µ¥»÷¡°¿ªÊ¼¡±/³ÌÐò/¸½¼þ/ÃüÁîÌáʾ·û£¬ÊäÈëÃüÁî:ntsd -c q -p PID(°Ñ×îºóÄǸöPID£¬¸Ä³ÉÄãÒªÖÕÖ¹µÄ½ø³ÌµÄPID)¡£ÔÚ½ø³ÌÁбíÖÐÄã¿ÉÒԲ鵽ij¸ö½ø³ÌµÄPID£¬ÀýÈçÎÒÃÇÒª¹Ø±Õͼ1ÖеÄExplorer.exe½ø³Ì£¬ÊäÈë:ntsd -c q -p 408¼´¿É¡£

¡¡¡¡ÒÔÉϲÎÊý-p±íʾºóÃæ¸úËæµÄÊǽø³ÌPID£¬ -c q±íʾִÐÐÍ˳öNtsdµÄµ÷ÊÔÃüÁ´ÓÃüÁîÐаÑÒÔÉϲÎÊý´«µÝ¹ýÈ¥¾ÍÐÐÁË¡£

¡¡¡¡2. ʹÓÃרÃŵÄÈí¼þÀ´É±½ø³Ì

¡¡¡¡ÈÎÎñ¹ÜÀíÆ÷ɱ²»µôµÄ½ø³Ì£¬Äã¿ÉÒÔʹÓÃרÃŵÄÈí¼þ¹Ø±Õ¡£ÓкܶàÈí¼þ¿ÉÒÔɱ½ø³Ì£¬ÀýÈç½ø³ÌɱÊÖ¡¢IceSword¡¢ÁøÒ¶²ÁÑÛ¡¢ÏµÍ³²é¿´´óʦ¡¢Kill processµÈ¡£

TOP

NTSD ÖÐËù¸½µÄ°ïÖúÎļþ

usage: ntsd [-?] [-2] [-d] [-g] [-G] [-myob] [-lines] [-n] [-o] [-s] [-v] [-w]
[-r BreakErrorLevel] [-t PrintErrorLevel]
[-hd] [-pd] [-pe] [-pt #] [-pv] [-x | -x{e|d|n|i} ]
[-- | -p pid | -pn name | command-line | -z CrashDmpFile]
[-zp CrashPageFile] [-premote transport] [-robp]
[-aDllName] [-c "command"] [-i ImagePath] [-y SymbolsPath]
[-clines #] [-srcpath SourcePath] [-QR \\machine] [-wake ]
[-remote transport:server=name,portid] [-server transport:portid]
[-ses] [-sfce] [-sicv] [-snul] [-noio] [-failinc] [-noshell]

where: -? displays this help text
command-line is the command to run under the debugger
-- is the same as -G -g -o -p -1 -d -pd
-aDllName sets the default extension DLL
-c executes the following debugger command
-clines number of lines of output history retrieved by a remote client
-failinc causes incomplete symbol and module loads to fail
-d sends all debugger output to kernel debugger via DbgPrint
-d cannot be used with debugger remoting
-d can only be used when the kernel debugger is enabled
-g ignores initial breakpoint in debuggee
-G ignores final breakpoint at process termination
-hd specifies that the debug heap should not be used
for created processes. This only works on Windows Whistler.
-o debugs all processes launched by debuggee
-p pid specifies the decimal process Id to attach to
-pd specifies that the debugger should automatically detach
-pe specifies that any attach should be to an existing debug port
-pn name specifies the name of the process to attach to
-pt # specifies the interrupt timeout
-pv specifies that any attach should be noninvasive
-r specifies the (0-3) error level to break on (SeeSetErrorLevel)
-robp allows breakpoints to be set in read-only memory
-t specifies the (0-3) error level to display (SeeSetErrorLevel)
-w specifies to debug 16 bit applications in a separate VDM
-x sets second-chance break on *** exceptions
-x{e|d|n|i} sets the break status for the specified event
-2 creates a separate console window for debuggee
-i ImagePath specifies the location of the executables that generated
the fault (see _NT_EXECUTABLE_IMAGE_PATH)
-lines requests that line number information be used if present
-myob ignores version mismatches in DBGHELP.DLL
-n enables verbose output from symbol handler
-noio disables all I/O for dedicated remoting servers
-noshell disables the .shell (!!) command
-QR <\\machine> queries for remote servers
-s disables lazy symbol loading
-ses enables strict symbol loading
-sfce fails critical errors encountered during file searching
-sicv ignores the CV record when symbol loading
-snul disables automatic symbol loading for unqualified names
-srcpath specifies the source search path
-v enables verbose output from debugger
-wake wakes up a sleeping debugger and exits
-y specifies the symbol search path (see _NT_SYMBOL_PATH)
-z specifies the name of a crash dump file to debug
-zp specifies the name of a page.dmp file
to use with a crash dump
-remote lets you connect to a debugger session started with -server
must be the first argument if present
transport: tcp | npipe | ssl | spipe | 1394 | com
name: machine name on which the debug server was created
portid: id of the port the debugger server was created on
for tcp use: port=
for npipe use: pipe=
for 1394 use: channel=
for com use: port=,baud=,
channel=
for ssl and spipe see the documentation
example: ... -remote npipe:server=yourmachine,pipe=foobar
-server creates a debugger session other people can connect to
must be the first argument if present
transport: tcp | npipe | ssl | spipe | 1394 | com
portid: id of the port remote users can connect to
for tcp use: port=
for npipe use: pipe=
for 1394 use: channel=
for com use: port=,baud=,
channel=
for ssl and spipe see the documentation
example: ... -server npipe:pipe=foobar
-premote transport specifies the process server to connect to
transport arguments are given as with remoting

Environment Variables:

_NT_SYMBOL_PATH=[Drive:][Path]
Specify symbol image path.

_NT_ALT_SYMBOL_PATH=[Drive:][Path]
Specify an alternate symbol image path.

_NT_DEBUGGER_EXTENSION_PATH=[Drive:][Path]
Specify a path which should be searched first for extensions dlls

_NT_EXECUTABLE_IMAGE_PATH=[Drive:][Path]
Specify executable image path.

_NT_SOURCE_PATH=[Drive:][Path]
Specify source file path.

_NT_DEBUG_LOG_FILE_OPEN=filename
If specified, all output will be written to this file from offset 0.

_NT_DEBUG_LOG_FILE_APPEND=filename
If specified, all output will be APPENDed to this file.

_NT_DEBUG_HISTORY_SIZE=size
Specifies the size of a server's output history in kilobytes

Control Keys:

Quit debugger
Break into Target
Force a break into debuggee (same as Ctrl-C)
Debug Current debugger
Toggle Verbose mode
Print version information
ntsd: exiting - press enter ---

TOP

¹ûÈ»ºÃÓÃ,¶àл¥Ö÷·ÖÏí!

µ«ÈÔÓв¿·Ö"Á÷Ã¥"Èí¼þÎÞ·¨½áÊø¡£

[ ±¾Ìû×îºóÓÉ 88197191 ÓÚ 2006-7-26 09:55 ±à¼­ ]

TOP

ÊÕ²Ø..¸Ðл¸÷λ¡£ÓÐѧµ½NÕÐ

TOP

ºÃÓÃ~!

TOP

Ì«¶àÁ˰É.Í·ÔεÄ

TOP

Êղأ¡ºÃ¶«Î÷¡£

TOP

²»´í£¬ÓÖÒ»ÕÐ

TOP

²»´í£¬ÓÖѧÁËÒ»ÕÐ

TOP

лл

TOP

ºÃ·½·¨...44

TOP

¶àл¥Ö÷!

TOP