: MS Windows XP
1
1.1
MS DOS, Win32 , . . Win32 .
:
- 4 ( 32- );
- ;
- (, DLL);
- .
:
- (PID);
- ;
- (access token);
- ;
- (Handles) ;
- ..
() - . .1.
1 .
1 2, 3 4.
. , ( ). .
Windows :
- Idle ( );
- System ( );
- (Smss.exe);
- Windows (Csrss.exe);
- (Winlogon.exe);
- (Services.exe) (, , Svchost.exe);
- (Lsass.exe).
, Idle System, , - .
(Session Manager) Smss.exe , . Csrss.exe Winlogon, .
Windows - Winlogon.exe . Alt+Ctrl+Del Winlogon .
LSASS. LSASS - , (access token object), . Winlogon . Userinit HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon.
|
|
Userinit.exe, , Shell Explorer.exe. Userinit.exe . Explorer.exe Winlogon. Explorer.exe () .
, , . , , , .
. . , Explorer.exe .
- , (Thread). , . , . , ( ). (. . 2) :
2 - ()
, , CreateThread.
.
WinNT, 2000, XP Windows Server ( 32), .
1.2
Windows (Task Manager), , , , . Alt+Ctrl+Del . . 3.
3 - ( )
.3 , . , , 0 , ( ).
.3 .
(. .4) , , .
, . .
|
|
Sysinternals Process Explorer, , Microsoft, . .
4 - ( )
2.
1. , ( ).
2. ( ). .
3. ( ).
4. , , Open Office.
5. (Open Office, Visual Studio).
6.
1
2 | |
1, 2, 4, 5 | |
1, 2, 6 | |
1, 5, 7 | |
1, 2, 8 | |
1, 5, 6 | |
4, 7, 8 | |
2, 3, 4 | |
1, 2, 7 | |
1, 2, 8 | |
1, 3, 4 |
2 -
- | |
- |
3.
Open Office .
:
1. , , ,
2.
3. , .
1. , ,
2. . MS Windows, ?
3. . 2 .
4. ? ?
5. MS Windows ?
6. , Get-Process PowerShell.