TRW 2000 for Windows 9x °æ±¾ 1.00
¸üÐÂ
1999.12,25 µÚÒ»¸ö·¢²¼°æ±¾ (1.00)
2000. 1.19 1.05
--------------------------------------------------------------------------------
Ó÷¨
TRW2000 ·¢²¼°æ±¾ÊÇÒ»¸öZIPѹËõ°ü¡£Ö»Òª½«Æä½âѹËõµ½Ò»¸öĿ¼Ï£¬È»ºóÔËÐÐTRW2000.EXE
¼´¿É , ÎÞÐë°²°²×°»òÕßÖØÆô¼ÆËã»ú¡£
Èç¹ûÄúʹÓÃÊÇÖÇÄÜÊó±ê£¬ÇëÔÚTRW2000.INIÖÐÉèÖá¡INTELLIMOUSE=ON in
Èç¹ûÄú·¢ÏÖÄúµÄÊó±êÓÐÎÊÌâ»ò¹¤×÷²»Õý³££¬²»·ÁÊÔÊÔÔÚTRW2000.INIÖÐÉèÖà WINMOUSE=ON ,
µ«ÎÒÃDz»ÍƼöÄúÕâÑù×ö£¬ÒòΪÕâÑù»á½µµÍÎȶ¨ÐÔ¡£
Èç¹ûÄúÐèҪʹÓÃͼÐÎÇý¶¯£¬ÇëÔÚTRW2000.INIÖÐÉèÖà GRAPHICS=ON ¡£
ÉèÖà HOTKEY=XXXX ¿ÉÒÔ¸ü¸Ä0¼¶µÄÈȼü£¬Ä¬ÈϵÄ0¼¶ÈȼüÊÇ Ctrl+M ¡£
ÉèÖà R3HOTKEY=XXXX ¿ÉÒÔ¸ü¸Ä3¼¶µÄÈȼü, ĬÈϵÄÊÇ Ctrl+N
--------------------------------------------------------------------------------
¼ò½é
±ÈSoftICE¸ü¼ÓÇ¿´ó:
. »ùÓÚ¿ª·ÅϵͳÉè¼Æ£¬Ö§³Ö²å¼þ£¨plug-ins£© (²âÊÔ°æÔݲ»Ö§³Ö)
. ¶¯Ì¬×°ÔØ£¬¶¯Ì¬Ð¶ÔØ£¬ËæʱÔËÐÐ
. ×Ô¶¯ÏÔʾËùÓÐ 32λ/16λ µ÷Óú¯ÊýÃû
. Ö§³ÖËùÓÐÀàÐ͵ÄÏÔʾÊÊÅäÆ÷
. Ö§³Ö¼´Ê±Ð´Îļþ
. Ö§³Ö¸ü¶àµÄÐÂÃüÁî:¡¡PDLL32 PNEWSEC TRNEWTCB TRNEWDOS PMODULE SUSPEND
--------------------------------------------------------------------------------
²âÊÔ
²âÊÔÒ»: Dos±£»¤Ä£Ê½³ÌÐò²âÊÔ
1. ÔËÐÐ TRW2000
2. ÔÚWin95Ï´ò¿ªÒ»¸öDOS´°¿Ú
3. ÔÚTRW2000µÄ²Ëµ¥ÖÐÑ¡Ôñ 'trnewdos'
4. ÔÚDOSÌáʾ·ûÏÂÔËÐÐ PMODE.EXE
5. ·µ»Ø TRW2000ÖÐ, Äú»á·¢ÏÖÄúÒѾͣÔÚ¸ÃDOSÓ¦ÓóÌÐòµÄÈë¿Ú´¦ÁË¡£
´ËʱÄú¿ÉÒÔÓÐ2ÖÖÑ¡Ôñ£º
Ñ¡Ôñ 1:
g 342
t
g 342
ÔÙ°´ ¼üÊý´Î, ¾Í¿ÉÒÔ½øÈë 16λµÄ±£»¤Ä£Ê½ÁË!
Èç¹ûʹÓÃ'g 4dd', ÔÙ°´ ¼üÊý´Î£¬Ôò»á½øÈë 32λ±£»¤Ä£Ê½!
Ñ¡Ôñ 2: Ö»Òª:
g if cs<100 ;½øÈë PM16
g if cs!=cs ;³¥ÊÔ½øÈë PM32
g if cs!=cs ;ÔÙÀ´Ò»´Î£¬ÏÖÔÚ¾ÍÊÇ PM32 ÁË
tes²âÊÔ¶þ£º
ÔËÐÐ NOTEPAD.exe, ÔÙÔڲ˵¥ÖÐÑ¡Ôñ "help"£ü"about notepad", ³öÏÖ¹ØÓÚNOTEPADµÄ¶Ô»°¿ò¡£
ÔËÐÐ TRW2000 , ²¢°´Ctrl+N ¼ü¼¤»î TRW2000
´ËʱÎÒÃÇÒ²ÓÐ2ÖÖÑ¡Ôñ£º
Ñ¡Ôñ 1:
hwnd
´Ó hwnd ÁбíÖÐÕÒ³ö'(Dialog)'µÄ¾ä±ú
bpmsg wm_destroy
bl
g
»Øµ½ NOTEPAD ÖÐ, °´"OK", ´Ëʱ±ã¼¤»î TRW2000
°´ F12(Ï൱pretÃüÁî) Êý´Î,ÎÒÃǾͿÉÒÔÕÒµ½Õâ¸ö¶Ô»°¿òÀ´×ÔÒÔϵĵ÷ÓÃ
shell32.dll call [DialogBoxParamA]
notepad.exe call [ShellAboutA]
Ñ¡Ôñ 2:
Ôڲ˵¥ÖÐÑ¡"pmodule", È»ºóÎÒÃÇѸËٻص½ notepad.exe ÖУ¬¾Í»á·¢ÏÖÍ£ÔÚµ÷ÓôúÂë "call
[ShellAboutA]"Ö®ºóÁË.
tes²âÊÔÈý: ÌØȨ¼¶3¼¶µÄÈȼüºÍ 'SUSPEND'ÃüÁî
ÔËÐÐ TRW2000
ÔËÐÐ NOTEPAD.exe,
°´ ÌØȨ¼¶3¼¶µÄÈȼü Ctrl+N ¼¤»î TRW2000,
Ö´ÐÐ"PMODULE"ÃüÁî
ÏÖÔÚÎÒÃÇÍ£ÔÚ NOTEPAD µÄÁì¿ÕÁË!
ÔÙÖ´ÐÐ'SUSPEND'ÃüÁî,ÎÒÃǽ«»á·µ»Ø Windows ,
ÏÖÔÚÄú»á·¢ÏÖ NOTEPAD ±»ÔÝÍ£ÁË!!
´ËʱÄú³ýÁ˲»ÄܹرÕËüÖ®Íâ¿ÉÒÔ¶ÔËü×öÈκÎÊÂÁË£¬
ÔÙ°´Ò»´Î Ctrl+N , Äú»á·¢ÏÖÎÒÃÇÓֻص½¶ÔNOTEPADµÄ¸ú×ٸ߶È״̬ÖÐÁË¡£
tes²âÊÔËÄ: ²¶»ñÐÂÏß³Ì
ÔÚTRW2000µÄ²Ëµ¥ÖÐÑ¡Ôñ 'trnewtcb'
ÏÖÔÚÄúÎÞÂÛÊÇÔËÐÐÈκΠ32λ»òÕß 16λ³ÌÐò£¬TRW2000 ¶¼ÄÜÂíÉϲ¶»ñÕâ¸öÐÂÏ̲߳¢Í£ÔÚ²Ù×÷
ÂëµÄÈë¿Ú´¦¡£
tes²âÊÔÎå:
Èç¹ûÓÃÊó±êÓÒ»÷ËõСÔÚϵͳÀ¸ÖеÄTRW2000ͼ±ê£¬»á³öÏÖÒ»¸öµ¯³ö²Ëµ¥À´£¬µ«¼ÙÉèÎÒÏëÖªµÀ
ϵͳÊÇÈçºÎ×öµÄ»°£¬
Ö»ÒªÔËÐÐ TRW2000, ÓÃÊó±êÓÒ»÷rϵͳÀ¸ÖеÄÈκÎÒ»¸öÓû§Í¼±ê£¬¾Í»áµ¯³öÏàÓ¦µÄ²Ëµ¥À´£¬
ÔÙ°´Ctrl+N ¼¤»îTRW2000.È»ºóÖ´ÐÐ'pmodule'ÃüÁÔÙÓÃÊó±êµã»÷µ¯³ö²Ëµ¥ÒÔÍâµÄÈÎÒâµØ·½
ʹµ¯³ö²Ëµ¥¹Ø±Õ£¬´Ëʱ TRW2000 ±ã±»¼¤»î²¢ÏÔʾ³öÕâ¸öµ¯³ö²Ëµ¥µÄÀ´Ô´Êǵ÷ÓÃ'TrackPopupMenu'.
--------------------------------------------------------------------------------
Èȼü
1. Ctrl + M
ÌØȨ¼¶0¼¶µÄÈȼü£¬Äܹ»Á¢¼´ÖжÏWin9x¡£
Ï൱ÓÚ Soft-ICE µÄÈȼü Ctrl+D.
2. Ctrl + N
ÌØȨ¼¶3¼¶µÄÈȼü¡£
ÔÚ¾ø´ó¶àÊýʱºò£¬ÎÒÃDz¢²»ÐèÒªÔÚ0¼¶ÉÏÖжϡ£¿ÉÒÔÖжÏWindowsµÄÌØȨ¼¶3¼¶µÄÇ°
̨Ï̡߳£
ÕâÓ¦¸ÃÊÇÎÒÃÇ×î³£Óõġ£
Èç¹ûÔÚWin95µÄDOS´°¿ÚÖа´£¼Ctrl+N£¾£¬ TRW½«»áÖжϵ±Ç°ÕýÔÚÔËÐÐµÄ DOS »òÕß DPMI ³Ì
Ðò¡£
Èç¹ûÔÚÈ«ÆÁÄ»µÄDOS·½Ê½Ï°´£¼Ctrl+N£¾£¬½«²»»á²úÉúÈκζ¯×÷¡£
Èç¹ûÄú°´ÁË£¼Ctrl+N£¾µ«È´Ã»ÓÐÈκη´Ó¦µÄ»°£¬¿ÉÒÔÔÙÈÎÒâ¼ü»òÕ߶¯¶¯Êó±ê£¬¿´¿´»á·¢ÉúЩ
ʲôÊÂŶ :D
Ïà¹ØÄÚÈÝ:
HotKeyÃüÁî
--------------------------------------------------------------------------------
´úÂë´°¿Ú
ÔÚ´úÂë´°¿ÚÖУ¬
: ÔÚµ±Ç°µÄ²Ù×÷ÂëÉèÖöϵ㣬µÈͬÓÚ
BPX cs:eip
: ÔËÐе½µ±Ç°µÄ²Ù×÷Âë´¦£¬µÈͬÓÚ
GOX cs:eip
ÃüÁî
ADD ADDR BC BD BE BL BP BPE BPINT3 BPIO BPM BPMSG BPMX BPX CLEARDR CMT CODE D E
EC EXP EXP16 EXP32 FKEYFILE ONT G GDT H HBOOT HELP HotKey HWND IDT LDT LINES
MakePE MOD16 MOD32 NAME P PAGE PageIn PDLL32 PEDump PHYS PMODULE PNEWSEC PRET
PROC R RS S SRC SRCLINES SS Suspend SYM T TABLE task thread TRNEWDOS TRNEWTCB
TRTCB U VCALL VER VM VXD VXDSYM W WC WD WMSG WR WS X
.¡¡¡¡´ú±íµ±Ç°Öµ£¨È統ǰ½ø³Ì£¬µ±ÄÚ´æÇøÓòµÈ£©
£¿¡¡ °ïÖú£¬Ï൱ÓÚ¡°HELP¡±»ò¡°H¡±ÃüÁî
ADD STACK|DATA|DASM
¡¡Ôö¼ÓÒ»¸ö¶ÑÕ»/Êý¾Ý/·´»ã±à´°¿Ú
¡¡¡¡¡¡Àý£ºADD¡¡STACK
¡¡¡¡¡¡¡¡¡¡ADD¡¡DATA
¡¡¡¡¡¡¡¡¡¡ADD¡¡DASM
ADDR¡¡ÄÚ´æ¾ä±ú£ü¹ý³ÌÃû
¡¡¡¡¡¡ÏÔʾ»òÊÇÇл»ÄÚ´æÇøÓò
¡¡¡¡¡¡ÓÃÀ´²ì¿´Ä³Ò»¸öÈÎÎñµÄ˽ÓÐÄÚ´æÇøÓò, »òÊǼӲÎÊý[ÄÚ´æÇøÓò¾ä±ú|¹ý³ÌÃû]ÔÚTRW2000
ÖÐÇл»Ä³Ò»ÈÎÎñµÄ˽ÓÐÄÚ´æÇøÓòΪµ±Ç°¿ÉÑ°Ö·µÄÄÚ´æÇøÓò¡£
¡¡¡¡¡¡Ò»Ð©²ÎÊýµÄÏÔʾ: .HANDLE ÄÚ´æÇøÓò¿ØÖÆ¿éµÄµØÖ·
¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡ .PGTPTR ÿ¸öÈÎÎñ˽ÓÐÒ³±íµÄÆðÖ·
.TABLES ÿ¸ö˽ÓÐÒ³±íÖеıíÏîÊýÄ¿
.MINADDR ÿ¸öÈÎÎñµÄÏßÐÔµØÖ·µÄÆðÖ·
.MAXADDR ÿ¸öÈÎÎñµÄÏßÐÔµØÖ·µÄÖÕÖ·
.MUTEX VMMÓÃÓÚÒ³±í¹ÜÀíµÄ¾ä±ú
.OWNER ʹÓÃÕâ¿éÄÚ´æÇøÓòµÄʵÀýµÄÃû×Ö¡£Èç¹ûÓжà¸öÏàͬÃû×ÖµÄʵÀý
ÔËÐУ¬ADDR´øOWNERÃû×ÖÇл»µÄ»°£¬Çе½±íÖеĵÚÒ»¸öÓдËNAMEµÄʵÀýËùÕ¼µÄÄÚ´æÇøÓò¡£Ëù
ÒÔ´øHANDLEÇл»µÄ»°±È½Ï¾«È·¡£µ±ÓÃADDR¼Ó²ÎÊýºó£¬¿ÉÒÔÓÃÉÏÃæÌáµ½¹ýµÄ"."ÃüÁîÀ´»Øµ½
TRW2000µ¯³öʱËùÊôµÄÈÎÎñÄÚ´æÇøÓò¡£
¡¡¡¡¡¡
BC list|*
Çå³ýÒ»¸ö»ò¶à¸ö¶Ïµã
¡¡¡¡ Ó÷¨£ºÇå³ý¶Ïµãºó£¬ÓÃBLÃüÁî¾Í¿´²»µ½¶ÏµãÁÐ±í£¬ÇÒ±»Çå³ýµÄ¶Ïµã²»ÔÙÆð×÷Óá£
¡¡¡¡¡¡¡¡²ÎÊý: list: ¿ÉÒÔÊǽ«ÒªÇå³ýµÄһϵÁжϵ㣬ÖмäÓÿոñ»ò¶ººÅ¸ô¿ª¡£
¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡ * : Çå³ýËùÓеĶϵ㡣¡¡
BD¡¡list|*
¡¡Ê¹Ò»¸ö»ò¶à¸ö¶ÏµãʧЧ
¡¡¡¡¡¡¡¡Ê¹Ä³¸ö¶ÏµãʧЧÓë BC ÃüÁîµÄÇå³ý²»Í¬£¬ÔÝʱʧЧµÄ¶Ïµã¿ÉÒÔÓà BE ÃüÁîÀ´»Ö¸´¡£
¶ø BC ÃüÁîÊdz¹µ×Çå³ý¡£
¡¡¡¡¡¡¡¡²ÎÊý:list: ¿ÉÒÔÊǵ¥¸ö£¬Ò²¿ÉÒÔÊÇһϵÁжϵ㣬ÖмäÓÿոñ»ò¶ººÅ¸ô¿ª¡£
¡¡¡¡¡¡¡¡¡¡¡¡¡¡ * : ½ûÖ¹ËùÓеĶϵ㡣
BE¡¡list|*
»Ö¸´±» BD ÃüÁîʹ֮ʧЧµÄ¶Ïµã¡£(ÿµ±Ð¶¨Òå¶Ïµã»ò±à¼¶Ïµãʱ£¬ÏµÍ³×Ô¶¯½«Æä
ÖÃΪÓÐЧ)
¡¡¡¡¡¡¡¡²ÎÊý:list: ¿ÉÒÔÊǵ¥¸ö£¬Ò²¿ÉÒÔÊÇһϵÁжϵ㣬ÖмäÒÔ¿Õ¸ñ»ò¶ººÅ¸ô¿ª¡£
¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡* : »Ö¸´ËùÓеĶϵ㡣
BL¡¡¡¡¡¡ÏÔʾµ±Ç°ËùÉèµÄ¶Ïµã
¡¡¡¡¡¡¡¡Óà BL ÃüÁîÏÔʾµ±Ç°ËùÓжϵãµÄÐòºÅ(Õâ¸öÐòºÅ¾ÍÊÇʹÓÃBC BD BDµÈÃüÁîʱҪָ¶¨
µÄ)¡¢ÀàÐÍ¡¢ÊÇ·ñ±»½ûÖ¹µÈÐÅÏ¢¡£
¡¡¡¡¡¡¡¡Èç¹ûÊDZ»BD½ûÖ¹µÄ¶Ïµã£¬»áÔÚÐòºÅºó³öÏÖÒ»¸ö"*"ºÅ¡£
BP¡¡¡¡[address][if (condition)]
ÉèÖÃͨ¹ýÖ´ÐеØÖ·»òËùÉèÌõ¼þ¼¤·¢µÄ¶Ïµã¡£
¡¡¡¡¡¡Àý£ºBP if (eip>10000)
BPE¡¡number
¡¡¡¡¡¡¡¡±à¼Ò»¸öÒÑ´æÔڵĶϵ㡣
¡¡¡¡¡¡¡¡ÓÃBPEÃüÁî¿ÉÒԺܷ½±ãµØÐÞ¸ÄÒ»¸öÒѾ´æÔڵĶϵ㡣
¡¡¡¡¡¡¡¡µ«Òª×¢ÒâÒ»µã: BPE ÔÚÖ´ÐÐʱ,»áÏȽ«ÄãËùÒªÐ޸ĵĶϵãÇå³ý,È»ºóÔÙ½«¸Ä¹ýµÄʹÄÜ¡£
¡¡¡¡¡¡¡¡Èç¹ûÄãÔÚÐÞ¸Äʱ°´ESC¼üÍ˳öÐÞ¸Ä,ÄÇôÔÏȵĶϵãÒ²¾Í²»´æÔÚÁË, Ð޸ĴíÎóµÄ½á¹û
Ò²ÊÇÒ»ÑùµÄ£¬»áÔì³ÉÔÏȵĶϵãÏûʧ¡£
BPIO port
ÉèÖÃÒ»¸öÓÉI/O¶Ë¿Ú´¥·¢µ÷ÊԼĴæÆ÷¶Ïµã¡£
Ïà¹ØÄÚÈÝ: BreakPoint Overall
BMSG hwnd [msg]¡¡¡¡¡¡¡¡¡¡¡¡hwndΪ¾ä±ú¡¡¡¡msgΪÓÃÓÚ´¥·¢µÄÏûÏ¢
BPMSG hwnd [msg]
ÉèÖÃÓÉWindowsÏûÏ¢´¥·¢µÄ¶Ïµã
Ïà¹ØÄÚÈÝ:
WMSG
BreakPoint Overall
Àý:
BMSG 12c wm_destroy
BPM address R
BPM address W
BPM address X
ͨ¹ýDRxÉèÖÃÒ»¸öÓ²¼þ¶Ïµã
Ïà¹ØÄÚÈÝ: BreakPoint Overall
BPMX µØÖ·
ͨ¹ýDRxÉèÖÃÒ»¸ö¿ÉÖ´ÐеĶϵã
µÈͬÓÚÃüÁî 'BPM address X'
BP [[seg:]address]
BPX [[seg:]address]
Ö´ÐÐʱ¶Ïµã
TRW »áÔÚ´úÂëÖÐÏàӦλÖòåÈëÒ»Ìõ int3(0xcc) Ö¸Áî¡£
Ïà¹ØÄÚÈÝ:
BreakPoint Overall
BPMX
CLEARDR¡¡Çå³ýDRx¼Ä´æÆ÷
¡¡
CODE [ON|OFF|number]
ÉèÖôúÂë´°¿ÚµÄÏÔʾ·½Ê½
¡¡¡¡¡¡¡¡ ÉèΪONÔòÏÔʾ16½øÖƵĻúÆ÷Â룬ÉèΪOFFÔò²»ÏÔʾ16½øÖƵĻúÆ÷Âë
¡¡¡¡¡¡¡¡ number¾ö¶¨ÏÔʾ´úÂëµÄ·ç¸ñ£¨·½Ê½£©£¬¿ÉÒÔÒÔ¸÷ÖÖ·½Ê½ÏÔʾ
D [address]
D range >filename
½«ÄÚ´æij´¦µÄÄÚÈÝÓ³Ïñµ½Êý¾Ý´°¿Ú»òÕß½«ÄÚ´æij´¦µÄÄÚÈÝÓ³Ïñµ½ÎļþÖС£
Àý£º
¡¡¡¡¡¡¡¡¡¡ d 401000
d cs:402000
d 401000,402000 >myfile
d 401000 L 100 >myfile
E ¡¡¡¡[address [partern]]
±à¼ÄÚ´æ
Àý£º E ds:edi 'nothing',0
EC¡¡¡¡¡¡´ò¿ª»ò¹Ø±Õ×Ó´°¿Ú
¡¡¡¡¡¡¡¡Èç¹ûµ±Ç°×Ó´°¿Ú²»¿É¼û£¬ÄÇôECÃüÁ´ò¿ªËü£¬·´¹ýÀ´£¬ECÃüÁ¹Ø±ÕËü¡£
EXP ¡¡!
Exp ¡¡module-name!
Exp ¡¡partial_export_name
ÏÔʾһ¸öÄ£¿éËùÓеÄAPI¡£
ËÑË÷ËùÒýÓõÄËùÓÐÄ£¿éÊä³öµÄ API º¯ÊýÃû
EXP !
Exp kernel32!
Exp *
Exp Get*
Exp *window*
EXP16¡¡¡¡¡¡ÏÔʾ16λµÄexp
EXP32¡¡¡¡¡¡ÏÔʾ32λµÄexp
FILE¡¡ [source-filename]
Ñ¡Ôñ/ÏÔʾԴÎļþ¡£
FONT¡¡¡¡1£ü2
¡¡¡¡¡¡¡¡É趨TRW2000ÓÃÓÚÏÔʾµÄ×ÖÌ壬ĬÈÏΪ2¡£
FKEY [function-key strings]
ÏÔʾ/ÉèÖù¦Äܼü
Àý:
FKEY
FKEY f10 "d 2;U 3;"
G
ÔËÐÐ
G address ;ÔËÐе½ÓÉaddressÖ¸³öµÄµØÖ·, µÈͬÓÚ 'gox address'ÃüÁî
G if conditions ;Èç¹û conditions Âú×ãÔòÔËÐÐ
GDT¡¡¡¡[Selecter]
¡¡¡¡¡¡ÏÔʾָ¶¨È«¾ÖÑ¡Ôñ×ÓGDTµÄÏêϸÐÅÏ¢¡£
H [command]
HELP [command]
ÏÔʾËùÓÐÃüÁîµÄ°ïÖú£¬ºóÃæ¸úÃüÁîÃûÔòÏÔʾ¸ÃÃüÁîµÄÏêϸ˵Ã÷¡£
HOTKEY
ÏÔʾµ±Ç°ÓÐЧµÄÈȼü£¬Ò²¿ÉÒÔÏÔʾа´¼ü¡£
Ïà¹ØÄÚÈÝ:
Hot Keys
HBOOT¡¡ÖØÐÂÈÈÆô¶¯¼ÆËã»ú
HBOOT ½«ÖØÐÂÆô¶¯¼ÆËã»ú£¬µÈͬÓÚ°´ Ctrl+Alt+Del ×éºÏ¼ü¡£
HBOOT Ò»°ã¶¼Äܳɹ¦,Ö»ÓÐÌØÊâÇé¿öÏÂ(ijЩ²å¿¨ÐèÒªÖؼӵç)²ÅÓûúÆ÷ÉϵÄRESET»òP
OWER¼ü
HWND [HWND]
ÏÔʾWinodws¾ä±úÐÅÏ¢¡£
IDT¡¡¡¡number
¡¡¡¡¡¡ÏÔʾIDTµÄÐÅÏ¢
LDT¡¡¡¡number
¡¡¡¡¡¡ÏÔʾLDTµÄÐÅÏ¢
Page¡¡¡¡[address [L length]]
¡¡¡¡¡¡¡¡ÏÔʾҳ±íÐÅÏ¢¡£
¡¡¡¡¡¡¡¡address : ¶Î:Æ«ÒÆÁ¿ »ò Ñ¡Ôñ·û:Æ«ÒÆÁ¿ ¸ñʽµÄµØÖ·
¡¡¡¡¡¡¡¡length : ÒªÏÔʾҳµÄÊýÁ¿.PAGE ÃüÁîÓÃÀ´Áгöµ±Ç°Ò³Ä¿Â¼ºÍ¸÷¸öÒ³±íµÄÇé¿ö.
¡¡¡¡
PageIn
PageIn address
½«·Çµ±Ç°Ò³µ÷ÈëÄÚ´æ¡£
Àý£ºPageIn cs:401000
LINES [25 | 43 | 50 | 60]
ÉèÖÃ/ÏÔʾµ±Ç°ÏÔʾµÄÆÁÄ»ÐÐÊý¡£
Àý: lines 43
Ïà¹ØÖ÷Ìâ:
Ini file
MOD16 [hmod|mod_name]
ÏÔʾ16λģ¿éÁÐ±í£¬
Èç¹ûºó¸úmod_nameÔòÏÔʾָ¶¨Ä£¿éµÄÏêϸÐÅÏ¢¡£
Ó÷¨:
MOD16
MOD16 1cf
MOD16 KERNEL
MOD16 . ; .ÊÇÖ¸µ±Ç°Ä£¿é
MOD32 [hmod|mod_name]
ÏÔʾ32λģ¿éÁÐ±í£¬
Èç¹ûºó¸úmod_nameÔòÏÔʾָ¶¨Ä£¿éµÄÏêϸÐÅÏ¢¡£
Ó÷¨:
MOD32
MOD32 1cf
MOD32 KERNEL32
MOD32 . ; .ÊÇÖ¸µ±Ç°Ä£¿é
MAKEPE
´ÓÄÚ´æÖÐÕûÀí³öÒ»¸öÃûΪ 'newpe.exe' µÄPE¸ñʽµÄexeÎļþ¡£
ÿ´ÎʹÓøÃÃüÁîÇ°Ó¦ÏÈɾ³ýµ±Ç°Ä¿Â¼Ï嵀 'newpe.exe' ,·ñÔò TRW2000 »á½«ÐµÄ
Îļþ¸½¼ÓÔÚÔÎļþµÄºóÃæ¡£
µ±Ç°µÄ EIP ½«³ÉΪеijÌÐòÈë¿Ú¡£
¸ÃÃüÁÔÚµ±Ç°Ä¿Â¼ÏÂÉú³ÉÎļþ£¬µ«Éú³ÉÎļþµÄ Import table ÒѾÖØÐÂÉú³É¹ýÁË¡£
NAME¡¡¡¡address newname
¡¡¡¡¡¡¡¡¶¨ÒåÖ¸¶¨µØÖ·µÄзûºÅÃû
PDLL32
ÔËÐе½32λµÄ DLL µÄÈë¿Ú¡£
Ó÷¨:
PDLL32 mydll32.dll
PEDUMP
½«PEÎļþµÄÄÚ´æÓ³ÏñÖ±½ÓÓ³Ïñµ½Îļþ'DUMP1.EXE'£¬
ÄúֻҪʹÓà MakePE ÃüÁî¾Í¿ÉÒÔÖØÐÂÕûÀí³öÒ»¸ö¿ÉÓÃµÄ PE ¿ÉÖ´ÐÐÎļþÀ´¡£
BP if condition
Ìõ¼þ¶Ïµã£¬µ±Ìõ¼þÂú×ãʱ²úÉúÖжÏ
Àý£º¡¡bp if (eax>=3456787)
¡¡¡¡¡¡bp if (dx<543)
¡¡¡¡¡¡bp if (ch==23)
¡¡¡¡¡¡go if (ah!=34)
P µ¥²½¸ú×ÙÖ¸Áî
¡¡¡¡ P ÃüÁµ¥²½Ö´ÐгÌÐò¡£ÔÚ»ã±àģʽÖУ¬µ±Óöµ½ CALL,INT,LOOP,REPÖ¸Áîʱ£¬P½«²»¸ú
×Ù½øÈ¥,Ö±µ½ÕâЩָÁîÖ´ÐÐÍê±Ï£¬¿ØÖƲŷµ»ØTRW2000¡£»»¾ä»°Ëµ£¬PÃüÁîÊÇ"¿ç"¹ýÕâЩָÁî
µÄ¡£
¡¡¡¡ P ºó¼ÓRET ²ÎÊý£¬SoftICE½«Ò»Ö±µ¥²½Ö´ÐÐÖ±µ½ËüÕÒµ½Ò»Ìõ·µ»ØÓï¾ä(RET,RETF)¡£
¡¡¡¡ ÔÚÔ´³ÌÐòģʽÖУ¬P ÃüÁִÐÐÒ»¸öÔ´³ÌÐò±í´ïʽ£¬µ«Ò²²»¸ú×Ùµ½×ÓÀý³ÌÖÐÈ¥¡£P Ãü
Áîʵ¼ÊÉÏÊÇÀûÓÃÁ˵¥²½±êÖ¾¡£ ´ó¶àÊýÇé¿öÏÂÊÇÈç´Ë.µ«Åöµ½CALL,INT,LOOP,REPÖ¸Áîʱ£¬¾Í
ÓÃINT 3(Ò»´ÎÐÔ)ÔÚÕâЩָÁîµÄºóÃæÉèһϡ£
¡¡¡¡ P ÃüÁî¶ÔÓ¦µÄÓпì½Ý¼ü F10
PNEWSEC
ÔËÐÐÖ±µ½½øÈëÒ»¸ö PE ³ÌÐòÄÚ´æµÄÐ嵀 section £¨Õâ¸ö´Ê²»ÖªÈçºÎÃèÊö:D£©Ê±²ú
Éú¶Ïµã
PMODULE
'pret'£¨Ï൱ÓÚ°´£¼F12£¾£© Ö±ÖÁCS:EIPλÓÚÄ£¿éÖС£
PRET
ÔËÐе½Óöµ½ RET,RETF,IRETÖ¸ÁîʱͣÏ¡£
¿ì½Ý¼ü: F12
R ¡¡¡¡¡¡[-d | register-name | register-name [=] value]
¡¡¡¡¡¡¡¡ÏÔʾ»ò¸ü¸Ä¼Ä´æÆ÷µÄÄÚÈÝ¡£
¡¡¡¡¡¡¡¡Èç¹û R ÃüÁî²»¼Ó²ÎÊý£¬¹â±ê½«ÒƵ½¼Ä´æÆ÷´°¿ÚÖУ¬½øÐÐʵʱÐ޸ġ£Èç¹ûµ±Ç°¼Ä´æ
Æ÷´°¿Ú²»¿É¼û£¬ÄÇôÕâ¸öÃüÁ×Ô¶¯ÏÔʾËü¡£
¡¡¡¡¡¡ ÁíÍâ,ÐÞ¸ÄFL¼Ä´æÆ÷ʱ,²ÎÊý²»±Ø°´ÕÕ˳Ðò,Èç: R fl=o+a-c ¿ÉÒÔÒ»´ÎÐÞ¸Ä3¸ö±êÖ¾
λ¡£
RS
ÏÔʾÓû§ÆÁÄ»¡£ (¿ì½Ý¼üΪ£¼F4£¾).
S
ÔÚÄÚ´æÖÐËÑË÷Ö¸¶¨ÄÚÈÝ
Àý£º S 0 L -1 'window'
S 100,200 'bug12',34
SRC
Çл»Ô´´úÂëģʽ£¬¿ÉÒÔÊÇÔ´´úÂë£ü»ìºÏ´úÂë£üµ¥´¿µÄ¿ÉÖ´ÐдúÂë
SUSPEND
ÔÝÍ£µ±Ç°µÄỊ̈߳¬²¢Í˳ö TRW2000£¬°´Èȼü·µ»Ø¡£
SYM
ÏÔʾËùÓеĵ÷ÊÔ·ûºÅÁÐ±í¡£
T¡¡¡¡¡¡ [startaddress][count]
¡¡¡¡¡¡¡¡µ¥²½¸ú×ÙÖ¸Áî¡£T ÃüÁîÊÇÀûÓÃCPUµÄµ¥²½±êÖ¾À´½øÐе¥²½¸ú×ٵġ£Èç¹ûÖ¸¶¨ starta
ddress£¬½«´ÓÖ¸¶¨µÄµØÖ·´¦¿ªÊ¼µ¥²½¸ú×Ù¡£Èç¹û¼Ä´æÆ÷´°¿Ú¿É¼û£¬Ôò¼Ä´æÆ÷´°¿Ú½«¸ßÁÁÏÔʾ
ÄÄЩ¸Ä±äµÄ¼Ä´æÆ÷µÄÖµ¡£
¡¡¡¡¡¡ ¿ì½Ý¼üΪ£¼F7£¾
TABLE [table name]
Ñ¡Ôñ/ÏÔʾµ÷ÊÔ·ûºÅ±í
TASK
ÏÔʾÈÎÎñÁбí
THREAD
ÏÔʾÏ̵߳ÄÓйØÐÅÏ¢¡£
Ó÷¨:
THREAD [TCB]
THREAD . ; .´ú±íµ±Ç°Ïß³Ì
TRNEWDOS
²¶»ñÁíÍâµÄDOS³ÌÐò¡£
TRNEWTCB
²¶»ñÒ»¸öеÄÏ̵߳ÄÈë¿Ú²Ù×÷Âë
Ö§³Ö 32λºÍ16λ³ÌÐò
²»ÒªÔÚDOSÌáʾ·ûÏÂÔËÐÐ Windows ³ÌÐò£¬·ñÔò TRW2000 »á²¶»ñ START.EXE¡£
TRTCB
¸ú×ÙÒ»¸öÕýÔÚÔËÐеÄÏ̡߳£
U [address]
U range >filename
ÔÚ´úÂë´°¿Ú·´»ã±à³ÌÐò»ò½«·´»ã±àµÄ´úÂëÊä³öµ½Ò»¸öÎļþ¡£
Àý£º u 401000
u cs:402000
u 401000,402000 >myfile
u 401000 L 100 >myfile
VER¡¡¡¡ ÏÔʾTRW2000µÄ°æ±¾ÐÅÏ¢
VCALL
Ó÷¨:
Vcall * -ÏÔʾËùÓÐµÄ VxD µ÷ÓÃ
Vcall num -Èç¹ûÖ¸¶¨µÄnum<10000h, ÏÔʾËùÓÐµÄ VxD µ÷ÓÃ
-Èç¹ûÖ¸¶¨µÄnum>10000h, ÔòÏÔʾËùÖ¸¶¨µÄ VxD µ÷ÓÃ
Vcall partial-name£¨Õâ¸öСµÜûÓÐÓùý£¬²»ÖªÈçºÎÒëÁˣޣߣޣ©
Àý:
Vcall 0d
Vcall 100001
Vcall *sys*
VM¡¡¡¡¡¡[VMID]
ÏÔʾÐéÄâ»úµÄÐÅÏ¢¡£
¡¡¡¡¡¡¡¡Èç¹ûVMÃüÁî²»¼Ó²ÎÊý£¬½«ÏÔʾϵͳÖÐËùÓÐÐéÄâ»úµÄÐÅÏ¢¡£Èç¹û¼Ó VMID ²ÎÊý,¸ÃVM
µÄ¼Ä´æÆ÷Öµ½«±»ÏÔʾ¡£
¡¡¡¡¡¡¡¡ÕâÀïµÄ¼Ä´æÆ÷ÖµÊÇÔÚVM¿ØÖÆ¿éÓû§ÇøÖеļĴæÆ÷Öµ¡£ËùÒÔ£¬ÕâЩ¼Ä´æÆ÷±íʾµÄÊÇ×î
ºóµ±ÓÐÄÚ´æµØÖ·Çл»Ê±´æÈë¸Ã¿ØÖÆ¿éʱµÄÖµ¡£
¡¡¡¡¡¡¡¡µ±TRW2000µ¯³öʱÕýºÃij¸öVM ÕýÔÚÔËÐеĻ°£¬ÔڼĴæÆ÷´°¿ÚÖеÄÖµ²ÅÊÇÕæÕýµ±Ç°µÄ
Öµ£¬¶ø²»ÊÇÓÃVMÃüÁîÔÚÃüÁî´°¿ÚÖп´µ½µÄÖµ¡£
¡¡¡¡¡¡¡¡ÓÐÒ»µãҪעÒâ:Èç¹ûÄãÔÚij¸öÖжÏÀý³ÌÖеÄÍ·¼¸¾äÖ¸Áî´¦£¬¶ø´ËʱÕâ¸öVMµÄ¼Ä´æÆ÷
ÖµÕýÔÚ±»´æÈë¿ØÖƿ飬ÄÇô¿ÉÄܵ±Ç°Ö»ÓÐCS:IPµÄÖµ(ÓÉVMÏÔʾ)ÊÇÕæµÄ¡£ÆäÓàµÄÓпÉÄÜ»¹Ã»
ÓдæÈë¿ØÖÆ¿é¡£
VXD¡¡¡¡ [VXDNAME]
¡¡¡¡¡¡¡¡ÏÔʾWindows VxD Ó³Ïó¡£
¡¡¡¡¡¡¡¡VXD ÃüÁÏÔʾָ¶¨µÄij¸öVxDµÄÐÅÏ¢¡£Èç¹û²»¼Ó²ÎÊý£¬VXDÃüÁÏÔʾϵͳÖÐËùÓÐ
µÄÐéÄâÉ豸Çý¶¯³ÌÐòµÄÓ³Ï󡣶¯Ì¬×°ÔصÄVxD½«ÏÔʾÔÚ¾²Ì¬×°ÔصÄVxDºóÃæ¡£
¡¡¡¡¡¡¡¡
W range filename
½«ÄÚ´æÄÚÈÝдÈëÖ¸¶¨Îļþ
Àý£º w ds:401000,402000 myfile
w 401000 L 100 c:\myfile.bin
WC [codewindow_lines]
ÉèÖôúÂë´°¿ÚµÄÐÐÊý£¬Èç¹û²»´ø²ÎÊýÔòÇл»Æ俪/¹Ø״̬¡£
Àý:
wc 25
wc
WD [datawindow_lines]
ÉèÖÃÊý¾Ý´°¿ÚµÄÐÐÊý£¬Èç¹û²»´ø²ÎÊýÔòÇл»Æ俪/¹Ø״̬¡£
ex:
wd 25
wd
WR¡¡¡¡¡¡´ò¿ª»ò¹Ø±Õ¼Ä´æÆ÷´°¿Ú
¡¡¡¡¡¡¡¡Èç¹ûµ±Ç°¼Ä´æÆ÷´°¿Ú²»¿É¼û£¬ÄÇôWRÃüÁʹ֮¿É¼û£¬·´¹ýÀ´£¬WRÃüÁʹ¼Ä´æÆ÷
´°¿Ú²»¿É¼û¡£
¡¡¡¡¡¡¡¡¼Ä´æÆ÷´°¿ÚÏÔʾ80386¼Ä´æÆ÷¼¯¡£
WS¡¡¡¡¡¡´ò¿ª»ò¹Ø±Õ¶ÑÕ»´°¿Ú
¡¡¡¡¡¡¡¡Èç¹ûµ±Ç°¶ÑÕ»´°¿Ú²»¿É¼û£¬ÄÇôWSÃüÁʹ֮¿É¼û£¬·´¹ýÀ´£¬WSÃüÁʹ¶ÑÕ»´°¿Ú
²»¿É¼û¡£
WMSG - ÏÔʾWindowsÏûÏ¢
Ó÷¨:
WMSG [partial-name] [WMSG-number]
Àý:
WMSG 12
WMSG wm_destroy
X¡¡¡¡¡¡¡¡Í˳öµ±Ç°µ÷ÊÔ״̬£¬·µ»ØWindows
--------------------------------------------------------------------------------
ËùÓжϵãÓï·¨
¼¸ºõËùÓеĶϵ㶼¿ÉÒÔͨ¹ýÈçϵÄÓï·¨£º
BP?? [IF (conditions)] [DO "statement"]
¶øÇÒ¿ªÊ¼µÄ2¸ö×Öĸ 'BP' ¿ÉÒÔ´ú»»³É 'GO'£¬¼´:
GO?? [IF (conditions)] [DO "statement"]
À´ÉèÖÃÌõ¼þ¶Ïµã¡£ TRW2000 Äܹ»¸ù¾ÝÒªÇóÉèÖá¢Ê¹ÓúÍÇå³ýÕâЩ¶Ïµã¡£
conditions:
Ìõ¼þ±ØÐëÓñÕÀ¨·ûÀ¨ÆðÀ´£¬ÅжÏÌõ¼þ¿ÉÒÔÊÇ
>,<,==,>=,<=,!=
Do statement:
¿ÉÒÔÊÇÈκÎÓÐЧµÄ TRW2000 µÄÃüÁµ«±ØÐëÓÃË«ÒýºÅ""ÒýÆðÀ´¡£
Àý:
BPX cs:401000 if (eax>200) do "d eax"
GOX 401000 if (cs!=28) do "d ss:esp"
G if (eip<1000)
--------------------------------------------------------------------------------
INI Îļþ
²ÎÊýÎļþtrw2000.ini ±ØÐëºÍTRW2000.EXEλÓÚÏàͬĿ¼Ï¡£
¾ÙÀýÈçÏÂ:
; TRW2000 Initialize file
; Please modify it as your habit .
;PLUGS=C:\MY_PLUGS\HELLO.SYS
F1=^HELP ; Command length CAN'T be longer than 15 characters !
; This command length is 5 charcaters .
F3=^SRC
F4=^RS
F5=^X
F6=^EC
F7=^HERE
F8=^T
F9=^BPX
F10=^P
F12=^PRET
;HOTKEY=320D ;Ctrl+M
;R3HOTKEY=310E ;Ctrl+N
GRAPHICS=ON
;INTELLIMOUSE=OFF
WINMOUSE=ON
LINES=50 ¡¡¡¡¡¡¡¡;Ê®½øÖÆ
--------------------------------------------------------------------------------
µ÷ÊÔ·ûºÅ
TRW2000 »á×Ô¶¯×°ÔØËüËùÔÚĿ¼ÏµÄËùÓÐ *.SYM Îļþ¡£µ±È»ÄúÒ²¿ÉÒÔͨ¹ý'LOAD'°´Å¥À´¼Ó
ÔØÒ»¸öÐ嵀 .SYM Îļþ¡£Èç¹û .SYM °üº¬ÓÐÐкÅÐÅÏ¢£¬ TRW2000 »á³¢ÊÔ¼ÓÔØÔ´Îļþ¡£ÍƼö
Äú×îºÃʹÓà Microsoft MAPSYM 6.0 À´Éú³É .SYM Îļþ¡£
TRW2000 Ö§³ÖPEÎļþÖеÄCOFF¸ñʽµÄµ÷ÊÔÐÅÏ¢¡£
Ïà¹ØÖ÷Ìâ:
TABLE,FILE,SRC,SYMÃüÁî
|