wj32
4201dfad3b
fixed kernel handle viewing on Windows 7
...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1670 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-08-06 09:11:03 +00:00
wj32
5bb2c4f1b3
fixed object type retrieval on Windows 7
...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1669 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-08-06 07:03:28 +00:00
wj32
09e59eeca0
significant logging improvements
...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1630 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-07-24 05:04:59 +00:00
wj32
3e3b458759
system service hooking works!
...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1624 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-07-22 07:59:06 +00:00
wj32
1f89c57334
improved KphUnsafeReadVirtualMemory
...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1618 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-07-21 09:53:09 +00:00
wj32
bbdf6b3f49
added ability to unload drivers
...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1613 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-07-20 09:45:43 +00:00
wj32
4f8aabf04f
added paged code sections to KPH
...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1508 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-07-03 07:36:49 +00:00
wj32
00771a7925
added more debugging messages + autoreload.cmd
...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1469 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-06-26 07:43:31 +00:00
wj32
a17e10d425
* added KphQueryProcessHandles
...
* added KphOpenThreadProcess
* hidden processes scanner can now detect FUTo
* KPH cleanup - added argument attributes
* improved auto-ForeColor
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1436 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-06-20 02:47:04 +00:00
wj32
0de2790f9c
KPH code cleanup
...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1288 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-17 04:40:24 +00:00
wj32
ac906ee65e
more ULONG_PTR usage in KPH
...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1247 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-08 08:46:00 +00:00
wj32
30114f9047
added more comments to KProcessHacker
...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1231 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-04 10:16:27 +00:00
wj32
741af29084
* KProcessHacker can now perform process memory reading/writing by itself and does not require MmCopyVirtualMemory
...
* added KphAssignImpersonationToken
* added KphAcquireProcessRundownProtection and KphReleaseProcessRundownProtection
* added some impersonation code
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1226 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-03 07:03:02 +00:00
wj32
20f2741361
* #2779558 - "TreeViewAdv font cannot be initialized"
...
* fixed KProcessHacker BSOD on some Vista systems
* added -nokph command line switch to disable KProcessHacker
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1133 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-23 23:41:35 +00:00
wj32
557503df5a
* added some more undocumented defs
...
* fixed error detection with Native API calls - ThrowLastError() would call Marshal.GetLastWin32Error() which doesn't even apply to Native API calls and would return without throwing an exception, causing random crashes!
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1119 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-22 09:38:30 +00:00
wj32
4dba651028
added ExpGetProcessInformation (not used yet)
...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1116 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-21 09:01:12 +00:00
wj32
69a6811b71
added KphTerminateThread -> PspTerminateThreadByPointer
...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1102 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-19 22:36:44 +00:00
wj32
1aaf0c4b2f
new KPH method: scans for PsTerminateProcess instead of using fixed offsets
...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1101 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-19 11:26:44 +00:00
wj32
22bf8a798e
KphTerminateProcess now uses PsTerminateProcess where possible; if the wrong address is found it should not BSOD the system because the first 5 bytes are checked against the known standard function prologue.
...
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1099 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-19 09:51:04 +00:00
wj32
36d0d9299a
* added new system for OS version-dependent data
...
* fixed GenericMapping offset for Windows XP
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1087 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-18 08:02:21 +00:00
wj32
fd789a3cbf
* KphAttachProcess* functions
...
* improved handle viewing
* improved start addresses on Windows XP
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1085 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-18 02:52:10 +00:00
wj32
5eccb86895
* reorganized KProcessHacker
...
* added KphDuplicateObject
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1078 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-17 02:29:25 +00:00