阅读:1978回复:2
如何从ETHREAD获取进程ID?
请问如何从ETHREAD中得到该线程所属进程的进程ID?谢谢!
|
|
沙发#
发布于:2008-07-24 16:55
lkd> dt _ETHREAD
nt!_ETHREAD +0x000 Tcb : _KTHREAD +0x1c0 CreateTime : _LARGE_INTEGER +0x1c0 NestedFaultCount : Pos 0, 2 Bits +0x1c0 ApcNeeded : Pos 2, 1 Bit +0x1c8 ExitTime : _LARGE_INTEGER +0x1c8 LpcReplyChain : _LIST_ENTRY +0x1c8 KeyedWaitChain : _LIST_ENTRY +0x1d0 ExitStatus : Int4B +0x1d0 OfsChain : Ptr32 Void +0x1d4 PostBlockList : _LIST_ENTRY +0x1dc TerminationPort : Ptr32 _TERMINATION_PORT +0x1dc ReaperLink : Ptr32 _ETHREAD +0x1dc KeyedWaitValue : Ptr32 Void +0x1e0 ActiveTimerListLock : Uint4B +0x1e4 ActiveTimerListHead : _LIST_ENTRY +0x1ec Cid : _CLIENT_ID //这不就是嘛 |
|
板凳#
发布于:2008-07-25 13:03
BS硬编码。
PEPROCESS IoThreadToProcess( IN PETHREAD Thread ); |
|