
ããå€§èŠæš¡ãªéèæ©é¢ã§äžå¿«ãªäºä»¶ãçºçããŸãããæ»æè ã¯ãããã¯ãŒã¯ã«äŸµå ¥ãããã¹ãŠã®éèŠãªæ å ±ããããã¥ãŒã ã¯ãªãŒãã³ã°ãããŸãããæ»æè ã¯ããŒã¿ãã³ããŒããŠãªã¢ãŒããªãœãŒã¹ã«éä¿¡ããŸããã Group-IBã®æ³å»åŠå°éå®¶ã¯ã説æãããåºæ¥äºããããã6ãæåŸã«å©ããæ±ããŸããâŠããã®æãŸã§ã«ãäžéšã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ãšãµãŒããŒã¯ãã§ã«ãµãŒãã¹ã忢ããŠãããæ»æè ã®ã¢ã¯ã·ã§ã³ã®çè·¡ã¯ãç¹æ®ãªãœãããŠã§ã¢ã®äœ¿çšãšèª€ã£ããã®ã³ã°ã®ããã«ç Žå£ãããŠããŸããããã ããã€ã³ã·ãã³ãã«é¢ä¿ãããµãŒããŒã®1ã€ã§WindowsããŒãžã³ã°ãã¡ã€ã«ãèŠã€ãããããããå°éå®¶ãã€ã³ã·ãã³ãã«é¢ããéèŠãªæ å ±ãååŸããŸããã
ãã®èšäºã§ã¯ãPavel ZevakhinãGroup-IB Forensic Scââience Labã¯ãæ³å»åŠç ç©¶äžã«Windowsã¹ã¯ãããã¡ã€ã«ã§æ€åºã§ããããŒã¿ã«ã€ããŠèª¬æããŠããŸãã
ããŒã1ãpagefile.sysãé ããŠãããã®
ãããã£ãŠãpagefile.sysã¯Windowsãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ããŒãžã³ã°ãã¡ã€ã«ã§ããååãªRAMããªãå ŽåãWindowsã¯ããŒããã£ã¹ã¯ã«ç¹å®ã®ã¹ããŒã¹ãäºçŽããããã䜿çšããŠæ©èœãåäžãããŸããã€ãŸããããŒã¿ã®äžéšãRAMããpagefile.sysãã¡ã€ã«ã«ã¢ã³ããŒãããŸããå€ãã®å Žåãç ç©¶è ãå¿ èŠãšããæ å ±ã¯ããŒãžã³ã°ãã¡ã€ã«ã«ã®ã¿æ®ããŸãã
ããŒãžã³ã°ãã¡ã€ã«ãžã®ã¢ããããŒãã¯ã4 KBãããã¯ã§ããŒãžããšã«è¡ããããããããŒã¿ã¯ããŒãžã³ã°ãã¡ã€ã«ã®é£ç¶ããé åãå ããããšãããã¡ã€ã«ã®ç°ãªãéšåã«ããããšããããŸããããã¯ãã»ãšãã©ã®å Žåããã®ãã¡ã€ã«ã§èŠã€ãã£ãæ å ±ãå®å šæ§ã倱ã£ãŠååŸãããããšãæå³ããŸãã
ãã¡ã€ã«ã·ã¹ãã å ã®pagefile.sysã®ãµã€ãºã¯ãããã©ã«ãã§ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«ãã£ãŠèšå®ãããŸããããŠãŒã¶ãŒã¯ãã€ã§ãããŒãžã³ã°ãã¡ã€ã«ãç¡å¹ã«ããããæå€§ãµã€ãºã倿Žãããã§ããŸãããã¡ã€ã«ã®ããã©ã«ãã®å Žæã¯ã·ã¹ãã ããŒãã£ã·ã§ã³ã®ã«ãŒãã§ããããŠãŒã¶ãŒããã¡ã€ã«ãé 眮ããå Žæã«å¿ããŠãä»ã®è«çãã©ã€ãã«é 眮ã§ããŸãããã®äºå®ãèŠããŠããå¿ èŠããããŸãã
pagefile.sysã®æœåºã«åãæããåã«ããã¡ã€ã«ã·ã¹ãã ã®èгç¹ãããã®ãã¡ã€ã«ãäœã§ããããçè§£ããå¿ èŠããããŸãããããè¡ãã«ã¯ãAccessData FTKImagerãœãããŠã§ã¢ã䜿çšããŸãã
é ã | æ¬åœ | ææè SID | S-1-5-32-544 |
ã·ã¹ãã | æ¬åœ | ãªãŒããŒå | 管çè |
èªã¿åãå°çš | 誀ã | ã°ã«ãŒãSID | S-1-5-18 |
ã¢ãŒã«ã€ã | æ¬åœ | ã°ã«ãŒãå | ã·ã¹ãã |
ããã¯ãã³ããŒã容æã§ã¯ãªãé ãã·ã¹ãã ãã¡ã€ã«ã§ããããšãããããŸãã
ã§ã¯ãã©ãããã°ãã®ãã¡ã€ã«ãå ¥æã§ããŸããïŒããã¯ããã€ãã®æ¹æ³ã§è¡ãããšãã§ããŸãã
- , FTK Imager KAPE
- â .
pagefile.sysãã¡ã€ã«ã¯ããªã¥ãŒã ã·ã£ããŠã³ããŒããã³ä»ã®è«çãã©ã€ãã«é 眮ã§ããããšãå¿ããªãã§ãã ããã確ãã«ããŠãŒã¶ãŒèªèº«ãã·ã£ããŠã³ããŒã«ãŒã«ãèšå®ããããŒãžã³ã°ãã¡ã€ã«ã®ã³ããŒãé€å€ããå ŽåããããŸãïŒã·ã¹ãã ã¬ãžã¹ããªã«HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ BackupRestore \ FilesNotToSnapshotãã©ã³ãããããã·ã£ããŠã³ããŒããé€å€ããããã¡ã€ã«ãæå®ãããŠããŸãïŒã
äžã®ç»åã§ã¯ãçŸåšã®ããŒãžã³ã°ãã¡ã€ã«ïŒç»åäž-巊端ïŒãšãç°ãªãæéã«äœæãããã·ã£ããŠã³ããŒããåããã©ã€ãããååŸãããããŒãžã³ã°ãã¡ã€ã«ã§ãæ€åºãããããŒã¿ã®éãã©ã®ããã«å€åãããã確èªã§ããŸãã

èŠããŠããã¹ãéèŠãªãã€ã³ãïŒãã«ã10525以éãWindows10ã¯ããŒãžã³ã°ãã¡ã€ã«å§çž®ã䜿çšããŸããã¡ã¢ãªãå°ãªããªããšãã·ã¹ãã ã¯åããã»ã¹ã§æªäœ¿çšã®ã¡ã¢ãªãªãœãŒã¹ãçž®å°ããããå€ãã®ã¢ããªã±ãŒã·ã§ã³ãåæã«ã¢ã¯ãã£ãã«ä¿ã€ããšãã§ããŸãããã®ãããªãã¡ã€ã«ãè§£åããã«ã¯ãå°çšã®ãœãããŠã§ã¢ã䜿çšããå¿ èŠããããŸããããšãã°ãMaximSukhanovã®winmem_decompressãŠãŒãã£ãªãã£ã䜿çšããŠè§£åã§ããŸãã

ããã¯ãå ã®ããŒãžã³ã°ãã¡ã€ã«ãæ€çŽ¢ããŠãçµæãè¿ãããªãå ŽåããŸãã¯å¿ èŠãªããŒã¿ãå§çž®ãããŠããå Žåã«åœ¹ç«ã¡ãŸãã
ãããã£ãŠãpagefile.sysãã¡ã€ã«ãæã«å ¥ããŠã調æ»ãéå§ã§ããŸãããããŠããã§ã¯ã2ã€ã®ç¶æ³ãç¹å®ããå¿ èŠããããŸãã1ã€ç®ã¯äœãæ¢ãã¹ãããããã£ãŠãããšãããã1ã€ã¯ããããªããšãã§ããæåã®ã±ãŒã¹ã§ã¯ããããã¯ãã¡ã€ã«ã®æçã1ã€ãŸãã¯å¥ã®ãœãããŠã§ã¢ã®äœæ¥ã®çè·¡ãããçš®ã®ãŠãŒã¶ãŒã¢ã¯ãã£ããã£ã§ããå¯èœæ§ããããŸãããã®ãããªæ€çŽ¢ã«ã¯ãéåžžã16é²ãšãã£ã¿ãŒã®X-Ways WinHEXïŒãŸãã¯ãã®ä»ïŒã䜿çšãããŸãã 2çªç®ã®ã±ãŒã¹ã§ã¯ãMAGNET AXIOMãBelkasoft Evidence CenterãæååãŠãŒãã£ãªãã£ïŒã¡ã€ã³ã§æãé »ç¹ã«äœ¿çšããããšèŠãªãããšãã§ããŸãïŒããœãããŠã§ã¢ãªã©ã®ç¹æ®ãªãœãããŠã§ã¢ã«äŸåããå¿ èŠããããŸããPhotorecïŒçœ²åããŒã¹ã®ãªã«ããªãœãããŠã§ã¢ïŒã¯ãå Žåã«ãã£ãŠã¯ãyaraã«ãŒã«ãé©çšããŸãïŒå€§ããªãã¡ã€ã«ãã¹ãã£ã³ããããšæ³å®ïŒããŸãã¯ããã¡ã€ã«ãæåã§è¡šç€ºããã ãã§ãã
pagefile.sysã«ã¯äœããããŸããïŒãŸãããªãããŒãžã³ã°ãã¡ã€ã«ã«çŠç¹ãåãããŠããã®ã§ããïŒãã¹ãŠãåçŽã§ããããã¯ãRAMããéšåçã«ã¢ã³ããŒããããããŒã¿ãã€ãŸããããã»ã¹ããã¡ã€ã«ãããã³ãã®ä»ã®ã¢ãŒãã£ãã¡ã¯ãã§ãããOSã§ã¢ã¯ãã£ãã«æ©èœããŠãããã®ã§ããããã¯ãã€ã³ã¿ãŒãããã®å±¥æŽãšIPã¢ãã¬ã¹ãäžéšã®ãã¡ã€ã«ãŸãã¯ãã¡ã€ã«èªäœã®èµ·åã«é¢ããæ å ±ãç»åãšããã¹ãã®ãã©ã°ã¡ã³ãã以åã«æ©èœããŠãããœãããŠã§ã¢ã®ãããã¯ãŒã¯ãªã¯ãšã¹ãã«é¢ããæ å ±ãããŒã¹ãããŒã¯ãã°ãã·ã¹ãã ãã¡ã€ã«ãªã©ã®åœ¢åŒã®ãã«ãŠã§ã¢ã®ãã¬ãŒã¹ã®äžéšã§ããå¯èœæ§ããããŸãã OSãã°ãªã©ã

ãã£ãŒã«ãã«è¡ããŸããã
å®éã®äºäŸãšç ç©¶ã«çŽæ¥ç§»ãæãæ¥ãŸãããã§ã¯ãããžã¿ã«ãã©ã¬ã³ãžãã¯ã®èгç¹ããWindowsã¹ã¯ãããã¡ã€ã«ã§äœã圹ç«ã€ã®ã§ããããã
ããã±ãŒã¹ã§ã¯ãããŸããŸãªãã«ãŠã§ã¢ã«ææãããã©ã€ãã®ç»åã調æ»ããããµã€ããŒç¯çœªè ãçµç¹ã®ã¢ã«ãŠã³ããããéãçãã ã
äœãã©ã®ããã«èµ·ãã£ããã«ã€ããŠå®å šãªçããäžããããã«ãæ³å»åŠè ã¯ææã®éå§ç¹ãæ»æè ã䜿çšããããŒã«ãããã³äžé£ã®è¡åã確ç«ããå¿ èŠããããŸãã調æ»äžã«ããã«ãŠã§ã¢ã®çè·¡ããã¹ãŠèŠã€ãã£ãããã§ã¯ãããŸããããããŠãããã¯pagefile.sysãè§£æãããå Žæã§ãããã§ã«ç¥ã£ãŠããããã«ãRAMããããŒãžã³ã°ãã¡ã€ã«ã«ã¢ã³ããŒããããããã»ã¹ã¡ã¢ãªããããŒãžãèŠã€ããããšãã§ããŸãããã®å Žåãããšãã°ããã®å Žåã®ããã«ãçœ²åæ¹æ³ã䜿çšããPhotorecãœãããŠã§ã¢ã䜿çšããŠåŸ©å ã§ããŸãã
: (), . , , , , - , .

äžèšã¯ããã®èª¿æ»äžã«ã¢ããããŒãããããã¡ã€ã«ïŒããŒãžã³ã°ãã¡ã€ã«ã®å é ããã®ãªãã»ããã«åºã¥ããŠPhotorecãå²ãåœãŠããã¡ã€ã«åïŒã®äŸã§ãããããã¯å®è¡å¯èœãã°ã©ãã£ãã¯ãããã¹ãããã®ä»ã®ãã¡ã€ã«ã§ããããšãããããŸããããããã°ããã¹ãŠãç°¡åã«ãªããŸããå¿ èŠãªåºæºãšã¿ã¹ã¯ã«åºã¥ããŠåæããŸãã
ãã®ç¹å®ã®ã±ãŒã¹ã§ã¯ãæªæã®ããã³ãŒããå«ãdllãã¡ã€ã«ãããŒãžã³ã°ãã¡ã€ã«ããå埩ãããŸããã以äžã¯ãVirusTotalã§ã®æ€åºã®äŸã§ãïŒæ€çŽ¢ã¯ãã¡ã€ã«ã®ãã§ãã¯ãµã ã«ãã£ãŠå®è¡ãããŸããïŒã

åæäžã«ããããã®ãã¡ã€ã«ãçžäºäœçšã§ãããªã¢ãŒããµãŒããŒã®ã¢ãã¬ã¹ã確ç«ãããŸããã16é²ãšãã£ã¿X-WaysWinHEXã䜿çšããŠããªã¢ãŒããµãŒããŒã®ã¢ãã¬ã¹ãå«ãè¡ã調ã¹ãããpagefile.sysã§èŠã€ãããŸãããããã¯ãæ€åºããããã¡ã€ã«ãOSã§æ©èœããŠããããªã¢ãŒããµãŒããŒãšã¢ã¯ãã£ãã«å¯Ÿè©±ããŠããããšã瀺ããŠããŸãããããŠã2018幎12æã®VirusTotalãµãŒãã¹ã®æ€åºã¯æ¬¡ã®ãšããã§ãã


ãããã£ãŠããã®å Žåãpagefile.sysã«ããæ å ±ã®ãããã§ãææãã§ãŒã³å šäœã確ç«ãããŸããã
ã»ãã«äœãïŒ
ä»ã®ãã¬ãŒã¹ã«å ããŠãbase64ã§ãšã³ã³ãŒããããã¹ã¯ãªãŒã³ã·ã§ãããã¹ã¯ãããã¡ã€ã«ã«å«ãŸããŠããå ŽåããããŸããããšãã°ããã³ãã³ã°ã®Trojan Buhtrapã¯ãéä¿¡æã«ãã®ãããªãã®ãäœæããŸãã
ãã®ç¹å®ã®ã±ãŒã¹ã§ã¯ããã¡ã€ã«ã®å é ã¯/ 9j / 4AAQSkZJRgABAQEAYABgAAD /ã§ãããããã¯ãjpegãã¡ã€ã«ã®base64ã§ãšã³ã³ãŒããããããããŒã§ãïŒç»åã®äžéšã衚瀺ãããŠããŸãïŒã

äžèšã®ã¹ããããã¯ã³ããŒããããã³ãŒããããjpgæ¡åŒµåã远å ãããŸããã幞éãªããšã«ãæ€åºãããã¹ã¯ãªãŒã³ã·ã§ããã«ã¯ããªãŒãã³ãœãããŠã§ã¢ã1CïŒAccountingããåããã¢ã«ãŠã³ãã£ã³ã°ã³ã³ãã¥ãŒã¿ãŒã®ã¢ã¯ãã£ããªãã¹ã¯ãããã®å®å šãªã¹ãããã·ã§ãããå«ãŸããäŒç€Ÿã®è²¡åæ®é«ããã®ä»ã®éèŠãªããŒã¿ã衚瀺ãããŠããŸãããä»ã®æ€åºããããšã³ã³ãŒããããç»åã¯ãæ å ±ãããŒãžã³ã°ãã¡ã€ã«ã«ä¿åãããæ¹æ³ã®ããã«äžå®å šïŒå£ããïŒã§ããã
ããäžã€ã®äŸãã€ã³ã·ãã³ãã®1ã€ã§ãCobalt Strikeãã¬ãŒã ã¯ãŒã¯ã®çè·¡ãèŠã€ãããŸããïŒã¹ã¯ãããã¡ã€ã«ã®äžè¬çãªè¡-SMBã¢ãŒããstatus_448ãReflectiveLoaderïŒã


ãããŠãã¢ãžã¥ãŒã«ã®ã¢ã³ããŒãã詊ã¿ãããšãã§ããŸããäžã®ç»åã§ã¯ããããã¯keylogger.dllãšscreenshot.dllã§ãããä»ã«ãããå¯èœæ§ããããŸãã
é²ããCobalt Strikeã®äžéšã§ããããµã€ããŒç¯çœªè ã«ãã£ãŠãã䜿çšãããmimikatzã¢ãžã¥ãŒã«ã¯ãWindows Credentials Editorã®æ©èœãå®è£ ãããã°ã€ã³ãããŠãŒã¶ãŒã®èªèšŒããŒã¿ãã¯ãªã¢ããã¹ãã§æœåºã§ããããã«ããããŒã«ã§ãããã®æ©èœã®çè·¡ãããªãã¡æ¬¡ã®æååãèŠã€ãã£ãã®ã¯ã¹ã¯ãããã¡ã€ã«ã§ããã
- sekurlsa :: logonPasswords-ã¢ã«ãŠã³ãã®ãã°ã€ã³ãšãã¹ã¯ãŒããæœåºããŸã
- token :: elevate-SYSTEMãžã®ã¢ã¯ã»ã¹æš©ãææ Œããããããã¡ã€ã³ç®¡çè ããŒã¯ã³ãæ€çŽ¢ããŸã
- lsadump :: sam-SysKeyãååŸããŠSAMã¬ãžã¹ããªãã¡ã€ã«ãããšã³ããªã埩å·åããŸã
- log Result.txt-ãœãããŠã§ã¢ã®çµæãèšé²ãããŠãããã¡ã€ã«ïŒãã¡ã€ã«ã·ã¹ãã ã§ãã®ãã¡ã€ã«ãæ¢ãããšãå¿ããªãã§ãã ããïŒïŒ
次ã®äŸã¯ãå€ãã®ã¢ãžã¥ãŒã«ã§æ§æããããã³ãã³ã°ããã€ã®æšéЬRanbyusã®æ©èœã®ãã¬ãŒã¹ã§ããããç ç©¶ã§ã¯ãã·ã£ããŠã³ããŒïŒVSSïŒã«ãã£ãããŒãžã³ã°ãã¡ã€ã«ããRanbyusãœãããŠã§ã¢ã®æ©èœãæ¡åŒµããã¢ããªã³ã«ãã£ãŠçæãããæååãèŠã€ããŸããããã®è¡ã«ã¯ãç¹ã«ããclient-bankãã·ã¹ãã ã«å ¥åããããŠãŒã¶ãŒèªèšŒããŒã¿ïŒãã°ã€ã³ãšãã¹ã¯ãŒãïŒãå«ãŸããŠããŸãããäŸãšããŠãpagefile.sysãã¡ã€ã«ã«ãã管çãµãŒããŒã«é¢ããæ å ±ãå«ããããã¯ãŒã¯èŠæ±ã®äžéšïŒ

å®éããã«ãŠã§ã¢ã«ããCïŒCãµãŒããŒãžã®POSTãªã¯ãšã¹ãã®äŸãããªã¯ãšã¹ãã«å¯Ÿãããããã®ãµãŒããŒã®å¿çãèŠãã®ã¯éåžžã«äžè¬çã§ãã以äžã¯ãBuhtrapãœãããŠã§ã¢ãšãã®å¶åŸ¡ãµãŒããŒéã®çžäºäœçšã®äŸã«é¢ãããã®ãããªã±ãŒã¹ã§ãã

ããã§ããã®æçš¿ãéå§ããã±ãŒã¹ãæãåºããŠã¿ãŸããããå€ãã®ãµãŒããŒãšã¯ãŒã¯ã¹ããŒã·ã§ã³ãããå€§èŠæš¡ãªçµç¹ã§ã€ã³ã·ãã³ããçºçããŸããããã®éã«ãæ»æè ã¯ãããã¯ãŒã¯ã«äŸµå ¥ãããã¡ã€ã³ã³ã³ãããŒã©ãŒç®¡çè ã®1人ã®è³æ Œæ å ±ãä¹ã£åã£ãŠãããæ£èŠã®ãœãããŠã§ã¢ã䜿çšããŠãããã¯ãŒã¯ãç§»åããŸããã圌ãã¯éèŠãªæ å ±ãã³ããŒãããã®ããŒã¿ãé éå°ã«éä¿¡ããŸãããå¿çã®æç¹ã§ãå幎以äžãçµéããäžéšã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ãšãµãŒããŒã¯ãã§ã«åäœã忢ããŠãããæ»æè ã®è¡åã®çè·¡ã¯ãç¹æ®ãªãœãããŠã§ã¢ã®äœ¿çšãšèª€ã£ããã®ã³ã°ã®ããã«ããããã§ãç Žå£ãããŸããã
å¿çããã»ã¹äžã«ãã€ã³ã·ãã³ãã«é¢äžããWindows Server2012ãå®è¡ããŠãããµãŒããŒã«ç§»åããŸãããã·ã¹ãã ãã°ãã¡ã€ã«ãè€æ°åäžæžãããã空ããã£ã¹ã¯é åãäžæžããããŸãããããããã¹ã¯ãããã¡ã€ã«ããããŸããïŒåèµ·åããã«ãµãŒããŒãé·æéæäœããããŒãžã³ã°ãã¡ã€ã«ã®ãµã€ãºã倧ããããããµã€ããŒç¯çœªè ã®ãœãããŠã§ã¢ãšã¹ã¯ãªããã®èµ·åã®çè·¡ãä¿æãããŸãããããã¯ã調æ»ã®æç¹ã§ã¯ãå埩ã®å¯èœæ§ãªãã«ãã¡ã€ã«ã·ã¹ãã ã«ååšããŠããŸããã§ãããäŸµå ¥è ã«ãã£ãŠäœæãã³ããŒããããã®åŸåé€ããããã£ã¬ã¯ããªãšãã¡ã€ã«ïŒãã¹ãšååïŒãããŒã¿ã®ã³ããŒå ã®çµç¹ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã®IPã¢ãã¬ã¹ãããã³ãã®ä»ã®éèŠãªæ å ±ã«é¢ããæ å ±ãä¿æãããŠããŸãã
è峿·±ãããšã«ãããŸããŸãªãã©ã¬ã³ãžãã¯ãœãããŠã§ã¢ã䜿çšããèªååæã§ã¯å®å šãªçµæãåŸããããç¹å®ã®æ€çŽ¢åºæºããªãã£ããããå°éå®¶ã¯X-WaysWinHEX16é²ãšãã£ã¿ãŒã䜿çšããããŒãžã³ã°ãã¡ã€ã«ã®æååæã«é ŒããŸããã
以äžã¯ãå°éå®¶ãèŠã€ãããã®ã®ããã€ãã®äŸã§ãã



pcsp.exeããã³ADExplorer.exeãŠãŒãã£ãªãã£ã®äœ¿çšã«é¢ããæ å ±ïŒæ¥ä»ãšãã¹ã®äž¡æ¹ãååšããŸãïŒã
ããã«-vbsã¹ã¯ãªããã®äœ¿çšã«é¢ããæ å ±ïŒç»åå -æåãšæåŸïŒã
以åã«äŸµå®³ããããã¡ã€ã³ã³ã³ãããŒã©ãŒç®¡çè ã®1人ã®è³æ Œæ å ±ïŒãã°ã€ã³ãšãã¹ã¯ãŒãïŒã瀺ãããŠããããšã¯æ³šç®ã«å€ããŸãã


ãã®çµæãã€ã³ã·ãã³ãã«é¢ããéèŠãªæ å ±ã®ã»ãšãã©ãã¹ãŠããããããã®ãµãŒããŒã®ããŒãžã³ã°ãã¡ã€ã«ã§èŠã€ãããŸãããæ»æè ã®ããŒã«ãšäŒæ¥ãããã¯ãŒã¯ã§ã®æ»æè ã®ã¢ã¯ã·ã§ã³ã®äžéšãã€ã³ã¹ããŒã«ãããŠããŸãã
ãããŠçµè«ãšããŠããã¡ãããã€ã³ã¿ãŒããããµã€ããžã®ã¢ã¯ã»ã¹ã«é¢ããããŒã¿ïŒé»åã¡ãŒã«ããã¯ã¹ã®äœ¿çšã«é¢ããæ å ±ãèŠã€ããããšãã§ããå ŽåããããŸãïŒããã¡ã€ã«ããã£ã¬ã¯ããªã«é¢ããæ å ±ãªã©ãä»ã®ã¢ãŒãã£ãã¡ã¯ãã«ã€ããŠèšåãã䟡å€ããããŸãã


ãŸããããŒãžã³ã°ãã¡ã€ã«ãé 眮ãããããªã¥ãŒã ã®ã³ã³ãã¥ãŒã¿ãŒåãã·ãªã¢ã«çªå·ãªã©ã®æ å ±ãèŠã€ããããšãã§ããŸãã

ããªãã§ãããã¡ã€ã«ããã®æ å ±ããããŠãã¡ãããWindowsã·ã¹ãã ãã°ã
ãããã£ãŠãpagefile.sysã«ã¯ãåæã«åœ¹ç«ã€ããŸããŸãªã¢ãŒãã£ãã¡ã¯ããå®éã«å€æ°å«ãŸããŠããå¯èœæ§ããããŸããããããããŒãžã³ã°ãã¡ã€ã«ã®æ¢çŽ¢ãæ±ºããŠç¡èŠããŠã¯ãªããªãçç±ã§ããå¿ èŠãªããŒã¿ããã¹ãŠæã£ãŠããå Žåã§ãããšã«ããpagefile.sysã調ã¹ãŠãã ãããç·Žç¿ã¯ãäœããæ¬ ããŠããŠéèŠã§ãããããããªãããšã瀺ããŠããŸãã