Commit Graph

22 Commits

Author SHA1 Message Date
wj32 4201dfad3b fixed kernel handle viewing on Windows 7
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1670 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-08-06 09:11:03 +00:00
wj32 5bb2c4f1b3 fixed object type retrieval on Windows 7
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1669 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-08-06 07:03:28 +00:00
wj32 09e59eeca0 significant logging improvements
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1630 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-07-24 05:04:59 +00:00
wj32 3e3b458759 system service hooking works!
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1624 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-07-22 07:59:06 +00:00
wj32 1f89c57334 improved KphUnsafeReadVirtualMemory
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1618 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-07-21 09:53:09 +00:00
wj32 bbdf6b3f49 added ability to unload drivers
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1613 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-07-20 09:45:43 +00:00
wj32 4f8aabf04f added paged code sections to KPH
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1508 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-07-03 07:36:49 +00:00
wj32 00771a7925 added more debugging messages + autoreload.cmd
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1469 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-06-26 07:43:31 +00:00
wj32 a17e10d425 * added KphQueryProcessHandles
* added KphOpenThreadProcess
* hidden processes scanner can now detect FUTo
* KPH cleanup - added argument attributes
* improved auto-ForeColor

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1436 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-06-20 02:47:04 +00:00
wj32 0de2790f9c KPH code cleanup
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1288 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-17 04:40:24 +00:00
wj32 ac906ee65e more ULONG_PTR usage in KPH
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1247 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-08 08:46:00 +00:00
wj32 30114f9047 added more comments to KProcessHacker
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1231 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-04 10:16:27 +00:00
wj32 741af29084 * KProcessHacker can now perform process memory reading/writing by itself and does not require MmCopyVirtualMemory
* added KphAssignImpersonationToken
* added KphAcquireProcessRundownProtection and KphReleaseProcessRundownProtection
* added some impersonation code

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1226 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-03 07:03:02 +00:00
wj32 20f2741361 * #2779558 - "TreeViewAdv font cannot be initialized"
* fixed KProcessHacker BSOD on some Vista systems
* added -nokph command line switch to disable KProcessHacker

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1133 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-23 23:41:35 +00:00
wj32 557503df5a * added some more undocumented defs
* fixed error detection with Native API calls - ThrowLastError() would call Marshal.GetLastWin32Error() which doesn't even apply to Native API calls and would return without throwing an exception, causing random crashes!

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1119 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-22 09:38:30 +00:00
wj32 4dba651028 added ExpGetProcessInformation (not used yet)
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1116 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-21 09:01:12 +00:00
wj32 69a6811b71 added KphTerminateThread -> PspTerminateThreadByPointer
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1102 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-19 22:36:44 +00:00
wj32 1aaf0c4b2f new KPH method: scans for PsTerminateProcess instead of using fixed offsets
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1101 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-19 11:26:44 +00:00
wj32 22bf8a798e KphTerminateProcess now uses PsTerminateProcess where possible; if the wrong address is found it should not BSOD the system because the first 5 bytes are checked against the known standard function prologue.
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1099 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-19 09:51:04 +00:00
wj32 36d0d9299a * added new system for OS version-dependent data
* fixed GenericMapping offset for Windows XP

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1087 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-18 08:02:21 +00:00
wj32 fd789a3cbf * KphAttachProcess* functions
* improved handle viewing
* improved start addresses on Windows XP

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1085 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-18 02:52:10 +00:00
wj32 5eccb86895 * reorganized KProcessHacker
* added KphDuplicateObject

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1078 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-04-17 02:29:25 +00:00