Windows NT«OÅ@¤l¨t²Î

 

ùþªìÃÑ

                ½Ñ¦ìWindows NTªºª±®a¡AÀ³¸Ó¹ï«OÅ@¤l¨t²Î³o­Ó¦Wµü¤£ºz¥Í¡A­è¶}©l±µÄ²Windows NT®É¡A¹ï©ó¥¦ªº¬[ºc¤]¬O¥Rº¡¤F¦n©_¡A´¿¦bWindows NT¤WTrace Windows CEªº¼ÒÀÀ¾¹¡Aı±o³o¨Ç¯à±N¤£¦PÀô¹Ò¤U¶}µoªºµ{¦¡¾ã¦X¦b¤@°_ªº§Þ³Nº¡¦³½ì¡A³z¹L³o¦¸ªº¤å³¹¡A§Ú±N¹ïWindows NTªº«OÅ@¤l¨t²Î°µ¤@­Ó¤¶²Ð¡A¦bWindows NT¤¤«OÅ@¤l¨t²Î§êºt¤F­«­nªº¨¤¦â¡A±qµn¤J¨t²Î¨ì±Ò°Ê¦U­ÓÀ³¥Îµ{¦¡¡A«OÅ@¤l¨t²Î³£¦b¹õ«á´x±±¤j§½,¡C

 

                ¦b¦¹§Ú¥ý²­z¤@¤UWindows NTªº¶}¾÷¬yµ{¡A¦w¸ËWindows NT«á¡ABootºÏ°Ï·|³Q§ï¼g¡APartitionªººÏ°Ï¨Ã¤£·|³Q°Ê¨ì¡C¤£¹L¡AWindows 9X·|°Ê¨ìPartitionªººÏ°Ï¡A¨Ï¥ÎLinux Liloªºª±®a¡AÀ³¸Ó¦b­«ÄéWindows 9X«á¡A·|¹J¨ì­ì¨Ó¸Ë¦bµwºÐLilo©Ò§ó§ïªºPartitionºÏ°Ï³Q°Ê¹L¤F¡C¦p¤U¹Ï(¤@)¡A¬O§ÚµwºÐBootºÏ°Ïªº³¡¥÷¸ê®Æ¡A¦b¶}¾÷®É¡A·|¥ÑBootºÏ°Ï±Ò°ÊNTLDR¡A§Ú­Ì¥i¥H¬Ý¨ì¡A¨ä¤¤¥]¬A¤F¦pªGBootºÏ°Ï¥¼¯à¶¶§Q§ä¨ìNTLDR³o­ÓÀɮ׮ɡA©Òµo¥XªºÄµ§i°T®§¡C

 

                ¦bWindows NT¤¤¡ANTLDR°£¤F­t¦³´£¨Ñ¦h­«¶}¾÷ªº¯à¤O¥~¡AÁÙªÓ­t¤F§â³\¦hWindows NT¨t²ÎÀɮ׸ü¤Jªº­«­n¨Ï©R¡C¦bNTLDR¸ü¤J¥H«á¡A¦P®É¤]±N¨t²Î¥Ñ¯u¹ê¼Ò¦¡¤Á¤J«OÅ@¼Ò¦¡¡C¦p¤U¹Ï(¤G)¡A¬O§Ú¦bNTLDR°õ¦æÀɤ¤©Ò§ä¨ìªº¤@¨Çº¡¦³½ìªº°T®§¡A¹³§Ú­Ì¤@¶}¾÷®É©Ò¬Ý¨ìªº ¡¨ NTDETECT V4.0 ¥¿¦bÀˬdµwÅ顨 «K¬O¥ÑNTLDR©Ò¨q¥Xªº¡C°£¦¹¤§¥~NTLDR¤]­t³d§âNTDETECT.COM©Ò°»´úªº¸ê®Æ¶Çµ¹NTOSKRNL.EXE(¦¹ÀÉ¥i»¡¬ONT¯u¥¿ªº®Ö¤ß)¡A¨Ã§âNTOSKRNL.EXE ¸ü¤J°O¾ÐÅé°õ¦æ¡C¦b¹Ï(¤T)¡A¬ONTLDR°õ¦æÀɤ¤©Ò¥]§tªº¶}¾÷¿ï³æªº°T®§¡A¬Ý¨ì³o°T®§³Q¥]¦bNTLDR°õ¦æÀɤ¤¡A´Nª¾¹D¥¦¬O¶}¾÷¿ï³æ¤Î¬yµ{³Ìªìªº±±¨îªÌ¤F¡C

 

                ·íµM¡ANTLDR¥»¨­¤]´£¨Ñ¤F°ò¥»ªºÀɮרt²Î¡A¥i¥H¦b±Ò°ÊNTªº¹Lµ{¤¤¡AŪ¨úFAT16 ¤Î NTFS ®æ¦¡ªºÀɮרt²Î,¡C¦b¹Ï(¥|)¡A«K¬OWindows NT±Ò°Êªº¤@­Ó²¹Ï¡C

 

 

 

 

 

 


¹Ï(¤@)

NTDETECT V4.0 Checking Hardware ...

NTDETECT V4.0 ¥¿¦bÀˬdµwÅé ...

........

............

°Ñ¼Æ 'osloadpartition' ³]©w¤£¥¿½T

½ÐÀˬd 'systempartition' ¸ô®|¡D

°Ñ¼Æ 'osloadfilename' ¨Ã¥¼«ü¦V¥¿½TªºÀɮסD

<winnt root>\system32\ntoskrnl.exe.

<winnt root>\system32\hal.dll.

'osloader'\hal.dll

load needed DLLs for HAL.

find system drivers.

read system drivers.

did not load system boot device driver

load system hardware configuration file.

\SYSTEM32\CONFIG\SYSTEM

 
 

 

 

 

 

 

 

 

 

 

 

 


¹Ï(¤G)

 

½Ð¿ï¾Ü±z·Q­n±Ò°Êªº§@·~¨t²Î¡G

 

¨Ï¥Î ¡ô Áä©M ¡õ Áä¡A±N±z·Q­nªº¿ï¶µ¤Ï¥Õ¡A

¿ï©w«á¡A½Ð«ö Enter Áä½T»{¡D

 
 

 

 

 


¹Ï(¤T)

 

BootSect

 
 

 

 

 

 

 

 

 

 

 

 

 


¹Ï(¥|)

 

 

 

ùþ¤l¨t²Î?

 

                ´£¨ì«OÅ@¤l¨t²Î¡A­º¥ý¡A§Ú­n¥ý¤¶²Ð¤@¤U¦bWin32ªºPEÀɮ׮榡¤¤©Ò´£¨Ñªº¤@­ÓÄæ¦ì ¡§SUBSYSTEM¡¨¡A¦p¹Ï(¤­)¡A¬O¦bVCªº½u¤W¤å¥ó©Ò°O¸ü¦³ÃöSUBSYSTEMªº¸ê°T¡A

 

/SUBSYSTEM:{CONSOLE|WINDOWS|NATIVE|WINDOWSCE|POSIX|}[,left[,right]]

You can specify any of the following subsystems:

The CONSOLE subsystem handles a Win32 character-mode application that use a console supplied by the operating system.

The WINDOWS subsystem handles an application that does not require a console and creates its own windows, if required.

The NATIVE subsystem handles a Windows NT device driver.

The WINDOWSCE subsystem handles Windows CE consumer electronics applications.

The POSIX subsystem handles a POSIX application in Windows NT.

 
 

 

 

 

 

 

 

 

 

 


¹Ï(¤­)

        ¬JµM´£¨ì¤FSUBSYSTEM¡A§Ú´NÁ|´X­Ó§Ú­Ì±`¨£¨ìªº¨Ò¤l¡A¦p¤U¹Ï(¤»)¡A´N¬O§Ú¦bWindows NT¤¤§Q¥Î§Ö³tÀ˵ø(¦pªG§A¦³¸Ë¡¨§Ö³tÀ˵ø¡¨ªº¸Ü¡A¿ï¾ÜÀɮ׫á¡A«ö¤U¥kÁä¡A´N·|¦bPOPUP MENU¤¤¬Ý¨ì¥¦¤F) ¨Ó¬d¬Ý\WINNT\SYSTEM32\*.SYSªºÀɮסA¦bNT¤¤Device DriverÀɮתº°ÆÀɦW¬°SYS¡A§Ú­Ì¥i¥H¦bSubsystemªºÄæ¦ì¤¤¬Ý¨ì¡¨Image doesn¡¦t  require a subsystem¡¨¡A¦P²z¡C¦b¹Ï(¤C)¡A«h¬O¤@­ÓWin32 ¨Ï¥Î¨ìGUI¬É­±ªºÀ³¥Îµ{¦¡¦b¡¨§Ö³tÀ˵ø¡¨¤Uªºµ²ªG¡C¹Ï(¤K)¬°Win32 Console ModeªºÀ³¥Îµ{¦¡¡C

 

 

 

 

 

 


¹Ï(¤»)

 

 

 

 

¹Ï(¤C)

 

 

 

 

 

 


¹Ï(¤K)

 

                »¡¨ì³o¨à¡A§Ú·Q¨ì¦bInside NT Second Edition ¤¤¦³¤@­ÓCreating Processªº¬yµ{¹Ï¡A§Ú¤]µe¤F¤@­Ó²¹Ï¦p¹Ï(¤E)¡C¦b²Ä¤@³¡¥÷¡A¶}±ÒEXEÀÉ«á¡A.·|§PÂ_³o­ÓÀɮשÒÄݪº¤l¨t²Î¡A¨Ã¶}±Ò©Ò¿ï¾Üªºª«¥ó¡C²Ä¤G³¡¥÷¡A²£¥ÍWindows NT ªºExecutive Process Object¡A¨Ã²£¥Í©Ò»Ýªº¸ê®Æµ²ºc¡A¤Î°t¸m°O¾ÐÅéªÅ¶¡¡C²Ä¤T³¡¥÷¡A²£¥Í·sªº°õ¦æ§Ç¤Îµ{¦¡°ïÅ|¡C²Ä¥|³¡¥÷¡A§â·s²£¥Íªº¦æµ{³qª¾©ÒÄݪº¤l¨t²Î¡C²Ä¤­³¡¥÷¡A¶}©l°õ¦æ·s²£¥Íªº°õ¦æ§Ç¡C²Ä¤»³¡¥÷¡A°õ¦æ·s²£¥Íªº¦æµ{¡C

       

                ¨ä¹ê¡A¦b³o§Ú¥u§â³¡¥÷ªº¤º®e°µ¤@­Ó»¡©ú¡A¦bInside Windows NT Second Edition¤¤¹ï¤@­Ó¦æµ{ªº±Ò©l¦³º¡¤£¿ùªº»¡©ú¡C¦b¦¹§Ú´N¤£¦A²Ö­z¡A³o¨â´Áªº¤å³¹¡A³o¥»®Ñµ¹¤F§Ú¤£¤ÖHint(¦p¥»½g¤å³¹ªº¹Ï(¤E)¡A(¤Q)¡A(¤Q¤@))¡A¤]Åý§Ú¥i¥H¬Ù¥h¤£¤Ö´M§ä¤@¨Ç²Ó¸`¸ê®Æªº®É¶¡¡A¦pªGŪªÌ¹ï³o¤è­±¦³¿³½ìªº¸Ü¡A§Ú¬Û«H¨º¨M¹ï¬O¤@¥»¤£¿ùªº¦n®Ñ¡C

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 


¹Ï(¤E)

 


                ¦p¤U¹Ï(¤Q)¡A¬ONT¤¤¦U¤l¨t²Î©Ò¨Ï¥ÎªºµêÀÀ¾÷¾¹ªº°õ¦æÀɦW¡A§Ú­Ì¥i¥Hµo²{¹³

(1)CMD.EXE:¥D­n¥Î©ó*.BAT¡A¤Î§Ú­Ì¤@¯ë±`¥ÎªºDOS Command(¦p:DIR..etc)¡C©Ò¥H¡A¦pªG§Ú­Ì§âCMD.EXE§ï¦Wªº¸Ü¡A¦A³z¹LÀÉ®×Á`ºÞ¥h°õ¦æAUTOEXEC.BAT«K·|±o¨ì¦p¤Uªºµ²ªG¡CŪªÌ¥i¯à·|ÃhºÃ¡A¬°¦ó­n³z¹LÀÉ®×Á`ºÞ¡A¦Ó¤£±Ò°ÊDOS  BOX©O?¨º¬O¦]¬°¦bNT¤¤ªºDOS BOX´N¬O³z¹LCMD.EXE¨Ó¼ÒÀÀªº¡A¦]¬°§Ú­Ì§âCMD.EXE§ï¦W¤F¡A©Ò¥H­ì¨ÓªºDOS BOX±¶®|©Ò«üªºÀɮפw¤£¦s¦b¡C¨ä¹ê¡A§Úı±oCMD.EXEªº¨¤¦â¦p¦P¬O¥H«eDOS¤UªºCOMMAND.COM¡A§êºt¤FCOMMAND INTERPRETER ªº¨¤¦â¡C


 

 


        (2)NTVDM.EXE:·í§Ú­Ì¦bDOS BOX¤¤±Ò°Ê¤@­ÓDOSªºµ{¦¡®É¡A¨t²Î·|³z¹LNTVDM.EXE³o­ÓDOSªºµêÀÀ¾÷¾¹¡A¨Ó§â³o­ÓDOSªºµ{¦¡©ñ¤J°O¾ÐÅ餤°õ¦æ¡A¦pªG§Ú­Ì§âNTVDM.EXE§ï¦W«á¡C¦A±Ò°ÊDOSªºÀ³¥Îµ{¦¡«K·|²£¥Í¦p¤Uªº¿ù»~

 

 

 

 

 


                ¥Ñ©óDOSªºÀ³¥Îµ{¦¡»PWin16ªºÀ³¥Îµ{¦¡¬O¨Ï¥Î¦P¤@­ÓµêÀÀ¾÷¾¹¡A
¥H¦bNTVDM.EXE§ï¦Wªº±¡ªp¤U¡A°õ¦æWin16ªºÀ³¥Îµ{¦¡·|±o¨ì¦p¤Uªº¿ù»~µ²ªG

 


(3)Win 32ªºÀ³¥Îµ{¦¡¡A¬OWindows NT¨t²Î¦b¤@±Ò°Ê«á­º¥ý´£¨Ñªº¤l¨t²Î¡A¨ä¥¦ªº«OÅ@¤l¨t²Î³£¬O»Ý­n³z¹LWin32¤l¨t²Îªº¨ó§U¤~¦³¥i¯à§¹¦¨©Ò»Ýªº¤u§@¡Aµ§ªÌ¦b¦¹´N¤£­Ó§O¤¶²ÐPOSIX¤ÎOS/2¤l¨t²Î¤F¡A¦b¥»¤åªºµy«á§Ú·|¦³¤@­Ó¬ÛÃöªº»¡©ú¡C

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 


¹Ï(¤Q)

                ¦p¹Ï(¤Q¤@)¡A¸Ì­±¦³¤@¨ÇÃö©ó¤l¨t²Îªº­«­nÀɮצWºÙ¡A§Ú­Ì¥i¥Hµo²{¤l¨t²Î±`±`³£¬O¤@­ÓEXE ÀÉ»P¤@­ÓDLLÀÉ¡A§Ú¨Ã¨S¹ê¦a»s§@¤@­Ó¤l¨t²Îªº¸gÅç¡A¤£¹Lµy«á¡A§Ú·|°w¹ï¥Ø«e¤w¦s¦bªº¤l¨t²Î°µ¤@­Ó±´¯Á¡C

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Services.exe     Service Controller Process

Winlogon.exe    Logon Process

Smss.exe        Session Manager Process

Psxss.exe        POSIX Subsystem Process

OS2ss.exe       OS/2 Subsystem Process

Csrss.exe        Win32 Subsystem Process

Ntdll.dll         Internal Support Functions and System Service

                   Dispatch stubs to Executive Functions

Kernel32.dll      Win32 Subsystem DLLs

User32.dll

GDI32.dll

Psxdll.dll         POSIX Subsystem DLL

NTOSKRNL.EXE  Executive and Kernel

Hal.dll           Hardware Abstraction Layer

Win32k.sys       Win32 User and GDI Kernel-mode Components

 

 
 

 

 

 

 

 

 

 

 

 

 

 

 

 

 


¹Ï(¤Q¤@)

 

ùþWin32¤l¨t²Î

         ¦bWindows NTªºµn¿ýµe­±¥X²{¥H«e¡AWin32¤l¨t²Î«K³Q«Ø¥ß¤F¡A¦bWin32¤l¨t²Îªì©l¤Æ®É¡A¨t²Î¤¤¥u¦s¦b4­ÓProcess¤À§O¬°

 

Process

PID

Pri

System

0x02

8

Smss

0x19

B

Csrss

0x21

D

Idle

0x00

0

 

 

                ¬JµM¡AWin32¬OWindows NT©Ò±Ò°Êªº²Ä¤@­Ó¤l¨t²Î¡A¨ºWin32¤l¨t²ÎCSRSS.EXE°õ¦æÀÉ¡A¬O¦p¦ó§¹¦¨ªº©O? ¬Û«HŪªÌÀ³¸ÓÁÙ°O±o¡ADevice Driver ¬OÄÝ©óKernel Modeªºµ{¦¡¡A¦]¦¹¡A¦bDriverªºSubsystemÄæ¦ì·|Åã¥Ü³o­Ó°õ¦æÀɤ£»Ý­n¤l¨t²Î¡A¨ºCSRSS.EXE©O?

 

     ¦p¤U¹Ï(¤Q¤G)¡A§Ú­Ì¥i¥Hµo²{CSRSS.EXE¤£¦P©ó¤@¯ëªºWin32µ{¦¡¡A¥¦¨Ã¤£»Ý­n¤@­Ó¤l¨t²Î¨Óºû«ù¥¦¡C¦³½ìªº¬O¡A¦bImport Table¤¤§Ú­Ì¬Ý¨ìCSRSRV.DLL³o­ÓWin32¤l¨t²Îªº°ÊºA³sµ²¨ç¦¡®w¡A¦P¼Ëªº¡A¦b¥¦­ÌLoad¨ì°O¾ÐÅé«e¡A¨t²ÎÁÙ¨S¦³¥ô¦ó¤@­Ó¤l¨t²Î§Î¦¨¡A¦]¦¹³o­ÓCSRSRV.DLLªºSubsystemÄæ¦ì¤]¬OÅã¥Ü¤£»Ý­n¤l¨t²Î¡C

 

   ¦b¹Ï(¤Q¤T)¤¤¡A§Ú­Ì¥i¥H¦bCSRSS.EXEªºImport Table¤¤¬Ý¨ìCSRSRV.DLL©Ò´£¨ÑªºCsrServerInitialization¨ç¦¡¡A³o¬OCSRSS.EXE¦bªì©l¤ÆWin32Àô¹Òªº¹Lµ{¤¤©Ò·|©I¥sªº¤@­Ó¥²³Æ¨ç¦¡¡C

 

        ŪªÌ¥i¥HÆ[¹î¨ä¥¦Win32ªºÀ³¥Îµ{¦¡¡A·|µo²{¥¦­Ì¬ÛÃö©ó¤l¨t²Îªº¤@¨Ç¦³½ìªº¨Æ±¡¡C¤×¨ä¡A¤l¨t²Î©¹©¹³£¬O¤@­ÓEXEÀɦñÀHµÛDLLÀɩҫإ߰_ªº¤@­Ó¬[ºc¡A³z¹L¤l¨t²ÎªºDLLÀÉ¡A¥i¥H§â³\¦hÀô¹Ò©Ò¥²»Ýªº°ò¥»¨ç¦¡µ¹¹ê§@¦b¤l¨t²ÎªºDLL¤¤¡C

 

        ¹Ï(¤Q¥|) ¡V(¤Q¤»)¤À§O¬OCSRSRV.DLLªºSubsystem¸ê®Æ¡AImport Table¤ÎExport Table¡A²´¦yªºÅª§äÀ³¸Ó¥i¥H±q¹Ï(¤Q¤»)ªºExport Table¤¤¬Ý¨ì³o­ÓCSRSRV.DLL´£¨Ñ¤F³\¦h»PWin32¦æµ{ºÞ²z¤Î¤Þ½u©I¥sªº¨ç¦¡¡C¦b¹Ï(¤Q¤»)¤¤¡A§Ú­Ì¤]¬Ý¨ì¦pKernel32.dll¤@¯ë¡ACSRSRV.DLL¤]¬O·|¥h¨Ï¥Î¨ì³\¦hNTDLL.DLL©Ò´£¨Ñªº¨t²Î¨ç¦¡(ŪªÌÀ³¸ÓÁÙ°O±o¤W´Á¤å³¹©Ò´£¨ìNTDLL.DLLªº2E¤¤Â_§a!¡C¡C¡C¡C^_^)¡A©Ò¥HÅo!¨ä¹ê³\¦hªº¤l¨t²Î¥\¯à³£¬O³o¼Ë¤@ÂI¤@ºwªº¥Î³\¦h¨t²Î¤ñ¸û§C¶¥ªº¨ç¦¡¨Ó³v¤@ºc¦¨ªº¡C¤×¨ä¡AWin32¤l¨t²Î¬ONT¤¤³Ì­«­nªº¤@­Ó¤l¨t²Î¤F¡C±q¨t²Î¤@ªì©l¡A¨ì¨t²ÎÃö¾÷³£·|¦s¦b¨Ï¥ÎªÌªº¹q¸£¤¤¡C

 

 

 

 

 

 


¹Ï(¤Q¤G)

 

 

 

 

 

 

 

 

 


¹Ï(¤Q¤T)

 

 

 

 

 


¹Ï(¤Q¥|)

 

 

 

 

 


¹Ï(¤Q¤­)

 

 

 

 

 

 

 

 

 


¹Ï(¤Q¤»)

 

ùþWin16¤l¨t²Î


                »¡¨ìWin16¡A¬O³o½g¤å³¹¤¤§Ú³Ì³ßÅwªº³¡¥÷¤F¡A¦]¬°§Úı±o¥¦«D±`ªº¦³½ì¡A¹L¥hWindows3.1®É¥NWin16ªºÀ³¥Îµ{¦¡¬O¦@¥Î¤@­ÓµêÀÀªº°O¾ÐÅéªÅ¶¡¡A¦P¼Ëªº±¡ªp¦bWindows NT¤¤¤]¬O¦p¦¹¡A¦pªG§Ú­Ì¦bNT¤¤±Ò°Ê¤@­Ó¥H¤WªºWin16À³¥Îµ{¦¡¡A§Ú­Ì·|µo²{¥¦­Ì³£·|¦b¦P¤@­ÓNTVDM.EXE¤§¤¤(NT Virtual DOS Machine)¡A¤]´N¬O»¡¥Ø«e¨t²Î¤¤ªºWin16À³¥Îµ{¦¡¬O¬¡¦b¤@­ÓDOSµêÀÀ¾÷¾¹¤¤¡A¤£¹LNT¤]¤£¬O³o¼Ëªº¤£³q¤H±¡ªº³á!¥Ñ©óWin16À³¥Îµ{¦¡¹w³]¬O¦@¥Î¤@¶ô°O¾ÐÅéªÅ¶¡¡A¥B¥u¤À¨ì¤@­ÓCPU®É¶¡¡A©Ò¥H¦pªG­nÅýWin16À³¥Îµ{¦¡±o¨ì¸û¤½¥­ªº¹ï«Ýªº¸Ü¡A¥i¥H¦Ò¼{¦b±Ò°ÊWin16À³¥Îµ{¦¡®É¡A¦p¤U¹Ï¡A§â¡¨¦b­Ó§Oªº°O¾ÐÅéªÅ¶¡°õ¦æ¡¨