ビジネス WinDbgアプリケーション開発技術 イメージロード(ユーザモードとカーネルモード)


WinDbg環境の有効性を確認する

 私たちはこれまでWinDbg環境の一部を整備してきました。このため、「File/Kernel Debug...」と選択し、「Local」タブ経由でローカルコンピュータに接続すると、次のような情報が表示されてくるはずです。
Microsoft (R) Windows Debugger  Version 6.5.0003.7
Copyright (c) Microsoft Corporation. All rights reserved.

Connected to Windows XP 2600 x86 compatible target, ptr64 FALSE
Symbol search path is: srv*c:\ossymbols*http://msdl.microsoft.com/download/symbols
*******************************************************************************
WARNING: Local kernel debugging requires booting with /debug to work optimally.
*******************************************************************************
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp2_gdr.050301-1519
Kernel base = 0x804d9000 PsLoadedModuleList = 0x8055c420
Debug session time: Sat Sep  3 12:00:04.498 2005 (GMT+9)
System Uptime: 0 days 5:38:19.073
 今回は、ここまでの環境整備がすでに完了している前提で、次のような操作を行います。

・Windowsシステム内部情報を表示する
・最新Windowsシステムデバッグシンボルをダウンロードする
・詳細なWindowsシステム内部情報を表示する


Windowsシステム内部情報を表示する
 次のコマンドを実行してください。
lkd> lm
start    end        module name
804d9000 806ed100   nt         (pdb symbols)          c:\ossymbols\ntoskrnl.pdb\32962337F0F646388B39535CD8DD70E82\ntoskrnl.pdb

Unloaded modules:
f3d04000 f3d2e000   kmixer.sys
f3d04000 f3d2e000   kmixer.sys
f4130000 f415a000   kmixer.sys
f99af000 f99b0000   drmkaud.sys
f4312000 f431f000   DMusic.sys
f4ad5000 f4ae3000   swmidi.sys
f415a000 f417d000   aec.sys 
f97dd000 f97df000   splitter.sys
f4811000 f4820000   Serial.SYS
f9041000 f9045000   wADV01nt.sys
f9045000 f9048000   wADV02NT.sys
f9049000 f904c000   wADV05NT.sys
f95e9000 f95ee000   wVchNTxx.sys
f95e1000 f95e9000   wATV01nt.sys
f95d9000 f95de000   wATV02NT.sys
f9341000 f934a000   wATV04nt.sys
f95d1000 f95d7000   wCh7xxNT.sys
f95c9000 f95cf000   wATV06nt.sys
f975d000 f9760000   wADV07nt.sys
f9759000 f975c000   wADV08nt.sys
f9755000 f9758000   wADV09nt.sys
f95c1000 f95c8000   wATV10nt.sys
f9751000 f9754000   wADV11nt.sys
f95f9000 f95fe000   Cdaudio.SYS
f9035000 f9038000   Sfloppy.SYS

 最新Windowsシステムデバッグシンボルをダウンロードする
 Microsoft社のシンボルサーバとシンボル格納用のローカルフォルダを設定後、次のコマンドを実行します。シンボルサーバから大量の情報がローカルフォルダにダウンロードされてくるはずです。結構時間もかかりますから、ダウンロードが完了するのを待ちます。ERRORやWarningなどのメッセージも入っていると思いますが、無視しておいてください。
lkd> .reload /f
Connected to Windows XP 2600 x86 compatible target, ptr64 FALSE
Loading Kernel Symbols
.............................*** ERROR: Module load completed but symbols could not be loaded for \SystemRoot\System32\DRIVERS\i81xnt5.sys
..*** ERROR: Module load completed but symbols could not be loaded for \SystemRoot\system32\drivers\es198x.sys
..*** ERROR: Symbol file could not be found.  Defaulted to export symbols for \SystemRoot\system32\drivers\drmk.sys - 
..*** ERROR: Module load completed but symbols could not be loaded for \SystemRoot\System32\DRIVERS\HCF_MSFT.sys
......*** WARNING: Unable to verify timestamp for \SystemRoot\System32\DRIVERS\fdc.sys
*** ERROR: Module load completed but symbols could not be loaded for \SystemRoot\System32\DRIVERS\fdc.sys
........................*** ERROR: Module load completed but symbols could not be loaded for \SystemRoot\System32\DRIVERS\wSiINTxx.sys
.................................*** ERROR: Symbol file could not be found.  Defaulted to export symbols for \SystemRoot\System32\i81xdnt5.dll - 
........
Loading unloaded module list
.........................
Loading User Symbols
.................................*** ERROR: Module load completed but symbols could not be loaded for C:\WINDOWS\system32\xpsp2res.dll
.........................

詳細なWindowsシステム内部情報を表示する
 最初に実行したコマンドと同じものを実行します。しかし、今回表示される情報は前回とまったく異なるはずです。ここでは表示される情報の違いを確認するだけにしておきます。
lkd> lm
start    end        module name
01000000 0106b000   windbg     (pdb symbols)          c:\ossymbols\windbg.pdb\08A5AE407DDA4A298B31541F5263A43C1\windbg.pdb
02000000 022b7000   dbgeng     (pdb symbols)          c:\ossymbols\dbgeng.pdb\C5D1E7FC507A42D6B3C85FDCC70601D21\dbgeng.pdb
02d50000 02d96000   symsrv     (pdb symbols)          c:\ossymbols\symsrv.pdb\1637E9D797D94BEA8F33F4CCD89AF5061\symsrv.pdb
02dd0000 02e23000   exts       (pdb symbols)          c:\ossymbols\exts.pdb\AAAA7A57238C432980122319186B3EC11\exts.pdb
02e30000 02e61000   kext       (pdb symbols)          c:\ossymbols\kext.pdb\AE26E338CEAD4BCEA9397F81A484AAA31\kext.pdb
03000000 03118000   dbghelp    (pdb symbols)          c:\ossymbols\dbghelp.pdb\06C2195B84264EE2B067C894327B1BA41\dbghelp.pdb
040c0000 041c9000   ext        (pdb symbols)          c:\ossymbols\ext.pdb\37E356DB071C4EBFA4E8C5188B47FCE71\ext.pdb
041d0000 0433d000   kdexts     (pdb symbols)          c:\ossymbols\kdexts.pdb\65D27CC03CDC44CFA2BBB8276C7773D51\kdexts.pdb
20000000 20560000   xpsp2res   (no symbols)           
3b100000 3b11b000   IMJPCD     (pdb symbols)          c:\ossymbols\imjpcd.pdb\3F9FAF0A1\imjpcd.pdb
4edc0000 4ee16000   imjp81     (pdb symbols)          c:\ossymbols\imjp81.pdb\3F9FB17F2\imjp81.pdb
58730000 58768000   uxtheme    (pdb symbols)          c:\ossymbols\uxtheme.pdb\B982B8FE390B4359AD3CCECC16C0D59F2\uxtheme.pdb
59250000 592a4000   NETAPI32   (pdb symbols)          c:\ossymbols\netapi32.pdb\6B3C00D125AA46A3BFA29A183401FB332\netapi32.pdb
5ab60000 5abf7000   COMCTL32   (pdb symbols)          c:\ossymbols\comctl32.pdb\738BFE9AAECA471D823230239CDC1ECB2\comctl32.pdb
60740000 60749000   LPK        (pdb symbols)          c:\ossymbols\lpk.pdb\C8E0E10EECAB4E90A1D1E442AF0AD0001\lpk.pdb
607c0000 60816000   hnetcfg    (pdb symbols)          c:\ossymbols\HNetCfg.pdb\F662D314F374499784BC0592B8DB8BEF1\HNetCfg.pdb
648f0000 649c0000   imjp81k    (pdb symbols)          c:\ossymbols\imjp81k.pdb\3F9FAF862\imjp81k.pdb
71980000 719bf000   mswsock    (pdb symbols)          c:\ossymbols\mswsock.pdb\F664880369E243B78A8603165451EAB02\mswsock.pdb
719c0000 719c8000   wshtcpip   (pdb symbols)          c:\ossymbols\wshtcpip.pdb\DE010D61873545F49D43D91367E871DC2\wshtcpip.pdb
719d0000 719d8000   WS2HELP    (pdb symbols)          c:\ossymbols\ws2help.pdb\537CE830EFE94FE3A92C95153BDB71462\ws2help.pdb
719e0000 719f7000   WS2_32     (pdb symbols)          c:\ossymbols\ws2_32.pdb\07AC08831007408D919E0CCF1EA499BF2\ws2_32.pdb
71a00000 71a0b000   wsock32    (pdb symbols)          c:\ossymbols\wsock32.pdb\E7B6C17E43604822813D3B65499B6C0F2\wsock32.pdb
71a50000 71a62000   MPR        (pdb symbols)          c:\ossymbols\mpr.pdb\637FC2DC1D0A490799B088562BF4F29A2\mpr.pdb
72220000 72225000   sensapi    (pdb symbols)          c:\ossymbols\sensapi.pdb\EA5A940052D941D7A1C77521A8AEEFD62\sensapi.pdb
73620000 7364e000   msctfime   (pdb symbols)          c:\ossymbols\msctfime.pdb\ECE04C0393764AD0B3E9658C0D8BA88D1\msctfime.pdb
73f80000 73feb000   USP10      (pdb symbols)          c:\ossymbols\usp10.pdb\14C8D7F8AB3C48A4B95A73BAC9A6B02C1\usp10.pdb
74660000 746ab000   MSCTF      (pdb symbols)          c:\ossymbols\msctf.pdb\27CE4025AEE44B569B9ED28F7B4E15E32\msctf.pdb
74d70000 74ddc000   RICHED20   (pdb symbols)          c:\ossymbols\riched20.pdb\4CEEB22B2E9046E396D2914386EC32FE2\riched20.pdb
759b0000 75a60000   USERENV    (pdb symbols)          c:\ossymbols\userenv.pdb\C72199CE55A04CD2A965557CF1D97F4E2\userenv.pdb
75c40000 75cdc000   urlmon     (pdb symbols)          c:\ossymbols\urlmon.pdb\28171F84015E4D708D98D87DD04D15032\urlmon.pdb
762e0000 762fd000   IMM32      (pdb symbols)          c:\ossymbols\imm32.pdb\2C17A49C251B4C8EB9E2AD13D7D9EA162\imm32.pdb
765c0000 76653000   CRYPT32    (pdb symbols)          c:\ossymbols\crypt32.pdb\4087B6738F3B4A1AA9C545877746B8892\crypt32.pdb
76660000 76704000   WININET    (pdb symbols)          c:\ossymbols\wininet.pdb\E1A2E29AD672487EB6C57A58387D9CAC2\wininet.pdb
76970000 76aad000   ole32      (pdb symbols)          c:\ossymbols\ole32.pdb\4671376970554AEC9C23D75CE9B25C552\ole32.pdb
76af0000 76b1b000   WINMM      (pdb symbols)          c:\ossymbols\winmm.pdb\4FC9F179964745CAA3C78D6FADFC28322\winmm.pdb
76ba0000 76bab000   psapi      (pdb symbols)          c:\ossymbols\psapi.pdb\A5C3A1F9689F43D8AD228A09293889702\psapi.pdb
76d10000 76d29000   iphlpapi   (pdb symbols)          c:\ossymbols\iphlpapi.pdb\E9B6A87967AC4325BBF09147F7FEF1222\iphlpapi.pdb
76e30000 76e3e000   rtutils    (pdb symbols)          c:\ossymbols\rtutils.pdb\7FFB6B0702ED43D892CD0849BD5C2E732\rtutils.pdb
76e40000 76e52000   rasman     (pdb symbols)          c:\ossymbols\rasman.pdb\3D151A071ADA48E8B829E92D63F837272\rasman.pdb
76e60000 76e8f000   TAPI32     (pdb symbols)          c:\ossymbols\tapi32.pdb\5563FE83E67C47DCB9E113A6640F1EC12\tapi32.pdb
76e90000 76ecc000   RASAPI32   (pdb symbols)          c:\ossymbols\rasapi32.pdb\7A1262AF55714126BEF6A0DC7F0F0C742\rasapi32.pdb
76ed0000 76ef7000   DNSAPI     (pdb symbols)          c:\ossymbols\dnsapi.pdb\A799ADC315524318B409040F33C17AA22\dnsapi.pdb
76f70000 76f76000   rasadhlp   (pdb symbols)          c:\ossymbols\rasadhlp.pdb\1FA989B2899C4E3E94CB74000514F5922\rasadhlp.pdb
770d0000 7715c000   oleaut32   (pdb symbols)          c:\ossymbols\oleaut32.pdb\149FB0C830BC400DBA99728EFB58A1132\oleaut32.pdb
77160000 77262000   comctl32_77160000   (pdb symbols)          c:\ossymbols\MicrosoftWindowsCommon-Controls-6.0.2600.2180-comctl32.pdb\C454919C031643618F4CAC675CBC64401\MicrosoftWindowsCommon-Controls-6.0.2600.2180-comctl32.pdb
77bb0000 77bb8000   VERSION    (pdb symbols)          c:\ossymbols\version.pdb\180A90C40384463E82DDC45B2C8AB76E2\version.pdb
77bc0000 77c18000   msvcrt     (pdb symbols)          c:\ossymbols\msvcrt.pdb\A678F3C30DED426B839032B996987E381\msvcrt.pdb
77c40000 77c52000   MSASN1     (pdb symbols)          c:\ossymbols\msasn1.pdb\754C967792684AA899268F9F0C20F35E2\msasn1.pdb
77cb0000 77cd3000   msv1_0     (pdb symbols)          c:\ossymbols\msv1_0.pdb\56998E10FA6C491A9A7B2E3A03C37DB82\msv1_0.pdb
77cf0000 77d7f000   USER32     (pdb symbols)          c:\ossymbols\user32.pdb\EE2B714D83A34C9D88027621272F83262\user32.pdb
77d80000 77e29000   ADVAPI32   (pdb symbols)          c:\ossymbols\advapi32.pdb\455D6C5F184D45BBB5C5F30F829751142\advapi32.pdb
77e30000 77ec1000   RPCRT4     (pdb symbols)          c:\ossymbols\rpcrt4.pdb\BEA45A721DA141DAA3BA86B3A20311532\rpcrt4.pdb
77ed0000 77f16000   GDI32      (pdb symbols)          c:\ossymbols\gdi32.pdb\1FA0F418684D4EFA9F8447E4192B18522\gdi32.pdb
77f20000 77f96000   SHLWAPI    (pdb symbols)          c:\ossymbols\shlwapi.pdb\0D05DCE7ECA14C95B1F3F4B88D0A99792\shlwapi.pdb
77fa0000 77fb1000   Secur32    (pdb symbols)          c:\ossymbols\secur32.pdb\85DD72BF4CAD42EFB989699A8B082F1D2\secur32.pdb
7c800000 7c931000   kernel32   (pdb symbols)          c:\ossymbols\kernel32.pdb\FB334FB28FA34128BDE9229285BE4C2F2\kernel32.pdb
7c940000 7c9dd000   ntdll      (pdb symbols)          c:\ossymbols\ntdll.pdb\36515FB5D04345E491F672FA2E2878C02\ntdll.pdb
7d5b0000 7ddad000   SHELL32    (pdb symbols)          c:\ossymbols\shell32.pdb\290E0039FDA7491EAB979ECE585EE06D2\shell32.pdb
804d9000 806ed100   nt         (pdb symbols)          c:\ossymbols\ntoskrnl.pdb\32962337F0F646388B39535CD8DD70E82\ntoskrnl.pdb
806ee000 80701d80   hal        (pdb symbols)          c:\ossymbols\halacpi.pdb\BECA5A4012524CD290B45877E8FC674F1\halacpi.pdb
bf800000 bf9c0380   win32k     (pdb symbols)          c:\ossymbols\win32k.pdb\A3AB09585A2B460A862026EAC39852742\win32k.pdb
bf9c1000 bf9d2580   dxg        (pdb symbols)          c:\ossymbols\dxg.pdb\6443AD3CC36F49BD8A4D7F5259E15F591\dxg.pdb
bf9d3000 bfa7e940   i81xdnt5   (export symbols)       \SystemRoot\System32\i81xdnt5.dll
f3d04000 f3d2df00   kmixer     (pdb symbols)          c:\ossymbols\kmixer.pdb\AEC79945DFCC4F5EB217F5B7F4A58DDF1\kmixer.pdb
f3e46000 f3e86100   HTTP       (pdb symbols)          c:\ossymbols\http.pdb\2A3807D891D340B59E75A7E5AF1BCA421\http.pdb
f417d000 f4191400   wdmaud     (pdb symbols)          c:\ossymbols\wdmaud.pdb\69752CA941714E8B8AFCD29F503CE9AC2\wdmaud.pdb
f45f2000 f4643300   srv        (pdb symbols)          c:\ossymbols\srv.pdb\4070BFC0969D400EBC0251E3E3043D872\srv.pdb
f4694000 f46c0400   mrxdav     (pdb symbols)          c:\ossymbols\mrxdav.pdb\39E18188AC3942C7B4CA8F4ABC3B15BF1\mrxdav.pdb
f46c1000 f46d0900   Cdfs       (pdb symbols)          c:\ossymbols\cdfs.pdb\E4641046039940509C2A785DBB90414D2\cdfs.pdb
f4751000 f475fd80   sysaudio   (pdb symbols)          c:\ossymbols\sysaudio.pdb\0680FF5C8E3A4B7CBDED87903282A5A32\sysaudio.pdb
f4a01000 f4a18480   dump_atapi   (pdb symbols)          c:\ossymbols\atapi.pdb\25228DED4EEC41F29756FC1568E4B63F1\atapi.pdb
f4a19000 f4a3c000   Fastfat    (pdb symbols)          c:\ossymbols\fastfat.pdb\49F9F5CA625D4A5C9DC927485DA7809F2\fastfat.pdb
f4a4c000 f4a4e900   Dxapi      (pdb symbols)          c:\ossymbols\dxapi.pdb\A63AA409BC33424F9C61C4743C15609B1\dxapi.pdb
f4a64000 f4a84f00   ipnat      (pdb symbols)          c:\ossymbols\ipnat.pdb\092A0221D21B46AAA8C920C2B27E13E71\ipnat.pdb
f4b25000 f4b46d00   afd        (pdb symbols)          c:\ossymbols\afd.pdb\F999EE0290D54451AEBCA30AD24CAAB22\afd.pdb
f4b47000 f4b6ec00   netbt      (pdb symbols)          c:\ossymbols\netbt.pdb\68363A5520E247C5830D7E67ABA19D072\netbt.pdb
f4b6f000 f4bc6d80   tcpip      (pdb symbols)          c:\ossymbols\tcpip.pdb\089EC52BD5FB4827981E1076236CE94C2\tcpip.pdb
f4bc7000 f4bd9400   ipsec      (pdb symbols)          c:\ossymbols\ipsec.pdb\3A13FAB12CEF49028B6AA15B4CDF05CD2\ipsec.pdb
f8d53000 f8d5bd80   HIDCLASS   (pdb symbols)          c:\ossymbols\hidclass.pdb\216F6902ECF84F0A9A75DB2AB532241F1\hidclass.pdb
f8db7000 f8db9f80   mouhid     (pdb symbols)          c:\ossymbols\mouhid.pdb\4608C01F9F6A4247A0A7FF3123D8D55C1\mouhid.pdb
f8dbf000 f8dc1580   hidusb     (pdb symbols)          c:\ossymbols\hidusb.pdb\D9EE4738B1034525A0FCE098D724547D1\hidusb.pdb
f8dcb000 f8dfe200   update     (pdb symbols)          c:\ossymbols\update.pdb\C0E5C10D07AF4A139C0D21FC3510983C1\update.pdb
f8dff000 f8e2f100   rdpdr      (pdb symbols)          c:\ossymbols\rdpdr.pdb\A81F0F623C3940169DC2E1C410338A031\rdpdr.pdb
f8e30000 f8e46680   ndiswan    (pdb symbols)          c:\ossymbols\ndiswan.pdb\4C16F7937E5B43DCA456976A6860A80C2\ndiswan.pdb
f8e47000 f8e69e80   USBPORT    (pdb symbols)          c:\ossymbols\usbport.pdb\6577C031727943E7BE2D4A8742B28F141\usbport.pdb
f8e85000 f8e98680   parport    (pdb symbols)          c:\ossymbols\parport.pdb\108A07CF6CCD442D9CC62CB94D8ADE1C1\parport.pdb
f8e99000 f8f768c0   HCF_MSFT   (no symbols)           
f8f77000 f8f99680   ks         (pdb symbols)          c:\ossymbols\ks.pdb\229E1E4007D54B0899543A3F3B247F882\ks.pdb
f8f9a000 f8fbd980   portcls    (pdb symbols)          c:\ossymbols\portcls.pdb\9380C119FB254169B3415C54DEF742F52\portcls.pdb
f8fbe000 f8fec480   es198x     (no symbols)           
f8fed000 f9000780   VIDEOPRT   (pdb symbols)          c:\ossymbols\videoprt.pdb\4F7109A70A214E10A9EB16F46D99D5681\videoprt.pdb
f9001000 f90284c0   i81xnt5    (no symbols)           
f9031000 f9033280   rasacd     (pdb symbols)          c:\ossymbols\rasacd.pdb\20B90C6127114BDC88DE7FA31D8618701\rasacd.pdb
f904d000 f904fee0   wSiINTxx   (no symbols)           
f9087000 f90a1580   Mup        (pdb symbols)          c:\ossymbols\mup.pdb\B31678EDA6824BB19A2A0B8081DBF7D72\mup.pdb
f90a2000 f90cea80   NDIS       (pdb symbols)          c:\ossymbols\ndis.pdb\42ED3DC0817A4246B157736BBAF668742\ndis.pdb
f90cf000 f915b480   Ntfs       (pdb symbols)          c:\ossymbols\ntfs.pdb\CF3F539EE3B2408887756DD42D7E53442\ntfs.pdb
f915c000 f9172780   KSecDD     (pdb symbols)          c:\ossymbols\ksecdd.pdb\E9FEAB740C29470CB973CD9D584FE5A51\ksecdd.pdb
f9173000 f9184e80   sr         (pdb symbols)          c:\ossymbols\sr.pdb\B2985B1EA5A340DCA067B59677B5CAAF1\sr.pdb
f9185000 f91a3780   fltmgr     (pdb symbols)          c:\ossymbols\fltMgr.pdb\A3669C0E41994AC2AD2BD6F85D4B1A041\fltMgr.pdb
f91a4000 f91bb480   atapi      (pdb symbols)          c:\ossymbols\atapi.pdb\25228DED4EEC41F29756FC1568E4B63F1\atapi.pdb
f91bc000 f91e1400   dmio       (pdb symbols)          c:\ossymbols\dmio.pdb\A2AA03114EB84B26A6B8E29367484C881\dmio.pdb
f91e2000 f9200880   ftdisk     (pdb symbols)          c:\ossymbols\ftdisk.pdb\370ADA20D01E457AB6AC095AF8D099681\ftdisk.pdb
f9201000 f9211600   pci        (pdb symbols)          c:\ossymbols\pci.pdb\206656EB8AAA4BFCAE215D6EE55305881\pci.pdb
f9212000 f923f800   ACPI       (pdb symbols)          c:\ossymbols\acpi.pdb\F2E034F2911844B491BDAB612C220EAB1\acpi.pdb
f9261000 f9269c00   isapnp     (pdb symbols)          c:\ossymbols\isapnp.pdb\40205FF7480844E98F62335DD78B4F8E1\isapnp.pdb
f9271000 f927fe80   ohci1394   (pdb symbols)          c:\ossymbols\ohci1394.pdb\5098D8F19EF54CB69C9851ECE5CF6B641\ohci1394.pdb
f9281000 f928e000   1394BUS    (pdb symbols)          c:\ossymbols\1394bus.pdb\27C2887AF3E64D83AF628FEF2E49D68D1\1394bus.pdb
f9291000 f929b500   MountMgr   (pdb symbols)          c:\ossymbols\mountmgr.pdb\E76D919C975C47B1AB592D6BF9A53C1B1\mountmgr.pdb
f92a1000 f92ad480   VolSnap    (pdb symbols)          c:\ossymbols\volsnap.pdb\37AD1DAAA6A04AF8B6FC8478DAFCBDE61\volsnap.pdb
f92b1000 f92b9e00   disk       (pdb symbols)          c:\ossymbols\disk.pdb\D9F2945AC6DF4EEDB1E66ED610B7A04A1\disk.pdb
f92c1000 f92cd200   CLASSPNP   (pdb symbols)          c:\ossymbols\classpnp.pdb\12E3EB58301B4AC3A5B2D3921F91313A2\classpnp.pdb
f92f1000 f9300180   nic1394    (pdb symbols)          c:\ossymbols\nic1394.pdb\3E420813BB1A4EEB82A73A3AE60875101\nic1394.pdb
f9301000 f930a480   NDProxy    (pdb symbols)          c:\ossymbols\ndproxy.pdb\EE437B1D5CC3470E9E89EFBEF9CD9B241\ndproxy.pdb
f9391000 f9399900   msgpc      (pdb symbols)          c:\ossymbols\msgpc.pdb\E8FB7A9C282647C1B5AE021FDB52C34A1\msgpc.pdb
f93a1000 f93a9880   Fips       (pdb symbols)          c:\ossymbols\fips.pdb\CD572ED242DA4016AA1777EB3F54BBB42\fips.pdb
f93b1000 f93b9700   wanarp     (pdb symbols)          c:\ossymbols\wanarp.pdb\FDB397B5509448699BDFDF4E2214A5D61\wanarp.pdb
f93c1000 f93cfd80   arp1394    (pdb symbols)          c:\ossymbols\arp1394.pdb\6CD94FE01AC044F98A5BFB2E84326C211\arp1394.pdb
f9431000 f943c280   p3         (pdb symbols)          c:\ossymbols\p3.pdb\83619DB519044E0D9E207F3C15E2C3611\p3.pdb
f9441000 f944fb80   drmk       (export symbols)       \SystemRoot\system32\drivers\drmk.sys
f9451000 f945d080   i8042prt   (pdb symbols)          c:\ossymbols\i8042prt.pdb\F869B9CF49F740EA8295BD75997B338D2\i8042prt.pdb
f9461000 f946b380   Imapi      (pdb symbols)          c:\ossymbols\imapi.pdb\790C6839B52C4BCCBF75CC04FD23CA801\imapi.pdb
f9471000 f947d180   cdrom      (pdb symbols)          c:\ossymbols\cdrom.pdb\849D224C3F8F411DB1F0591C655A3F651\cdrom.pdb
f9481000 f948e980   redbook    (pdb symbols)          c:\ossymbols\redbook.pdb\1E1D4F22947E487A8472B5E01CF664D51\redbook.pdb
f9491000 f949d880   rasl2tp    (pdb symbols)          c:\ossymbols\rasl2tp.pdb\814E65B178D34814B403A26E2DC870422\rasl2tp.pdb
f94a1000 f94ab200   raspppoe   (pdb symbols)          c:\ossymbols\raspppoe.pdb\0F527A0AA94E4116AB3BDC8605A441431\raspppoe.pdb
f94b1000 f94bcd00   raspptp    (pdb symbols)          c:\ossymbols\raspptp.pdb\E1B38928B9CF41AA829FF8252DA9BE582\raspptp.pdb
f94c1000 f94caf00   termdd     (pdb symbols)          c:\ossymbols\termdd.pdb\9D17EEE8E3684F9CB51249CEE7D2AC961\termdd.pdb
f94d1000 f94df100   usbhub     (pdb symbols)          c:\ossymbols\usbhub.pdb\A3CE86B8CE4941CC890AD17D38D0EF4D1\usbhub.pdb
f94e1000 f94e7200   PCIIDEX    (pdb symbols)          c:\ossymbols\pciidex.pdb\671C7864E7F74A9D8D84385D1A6347411\pciidex.pdb
f94e9000 f94ed900   PartMgr    (pdb symbols)          c:\ossymbols\partmgr.pdb\2BF62287ECEE48DFB06FF92BF1D0514B2\partmgr.pdb
f9501000 f9505500   watchdog   (pdb symbols)          c:\ossymbols\watchdog.pdb\E34D85BE76CF4B729B27F2CBD2559B881\watchdog.pdb
f9579000 f9580480   Modem      (pdb symbols)          c:\ossymbols\modem.pdb\0712D6DC4B1A4B3F836B767807D89BF61\modem.pdb
f9581000 f9586700   mouclass   (pdb symbols)          c:\ossymbols\mouclass.pdb\5AD51F05354A4C5FA0358FC0B60E0B371\mouclass.pdb
f9589000 f958ed00   kbdclass   (pdb symbols)          c:\ossymbols\kbdclass.pdb\8207E908221F480B8DF0B101EF62AFB41\kbdclass.pdb
f9591000 f9598000   fdc      T (no symbols)           
f9599000 f959e000   usbuhci    (pdb symbols)          c:\ossymbols\usbuhci.pdb\401251DB5CEF4774B90FF7054880FCBC1\usbuhci.pdb
f95a1000 f95a5880   TDI        (pdb symbols)          c:\ossymbols\tdi.pdb\5C695BF68B924AE9BA5283BD91AA12511\tdi.pdb
f95a9000 f95ad580   ptilink    (pdb symbols)          c:\ossymbols\ptilink.pdb\776B55BE9F5846AA8E4590CB42866E6A1\ptilink.pdb
f95b1000 f95b5080   raspti     (pdb symbols)          c:\ossymbols\raspti.pdb\B3C31E3A63DE4E868C024FEBAFF83F761\raspti.pdb
f95f1000 f95f6000   flpydisk   (pdb symbols)          c:\ossymbols\flpydisk.pdb\E1FDA85E9A4B409C84485F51EA17A3421\flpydisk.pdb
f9601000 f9606200   vga        (pdb symbols)          c:\ossymbols\vga.pdb\64C796A95260466CA898ED2D0540BB1A1\vga.pdb
f9609000 f960da80   Msfs       (pdb symbols)          c:\ossymbols\msfs.pdb\5FE94FBDD41B47EE90F09157273AF7A31\msfs.pdb
f9611000 f9618880   Npfs       (pdb symbols)          c:\ossymbols\npfs.pdb\BC1F3D9A55D04CD087AA5C5E30A75D8D1\npfs.pdb
f9641000 f9647180   HIDPARSE   (pdb symbols)          c:\ossymbols\hidparse.pdb\A7AED9BB82EF4AACBEDD15DAA32D69781\hidparse.pdb
f9649000 f964dec0   ADM8511    (pdb symbols)          c:\ossymbols\ADM8511.pdb\3B5524C13\ADM8511.pdb
f9671000 f9674000   BOOTVID    (pdb symbols)          c:\ossymbols\bootvid.pdb\3B7D83451\bootvid.pdb
f9715000 f9717f80   fsvga      (pdb symbols)          c:\ossymbols\fsvga.pdb\DD3ED3416E1E4FB8A6EBE90AC416725B1\fsvga.pdb
f9719000 f971b580   ndistapi   (pdb symbols)          c:\ossymbols\ndistapi.pdb\BFF5A188A558494DAA310545F7A347031\ndistapi.pdb
f9731000 f9734c80   mssmbios   (pdb symbols)          c:\ossymbols\mssmbios.pdb\CEAE494998B24A458588AE7866D1B9421\mssmbios.pdb
f9761000 f9762b80   kdcom      (pdb symbols)          c:\ossymbols\kdcom.pdb\3B7D83461\kdcom.pdb
f9763000 f9764100   WMILIB     (pdb symbols)          c:\ossymbols\wmilib.pdb\E4C3A9A4158C4C51BC4E2B46CA108AA51\wmilib.pdb
f9765000 f9766580   intelide   (pdb symbols)          c:\ossymbols\intelide.pdb\E9E510BE387D4D5A8A3CD81376DE50071\intelide.pdb
f9767000 f9768700   dmload     (pdb symbols)          c:\ossymbols\dmload.pdb\28B0BFC4C7864BBD92DD888A54E9FE841\dmload.pdb
f977f000 f9780a80   ParVdm     (pdb symbols)          c:\ossymbols\parvdm.pdb\A33862D098F54FD3B903D85C5B13CDB51\parvdm.pdb
f978d000 f978e100   swenum     (pdb symbols)          c:\ossymbols\swenum.pdb\D98CEE57A7E6460ABFEADB94BEDB11561\swenum.pdb
f978f000 f9790280   USBD       (pdb symbols)          c:\ossymbols\usbd.pdb\11D6688CD6BB464F9026586BE1CD28F81\usbd.pdb
f97b1000 f97b2f00   Fs_Rec     (pdb symbols)          c:\ossymbols\fs_rec.pdb\126BA98076424D57B0A558CDE9819EB31\fs_rec.pdb
f97b3000 f97b4080   Beep       (pdb symbols)          c:\ossymbols\beep.pdb\65DC45B439164E4C9DEFF20E161DC74C1\beep.pdb
f97b5000 f97b6080   mnmdd      (pdb symbols)          c:\ossymbols\mnmdd.pdb\9871421E8348450AA965551E05AEC4D21\mnmdd.pdb
f97b7000 f97b8080   RDPCDD     (pdb symbols)          c:\ossymbols\RDPCDD.pdb\770565601E554819A9670ADF167252531\RDPCDD.pdb
f97db000 f97dc100   dump_WMILIB   (pdb symbols)          c:\ossymbols\wmilib.pdb\E4C3A9A4158C4C51BC4E2B46CA108AA51\wmilib.pdb
f987c000 f987cc00   audstub    (pdb symbols)          c:\ossymbols\audstub.pdb\6B3BF8F0C8834E7E8EFE53B7A91E2A3F1\audstub.pdb
f98c4000 f98c4d00   dxgthk     (pdb symbols)          c:\ossymbols\dxgthk.pdb\ED52F57C00F5452FBEBABB7C5BA826DF1\dxgthk.pdb
f9933000 f9933b80   Null       (pdb symbols)          c:\ossymbols\null.pdb\77840F8CB3624E438D5D2F0913E4D30E1\null.pdb

Unloaded modules:
f3d04000 f3d2e000   kmixer.sys
f3d04000 f3d2e000   kmixer.sys
f3d04000 f3d2e000   kmixer.sys
f4130000 f415a000   kmixer.sys
f99af000 f99b0000   drmkaud.sys
f4312000 f431f000   DMusic.sys
f4ad5000 f4ae3000   swmidi.sys
f415a000 f417d000   aec.sys 
f97dd000 f97df000   splitter.sys
f4811000 f4820000   Serial.SYS
f9041000 f9045000   wADV01nt.sys
f9045000 f9048000   wADV02NT.sys
f9049000 f904c000   wADV05NT.sys
f95e9000 f95ee000   wVchNTxx.sys
f95e1000 f95e9000   wATV01nt.sys
f95d9000 f95de000   wATV02NT.sys
f9341000 f934a000   wATV04nt.sys
f95d1000 f95d7000   wCh7xxNT.sys
f95c9000 f95cf000   wATV06nt.sys
f975d000 f9760000   wADV07nt.sys
f9759000 f975c000   wADV08nt.sys
f9755000 f9758000   wADV09nt.sys
f95c1000 f95c8000   wATV10nt.sys
f9751000 f9754000   wADV11nt.sys
f95f9000 f95fe000   Cdaudio.SYS
f9035000 f9038000   Sfloppy.SYS

 ここで使用したWinDbgコマンドは「LM」というものですが、このコマンドにはいろいろなオプションが用意されています。WinDbgに慣れる意味でも各種オプションを試してみるとよいでしょう。

前へ | Windowsセキュリティセミナー | 次へ



 WinDbg入門  ホーム


Copyright©豊田孝 2004- 2009
本日は2009-01-06です。