09.02.2014 Views

Windows sysinternals

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 3 Process Explorer 73<br />

when loaded into memory. Memory strings might also include dynamically constructed data<br />

areas of the image’s memory range.<br />

Note In computer programming, the term “string” refers to a data structure consisting of a<br />

s equence of characters, usually representing human-readable text.<br />

FIGURE 3-22 The Strings tab of the DLL Properties dialog box.<br />

Click the Save button to save the displayed strings to a text file. To compare image and<br />

memory strings, save the image and memory strings to separate files and then identify the<br />

differences with a text-comparison utility.<br />

To search for specific text in the strings list, click the Find button to display the standard Find<br />

dialog box. To search for additional occurrences of the same text, simply press F3 or click<br />

Find and Find Next again—the search continues from the currently selected row.<br />

Handle View<br />

Procexp’s Handle view lists the object handles belonging to the process selected in the upper<br />

pane, as shown in Figure 3-23. Object handles are what programs use to manipulate system<br />

objects managed by kernel-mode code, such as files, registry keys, synchronization objects,<br />

memory sections, window stations, and desktops. Even though disparate types of resources<br />

are involved, all kernel object types use this consistent mechanism for managing access.<br />

www.it-ebooks.info

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!