Windows自动创建进程操控、控制台配置及无线程进程创建疑问
Hey there! As someone who’s dug into those same books, I get these questions—let’s break them down clearly:
1. Is the process running my "Hello World" console app created by Windows?
Short answer: Yes, but indirectly. When you run your app from a shell (like cmd.exe or PowerShell), the shell calls the CreateProcess() Win32 API. This API sends a request to the Windows kernel, which handles the actual creation of the process object, virtual address space, and the initial main thread. So the shell initiates the request, but Windows (the kernel) does the heavy lifting to spin up the process.
2. How can I manipulate this automatically created process?
There are a few practical ways to do this, depending on what you want to accomplish:
- Use Win32 APIs: First, get a handle to the process with
OpenProcess()(you’ll need the process ID, which you can grab via tools liketasklistor programmatically withCreateToolhelp32Snapshot()). Once you have the handle, you can:- Terminate it with
TerminateProcess() - Read/write its memory with
ReadProcessMemory()/WriteProcessMemory() - Adjust its priority with
SetPriorityClass()
- Terminate it with
- Command-line tools: Tools like
taskkill(to end the process) orwmic process(to query/modify process properties) work for quick manual manipulation. - Track it during launch: If you’re writing a launcher app, you can capture the process handle directly from
CreateProcess()(via thePROCESS_INFORMATIONstructure) and use that handle to manipulate the process immediately.
Bonus Question 1: How to configure the initial console window size and position if the process is created by the shell?
You have a couple of options here:
- Configure via code: In your "Hello World" app, call Win32 APIs like
SetConsoleWindowInfo()andSetConsoleScreenBufferSize()early in execution to set the window’s position and dimensions. You can get the current console handle withGetStdHandle(STD_OUTPUT_HANDLE). - Modify shell launch settings:
- For
cmd.exe, create a shortcut to your app, right-click it → Properties → Layout tab, then set the window size and position manually. - Use the
modecommand incmd.exebefore launching your app (e.g.,mode con cols=80 lines=20sets the console to 80 columns and 20 rows). - Launch via a custom script: Write a batch/PowerShell script that sets the console properties first, then runs your app.
- For
- Custom launch with
CreateProcess(): If you write a small launcher app, populate theSTARTUPINFOstructure’sdwX,dwY,dwXSize, anddwYSizefields before callingCreateProcess()—this lets you specify the exact window position/size when the process starts.
Bonus Question 2: How to create a process without any threads?
Normal CreateProcess() always creates a main thread for the process, so you need to use lower-level native APIs to pull this off:
- Use
NtCreateProcess()(a kernel-mode API exposed viantdll.dll). This function creates a process object and virtual address space but does not create any threads. Note that this API is not officially documented by Microsoft, so it’s subject to change between Windows versions. - After creating the process with
NtCreateProcess(), you can optionally inject a thread later usingNtCreateThreadEx()if you want the process to do something. Without any threads, the process will exist in the system but won’t execute any code—it will typically exit quickly unless you keep it alive via other means (though there’s rarely a practical use case for this beyond learning internals).
A quick note: Since
NtCreateProcess()is unmanaged, you’ll need to declare it in your C/C++ code using__declspec(dllimport)and link againstntdll.lib, or load it dynamically withLoadLibrary()andGetProcAddress().
内容的提问来源于stack exchange,提问作者user58569

