using System; using ProcessHacker.Native.Objects; namespace ProcessHacker.Native { /// /// Provides various utility methods. /// public static class NativeUtils { /// /// Calls a function. /// /// The address of the function. /// The first parameter to pass. /// The second parameter to pass. /// The third parameter to pass. public static void Call(IntPtr address, IntPtr param1, IntPtr param2, IntPtr param3) { // Queue a user-mode APC to the current thread. ThreadHandle.Current.QueueApc(address, param1, param2, param3); // Flush the APC queue. ThreadHandle.TestAlert(); } public static string FormatNativeKeyName(string nativeKeyName) { const string hklmString = "\\registry\\machine"; const string hkcrString = "\\registry\\machine\\software\\classes"; string hkcuString = "\\registry\\user\\" + System.Security.Principal.WindowsIdentity.GetCurrent().User.ToString().ToLower(); string hkcucrString = "\\registry\\user\\" + System.Security.Principal.WindowsIdentity.GetCurrent().User.ToString().ToLower() + "_classes"; const string hkuString = "\\registry\\user"; if (nativeKeyName.ToLower().StartsWith(hkcrString)) return "HKCR" + nativeKeyName.Substring(hkcrString.Length); else if (nativeKeyName.ToLower().StartsWith(hklmString)) return "HKLM" + nativeKeyName.Substring(hklmString.Length); else if (nativeKeyName.ToLower().StartsWith(hkcucrString)) return "HKCU\\Software\\Classes" + nativeKeyName.Substring(hkcucrString.Length); else if (nativeKeyName.ToLower().StartsWith(hkcuString)) return "HKCU" + nativeKeyName.Substring(hkcuString.Length); else if (nativeKeyName.ToLower().StartsWith(hkuString)) return "HKU" + nativeKeyName.Substring(hkuString.Length); else return nativeKeyName; } } }