Commit Graph

25 Commits

Author SHA1 Message Date
wj32 c5b40a16fc * #2647418 - "Add ctrl+A and ctrl+C to threads, token, modules etc"
* fixed nulls at the ends of handle names

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@761 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-02-28 05:22:03 +00:00
wj32 bc593b4064 fixed bug #2617880 - "Killing ProcessHacker within ProcessHacker and Terminator"
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@660 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-02-20 06:06:36 +00:00
wj32 41e2dbceb9 * fixed .NET detection (for real this time)
* no longer deletes the KPH service if it's already running
* PH no longer requires UAC elevation

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@628 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-02-15 00:25:27 +00:00
wj32 9eeac62fd9 * removed hooks from KPH - this means that it can now support multiple clients
* added Restart and Set Token menu items
* KphOpenTokenEx now creates an access state - limited user accounts now have complete admin access to processes and tokens
* fixed problem where if a process image file can't be accessed because of permissions PH says it's packed
* fixed problem with .NET executables not being recognized

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@627 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-02-14 23:52:04 +00:00
wj32 74df64961c * PH now uses KPH even under a limited user account, giving it full admin access (to processes) anyway
* eliminated most usages of Process.Modules because it doesn't use KPH

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@626 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-02-14 21:46:28 +00:00
wj32 466c0719e7 fixed SymbolProvider and ThreadProvider so that it is possible to view symbolic start addresses of System (PID 4) after it is unprotected
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@625 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-02-14 10:56:31 +00:00
wj32 399de14431 Process termination now uses KProcessHacker
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@617 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-02-13 05:27:47 +00:00
wj32 f5bf13a0ef Suspend and Resume functions for processes now use KProcessHacker
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@596 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-29 09:29:38 +00:00
wj32 2b560d67c6 implemented KphOpenProcessTokenEx
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@586 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-26 02:28:27 +00:00
wj32 e339410c75 KphOpenProcess and KphOpenThread work perfectly on Vista
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@578 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-25 10:15:43 +00:00
wj32 cec7a95128 * doesn't use KphOpenProcess (too risky with BSODs)
* can protect and unprotect processes!

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@577 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-25 06:09:08 +00:00
wj32 e4fe153f83 new capability for KProcessHacker: custom rewrite of NtOpenProcess, bypassing almost all types of hooks!
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@576 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-25 03:52:32 +00:00
wj32 6578903105 * added SSDT restoration capability
* automatically deletes service after a reboot
* no longer hooks file and key functions
* added website to README.txt

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@537 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-19 03:18:07 +00:00
wj32 de69f8d0ea disable KPH by default and add an option to enable it
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@531 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-18 08:22:34 +00:00
wj32 e69b70caf4 fixed memory corruption issues with the client
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@530 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-18 07:56:22 +00:00
wj32 f43d8fb4cd better ServiceLimit finder, now unhooks as soon as the client disconnects
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@529 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-18 05:49:44 +00:00
wj32 dfe178fb4c Make a guess about the size of the SSDT if we couldn't find KiServiceLimit. This fixes the SSDT on XP.
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@528 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-18 04:17:02 +00:00
wj32 9f93629b61 make KProcessHacker un-unloadable
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@524 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-18 02:04:04 +00:00
wj32 ebe69f5c6d easier hooking, now hooks ZwOpenThread
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@522 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-17 23:17:21 +00:00
wj32 7a7d4d0f53 no kernel-kill tool needed - KProcessHacker transparently lets Process Hacker call the unhooked functions
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@520 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-17 10:04:59 +00:00
wj32 88488c2561 fixed deletion of the existing service
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@518 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-17 08:00:48 +00:00
wj32 26fed602c4 automatically creates the KProcessHacker service and deletes it afterwards
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@516 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-17 06:41:22 +00:00
wj32 24f9427887 * ProcessHacker can now find and dump the original KiServiceTable
* PE reader reads relocations
* Added kernel-mode kill method to Terminator

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@515 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-17 06:32:30 +00:00
wj32 972228f469 KProcessHacker now hooks stuff, but doesn't really do anything useful...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@509 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-16 08:02:41 +00:00
wj32 7587160c6c KPH is half-working...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@503 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-01-15 08:35:57 +00:00