You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows自动创建进程操控、控制台配置及无线程进程创建疑问

Answers to Your Windows Internals Questions

Hey there! As someone who’s dug into those same books, I get these questions—let’s break them down clearly:

1. Is the process running my "Hello World" console app created by Windows?

Short answer: Yes, but indirectly. When you run your app from a shell (like cmd.exe or PowerShell), the shell calls the CreateProcess() Win32 API. This API sends a request to the Windows kernel, which handles the actual creation of the process object, virtual address space, and the initial main thread. So the shell initiates the request, but Windows (the kernel) does the heavy lifting to spin up the process.

2. How can I manipulate this automatically created process?

There are a few practical ways to do this, depending on what you want to accomplish:

  • Use Win32 APIs: First, get a handle to the process with OpenProcess() (you’ll need the process ID, which you can grab via tools like tasklist or programmatically with CreateToolhelp32Snapshot()). Once you have the handle, you can:
    • Terminate it with TerminateProcess()
    • Read/write its memory with ReadProcessMemory()/WriteProcessMemory()
    • Adjust its priority with SetPriorityClass()
  • Command-line tools: Tools like taskkill (to end the process) or wmic process (to query/modify process properties) work for quick manual manipulation.
  • Track it during launch: If you’re writing a launcher app, you can capture the process handle directly from CreateProcess() (via the PROCESS_INFORMATION structure) and use that handle to manipulate the process immediately.

Bonus Question 1: How to configure the initial console window size and position if the process is created by the shell?

You have a couple of options here:

  • Configure via code: In your "Hello World" app, call Win32 APIs like SetConsoleWindowInfo() and SetConsoleScreenBufferSize() early in execution to set the window’s position and dimensions. You can get the current console handle with GetStdHandle(STD_OUTPUT_HANDLE).
  • Modify shell launch settings:
    • For cmd.exe, create a shortcut to your app, right-click it → Properties → Layout tab, then set the window size and position manually.
    • Use the mode command in cmd.exe before launching your app (e.g., mode con cols=80 lines=20 sets the console to 80 columns and 20 rows).
    • Launch via a custom script: Write a batch/PowerShell script that sets the console properties first, then runs your app.
  • Custom launch with CreateProcess(): If you write a small launcher app, populate the STARTUPINFO structure’s dwX, dwY, dwXSize, and dwYSize fields before calling CreateProcess()—this lets you specify the exact window position/size when the process starts.

Bonus Question 2: How to create a process without any threads?

Normal CreateProcess() always creates a main thread for the process, so you need to use lower-level native APIs to pull this off:

  • Use NtCreateProcess() (a kernel-mode API exposed via ntdll.dll). This function creates a process object and virtual address space but does not create any threads. Note that this API is not officially documented by Microsoft, so it’s subject to change between Windows versions.
  • After creating the process with NtCreateProcess(), you can optionally inject a thread later using NtCreateThreadEx() if you want the process to do something. Without any threads, the process will exist in the system but won’t execute any code—it will typically exit quickly unless you keep it alive via other means (though there’s rarely a practical use case for this beyond learning internals).

A quick note: Since NtCreateProcess() is unmanaged, you’ll need to declare it in your C/C++ code using __declspec(dllimport) and link against ntdll.lib, or load it dynamically with LoadLibrary() and GetProcAddress().

内容的提问来源于stack exchange,提问作者user58569

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 06:24:35