diff --git a/trunk/ProcessHacker/Components/ProcessList.cs b/trunk/ProcessHacker/Components/ProcessList.cs
index 440a42a2c..14caef82b 100644
--- a/trunk/ProcessHacker/Components/ProcessList.cs
+++ b/trunk/ProcessHacker/Components/ProcessList.cs
@@ -49,54 +49,6 @@ namespace ProcessHacker
this.KeyDown(sender, e);
}
- private string GetKernelFileName()
- {
- int RequiredSize = 0;
- int[] ImageBases;
-
- Win32.EnumDeviceDrivers(null, 0, ref RequiredSize);
- ImageBases = new int[RequiredSize];
- Win32.EnumDeviceDrivers(ImageBases, RequiredSize * sizeof(int), ref RequiredSize);
-
- for (int i = 0; i < RequiredSize; i++)
- {
- if (ImageBases[i] == 0)
- continue;
-
- StringBuilder name = new StringBuilder(256);
- StringBuilder filename = new StringBuilder(256);
- string realname = "";
-
- Win32.GetDeviceDriverBaseName(ImageBases[i], name, 255);
- Win32.GetDeviceDriverFileName(ImageBases[i], filename, 255);
-
- try
- {
- System.IO.FileInfo fi = new System.IO.FileInfo(Misc.GetRealPath(filename.ToString()));
- bool kernel = false;
-
- realname = fi.FullName;
-
- foreach (string k in Misc.KernelNames)
- {
- if (realname.ToLower() == Environment.SystemDirectory.ToLower() + "\\" + k.ToLower())
- {
- kernel = true;
-
- break;
- }
- }
-
- if (kernel)
- return realname;
- }
- catch
- { }
- }
-
- return "";
- }
-
#region Properties
public bool DoubleBuffered
@@ -196,7 +148,7 @@ namespace ProcessHacker
if (pitem.PID == 4)
{
- filename = GetKernelFileName();
+ filename = Misc.GetKernelFileName();
}
else
{
diff --git a/trunk/ProcessHacker/Forms/HackerWindow.Designer.cs b/trunk/ProcessHacker/Forms/HackerWindow.Designer.cs
index 513d8e626..74c168574 100644
--- a/trunk/ProcessHacker/Forms/HackerWindow.Designer.cs
+++ b/trunk/ProcessHacker/Forms/HackerWindow.Designer.cs
@@ -758,7 +758,7 @@
// splitMain.Panel2
//
this.splitMain.Panel2.Controls.Add(this.tabControl);
- this.splitMain.Size = new System.Drawing.Size(804, 423);
+ this.splitMain.Size = new System.Drawing.Size(804, 489);
this.splitMain.SplitterDistance = 355;
this.splitMain.TabIndex = 3;
//
@@ -772,7 +772,7 @@
this.tabControl.Location = new System.Drawing.Point(0, 0);
this.tabControl.Name = "tabControl";
this.tabControl.SelectedIndex = 0;
- this.tabControl.Size = new System.Drawing.Size(445, 423);
+ this.tabControl.Size = new System.Drawing.Size(445, 489);
this.tabControl.TabIndex = 5;
//
// tabProcess
@@ -782,7 +782,7 @@
this.tabProcess.Location = new System.Drawing.Point(4, 22);
this.tabProcess.Name = "tabProcess";
this.tabProcess.Padding = new System.Windows.Forms.Padding(3);
- this.tabProcess.Size = new System.Drawing.Size(437, 397);
+ this.tabProcess.Size = new System.Drawing.Size(437, 463);
this.tabProcess.TabIndex = 4;
this.tabProcess.Text = "Process";
this.tabProcess.UseVisualStyleBackColor = true;
@@ -844,7 +844,7 @@
this.treeMisc.Location = new System.Drawing.Point(6, 59);
this.treeMisc.Name = "treeMisc";
this.treeMisc.ShowNodeToolTips = true;
- this.treeMisc.Size = new System.Drawing.Size(425, 332);
+ this.treeMisc.Size = new System.Drawing.Size(425, 398);
this.treeMisc.TabIndex = 1;
//
// tabThreads
@@ -853,7 +853,7 @@
this.tabThreads.Location = new System.Drawing.Point(4, 22);
this.tabThreads.Name = "tabThreads";
this.tabThreads.Padding = new System.Windows.Forms.Padding(3);
- this.tabThreads.Size = new System.Drawing.Size(437, 391);
+ this.tabThreads.Size = new System.Drawing.Size(437, 229);
this.tabThreads.TabIndex = 6;
this.tabThreads.Text = "Threads";
this.tabThreads.UseVisualStyleBackColor = true;
@@ -864,7 +864,7 @@
this.tabModules.Location = new System.Drawing.Point(4, 22);
this.tabModules.Name = "tabModules";
this.tabModules.Padding = new System.Windows.Forms.Padding(3);
- this.tabModules.Size = new System.Drawing.Size(437, 391);
+ this.tabModules.Size = new System.Drawing.Size(437, 229);
this.tabModules.TabIndex = 0;
this.tabModules.Text = "Modules";
this.tabModules.UseVisualStyleBackColor = true;
@@ -883,7 +883,7 @@
this.listModules.Location = new System.Drawing.Point(3, 3);
this.listModules.Name = "listModules";
this.listModules.ShowItemToolTips = true;
- this.listModules.Size = new System.Drawing.Size(431, 385);
+ this.listModules.Size = new System.Drawing.Size(431, 223);
this.listModules.TabIndex = 1;
this.listModules.UseCompatibleStateImageBehavior = false;
this.listModules.View = System.Windows.Forms.View.Details;
@@ -915,7 +915,7 @@
this.tabMemory.Location = new System.Drawing.Point(4, 22);
this.tabMemory.Name = "tabMemory";
this.tabMemory.Padding = new System.Windows.Forms.Padding(3);
- this.tabMemory.Size = new System.Drawing.Size(437, 391);
+ this.tabMemory.Size = new System.Drawing.Size(437, 229);
this.tabMemory.TabIndex = 1;
this.tabMemory.Text = "Memory";
this.tabMemory.UseVisualStyleBackColor = true;
@@ -935,7 +935,7 @@
this.listMemory.Location = new System.Drawing.Point(3, 3);
this.listMemory.Name = "listMemory";
this.listMemory.ShowItemToolTips = true;
- this.listMemory.Size = new System.Drawing.Size(431, 385);
+ this.listMemory.Size = new System.Drawing.Size(431, 223);
this.listMemory.TabIndex = 2;
this.listMemory.UseCompatibleStateImageBehavior = false;
this.listMemory.View = System.Windows.Forms.View.Details;
@@ -1058,7 +1058,7 @@
this.listProcesses.Location = new System.Drawing.Point(0, 0);
this.listProcesses.Name = "listProcesses";
this.listProcesses.Provider = null;
- this.listProcesses.Size = new System.Drawing.Size(355, 422);
+ this.listProcesses.Size = new System.Drawing.Size(355, 488);
this.listProcesses.TabIndex = 4;
this.listProcesses.SelectedIndexChanged += new System.EventHandler(this.listProcesses_SelectedIndexChanged);
this.listProcesses.KeyDown += new System.Windows.Forms.KeyEventHandler(this.listProcesses_KeyDown);
@@ -1082,7 +1082,7 @@
this.listThreads.Location = new System.Drawing.Point(3, 3);
this.listThreads.Name = "listThreads";
this.listThreads.Provider = null;
- this.listThreads.Size = new System.Drawing.Size(431, 385);
+ this.listThreads.Size = new System.Drawing.Size(431, 223);
this.listThreads.TabIndex = 0;
this.listThreads.DoubleClick += new System.EventHandler(this.listThreads_DoubleClick);
//
@@ -1094,7 +1094,7 @@
//
this.AutoScaleDimensions = new System.Drawing.SizeF(6F, 13F);
this.AutoScaleMode = System.Windows.Forms.AutoScaleMode.Font;
- this.ClientSize = new System.Drawing.Size(804, 423);
+ this.ClientSize = new System.Drawing.Size(804, 489);
this.Controls.Add(this.splitMain);
this.Controls.Add(this.panelVirtualProtect);
this.Controls.Add(this.panelProc);
diff --git a/trunk/ProcessHacker/Forms/HackerWindow.cs b/trunk/ProcessHacker/Forms/HackerWindow.cs
index 179565e51..e23da249d 100644
--- a/trunk/ProcessHacker/Forms/HackerWindow.cs
+++ b/trunk/ProcessHacker/Forms/HackerWindow.cs
@@ -555,6 +555,29 @@ namespace ProcessHacker
Win32.ShellExecuteEx(ref info);
}
+ private void inspectModuleMenuItem_Click(object sender, EventArgs e)
+ {
+ try
+ {
+ PEWindow pw = Program.GetPEWindow(listModules.SelectedItems[0].ToolTipText,
+ new Program.PEWindowInvokeAction(delegate(PEWindow f)
+ {
+ try
+ {
+ f.Show();
+ f.Activate();
+ }
+ catch
+ { }
+ }));
+ }
+ catch (Exception ex)
+ {
+ MessageBox.Show("Error inspecting:\n\n" + ex.Message, "Process Hacker", MessageBoxButtons.OK,
+ MessageBoxIcon.Error);
+ }
+ }
+
private void goToInMemoryViewModuleMenuItem_Click(object sender, EventArgs e)
{
string address = listModules.SelectedItems[0].SubItems[1].Text;
@@ -886,6 +909,40 @@ namespace ProcessHacker
}
}
+ private void inspectProcessMenuItem_Click(object sender, EventArgs e)
+ {
+ try
+ {
+ string path;
+
+ if (processSelectedPID == 4)
+ {
+ path = Misc.GetKernelFileName();
+ }
+ else
+ {
+ path = Misc.GetRealPath(processSelected.MainModule.FileName);
+ }
+
+ PEWindow pw = Program.GetPEWindow(path,
+ new Program.PEWindowInvokeAction(delegate(PEWindow f)
+ {
+ try
+ {
+ f.Show();
+ f.Activate();
+ }
+ catch
+ { }
+ }));
+ }
+ catch (Exception ex)
+ {
+ MessageBox.Show("Error inspecting:\n\n" + ex.Message, "Process Hacker", MessageBoxButtons.OK,
+ MessageBoxIcon.Error);
+ }
+ }
+
private void privilegesMenuItem_Click(object sender, EventArgs e)
{
ProcessPrivileges privForm = new ProcessPrivileges(processSelectedPID);
@@ -2156,49 +2213,5 @@ namespace ProcessHacker
LoadSettings();
}
-
- private void inspectProcessMenuItem_Click(object sender, EventArgs e)
- {
- try
- {
- PEWindow pw = Program.GetPEWindow(Misc.GetRealPath(processSelected.MainModule.FileName),
- new Program.PEWindowInvokeAction(delegate(PEWindow f)
- {
- try
- {
- f.Show();
- }
- catch
- { }
- }));
- }
- catch (Exception ex)
- {
- MessageBox.Show("Error inspecting:\n\n" + ex.Message, "Process Hacker", MessageBoxButtons.OK,
- MessageBoxIcon.Error);
- }
- }
-
- private void inspectModuleMenuItem_Click(object sender, EventArgs e)
- {
- try
- {
- PEWindow pw = Program.GetPEWindow(listModules.SelectedItems[0].ToolTipText,
- new Program.PEWindowInvokeAction(delegate(PEWindow f)
- {
- try
- {
- f.Show();
- }
- catch
- { }
- }));
- }
- catch (Exception ex)
- {
- MessageBox.Show("Error inspecting:\n\n" + ex.Message, "Process Hacker", MessageBoxButtons.OK,
- MessageBoxIcon.Error);
- }
- }
}
}
\ No newline at end of file
diff --git a/trunk/ProcessHacker/Forms/PEWindow.Designer.cs b/trunk/ProcessHacker/Forms/PEWindow.Designer.cs
index bf2e9a7dd..6e40fedfc 100644
--- a/trunk/ProcessHacker/Forms/PEWindow.Designer.cs
+++ b/trunk/ProcessHacker/Forms/PEWindow.Designer.cs
@@ -101,7 +101,7 @@
this.tabControl.Location = new System.Drawing.Point(0, 0);
this.tabControl.Name = "tabControl";
this.tabControl.SelectedIndex = 0;
- this.tabControl.Size = new System.Drawing.Size(423, 405);
+ this.tabControl.Size = new System.Drawing.Size(423, 402);
this.tabControl.TabIndex = 0;
//
// tabCOFFHeader
@@ -110,7 +110,7 @@
this.tabCOFFHeader.Location = new System.Drawing.Point(4, 22);
this.tabCOFFHeader.Name = "tabCOFFHeader";
this.tabCOFFHeader.Padding = new System.Windows.Forms.Padding(3);
- this.tabCOFFHeader.Size = new System.Drawing.Size(415, 379);
+ this.tabCOFFHeader.Size = new System.Drawing.Size(415, 376);
this.tabCOFFHeader.TabIndex = 0;
this.tabCOFFHeader.Text = "COFF Header";
this.tabCOFFHeader.UseVisualStyleBackColor = true;
@@ -126,7 +126,7 @@
this.listCOFFHeader.Location = new System.Drawing.Point(3, 3);
this.listCOFFHeader.Name = "listCOFFHeader";
this.listCOFFHeader.ShowItemToolTips = true;
- this.listCOFFHeader.Size = new System.Drawing.Size(409, 373);
+ this.listCOFFHeader.Size = new System.Drawing.Size(409, 370);
this.listCOFFHeader.Sorting = System.Windows.Forms.SortOrder.Ascending;
this.listCOFFHeader.TabIndex = 0;
this.listCOFFHeader.UseCompatibleStateImageBehavior = false;
@@ -148,7 +148,7 @@
this.tabCOFFOptionalHeader.Location = new System.Drawing.Point(4, 22);
this.tabCOFFOptionalHeader.Name = "tabCOFFOptionalHeader";
this.tabCOFFOptionalHeader.Padding = new System.Windows.Forms.Padding(3);
- this.tabCOFFOptionalHeader.Size = new System.Drawing.Size(415, 343);
+ this.tabCOFFOptionalHeader.Size = new System.Drawing.Size(415, 376);
this.tabCOFFOptionalHeader.TabIndex = 1;
this.tabCOFFOptionalHeader.Text = "COFF Optional Header";
this.tabCOFFOptionalHeader.UseVisualStyleBackColor = true;
@@ -164,7 +164,7 @@
this.listCOFFOptionalHeader.Location = new System.Drawing.Point(3, 3);
this.listCOFFOptionalHeader.Name = "listCOFFOptionalHeader";
this.listCOFFOptionalHeader.ShowItemToolTips = true;
- this.listCOFFOptionalHeader.Size = new System.Drawing.Size(409, 337);
+ this.listCOFFOptionalHeader.Size = new System.Drawing.Size(409, 370);
this.listCOFFOptionalHeader.Sorting = System.Windows.Forms.SortOrder.Ascending;
this.listCOFFOptionalHeader.TabIndex = 1;
this.listCOFFOptionalHeader.UseCompatibleStateImageBehavior = false;
@@ -186,7 +186,7 @@
this.tabImageData.Location = new System.Drawing.Point(4, 22);
this.tabImageData.Name = "tabImageData";
this.tabImageData.Padding = new System.Windows.Forms.Padding(3);
- this.tabImageData.Size = new System.Drawing.Size(415, 343);
+ this.tabImageData.Size = new System.Drawing.Size(415, 376);
this.tabImageData.TabIndex = 5;
this.tabImageData.Text = "Image Data";
this.tabImageData.UseVisualStyleBackColor = true;
@@ -203,7 +203,7 @@
this.listImageData.Location = new System.Drawing.Point(3, 3);
this.listImageData.Name = "listImageData";
this.listImageData.ShowItemToolTips = true;
- this.listImageData.Size = new System.Drawing.Size(409, 337);
+ this.listImageData.Size = new System.Drawing.Size(409, 370);
this.listImageData.TabIndex = 2;
this.listImageData.UseCompatibleStateImageBehavior = false;
this.listImageData.View = System.Windows.Forms.View.Details;
@@ -229,7 +229,7 @@
this.tabSections.Location = new System.Drawing.Point(4, 22);
this.tabSections.Name = "tabSections";
this.tabSections.Padding = new System.Windows.Forms.Padding(3);
- this.tabSections.Size = new System.Drawing.Size(415, 343);
+ this.tabSections.Size = new System.Drawing.Size(415, 376);
this.tabSections.TabIndex = 2;
this.tabSections.Text = "Sections";
this.tabSections.UseVisualStyleBackColor = true;
@@ -248,7 +248,7 @@
this.listSections.Location = new System.Drawing.Point(3, 3);
this.listSections.Name = "listSections";
this.listSections.ShowItemToolTips = true;
- this.listSections.Size = new System.Drawing.Size(409, 337);
+ this.listSections.Size = new System.Drawing.Size(409, 370);
this.listSections.TabIndex = 1;
this.listSections.UseCompatibleStateImageBehavior = false;
this.listSections.View = System.Windows.Forms.View.Details;
@@ -283,7 +283,7 @@
this.tabExports.Location = new System.Drawing.Point(4, 22);
this.tabExports.Name = "tabExports";
this.tabExports.Padding = new System.Windows.Forms.Padding(3);
- this.tabExports.Size = new System.Drawing.Size(415, 343);
+ this.tabExports.Size = new System.Drawing.Size(415, 376);
this.tabExports.TabIndex = 3;
this.tabExports.Text = "Exports";
this.tabExports.UseVisualStyleBackColor = true;
@@ -301,7 +301,7 @@
this.listExports.Location = new System.Drawing.Point(3, 3);
this.listExports.Name = "listExports";
this.listExports.ShowItemToolTips = true;
- this.listExports.Size = new System.Drawing.Size(409, 337);
+ this.listExports.Size = new System.Drawing.Size(409, 370);
this.listExports.SmallImageList = this.imageList;
this.listExports.Sorting = System.Windows.Forms.SortOrder.Ascending;
this.listExports.TabIndex = 0;
@@ -341,7 +341,7 @@
this.tabImports.Location = new System.Drawing.Point(4, 22);
this.tabImports.Name = "tabImports";
this.tabImports.Padding = new System.Windows.Forms.Padding(3);
- this.tabImports.Size = new System.Drawing.Size(415, 343);
+ this.tabImports.Size = new System.Drawing.Size(415, 376);
this.tabImports.TabIndex = 4;
this.tabImports.Text = "Imports";
this.tabImports.UseVisualStyleBackColor = true;
@@ -357,7 +357,7 @@
this.listImports.Location = new System.Drawing.Point(3, 3);
this.listImports.Name = "listImports";
this.listImports.ShowItemToolTips = true;
- this.listImports.Size = new System.Drawing.Size(409, 337);
+ this.listImports.Size = new System.Drawing.Size(409, 370);
this.listImports.Sorting = System.Windows.Forms.SortOrder.Ascending;
this.listImports.TabIndex = 1;
this.listImports.UseCompatibleStateImageBehavior = false;
@@ -381,7 +381,7 @@
//
this.AutoScaleDimensions = new System.Drawing.SizeF(6F, 13F);
this.AutoScaleMode = System.Windows.Forms.AutoScaleMode.Font;
- this.ClientSize = new System.Drawing.Size(423, 405);
+ this.ClientSize = new System.Drawing.Size(423, 402);
this.Controls.Add(this.tabControl);
this.FormBorderStyle = System.Windows.Forms.FormBorderStyle.SizableToolWindow;
this.Icon = ((System.Drawing.Icon)(resources.GetObject("$this.Icon")));
diff --git a/trunk/ProcessHacker/Forms/PEWindow.cs b/trunk/ProcessHacker/Forms/PEWindow.cs
index b38ab790a..2b439c35d 100644
--- a/trunk/ProcessHacker/Forms/PEWindow.cs
+++ b/trunk/ProcessHacker/Forms/PEWindow.cs
@@ -20,17 +20,28 @@ namespace ProcessHacker
Misc.SetDoubleBuffered(listCOFFHeader, typeof(ListView), true);
listCOFFHeader.ContextMenu = ListViewMenu.GetMenu(listCOFFHeader);
+ ColumnSettings.LoadSettings(Properties.Settings.Default.PECOFFHColumns, listCOFFHeader);
+
Misc.SetDoubleBuffered(listCOFFOptionalHeader, typeof(ListView), true);
listCOFFOptionalHeader.ContextMenu = ListViewMenu.GetMenu(listCOFFOptionalHeader);
+ ColumnSettings.LoadSettings(Properties.Settings.Default.PECOFFOHColumns, listCOFFOptionalHeader);
+
Misc.SetDoubleBuffered(listImageData, typeof(ListView), true);
listImageData.ContextMenu = ListViewMenu.GetMenu(listImageData);
+ ColumnSettings.LoadSettings(Properties.Settings.Default.PEImageDataColumns, listImageData);
+
Misc.SetDoubleBuffered(listSections, typeof(ListView), true);
listSections.ContextMenu = ListViewMenu.GetMenu(listSections);
+ ColumnSettings.LoadSettings(Properties.Settings.Default.PESectionsColumns, listSections);
+
Misc.SetDoubleBuffered(listExports, typeof(ListView), true);
- listExports.ContextMenu = ListViewMenu.GetMenu(listExports,
+ listExports.ContextMenu = ListViewMenu.GetMenu(listExports,
new RetrieveVirtualItemEventHandler(listExports_RetrieveVirtualItem));
+ ColumnSettings.LoadSettings(Properties.Settings.Default.PEExportsColumns, listExports);
+
Misc.SetDoubleBuffered(listImports, typeof(ListView), true);
listImports.ContextMenu = ListViewMenu.GetMenu(listImports);
+ ColumnSettings.LoadSettings(Properties.Settings.Default.PEImportsColumns, listImports);
_path = path;
this.Text = "PE File - " + path;
@@ -52,6 +63,12 @@ namespace ProcessHacker
private void PEWindow_FormClosing(object sender, FormClosingEventArgs e)
{
+ Properties.Settings.Default.PECOFFHColumns = ColumnSettings.SaveSettings(listCOFFHeader);
+ Properties.Settings.Default.PECOFFOHColumns = ColumnSettings.SaveSettings(listCOFFOptionalHeader);
+ Properties.Settings.Default.PEImageDataColumns = ColumnSettings.SaveSettings(listImageData);
+ Properties.Settings.Default.PESectionsColumns = ColumnSettings.SaveSettings(listSections);
+ Properties.Settings.Default.PEExportsColumns = ColumnSettings.SaveSettings(listExports);
+ Properties.Settings.Default.PEImportsColumns = ColumnSettings.SaveSettings(listImports);
Properties.Settings.Default.PEWindowSize = this.Size;
}
@@ -211,8 +228,8 @@ namespace ProcessHacker
item.Text = sh.Name;
item.SubItems.Add(new ListViewItem.ListViewSubItem(item, "0x" + sh.VirtualAddress.ToString("x8")));
- item.SubItems.Add(new ListViewItem.ListViewSubItem(item, "0x" + sh.PointerToRawData.ToString("x8")));
item.SubItems.Add(new ListViewItem.ListViewSubItem(item, "0x" + sh.VirtualSize.ToString("x")));
+ item.SubItems.Add(new ListViewItem.ListViewSubItem(item, "0x" + sh.PointerToRawData.ToString("x8")));
item.SubItems.Add(new ListViewItem.ListViewSubItem(item,
Misc.FlagsToString(typeof(SectionFlags), (long)sh.Characteristics)));
@@ -231,7 +248,7 @@ namespace ProcessHacker
for (int i = 0; i < _peFile.ImportData.ImportLookupTable.Count; i++)
{
listImports.Groups.Add(new ListViewGroup(_peFile.ImportData.ImportDirectoryTable[i].Name));
-
+
for (int j = 0; j < _peFile.ImportData.ImportLookupTable[i].Count; j++)
{
ImportLookupEntry entry = _peFile.ImportData.ImportLookupTable[i][j];
diff --git a/trunk/ProcessHacker/Forms/PEWindow.resx b/trunk/ProcessHacker/Forms/PEWindow.resx
index 6b6758110..7cbbda04e 100644
--- a/trunk/ProcessHacker/Forms/PEWindow.resx
+++ b/trunk/ProcessHacker/Forms/PEWindow.resx
@@ -127,20 +127,19 @@
AAEAAAD/////AQAAAAAAAAAMAgAAAFdTeXN0ZW0uV2luZG93cy5Gb3JtcywgVmVyc2lvbj0yLjAuMC4w
LCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODkFAQAAACZTeXN0
- ZW0uV2luZG93cy5Gb3Jtcy5JbWFnZUxpc3RTdHJlYW1lcgEAAAAERGF0YQcCAgAAAAkDAAAADwMAAADM
+ ZW0uV2luZG93cy5Gb3Jtcy5JbWFnZUxpc3RTdHJlYW1lcgEAAAAERGF0YQcCAgAAAAkDAAAADwMAAADK
AgAAAk1TRnQBSQFMAwEBAAEEAQABBAEAARABAAEQAQAE/wEhAQAI/wFCAU0BNgcAATYDAAEoAwABQAMA
- ARADAAEBAQABIAYAARD/AP8A/wD/AEIAAVYBVwFWAbgDBAEG9AADJgE4AVEBaQFRAfcBWwFeAVsB2dAA
- AQoBvgEWAf8BBgG4AREB/wEBAbEBCwH/AQABqQEFAf8BAAGhAQAB/wEAAZkBAAH/AQABkQEAAf8BAAGI
- AQAB/wEAAYABAAH/AQABiAEAAf8BAgGhAQcB/wEAAYsBAAH/AVkBXAFZAc/MAAEOAcMBGgH/AaAB1wGp
- Af8BnAHVAaUB/wGYAdMBoQH/AZQB0AGdAf8BkAHOAZgB/wGLAcsBkwH/AYcByQGOAf8BggHGAYkB/wEn
- AcMBhAH/ASMBwQGAAf8BHwG+ASUB/wEAAYwBAAH/AVkBWwFZAcTIAAERAccBHQH/AaUB2gGuAf8BogHY
- AasB/wGeAdYBpwH/AZoB1AGjAf8BlgHSAZ8B/wGTAc8BmgH/AY4BzAGVAf8BiQHKAZAB/wGFAccBiwH/
- AYEBxQGHAf8BJgHCAYIB/wEAAZEBAAH/AVkBXAFZAcnIAAERAccBHQH/AREBxwEdAf8BDgHDARoB/wEK
- Ab4BFgH/AQYBuAERAf8BAQGxAQsB/wEAAakBBQH/AQABoQEAAf8BAAGZAQAB/wEAAZEBAAH/AQMBowEL
- Af8BAAGdAQUB/wFYAVwBWAHR9AABUQFtAVEB9wFaAV8BWgHb+AABVgFYAVYBuwMEAQb/AP8A/wD/ANAA
- AUIBTQE+BwABPgMAASgDAAFAAwABEAMAAQEBAAEBBQABgBcAA/8BAAL/BgAC/wYAAv8GAAL/BgAB/wHn
- BgAB/wHHBgABgAEDBgABgAEBBgABgAEBBgABgAEDBgAB/wHnBgAB/wHnBgAC/wYAAv8GAAL/BgAC/wYA
- Cw==
+ ARADAAEBAQABIAYAARD/AP8A/wD/AEIAAVYBVwFWAbgDBAEG9AADJgE4AVEBaQFRAfcBWwFeAVsB2dEA
+ Ab4BCgH/AQABuAEFAf8BAAGxAQAB/wEAAakBAAH/AQABoQEAAf8BAAGZAQAB/wEAAZEBAAH/AQABiAEA
+ Af8BAAGAAQAB/wEAAYgBAAH/AQABoQEAAf8BAAGLAQAB/wFZAVwBWQHPzAABAgHDAQ4B/wGgAdcBqQH/
+ AZwB1QGlAf8BmAHTAaEB/wGUAdABnQH/AZABzgGYAf8BiwHLAZMB/wGHAckBjgH/AYIBxgGJAf8BGwHD
+ AYQB/wEXAcEBgAH/ARMBvgEZAf8BAAGMAQAB/wFZAVsBWQHEyAABBQHHAREB/wGlAdoBrgH/AaIB2AGr
+ Af8BngHWAacB/wGaAdQBowH/AZYB0gGfAf8BkwHPAZoB/wGOAcwBlQH/AYkBygGQAf8BhQHHAYsB/wGB
+ AcUBhwH/ARoBwgGCAf8BAAGRAQAB/wFZAVwBWQHJyAABBQHHAREB/wEFAccBEQH/AQIBwwEOAf8BAAG+
+ AQoB/wEAAbgBBQH/AQABsQEAAf8BAAGpAQAB/wEAAaEBAAH/AQABmQEAAf8BAAGRAQAB/wEAAaMBAAH/
+ AQABnQEAAf8BWAFcAVgB0fQAAVEBbQFRAfcBWgFfAVoB2/gAAVYBWAFWAbsDBAEG/wD/AP8A/wDQAAFC
+ AU0BPgcAAT4DAAEoAwABQAMAARADAAEBAQABAQUAAYAXAAP/AQAC/wYAAv8GAAL/BgAC/wYAAf8B5wYA
+ Af8BxwYAAYABAwYAAYABAQYAAYABAQYAAYABAwYAAf8B5wYAAf8B5wYAAv8GAAL/BgAC/wYAAv8GAAs=
diff --git a/trunk/ProcessHacker/Misc/Misc.cs b/trunk/ProcessHacker/Misc/Misc.cs
index 44d83c2ba..968e17464 100644
--- a/trunk/ProcessHacker/Misc/Misc.cs
+++ b/trunk/ProcessHacker/Misc/Misc.cs
@@ -104,6 +104,58 @@ namespace ProcessHacker
item.Enabled = true;
}
+ ///
+ /// Gets the file name of the currently running kernel.
+ ///
+ /// The kernel file name.
+ public static string GetKernelFileName()
+ {
+ int RequiredSize = 0;
+ int[] ImageBases;
+
+ Win32.EnumDeviceDrivers(null, 0, ref RequiredSize);
+ ImageBases = new int[RequiredSize];
+ Win32.EnumDeviceDrivers(ImageBases, RequiredSize * sizeof(int), ref RequiredSize);
+
+ for (int i = 0; i < RequiredSize; i++)
+ {
+ if (ImageBases[i] == 0)
+ continue;
+
+ StringBuilder name = new StringBuilder(256);
+ StringBuilder filename = new StringBuilder(256);
+ string realname = "";
+
+ Win32.GetDeviceDriverBaseName(ImageBases[i], name, 255);
+ Win32.GetDeviceDriverFileName(ImageBases[i], filename, 255);
+
+ try
+ {
+ System.IO.FileInfo fi = new System.IO.FileInfo(Misc.GetRealPath(filename.ToString()));
+ bool kernel = false;
+
+ realname = fi.FullName;
+
+ foreach (string k in Misc.KernelNames)
+ {
+ if (realname.ToLower() == Environment.SystemDirectory.ToLower() + "\\" + k.ToLower())
+ {
+ kernel = true;
+
+ break;
+ }
+ }
+
+ if (kernel)
+ return realname;
+ }
+ catch
+ { }
+ }
+
+ return "";
+ }
+
///
/// Formats a object into a string representation using the format "dd/MM/yy hh:mm:ss".
///
diff --git a/trunk/ProcessHacker/Program.cs b/trunk/ProcessHacker/Program.cs
index 519e3208f..1a3d37dc6 100644
--- a/trunk/ProcessHacker/Program.cs
+++ b/trunk/ProcessHacker/Program.cs
@@ -240,6 +240,15 @@ namespace ProcessHacker
PEWindow pw = null;
string id = "";
+ if (PEWindows.ContainsKey(path))
+ {
+ pw = PEWindows[path];
+
+ pw.Invoke(new MethodInvoker(delegate { action(pw); }));
+
+ return pw;
+ }
+
Thread t = new Thread(new ThreadStart(delegate
{
pw = new PEWindow(path);
diff --git a/trunk/ProcessHacker/Properties/Settings.Designer.cs b/trunk/ProcessHacker/Properties/Settings.Designer.cs
index ae9010957..11369b61c 100644
--- a/trunk/ProcessHacker/Properties/Settings.Designer.cs
+++ b/trunk/ProcessHacker/Properties/Settings.Designer.cs
@@ -310,5 +310,77 @@ namespace ProcessHacker.Properties {
this["PEWindowSize"] = value;
}
}
+
+ [global::System.Configuration.UserScopedSettingAttribute()]
+ [global::System.Diagnostics.DebuggerNonUserCodeAttribute()]
+ [global::System.Configuration.DefaultSettingValueAttribute("")]
+ public string PECOFFHColumns {
+ get {
+ return ((string)(this["PECOFFHColumns"]));
+ }
+ set {
+ this["PECOFFHColumns"] = value;
+ }
+ }
+
+ [global::System.Configuration.UserScopedSettingAttribute()]
+ [global::System.Diagnostics.DebuggerNonUserCodeAttribute()]
+ [global::System.Configuration.DefaultSettingValueAttribute("")]
+ public string PECOFFOHColumns {
+ get {
+ return ((string)(this["PECOFFOHColumns"]));
+ }
+ set {
+ this["PECOFFOHColumns"] = value;
+ }
+ }
+
+ [global::System.Configuration.UserScopedSettingAttribute()]
+ [global::System.Diagnostics.DebuggerNonUserCodeAttribute()]
+ [global::System.Configuration.DefaultSettingValueAttribute("")]
+ public string PEImageDataColumns {
+ get {
+ return ((string)(this["PEImageDataColumns"]));
+ }
+ set {
+ this["PEImageDataColumns"] = value;
+ }
+ }
+
+ [global::System.Configuration.UserScopedSettingAttribute()]
+ [global::System.Diagnostics.DebuggerNonUserCodeAttribute()]
+ [global::System.Configuration.DefaultSettingValueAttribute("")]
+ public string PESectionsColumns {
+ get {
+ return ((string)(this["PESectionsColumns"]));
+ }
+ set {
+ this["PESectionsColumns"] = value;
+ }
+ }
+
+ [global::System.Configuration.UserScopedSettingAttribute()]
+ [global::System.Diagnostics.DebuggerNonUserCodeAttribute()]
+ [global::System.Configuration.DefaultSettingValueAttribute("")]
+ public string PEExportsColumns {
+ get {
+ return ((string)(this["PEExportsColumns"]));
+ }
+ set {
+ this["PEExportsColumns"] = value;
+ }
+ }
+
+ [global::System.Configuration.UserScopedSettingAttribute()]
+ [global::System.Diagnostics.DebuggerNonUserCodeAttribute()]
+ [global::System.Configuration.DefaultSettingValueAttribute("")]
+ public string PEImportsColumns {
+ get {
+ return ((string)(this["PEImportsColumns"]));
+ }
+ set {
+ this["PEImportsColumns"] = value;
+ }
+ }
}
}
diff --git a/trunk/ProcessHacker/Properties/Settings.settings b/trunk/ProcessHacker/Properties/Settings.settings
index 3d33b71ee..11cd07e8e 100644
--- a/trunk/ProcessHacker/Properties/Settings.settings
+++ b/trunk/ProcessHacker/Properties/Settings.settings
@@ -74,5 +74,23 @@
439, 413
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
\ No newline at end of file
diff --git a/trunk/ProcessHacker/app.config b/trunk/ProcessHacker/app.config
index 19d5c9217..428f7b7ab 100644
--- a/trunk/ProcessHacker/app.config
+++ b/trunk/ProcessHacker/app.config
@@ -79,6 +79,24 @@
439, 413
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
\ No newline at end of file