A method of extracting dormancy data of windows operating system
An operating system and data technology, applied in the direction of electrical digital data processing, instrumentation, error detection/correction, etc., can solve the undisclosed technical solution of extracting Windows operating system dormant data, etc.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0042] The present invention will be further elaborated below in conjunction with the accompanying drawings and embodiments. like figure 1 Shown, method of the present invention comprises the following steps:
[0043] S100: read the status value of the signature field Signature of the system file hiberfil.sys: as figure 2 A schematic diagram of the data structure of the system file hiberfil.sys in the hibernation state in one embodiment of the present invention is shown. like figure 2 As shown, take the offset address 0x0000 of the system file hiberfil.sys as the head address, and read the content with a byte length of 0x1000 as the structure of the storage image PO_MEMORY_IMAGE of the page object, which includes the signature field Signature and the address of the home table FTP FirstTablePage ;like figure 2 As shown, the status value of the signature field Signature is the character HIBR stored in ASCII format, which means hibernation; the address FirstTablePage of th...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


