06 2022 档案
摘要:进程资源 备注: 这里的命令都是基于内核dmp调试 kd> !process 0 0 **** NT ACTIVE PROCESS DUMP **** PROCESS ffff84898203c440 →// 内核空间中的EPROCESS(Executive process block, 进程执行块
阅读全文
摘要:监控进程拉起 @echo off set xcmc1=PerfWndMonHelper.exe set xcmc2=PerfWndMonHelper_x86.exe :START_CHECK tasklist | findstr "%xcmc1%" > nul || goto START1 task
阅读全文
摘要:https://www.expreview.com/66341.html
阅读全文