Microsoft Windows Internals (4th Edition): Microsoft Windows Server 2003, Windows XP, and Windows 2000

 < Day Day Up >   

Index

[SYMBOL] [A] [B] [C] [D] [E] [F] [G] [H] [I] [J] [K] [L] [M] [N] [O] [P] [Q] [R] [S] [T] [U] [V] [W] [X]

safe mode

     boot logging

     boot option     post-splash screen crashes     starting services in

     user-mode programs SANs (System Area Networks) 2nd 3rd SAPICs (Streamlined Advanced Programmable Interrupt Controllers)

Savedump process 2nd 3rd

scalability, Windows

scatter/gather I/O

ScAutoStartServices function 2nd

ScCreateServiceDB function ScGetBootAndSystemDriverState function scheduling schemas, Active Directory ScLoadDeviceDriver function ScLogonAndStartImage function 2nd screen saver, Blue Screen ScRevertToLastKnownGood function

scripts     Software Restriction Policies

     WMI ScShutdownAllServices function SCSI (Small Computer System Interface) 2nd 3rd 4th 5th 6th

scsi() ARC syntax

Scsiport.sys

ScStartService function 2nd

secret service passwords secrets, Lsass 2nd

Section executive object typesection objects

     access-control lists (ACLs)     attributes

     cache manager 2nd

     data structures     memory management     process creation

     prototype PTEs

     shared memory and mapped files

     viewing

     viewing control areas

sectors

     bad-cluster recovery and spare

     boot

     boot process

     defined 2nd

secure attention sequence (SAS) 2nd 3rd

Secure Channel (SChannel) SSP

secure desktops, Winlogon

Secure Sockets Layer (SSL) 2nd

security     Access token executive object type     account rights and privileges, 516

     Address Windowing Extensions     auditing     AuthZ API

     Common Criteria (CC)

     components

     contexts

     driver-signing policy

     ETHREAD blocks     Evaluation Criteria (TCSEC)     executive object 2nd     executive object services     explicit file I/O     file object     IPSec

     job objects     kernel mode

     logging activity in unprivileged accounts     logon     mailslot

     memory protection 2nd 3rd

     named pipe

     NTFS consolidated security descriptors

     NTFS design requirement     NTFS security file

     object manager    object protection [See object security]

     processes 2nd 3rd     rating standards

     Recovery Console

     registry 2nd     Regmon tool     remote procedure call (RPC)

    Security Accounts Manager (SAM) [See Security Accounts Manager (SAM)]

    security descriptors [See security descriptors]

    security identifiers [See security identifiers (SIDs)]

     service accounts

     services 2nd 3rd

     Software Restriction Policies

     system code write protection 2nd

     threads

     troubleshooting access-denied errors

     viewing registry security settings

     warning regarding GUI security editors

     Windows and

     Windows NT file system

     WMI     zero-initialized pagesSecurity Accounts Manager (SAM)

     Active Directory and     privileges     security

security descriptors

     access control

     attributes

     file object

     NTFS consolidated     registry     service     viewing     warning regarding GUI security editors security editors, warning regarding GUIsecurity identifiers (SIDs)

     access checks     machine

     quota management     registry     viewing, using PsGetSid tool

security inheritance support DLL

security method, executive object

security policies

Security Policy Editor security quality of service (SQOS)

security reference monitor (SRM)     executive

     executive objects     initialization 2nd 3rd

     local procedure calls

     Lsass     security Security Support Provider Interface (SSPI) packages

security support providers (SSPs)

Security Target (ST) concept

security-descriptor cell data type

SeDefaultObjectMethod function

segment structure 2nd

SeLsaCommandPort

Semaphore executive object type

semaphores

     executive resources

     priority boosts after waiting for

send function

serial port boot options 2nd 3rd 4th

serialization, NDIS

SeRmCommandPort Server Message Block (SMB) protocol server versions, Windows

servers     file system driver     named pipe

     ports

     RPC server name publishing

     server farm online crash analysis

     Winsock

service accounts     interactive services     local service account     local system account     network service account     running services in alternate service applications

service control manager (SCM) [See also services]     auto-start device driver loading

     boot process 2nd     initialization     network binding

     safe mode boots

     service control programs (SCPs)

     services 2nd

     system processesservice control programs (SCPs)

     service applications     service control manager

     servicesService Host (Svchost) process

     as shared service process

     WMI providerservice packs, Windows     symbol files

     system service numbers

service provider interface (SPI),Winsock

Service-0x0-3e7$ windows station

services [See also device drivers]

     accepting boot and last know good

     components of

     executive object generic

     failures

     interactive

     listing installed

     memory manager 2nd

     service applications

     service control manager (SCM) 2nd

     service control programs (SCPs)     service descriptor tables    service dispatching [See system service dispatching]

     service processes     shared processes     shutdown of

     SrvAny tool

     startup errors

     startup of

     viewing details inside service processes

     Windows and Services for UNIX 2nd 3rd Services MMC snap-in 2ndServices.exe [See service control manager (SCM)] SeSecurityPrivilege and SeAuditPrivilege privileges SeSinglePrivilegeCheck and SePrivilegeCheck functions session layer, OSI model

session space     sessions

     viewing     x86 layouts session working sets

sessions

     NetBIOS

     session zero

     Terminal Services and multiple SetHandleInformation function 2nd

SetInformationJobObject function SetPriorityClass function

SetProcessAffinityMask function SetProcessShutdownParameters function

SetProcessWorkingSetSize function 2nd

SetProcessWorkingSetSizeEx function 2nd SetServiceStatus function SetThreadAffinityMask function

SetThreadIdealProcessor function

SetThreadPriorityBoost function

Setup function

Setup program, Windows

     boot process 2nd

     partitioning

     repair installs

     security identifiers (SIDs)

setup programs [See also installation]

     driver signing

     registry settings

     service applications

    Windows [See Setup program, Windows]

Setup.log     determining which HAL is running     kernel versions

     multiprocessor and uniprocessor file versions Setupdd.sys SetupDiEnumDeviceInterfaces function

SetupDiGetDeviceInterfaceDetail function

SetWindowsHook function

shadow copies

shared assemblies

shared cache map structures 2nd 3rd shared executive objects shared folders shared memory [See also section objects]     Section executive object type     section objects, mapped files, and     sections

     Windows NT shared resources 2nd [See also file objects]

shared service processesshell     boot option

    Explorer.exe as [See Explorer.exe]

     initialization

     NTFS shortcuts

     safe mode boots     user logon

     Userinit.exe short names, NTFS

short quantum 2ndshutdown

     clearing page file

     overview     service     shutdown levels 2nd

side-by-side assemblies

signaled state, dispatcher object 2nd

signature() syntax

signatures, hive 2nd

simple volumes

single sign-on

single-layered device drivers

size

     cache

     hive limits

SleepEx function

Small Computer System Interface (SCSI) 2nd 3rd 4th 5th 6th

small memory dump crash dump files

small pages small-IRP look-aside listSmss (Session Manager)

     Autochk.exe     boot process 2nd 3rd     Chkdsk

     creating sessions

     initialization

     Recovery Console

     system processes

sockets, Winsock soft page faults soft partitions soft real-time systems SoftICE tool software configuration, registry software data execution prevention (DEP)

Software Development Kit [See Platform Software Development Kit (SDK)]software interrupt request levels

     asynchronous procedure calls (APCs)     dispatch or deferred procedure call (DPC) interrupts     interrupt dispatching

     monitoring activity

software keys, device

software providers, VDS

Software Restriction Policies 2nd software resumption, system power states and

spanned volumes spare sectors

sparse data, compressing sparse files, NTFS 2nd

Spcmdcon.sys

special pool option, Driver Verifier 2ndspinlocks     functions of

     instack queued

     IRP synchronization

     kernel-mode mechanisms vs.

     multiprocessor thread dispatching

     queued

SQL Server

SRSetRestorePoint and SRRemoveRestorePoint functions

SrvAny tool

stability

stability, Windows

stacks

     creating thread, for processes

     heap manager stack traces

     inswapping and outswapping     IRP stack locations 2nd 3rd     network

     stack frame exception handlers     stack trashing and crash dump analysis     viewing device

     viewing thread

     Windows storage stack

standby pages 2nd 3rd 4th 5th 6th 7th

standby state, thread

start address, thread 2nd start command 2nd start I/O routine, device driver Start value, device driver start-device command, Plug and Play manager start-of-process function start-of-thread function

StartService function StartServiceCtrlDispatcher function 2nd

states     page     PFN entry

     shared page

     system power and device power 2nd

     thread scheduling and thread

static WMI classes stop codes

stop command, Plug and Play managerstorage area networking [See System Area Networks (SANs)]

storage management     disk drivers

     terminology

    volume management [See volume management]     watching physical disk I/O Storport.sys

stream caching, cache manager

stream control blocks (SCBs), NTFS

Streamlined Advanced Programmable Interrupt Controller (SAPIC)

Streams tool

streams, NTFS data

Strings tool

     looking inside prefetch files

     searching for device drivers by pool tags

     SYSTEM hive corruption problem

     troubleshooting pool leaks

striped volumes 2nd 3rd

striped volumes with parity

structured exception handling [See also exception dispatching]

Structured Query Language (SQL), WMI scripts and stub procedures, RPC subkey-list cell data type

subkeys, registry subsection structures, section object support images, process creation and

surprise-remove command, Plug and Play manager

SvcCtrlMain function 2nd

SwitchToFiber function

symbol server, Microsoft 2nd

Symbolic link executive object type symbolic links device object 2ndsymbols     kernel debugging 2nd     viewing, using Process Explorer symmetric encryption algorithms symmetric multiprocessing (SMP), Windows 2nd

SYNCH_LEVEL IRQLs 2nd synchronization

     deadlock detection 2nd     executive     heap

     high-IRQL

     kernel dispatcher objects

     KTHREAD blocks

     low-IRQL     memory manager internal

     multiprocessing     multiprocessor thread context switching

     Mutex executive object type     mutual exclusion

     scalability

     synchronous I/O requests to single-layered drivers     type object attribute     uniprocessor dispatcher database

     viewing global queued spinlocks

synchronous I/O

syscall instruction

sysenter instruction

sysexit instruction

sysinternals tools

     Accvio.exe

     Blue Screen screen saver

     ChkReg tool

     Clockres tool

     Dbgview.exe tool

     device drivers

     Diskmon tool

     EFSDump tool    Explorer PsExec tool [See PsExec tool]    Filemon tool [See Filemon tool]

    Handle tool [See Handle tool]     Junction tool     LDMDump tool

    LiveKd tool [See LiveKd tool]

     LogonSessions tool

     Msconfig tool

     Notmyfault tool 2nd 3rd 4th

     NTFSInfo tool     Pagedefrag tool     Pendmoves tool     PipeList tool     PsGetSid tool     Testlimit tool     Windows and

system access-control lists (SACLs) assignment System account

system accounts system architecture 2nd [See also system architecture, Windows] system architecture, Windows

     checked build versions

     checking Ntoskrnl versions

     differences between client and server versions

     portability     scalability

     symmetric multiprocessing (SMP)     system components [See also system components, Windows]

     user-mode and kernel-mode processes     viewing multiprocessor-specific support files on Windows 2000

System Area Networks (SANs) 2nd 3rd

system audit and system audit- object ACEssystem cache     centralized [See also cache manager]

     data structures

     extra memory

     system space

system clock

     boot options 2nd

     DPCs

     interrupts

     IRQLs

system code

system code write protection 2nd

system components, Windows

     determining which HAL is running

     device drivers [See also device drivers]

     environment subsystems and subsystem DLLs     examining undocumented interfaces     executive

     hardware abstraction layer [See also HAL (hardware abstraction layer)]     kernel [See also kernel]     Ntdll.dll library

System Disk Image (SDI) file boot options 2nd

system files corruption problem

SYSTEM hive 2nd 3rd 4th 5th 6th

System Information viewer tool

system mapped views system mechanisms, Windows     kernel event tracing     local procedure calls (LPCs)    object manager [See object manager]     system worker threads    trap dispatching [See trap dispatching]

     Windows global flags system memory pools

     configuring     Driver Verifier     look-aside lists

     monitoring usage

     types of

system monitoring [See Performance tool]

System object system page table entries (PTEs)

system power states     mapping device power states to

     power manager System process

system processes 2nd

     idle process     interrupts and DPCs     listing installed services

     service control manager (SCM)

     System process and system threads

     viewing service details inside service processes

     Winlogon, Lsass, and Userinit

system profile

System Restore

     as file system filter driver

     post-splash screen crashes

     restoring SYSTEM hive

System Restore Wizard

system service dispatching 2nd

     32-bit

     64-bit

     kernel-mode     KTHREAD blocks     mode transitions

     Regmon tool     service descriptor tables     viewing activity

system services [See also services; system service dispatching]

     dispatching and Ntdll.dll

     exceptions

     executive

     Windows and system shutdown 2ndsystem space     components     page table entries (PTEs)     x86 layoutssystem startup [See boot process]

system support processes system threads

system timer [See system clock]System tool     crash dump file settings

     page file configuration settings

system variables [See also kernel variables]

     cache flush

     cache manager mapping and pinning activity     cache manager MDL activity

     cache physical size and page fault     cache read activity

     cache virtual size and address     fast I/O

     intelligent read-ahead

     lazy writer System Volume Information directory 2nd system volumes 2nd 3rd

system worker threads 2nd 3rd 4th

system working sets 2nd 3rd 4th 5th

system-call hooking, Regmon and

System.alt

System.log

System.sav

Systematic Flaw Remediation, security rating and

SystemParametersInfo function

systemwide cache data structures

systemwide class registration data

systemwide dispatcher spinlock

systemwide settings, registry 2nd

SYSVOL directory

 < Day Day Up >   

Категории