mirror of
https://github.com/mirror/processhacker
synced 2026-06-08 16:03:24 +00:00
add various functionality
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@175 21ef857c-d57f-4fe0-8362-d861dc6d29cd
This commit is contained in:
@@ -303,28 +303,6 @@ wchar_t *GetWinStaDesktop()
|
||||
return result;
|
||||
}
|
||||
|
||||
void __declspec(naked) Caller()
|
||||
{
|
||||
__asm
|
||||
{
|
||||
pushad // save all the registers, we try not to screw up their thread
|
||||
mov eax, 0xaaaaaaaa // function
|
||||
|
||||
push 0xbbbbbbbb // push location of data_struct *data
|
||||
call eax // call our function
|
||||
|
||||
popad // get registers back
|
||||
|
||||
__emit 0xe9
|
||||
__emit 0xcc
|
||||
__emit 0xcc
|
||||
__emit 0xcc
|
||||
__emit 0xcc
|
||||
}
|
||||
}
|
||||
|
||||
void __declspec(naked) EndOfCaller() { }
|
||||
|
||||
static void Ep(data_struct *data)
|
||||
{
|
||||
data->fEP(0);
|
||||
|
||||
+49
-31
@@ -170,12 +170,14 @@
|
||||
this.copyServiceMenuItem = new System.Windows.Forms.MenuItem();
|
||||
this.selectAllServiceMenuItem = new System.Windows.Forms.MenuItem();
|
||||
this.getSNFAMenuItem = new System.Windows.Forms.MenuItem();
|
||||
this.exitProcessProcessMenuItem = new System.Windows.Forms.MenuItem();
|
||||
this.listProcesses = new ProcessHacker.ProcessList();
|
||||
this.buttonSearch = new wyDay.Controls.SplitButton();
|
||||
this.listThreads = new ProcessHacker.ThreadList();
|
||||
this.listServices = new ProcessHacker.ServiceList();
|
||||
this.vistaMenu = new wyDay.Controls.VistaMenu(this.components);
|
||||
this.exitProcessProcessMenuItem = new System.Windows.Forms.MenuItem();
|
||||
this.menuItem10 = new System.Windows.Forms.MenuItem();
|
||||
this.FSPWSSIDMenuItem = new System.Windows.Forms.MenuItem();
|
||||
this.panelProc.SuspendLayout();
|
||||
this.panelVirtualProtect.SuspendLayout();
|
||||
((System.ComponentModel.ISupportInitialize)(this.statusGeneral)).BeginInit();
|
||||
@@ -886,6 +888,7 @@
|
||||
//
|
||||
this.mainMenu.MenuItems.AddRange(new System.Windows.Forms.MenuItem[] {
|
||||
this.hackerMenuItem,
|
||||
this.menuItem10,
|
||||
this.windowMenuItem});
|
||||
//
|
||||
// hackerMenuItem
|
||||
@@ -894,7 +897,6 @@
|
||||
this.hackerMenuItem.MenuItems.AddRange(new System.Windows.Forms.MenuItem[] {
|
||||
this.selectAllHackerMenuItem,
|
||||
this.menuItem1,
|
||||
this.getSNFAMenuItem,
|
||||
this.inspectPEFileMenuItem,
|
||||
this.logMenuItem,
|
||||
this.aboutMenuItem,
|
||||
@@ -918,53 +920,53 @@
|
||||
// inspectPEFileMenuItem
|
||||
//
|
||||
this.vistaMenu.SetImage(this.inspectPEFileMenuItem, global::ProcessHacker.Properties.Resources.application_form_magnify);
|
||||
this.inspectPEFileMenuItem.Index = 3;
|
||||
this.inspectPEFileMenuItem.Index = 2;
|
||||
this.inspectPEFileMenuItem.Text = "Inspect &PE File...";
|
||||
this.inspectPEFileMenuItem.Click += new System.EventHandler(this.inspectPEFileMenuItem_Click);
|
||||
//
|
||||
// logMenuItem
|
||||
//
|
||||
this.vistaMenu.SetImage(this.logMenuItem, global::ProcessHacker.Properties.Resources.page_white_text);
|
||||
this.logMenuItem.Index = 4;
|
||||
this.logMenuItem.Index = 3;
|
||||
this.logMenuItem.Text = "&Log...";
|
||||
this.logMenuItem.Click += new System.EventHandler(this.logMenuItem_Click);
|
||||
//
|
||||
// aboutMenuItem
|
||||
//
|
||||
this.vistaMenu.SetImage(this.aboutMenuItem, global::ProcessHacker.Properties.Resources.information);
|
||||
this.aboutMenuItem.Index = 5;
|
||||
this.aboutMenuItem.Index = 4;
|
||||
this.aboutMenuItem.Text = "&About...";
|
||||
this.aboutMenuItem.Click += new System.EventHandler(this.aboutMenuItem_Click);
|
||||
//
|
||||
// optionsMenuItem
|
||||
//
|
||||
this.vistaMenu.SetImage(this.optionsMenuItem, global::ProcessHacker.Properties.Resources.page_gear);
|
||||
this.optionsMenuItem.Index = 6;
|
||||
this.optionsMenuItem.Index = 5;
|
||||
this.optionsMenuItem.Text = "&Options...";
|
||||
this.optionsMenuItem.Click += new System.EventHandler(this.optionsMenuItem_Click);
|
||||
//
|
||||
// helpMenuItem
|
||||
//
|
||||
this.vistaMenu.SetImage(this.helpMenuItem, global::ProcessHacker.Properties.Resources.help);
|
||||
this.helpMenuItem.Index = 7;
|
||||
this.helpMenuItem.Index = 6;
|
||||
this.helpMenuItem.Text = "&Help...";
|
||||
this.helpMenuItem.Click += new System.EventHandler(this.helpMenuItem_Click);
|
||||
//
|
||||
// exitMenuItem
|
||||
//
|
||||
this.vistaMenu.SetImage(this.exitMenuItem, global::ProcessHacker.Properties.Resources.door_out);
|
||||
this.exitMenuItem.Index = 8;
|
||||
this.exitMenuItem.Index = 7;
|
||||
this.exitMenuItem.Text = "E&xit";
|
||||
this.exitMenuItem.Click += new System.EventHandler(this.exitMenuItem_Click);
|
||||
//
|
||||
// windowMenuItem
|
||||
//
|
||||
this.windowMenuItem.Index = 1;
|
||||
this.windowMenuItem.Index = 2;
|
||||
this.windowMenuItem.Text = "&Window";
|
||||
//
|
||||
// statusBar
|
||||
//
|
||||
this.statusBar.Location = new System.Drawing.Point(0, 446);
|
||||
this.statusBar.Location = new System.Drawing.Point(0, 441);
|
||||
this.statusBar.Name = "statusBar";
|
||||
this.statusBar.Panels.AddRange(new System.Windows.Forms.StatusBarPanel[] {
|
||||
this.statusGeneral,
|
||||
@@ -1008,7 +1010,7 @@
|
||||
this.tabControlBig.Location = new System.Drawing.Point(0, 0);
|
||||
this.tabControlBig.Name = "tabControlBig";
|
||||
this.tabControlBig.SelectedIndex = 0;
|
||||
this.tabControlBig.Size = new System.Drawing.Size(804, 446);
|
||||
this.tabControlBig.Size = new System.Drawing.Size(804, 441);
|
||||
this.tabControlBig.TabIndex = 6;
|
||||
//
|
||||
// tabProcesses
|
||||
@@ -1017,7 +1019,7 @@
|
||||
this.tabProcesses.Location = new System.Drawing.Point(4, 22);
|
||||
this.tabProcesses.Name = "tabProcesses";
|
||||
this.tabProcesses.Padding = new System.Windows.Forms.Padding(3);
|
||||
this.tabProcesses.Size = new System.Drawing.Size(796, 420);
|
||||
this.tabProcesses.Size = new System.Drawing.Size(796, 415);
|
||||
this.tabProcesses.TabIndex = 0;
|
||||
this.tabProcesses.Text = "Processes";
|
||||
this.tabProcesses.UseVisualStyleBackColor = true;
|
||||
@@ -1036,7 +1038,7 @@
|
||||
// splitMain.Panel2
|
||||
//
|
||||
this.splitMain.Panel2.Controls.Add(this.tabControl);
|
||||
this.splitMain.Size = new System.Drawing.Size(790, 414);
|
||||
this.splitMain.Size = new System.Drawing.Size(790, 409);
|
||||
this.splitMain.SplitterDistance = 348;
|
||||
this.splitMain.TabIndex = 3;
|
||||
//
|
||||
@@ -1050,7 +1052,7 @@
|
||||
this.tabControl.Location = new System.Drawing.Point(0, 0);
|
||||
this.tabControl.Name = "tabControl";
|
||||
this.tabControl.SelectedIndex = 0;
|
||||
this.tabControl.Size = new System.Drawing.Size(438, 414);
|
||||
this.tabControl.Size = new System.Drawing.Size(438, 409);
|
||||
this.tabControl.TabIndex = 5;
|
||||
//
|
||||
// tabProcess
|
||||
@@ -1060,7 +1062,7 @@
|
||||
this.tabProcess.Location = new System.Drawing.Point(4, 22);
|
||||
this.tabProcess.Name = "tabProcess";
|
||||
this.tabProcess.Padding = new System.Windows.Forms.Padding(3);
|
||||
this.tabProcess.Size = new System.Drawing.Size(430, 388);
|
||||
this.tabProcess.Size = new System.Drawing.Size(430, 383);
|
||||
this.tabProcess.TabIndex = 4;
|
||||
this.tabProcess.Text = "Process";
|
||||
this.tabProcess.UseVisualStyleBackColor = true;
|
||||
@@ -1087,7 +1089,7 @@
|
||||
this.treeMisc.Location = new System.Drawing.Point(6, 59);
|
||||
this.treeMisc.Name = "treeMisc";
|
||||
this.treeMisc.ShowNodeToolTips = true;
|
||||
this.treeMisc.Size = new System.Drawing.Size(418, 323);
|
||||
this.treeMisc.Size = new System.Drawing.Size(418, 318);
|
||||
this.treeMisc.TabIndex = 1;
|
||||
//
|
||||
// tabThreads
|
||||
@@ -1096,7 +1098,7 @@
|
||||
this.tabThreads.Location = new System.Drawing.Point(4, 22);
|
||||
this.tabThreads.Name = "tabThreads";
|
||||
this.tabThreads.Padding = new System.Windows.Forms.Padding(3);
|
||||
this.tabThreads.Size = new System.Drawing.Size(430, 131);
|
||||
this.tabThreads.Size = new System.Drawing.Size(430, 199);
|
||||
this.tabThreads.TabIndex = 6;
|
||||
this.tabThreads.Text = "Threads";
|
||||
this.tabThreads.UseVisualStyleBackColor = true;
|
||||
@@ -1107,7 +1109,7 @@
|
||||
this.tabModules.Location = new System.Drawing.Point(4, 22);
|
||||
this.tabModules.Name = "tabModules";
|
||||
this.tabModules.Padding = new System.Windows.Forms.Padding(3);
|
||||
this.tabModules.Size = new System.Drawing.Size(430, 131);
|
||||
this.tabModules.Size = new System.Drawing.Size(430, 199);
|
||||
this.tabModules.TabIndex = 0;
|
||||
this.tabModules.Text = "Modules";
|
||||
this.tabModules.UseVisualStyleBackColor = true;
|
||||
@@ -1126,7 +1128,7 @@
|
||||
this.listModules.Location = new System.Drawing.Point(3, 3);
|
||||
this.listModules.Name = "listModules";
|
||||
this.listModules.ShowItemToolTips = true;
|
||||
this.listModules.Size = new System.Drawing.Size(424, 125);
|
||||
this.listModules.Size = new System.Drawing.Size(424, 193);
|
||||
this.listModules.TabIndex = 1;
|
||||
this.listModules.UseCompatibleStateImageBehavior = false;
|
||||
this.listModules.View = System.Windows.Forms.View.Details;
|
||||
@@ -1158,7 +1160,7 @@
|
||||
this.tabMemory.Location = new System.Drawing.Point(4, 22);
|
||||
this.tabMemory.Name = "tabMemory";
|
||||
this.tabMemory.Padding = new System.Windows.Forms.Padding(3);
|
||||
this.tabMemory.Size = new System.Drawing.Size(430, 131);
|
||||
this.tabMemory.Size = new System.Drawing.Size(430, 199);
|
||||
this.tabMemory.TabIndex = 1;
|
||||
this.tabMemory.Text = "Memory";
|
||||
this.tabMemory.UseVisualStyleBackColor = true;
|
||||
@@ -1178,7 +1180,7 @@
|
||||
this.listMemory.Location = new System.Drawing.Point(3, 3);
|
||||
this.listMemory.Name = "listMemory";
|
||||
this.listMemory.ShowItemToolTips = true;
|
||||
this.listMemory.Size = new System.Drawing.Size(424, 125);
|
||||
this.listMemory.Size = new System.Drawing.Size(424, 193);
|
||||
this.listMemory.TabIndex = 2;
|
||||
this.listMemory.UseCompatibleStateImageBehavior = false;
|
||||
this.listMemory.View = System.Windows.Forms.View.Details;
|
||||
@@ -1215,7 +1217,7 @@
|
||||
this.tabServices.Location = new System.Drawing.Point(4, 22);
|
||||
this.tabServices.Name = "tabServices";
|
||||
this.tabServices.Padding = new System.Windows.Forms.Padding(3);
|
||||
this.tabServices.Size = new System.Drawing.Size(796, 163);
|
||||
this.tabServices.Size = new System.Drawing.Size(796, 231);
|
||||
this.tabServices.TabIndex = 1;
|
||||
this.tabServices.Text = "Services";
|
||||
this.tabServices.UseVisualStyleBackColor = true;
|
||||
@@ -1303,10 +1305,16 @@
|
||||
//
|
||||
// getSNFAMenuItem
|
||||
//
|
||||
this.getSNFAMenuItem.Index = 2;
|
||||
this.getSNFAMenuItem.Index = 0;
|
||||
this.getSNFAMenuItem.Text = "Get Symbol Name From Address...";
|
||||
this.getSNFAMenuItem.Click += new System.EventHandler(this.getSNFAMenuItem_Click);
|
||||
//
|
||||
// exitProcessProcessMenuItem
|
||||
//
|
||||
this.exitProcessProcessMenuItem.Index = 2;
|
||||
this.exitProcessProcessMenuItem.Text = "Exit Process";
|
||||
this.exitProcessProcessMenuItem.Click += new System.EventHandler(this.exitProcessProcessMenuItem_Click);
|
||||
//
|
||||
// listProcesses
|
||||
//
|
||||
this.listProcesses.Dock = System.Windows.Forms.DockStyle.Fill;
|
||||
@@ -1314,7 +1322,7 @@
|
||||
this.listProcesses.Location = new System.Drawing.Point(0, 0);
|
||||
this.listProcesses.Name = "listProcesses";
|
||||
this.listProcesses.Provider = null;
|
||||
this.listProcesses.Size = new System.Drawing.Size(348, 413);
|
||||
this.listProcesses.Size = new System.Drawing.Size(348, 408);
|
||||
this.listProcesses.TabIndex = 4;
|
||||
this.listProcesses.SelectedIndexChanged += new System.EventHandler(this.listProcesses_SelectedIndexChanged);
|
||||
this.listProcesses.KeyDown += new System.Windows.Forms.KeyEventHandler(this.listProcesses_KeyDown);
|
||||
@@ -1338,7 +1346,7 @@
|
||||
this.listThreads.Location = new System.Drawing.Point(3, 3);
|
||||
this.listThreads.Name = "listThreads";
|
||||
this.listThreads.Provider = null;
|
||||
this.listThreads.Size = new System.Drawing.Size(424, 125);
|
||||
this.listThreads.Size = new System.Drawing.Size(424, 193);
|
||||
this.listThreads.TabIndex = 0;
|
||||
this.listThreads.DoubleClick += new System.EventHandler(this.listThreads_DoubleClick);
|
||||
//
|
||||
@@ -1349,7 +1357,7 @@
|
||||
this.listServices.Location = new System.Drawing.Point(3, 3);
|
||||
this.listServices.Name = "listServices";
|
||||
this.listServices.Provider = null;
|
||||
this.listServices.Size = new System.Drawing.Size(790, 157);
|
||||
this.listServices.Size = new System.Drawing.Size(790, 225);
|
||||
this.listServices.TabIndex = 0;
|
||||
this.listServices.DoubleClick += new System.EventHandler(this.listServices_DoubleClick);
|
||||
//
|
||||
@@ -1357,17 +1365,25 @@
|
||||
//
|
||||
this.vistaMenu.ContainerControl = this;
|
||||
//
|
||||
// exitProcessProcessMenuItem
|
||||
// menuItem10
|
||||
//
|
||||
this.exitProcessProcessMenuItem.Index = 2;
|
||||
this.exitProcessProcessMenuItem.Text = "Exit Process";
|
||||
this.exitProcessProcessMenuItem.Click += new System.EventHandler(this.exitProcessProcessMenuItem_Click);
|
||||
this.menuItem10.Index = 1;
|
||||
this.menuItem10.MenuItems.AddRange(new System.Windows.Forms.MenuItem[] {
|
||||
this.getSNFAMenuItem,
|
||||
this.FSPWSSIDMenuItem});
|
||||
this.menuItem10.Text = "Tools";
|
||||
//
|
||||
// FSPWSSIDMenuItem
|
||||
//
|
||||
this.FSPWSSIDMenuItem.Index = 1;
|
||||
this.FSPWSSIDMenuItem.Text = "Find SYSTEM process with same Session ID";
|
||||
this.FSPWSSIDMenuItem.Click += new System.EventHandler(this.FSPWSSIDMenuItem_Click);
|
||||
//
|
||||
// HackerWindow
|
||||
//
|
||||
this.AutoScaleDimensions = new System.Drawing.SizeF(6F, 13F);
|
||||
this.AutoScaleMode = System.Windows.Forms.AutoScaleMode.Font;
|
||||
this.ClientSize = new System.Drawing.Size(804, 468);
|
||||
this.ClientSize = new System.Drawing.Size(804, 463);
|
||||
this.Controls.Add(this.tabControlBig);
|
||||
this.Controls.Add(this.statusBar);
|
||||
this.Controls.Add(this.panelVirtualProtect);
|
||||
@@ -1553,6 +1569,8 @@
|
||||
private System.Windows.Forms.MenuItem getCommandLineProcessMenuItem;
|
||||
private System.Windows.Forms.MenuItem getSNFAMenuItem;
|
||||
private System.Windows.Forms.MenuItem exitProcessProcessMenuItem;
|
||||
private System.Windows.Forms.MenuItem menuItem10;
|
||||
private System.Windows.Forms.MenuItem FSPWSSIDMenuItem;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -336,6 +336,32 @@ namespace ProcessHacker
|
||||
}
|
||||
}
|
||||
|
||||
private void FSPWSSIDMenuItem_Click(object sender, EventArgs e)
|
||||
{
|
||||
Process[] processes = Process.GetProcesses();
|
||||
int myId = Win32.GetProcessSessionId(Process.GetCurrentProcess().Handle.ToInt32());
|
||||
|
||||
DeselectAll(listProcesses.List);
|
||||
|
||||
foreach (Process p in processes)
|
||||
{
|
||||
try
|
||||
{
|
||||
if (Win32.GetProcessUsername(p.Handle.ToInt32(), true) == "NT AUTHORITY\\SYSTEM" &&
|
||||
Win32.GetProcessSessionId(p.Handle.ToInt32()) == myId)
|
||||
{
|
||||
listProcesses.List.Items[p.Id.ToString()].Selected = true;
|
||||
listProcesses.List.Items[p.Id.ToString()].EnsureVisible();
|
||||
}
|
||||
}
|
||||
catch
|
||||
{ }
|
||||
}
|
||||
|
||||
tabControlBig.SelectedTab = tabProcesses;
|
||||
listProcesses.List.Select();
|
||||
}
|
||||
|
||||
private void inspectPEFileMenuItem_Click(object sender, EventArgs e)
|
||||
{
|
||||
OpenFileDialog ofd = new OpenFileDialog();
|
||||
@@ -773,6 +799,16 @@ namespace ProcessHacker
|
||||
servicesProcessMenuItem.Enabled = false;
|
||||
}
|
||||
|
||||
int phandle = Win32.OpenProcess(Win32.PROCESS_RIGHTS.PROCESS_QUERY_INFORMATION, 0, processSelectedPID);
|
||||
|
||||
if (Win32.GetProcessSessionId(phandle) ==
|
||||
Win32.GetProcessSessionId(Process.GetCurrentProcess().Handle.ToInt32()))
|
||||
injectorMenuItem.Enabled = true;
|
||||
else
|
||||
injectorMenuItem.Enabled = false;
|
||||
|
||||
Win32.CloseHandle(phandle);
|
||||
|
||||
priorityMenuItem.Enabled = true;
|
||||
inspectProcessMenuItem.Enabled = true;
|
||||
searchProcessMenuItem.Enabled = true;
|
||||
@@ -834,6 +870,7 @@ namespace ProcessHacker
|
||||
privilegesMenuItem.Enabled = false;
|
||||
groupsMenuItem.Enabled = false;
|
||||
servicesProcessMenuItem.Enabled = false;
|
||||
injectorMenuItem.Enabled = false;
|
||||
terminateMenuItem.Text = "&Terminate Processes";
|
||||
closeActiveWindowMenuItem.Text = "&Close Active Windows";
|
||||
suspendMenuItem.Text = "&Suspend Processes";
|
||||
|
||||
Reference in New Issue
Block a user