Method of extracting dormancy data of Windows operating system
An operating system and data technology, applied in the direction of electrical digital data processing, boot program, program control design, etc., can solve the undisclosed problems of extracting the dormant data technology scheme of the Windows operating system, etc.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0047] The present invention will be further elaborated below in conjunction with the accompanying drawings and embodiments. Such as figure 1 Shown, method of the present invention comprises the following steps:
[0048] S100: read the status value of the signature field Signature of the system file hiberfil.sys: as figure 2 A schematic diagram of the data structure of the system file hiberfil.sys in the hibernation state in one embodiment of the present invention is shown. Such as figure 2 As shown, take the offset address 0x0000 of the system file hiberfil.sys as the head address, and read the content with a byte length of 0x1000 as the structure of the storage image PO_MEMORY_IMAGE of the page object, which includes the signature field Signature and the address of the home table FTP FirstTablePage ;Such as figure 2As shown, the status value of the signature field Signature is the character HIBR stored in ASCII format, which means hibernation; the address FirstTablePa...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


