windbg双机调试:
kd> !dml_proc //1
Address PID Image file name
863df8a8 4 System
87863448 108 smss.exe
87ec5030 15c csrss.exe
881d4d40 190 wininit.exe
881d34c0 198 csrss.exe
88251c48 1c0 winlogon.exe
8827cd40 204 services.exe
88275770 20c lsass.exe
88273878 214 lsm.exe
883132c0 288 svchost.exe
88325030 2c4 vmacthlp.exe
8832b818 2e4 svchost.exe
88311648 360 svchost.exe
883d9af8 394 svchost.exe
883cf298 3b0 svchost.exe
88398878 3fc audiodg.exe
88415b48 444 svchost.exe
88453608 4bc svchost.exe
88484448 51c spoolsv.exe
8849ed40 540 svchost.exe
878aaa10 5bc taskhost.exe
888dbd40 65c Everything.exe
88906728 694 svchost.exe
88955478 6e8 VGAuthService.
88944270 714 vmtoolsd.exe
889c1498 164 sppsvc.exe
889bd830 210 svchost.exe
877ca1f8 818 dllhost.exe
88361d40 844 WmiPrvSE.exe
884014a0 85c dllhost.exe
88a9b720 8ec msdtc.exe
88b00030 970 VSSVC.exe
888aa030 9e0 userinit.exe
876734a8 9e8 dwm.exe
88588448 9f4 explorer.exe
88b8e810 a4c vmtoolsd.exe
88bb4720 a54 Everything.exe
88b16a60 b40 rundll32.exe
8774c8f0 d0c WmiPrvSE.exe
876be580 d98 SearchIndexer.
969e2c48 df8 SearchProtocol
969e7468 e0c SearchFilterHo
882cecb0 e90 WmiApSrv.exe
882c0b20 ec4 calc.exe
kd> .process /r /p 882c0b20 //2
Implicit process is now 882c0b20
.cache forcedecodeuser done
Loading User Symbols
................................
kd> .reload //3
Connected to Windows 7 7601 x86 compatible target at (Thu Aug 8 10:37:20.383 2019 (UTC + 8:00)), ptr64 FALSE
Loading Kernel Symbols
..........................................
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
.....................
................................................................
......................
Loading User Symbols
................................
Loading unloaded module list
......
kd> dt _KUSER_SHARED_DATA 7ffe0000
ntdll!_KUSER_SHARED_DATA
+0x000 TickCountLowDeprecated : 0
+0x004 TickCountMultiplier : 0xf99a027
+0x008 InterruptTime : _KSYSTEM_TIME
+0x014 SystemTime : _KSYSTEM_TIME
+0x020 TimeZoneBias : _KSYSTEM_TIME
+0x02c ImageNumberLow : 0x14c
+0x02e ImageNumberHigh : 0x14c
+0x030 NtSystemRoot : [260] "C:\Windows"
+0x238 MaxStackTraceDepth : 0
+0x23c CryptoExponent : 0
+0x240 TimeZoneId : 0
+0x244 LargePageMinimum : 0x200000
+0x248 Reserved2 : [7] 0
+0x264 NtProductType : 1 ( NtProductWinNt )
+0x268 ProductTypeIsValid : 0x1 ''
+0x26c NtMajorVersion : 6
+0x270 NtMinorVersion : 1
+0x274 ProcessorFeatures : [64] ""
+0x2b4 Reserved1 : 0x7ffeffff
+0x2b8 Reserved3 : 0x80000000
+0x2bc TimeSlip : 0
+0x2c0 AlternativeArchitecture : 0 ( StandardDesign )
+0x2c4 AltArchitecturePad : [1] 0
+0x2c8 SystemExpirationDate : _LARGE_INTEGER 0x0
+0x2d0 SuiteMask : 0x110
+0x2d4 KdDebuggerEnabled : 0x3 ''
+0x2d5 NXSupportPolicy : 0x2 ''
+0x2d8 ActiveConsoleId : 1
+0x2dc DismountCount : 0
+0x2e0 ComPlusPackage : 0xffffffff
+0x2e4 LastSystemRITEventTickCount : 0xf2d6
+0x2e8 NumberOfPhysicalPages : 0x3ff7e
+0x2ec SafeBootMode : 0 ''
+0x2ed TscQpcData : 0 ''
+0x2ed TscQpcEnabled : 0y0
+0x2ed TscQpcSpareFlag : 0y0
+0x2ed TscQpcShift : 0y000000 (0)
+0x2ee TscQpcPad : [2] ""
+0x2f0 SharedDataFlags : 0xe
+0x2f0 DbgErrorPortPresent : 0y0
+0x2f0 DbgElevationEnabled : 0y1
+0x2f0 DbgVirtEnabled : 0y1
+0x2f0 DbgInstallerDetectEnabled : 0y1
+0x2f0 DbgSystemDllRelocated : 0y0
+0x2f0 DbgDynProcessorEnabled : 0y0
+0x2f0 DbgSEHValidationEnabled : 0y0
+0x2f0 SpareBits : 0y0000000000000000000000000 (0)
+0x2f4 DataFlagsPad : [1] 0
+0x2f8 TestRetInstruction : 0xc3
+0x300 SystemCall : 0x76ea70b0
+0x304 SystemCallReturn : 0x76ea70b4
+0x308 SystemCallPad : [3] 0
+0x320 TickCount : _KSYSTEM_TIME
+0x320 TickCountQuad : 0x1161
+0x320 ReservedTickCountOverlay : [3] 0x1161
+0x32c TickCountPad : [1] 0
+0x330 Cookie : 0x36b37a7e
+0x334 CookiePad : [1] 0
+0x338 ConsoleSessionForegroundProcessId : 0n3780
+0x340 Wow64SharedInformation : [16] 0
+0x380 UserModeGlobalLogger : [16] 0
+0x3a0 ImageFileExecutionOptions : 0
+0x3a4 LangGenerationCount : 1
+0x3a8 Reserved5 : 0
+0x3b0 InterruptTimeBias : 0
+0x3b8 TscQpcBias : 0
+0x3c0 ActiveProcessorCount : 1
+0x3c4 ActiveGroupCount : 1
+0x3c6 Reserved4 : 0
+0x3c8 AitSamplingValue : 0
+0x3cc AppCompatFlag : 1
+0x3d0 SystemDllNativeRelocation : 0xfefa0000
+0x3d8 SystemDllWowRelocation : 0
+0x3dc XStatePad : [1] 0
+0x3e0 XState : _XSTATE_CONFIGURATION