smss!SmpStartCsr函数分析之SmpLoadSubSystemsForMuSession3389远程桌面新进程csrss.exe的由来 - 指南

news/2025/10/30 18:01:28/文章来源:https://www.cnblogs.com/yangykaifa/p/19177819

smss!SmpStartCsr函数分析之SmpLoadSubSystemsForMuSession3389远程桌面新进程csrss.exe的由来

You can troubleshoot most symbol related issues by turning on symbol loading diagnostics (!sym noisy) and repeating the command that caused symbols to be loaded.
You should also verify that your symbol search path (.sympath) is correct.
0: kd> kc
#
00 smss!SmpStartCsr
01 smss!SmpApiLoop
0: kd> dv
SmApiMsg = 0x0030fea8
CallingClient = 0x001637b8
CallPort = 0x00000010
State = 0x00000000
InitialCommandProcessId = 0
InitialCommandProcess = 0x77f2f6e8
InitialCommand = ""
DefaultInitialCommand = ""
WindowsSubSysProcessId = 0x2e8
MuSessionId = 0x30fea8
0: kd> dx -r1 ((smss!_SMAPIMSG *)0x30fea8)
((smss!_SMAPIMSG *)0x30fea8) : 0x30fea8 [Type: _SMAPIMSG *]
[+0x000] h [Type: _PORT_MESSAGE]
[+0x018] ApiNumber : SmStartCsrApi (5) [Type: _SMAPINUMBER]
[+0x01c] ReturnedStatus : 259 [Type: long]
[+0x020] u [Type: __unnamed]
0: kd> dx -r1 (*((smss!__unnamed *)0x30fec8))
(*((smss!__unnamed *)0x30fec8)) [Type: __unnamed]
[+0x000] CreateForeignSession [Type: _SMCREATEFOREIGNSESSION]
[+0x000] SessionComplete [Type: _SMSESSIONCOMPLETE]
[+0x000] TerminateForeignComplete [Type: _SMTERMINATEFOREIGNSESSION]
[+0x000] ExecPgm [Type: _SMEXECPGM]
[+0x000] LoadDefered [Type: _SMLOADDEFERED]
[+0x000] StartCsr [Type: _SMSTARTCSR]
[+0x000] StopCsr [Type: _SMSTOPCSR]
0: kd> dx -r1 (*((smss!_SMSTARTCSR *)0x30fec8))
(*((smss!_SMSTARTCSR *)0x30fec8)) [Type: _SMSTARTCSR]
[+0x000] MuSessionId : 0xffffffff [Type: unsigned long]
[+0x004] InitialCommandLength : 0x0 [Type: unsigned long]
[+0x008] InitialCommand [Type: unsigned short [128]]
[+0x108] InitialCommandProcessId : 0x0 [Type: unsigned long]
[+0x10c] WindowsSubSysProcessId : 0xdba90 [Type: unsigned long]


0: kd> dv
SmApiMsg = 0x0030fea8
CallingClient = 0x001637b8
CallPort = 0x00000010
State = 0x00000000
InitialCommandProcessId = 0
InitialCommandProcess = 0x77f2f6e8
InitialCommand = ""
DefaultInitialCommand = ""
WindowsSubSysProcessId = 0x2e8
MuSessionId = 0x30fea8
0: kd> dx -r1 ((smss!_SMAPIMSG *)0x30fea8)
((smss!_SMAPIMSG *)0x30fea8) : 0x30fea8 [Type: _SMAPIMSG *]
[+0x000] h [Type: _PORT_MESSAGE]
[+0x018] ApiNumber : SmStartCsrApi (5) [Type: _SMAPINUMBER]
[+0x01c] ReturnedStatus : 259 [Type: long]
[+0x020] u [Type: __unnamed]
0: kd> dx -r1 (*((smss!__unnamed *)0x30fec8))
(*((smss!__unnamed *)0x30fec8)) [Type: __unnamed]
[+0x000] CreateForeignSession [Type: _SMCREATEFOREIGNSESSION]
[+0x000] SessionComplete [Type: _SMSESSIONCOMPLETE]
[+0x000] TerminateForeignComplete [Type: _SMTERMINATEFOREIGNSESSION]
[+0x000] ExecPgm [Type: _SMEXECPGM]
[+0x000] LoadDefered [Type: _SMLOADDEFERED]
[+0x000] StartCsr [Type: _SMSTARTCSR]
[+0x000] StopCsr [Type: _SMSTOPCSR]
0: kd> dx -r1 (*((smss!_SMSTARTCSR *)0x30fec8))
(*((smss!_SMSTARTCSR *)0x30fec8)) [Type: _SMSTARTCSR]
[+0x000] MuSessionId : 0xffffffff [Type: unsigned long]
[+0x004] InitialCommandLength : 0x0 [Type: unsigned long]
[+0x008] InitialCommand [Type: unsigned short [128]]
[+0x108] InitialCommandProcessId : 0x0 [Type: unsigned long]
[+0x10c] WindowsSubSysProcessId : 0xdba90 [Type: unsigned long]

//
// Load subsystems for this session.
//

WindowsSubSysProcessId = 0;

Status = SmpLoadSubSystemsForMuSession (&MuSessionId,
&WindowsSubSysProcessId,

0: kd> t
smss!SmpLoadSubSystemsForMuSession:
001b:4858aa7c 55 push ebp
0: kd> dv
pMuSessionId = 0x0030fe50
pWindowsSubSysProcessId = 0x0030fe3c
InitialCommand = 0x0030fe28 ""
Status = 0n0
FileName = struct _UNICODE_STRING "--- memory read error at address 0x00000010 ---"
Win32kFileName = struct _UNICODE_STRING ""
State = 0x00000018
DelayTime = {68722687656}


0: kd> gu
GDI: VerifierInitialization: failed to get info from ntoskrnl

(s: 0 0x180.18c smss.exe) USRK-[Wrn] *** win32k: DBCS:[0] IME:[0] MiddleEast:[0] CTFIME:[0]
Installed
Installed
Breakpoint 4 hit
nt!PspCreateProcess:
80d3a1c0 6834010000 push 134h
0: kd> kc
#
00 nt!PspCreateProcess
01 nt!NtCreateProcessEx
02 nt!NtCreateProcess
03 nt!_KiSystemService
04 SharedUserData!SystemCallStub
05 ntdll!NtCreateProcess
06 ntdll!RtlCreateUserProcess
07 smss!SmpExecuteImage
08 smss!SmpLoadSubSystem
09 smss!SmpExecuteCommand
0a smss!SmpLoadSubSystemsForMuSession
0b smss!SmpStartCsr
0c smss!SmpApiLoop
0: kd> dv


0: kd> gu
nt!NtCreateProcessEx+0xae:
80d3af36 eb05 jmp nt!NtCreateProcessEx+0xb5 (80d3af3d)
0: kd> !process 0 0
**** NT ACTIVE PROCESS DUMP ****
PROCESS 899a2278 SessionId: none Cid: 0004 Peb: 00000000 ParentCid: 0000
DirBase: 0a200000 ObjectTable: e1000e38 HandleCount: 320.
Image: System

PROCESS 894ddd88 SessionId: none Cid: 0180 Peb: 7ffdf000 ParentCid: 0004
DirBase: 7b189000 ObjectTable: e1278720 HandleCount: 20.
Image: smss.exe

PROCESS 8940cd88 SessionId: 0 Cid: 01b0 Peb: 7ffdf000 ParentCid: 0180
DirBase: 7aa43000 ObjectTable: e1458b40 HandleCount: 304.
Image: csrss.exe

PROCESS 898c8250 SessionId: 0 Cid: 01c8 Peb: 7ffdf000 ParentCid: 0180
DirBase: 7a448000 ObjectTable: e1457ad0 HandleCount: 479.
Image: winlogon.exe

PROCESS 897f5250 SessionId: 0 Cid: 01f4 Peb: 7ffdf000 ParentCid: 01c8
DirBase: 7a1cc000 ObjectTable: e1669ec0 HandleCount: 301.
Image: services.exe

PROCESS 8988a020 SessionId: 0 Cid: 0200 Peb: 7ffdf000 ParentCid: 01c8
DirBase: 7a2d4000 ObjectTable: e16dc8e0 HandleCount: 395.
Image: lsass.exe

PROCESS 898618d0 SessionId: 0 Cid: 02c4 Peb: 7ffdf000 ParentCid: 01f4
DirBase: 79bc2000 ObjectTable: e144df68 HandleCount: 160.
Image: svchost.exe

PROCESS 8954f3f0 SessionId: 0 Cid: 02fc Peb: 7ffdf000 ParentCid: 01f4
DirBase: 79ca0000 ObjectTable: e144dfb8 HandleCount: 190.
Image: svchost.exe

PROCESS 894d0c10 SessionId: 0 Cid: 0388 Peb: 7ffdf000 ParentCid: 01f4
DirBase: 09fea000 ObjectTable: e142f830 HandleCount: 130.
Image: svchost.exe

PROCESS 895d98c0 SessionId: 0 Cid: 03bc Peb: 7ffdf000 ParentCid: 01f4
DirBase: 796af000 ObjectTable: e1439930 HandleCount: 79.
Image: svchost.exe

PROCESS 895e0c10 SessionId: 0 Cid: 03d8 Peb: 7ffdf000 ParentCid: 01f4
DirBase: 79575000 ObjectTable: e1439aa8 HandleCount: 589.
Image: svchost.exe

PROCESS 895538c0 SessionId: 0 Cid: 04a4 Peb: 7ffdf000 ParentCid: 01f4
DirBase: 79347000 ObjectTable: e17da1f8 HandleCount: 125.
Image: spoolsv.exe

PROCESS 8988bbf8 SessionId: 0 Cid: 04c0 Peb: 7ffdf000 ParentCid: 01f4
DirBase: 7908d000 ObjectTable: e17cab78 HandleCount: 159.
Image: msdtc.exe

PROCESS 894153f8 SessionId: 0 Cid: 052c Peb: 7ffdf000 ParentCid: 01f4
DirBase: 79413000 ObjectTable: e13d0140 HandleCount: 55.
Image: svchost.exe

PROCESS 89484950 SessionId: 0 Cid: 0594 Peb: 7ffdf000 ParentCid: 01f4
DirBase: 78f9b000 ObjectTable: e17e30e8 HandleCount: 36.
Image: svchost.exe

PROCESS 894fbd88 SessionId: 0 Cid: 05bc Peb: 7ffdf000 ParentCid: 01f4
DirBase: 78da1000 ObjectTable: e1294788 HandleCount: 42.
Image: tftpd6.exe

PROCESS 8984fd88 SessionId: 0 Cid: 06a8 Peb: 7ffdf000 ParentCid: 01f4
DirBase: 788c2000 ObjectTable: e1770838 HandleCount: 51.
Image: dfssvc.exe

PROCESS 896b7538 SessionId: 1 Cid: 06d4 Peb: 7ffdf000 ParentCid: 0180
DirBase: 7880e000 ObjectTable: e188c460 HandleCount: 0.
Image: csrss.exe

Image: csrss.exe 新的csrss.exe进程!!!父进程是smss!!!ParentCid: 0180

本文来自互联网用户投稿,该文观点仅代表作者本人,不代表本站立场。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如若转载,请注明出处:http://www.mzph.cn/news/951047.shtml

如若内容造成侵权/违法违规/事实不符,请联系多彩编程网进行投诉反馈email:809451989@qq.com,一经查实,立即删除!

相关文章

220kv数字化变电站保护解决方案综述[期刊理解]

220kv数字化变电站保护解决方案综述[期刊理解] 本文围绕双母接线型 220kV 数字化变电站,系统阐述了继电保护的实施方案、配置逻辑、故障处理机制及配合关系,核心重点可从以下五大维度梳理:重点内容:核心背景与数字…

2025年10月VI设计公司权威推荐排行榜:排名依据包括项目交付质量、客户满意度、创新能力和市场影响力

摘要 VI设计行业近年来随着品牌竞争加剧而快速发展,企业越来越重视视觉识别系统以提升市场竞争力。2025年,行业趋势聚焦于数字化整合和极简主义设计,帮助企业实现品牌焕新。本文基于权威数据和用户口碑,提供一份VI…

2025年0糖苏打水厂家权威推荐榜单:带帽苏打水/茉莉苏打水 /蜜桃苏打水源头厂家精选

随着健康饮食观念的普及,0糖苏打水市场呈现快速增长态势。行业数据显示,2025年中国无糖饮料市场规模预计突破800亿元,其中0糖苏打水品类年均增长率达25%以上。在这一市场背景下,生产企业的技术实力与品质管控能力成…

Bilidown Setup 1.2.7下载

软件已停更,目前能用,且用且珍惜 Bilidown Setup 1.2.7下载

rpm因依赖安装失败的一次检查记录

rpm安装rpm -i --test XaoS-3.0-1.i386.rpm 出现错误:error: failed dependencies:libslang.so.0 is needed by XaoS-3.0-1libpng.so.0 is needed by XaoS-3.0-1libaa.so.1 is needed by XaoS-3.0-但是,libslang.so.…

0296-Nand-机器语言

环境Time 2023-07-07前言 说明 参考:https://www.nand2tetris.org/ 目标 接上一节,通过模拟的 CPU 实现 mult 和 fill 程序。 mult // r2 = 0 @2 M=0// loop r1 > 0 (LOOP) @1 D=M @END D;JLE// r1 = r1 - 1 D=D-…

0295-Nand-时序逻辑

环境Time 2023-07-07前言 说明 参考:https://www.nand2tetris.org/ 参考:《编码:隐匿在计算机背后的语言》 目标 接上一节,实现 Bit、Register、RAM8、RAM64、RAM512、RAM4K、RAM16K、PC。 Bit /*** 1-bit registe…

[apt update docker 密钥问题]

问题输出 Get:26 http://mirrors.aliyun.com/ubuntu focal-backports/restricted amd64 DEP-11 Metadata [212 B] Get:27 http://mirrors.aliyun.com/ubuntu focal-backports/universe amd64 DEP-11 Metadata [30.5 kB…

0300-Nand-表示代码

环境Time 2023-07-09 Java 17前言 说明 参考:https://craftinginterpreters.com/contents.html https://github.com/GuoYaxiang/craftinginterpreters_zh https://space.bilibili.com/44550904目标 使用 Java 语言脚本…

Python逻辑运算 _ 今年过节能收礼吗

Python逻辑运算 _ 今年过节能收礼吗house_work_count = int(input("house_work_count:"))red_envelope_count = int(input("red_envelope_count:"))shopping_count = int(input("shopping_co…

ENGG5301 Information Theory 2025 Midterm Exam P3:Causal Encoding

题目为回忆版,解答是 GPT-5 写的。 考试时 (1) 问就想偏了,考后看到 GPT-5 的答案很气,不等式想不到直接 (1)(2)(3) 连跪,搞的 (4)(5) 问也没做。 从初中就开始烂完的不等式水平又发力了,但这课确实没啥心思去刷教…

0291-Nand-实现基础逻辑门(一)

环境Time 2023-07-06前言 说明 参考:https://www.nand2tetris.org/ 目标 通过最基础的 Nand(与非门)实现 Not、And、Or、Xor、Mux、DMux 几个基础门。 Not /*** Not gate:* out = not in*/ /** Sets out = in Nand …

NASM下载和安装教程(附安装包)

NASM 全称 Netwide Assembler,诞生于 1996 年,是一款面向 x86 与 x86-64 架构的开源汇编语言编译器。NASM 把纯文本的汇编指令翻译成可执行二进制、目标文件或固件镜像,支持 16/32/64 位三种运行模式,输出格式覆盖…

0292-Nand-实现基础逻辑门(二)

环境Time 2023-07-06前言 说明 参考:https://www.nand2tetris.org/ 目标 接上一节,通过基础的逻辑门实现 Not16、And16、Or16、Mux16 四个基础门。 Not16 /*** 16-bit Not:* for i=0..15: out[i] = not in[i]*/ /** …

单点登录SSO是怎么实现的?

单点登录SSO是怎么实现的?1,先解释什么是单点登录:单点登录的英文名叫做:Single Sign On(简称SSO) 2,介绍自己项目中涉及到的单点登录(即使没涉及过,也可以说实现的思路) 3,介绍单点登录的解决方案,以JWT为…

赋能智慧货运:视频汇聚平台EasyCVR打造货运汽车安全互联网视频监控与管理方案

一、背景介绍 随着互联网发展,货运中介平台大量涌现,行业纠纷也随之增多。尽管当前平台APP具备录音和定位功能,但货物交易流程的全方位监控仍无法实现。主流跟踪定位服务大部分聚焦货物轨迹与车辆定位,尚未实现货物…

2025年上海房产继承律师权威推荐榜单:继承律师/离婚律师/婚姻律师事务所精选

本文基于执业经验、专业能力、成功案例及业界口碑等核心维度,为您推荐上海地区房产继承领域的三位优秀律师,为面临遗产规划或继承难题的家庭提供参考。 行业背景与需求分析 近年来,房产继承法律需求呈现持续增长态势…

【SPIE出版、往届已EI检索】第二届遥感技术与图像处理国际学术会议(RSTIP 2025)

#SPIE 出版-ISSN:0277-786X# #高录用稳检索-快至见刊后1个月EI、Scopus检索# 第二届遥感技术与图像处理国际学术会议(RSTIP 2025) 2025 2nd International Conference on Remote Sensing Technology and Image Proce…

autotiny下载_v3.0.0.2

超级自动化软件 释放双手 实现自由by风吹呀儿吹 autotiny_3.0.0.2下载

2025 年井盖篦子最新推荐榜,技术实力与市场口碑深度解析铸铁套/树围/球墨铸铁单/溢流井/雨水井盖篦子公司推荐

引言 为精准筛选井盖篦子领域优质服务商,本次推荐榜由市政工程协会联合建筑材料检测中心共同发起测评,参考《GB/T 23858-2009 检查井盖》最新修订标准,采用 “三维九项” 测评体系。测评从技术维度(材质强度、防腐…