![]() |
Hey guys, The JOB is waiting for you! |
Post Reply
|
Page 12> |
| Author | ||
Meriadoc
Senior Member
Joined: 22 August 2006 Online Status: Offline Posts: 233 |
Post Options
Quote Reply
Topic: Hey guys, The JOB is waiting for you!Posted: 07 June 2009 at 10:00am |
|
Agree. Edited by Meriadoc - 07 June 2009 at 10:02am |
||
![]() |
||
wj32
Senior Member
Joined: 16 January 2009 Location: Australia Online Status: Offline Posts: 704 |
Post Options
Quote Reply
Posted: 07 June 2009 at 3:12am |
|
|
The thing is, the way David Solomon worded it, he was suggesting that unless PH had distinguishing features there was no point in developing it. Imagine if the features I mentioned didn't exist in PH. Would that make PH pointless? PH is open source, and that would be the biggest distinguishing factor.
|
||
|
MCTS: Windows Internals
Process Hacker, a free and open source process viewer. |
||
![]() |
||
SvenBomwollen
Senior Member
Joined: 29 August 2008 Location: Germany Online Status: Offline Posts: 1400 |
Post Options
Quote Reply
Posted: 07 June 2009 at 1:14am |
|
|
Hello, wj32.
Well, you explained the differences in your reply. ![]()
Kind regards, SvenBomwollen Edited by SvenBomwollen - 07 June 2009 at 1:18am |
||
![]() |
||
GamingMasteR
Senior Member
Joined: 10 August 2008 Online Status: Offline Posts: 210 |
Post Options
Quote Reply
Posted: 06 June 2009 at 4:15am |
|
|
I agree with wj32, PH acts well on infected boxed than PE does !!
|
||
![]() |
||
wj32
Senior Member
Joined: 16 January 2009 Location: Australia Online Status: Offline Posts: 704 |
Post Options
Quote Reply
Posted: 06 June 2009 at 3:51am |
|
( Rant: ) Do you really think the only process viewer there should be is Process Explorer? Is there really no point in creating a process viewer since Process Explorer already exists? For starters, Process Hacker is open source while Process Explorer is not. PH has advanced process termination while PE doesn't. PH highlights GUI threads. PH lets you enable/disable/remove privileges. PH lets you read/write memory. PH lets you unload modules. PH lets you change handle attributes. PH shows you all services and lets you modify them. I don't think Mark is even looking at the Feature Requests topic. I'm not saying that Mark is obliged to update PE with new features, but your attitude is very frustrating (it's not just you though). You're saying I'm not allowed to create a new process viewer with the features I want in it - I need to use PE and post everything on a wishlist, even if the features I request will never be added. ![]() |
||
|
MCTS: Windows Internals
Process Hacker, a free and open source process viewer. |
||
![]() |
||
dsolomon
Newbie
Joined: 01 July 2007 Location: United States Online Status: Offline Posts: 19 |
Post Options
Quote Reply
Posted: 06 June 2009 at 1:49am |
|
|
What's the point of this project? What are the key features that differ this from Process Explorer?
If there are some key things missing in Process Explorer, Mark wants to know about it - submit them in the forum in the usual place.
|
||
|
--David Solomon
Coauthor, Windows Internals (Microsoft Press) http://www.solsem.com |
||
![]() |
||
GamingMasteR
Senior Member
Joined: 10 August 2008 Online Status: Offline Posts: 210 |
Post Options
Quote Reply
Posted: 08 May 2009 at 9:36am |
|
|
Smart Kill is the best termination method i've seen till now . Enumerate the process's threads . Kill every thread by inserting APC that will call PspExitThread to the current thread . Don't insert the APC using normal KeInsertQueueApc routine because it could be hooked, use your own apc insertion method or use the unexported api KiInsertQueueApc . There're more spices Edited by GamingMasteR - 08 May 2009 at 9:45am |
||
![]() |
||
wj32
Senior Member
Joined: 16 January 2009 Location: Australia Online Status: Offline Posts: 704 |
Post Options
Quote Reply
Posted: 08 May 2009 at 8:02am |
|
If I knew C GUI programming then I would have coded PH entirely in C (not C++, I HATE C++). The only part of PH that is really .NET-based is the GUI. Have you looked inside the source code for KProcessHacker (kernel-mode driver)? It may contain things you could put in Kernel Detective . BTW: How does Kernel Detective terminate processes? KPH scans for PsTerminateProcess. |
||
|
MCTS: Windows Internals
Process Hacker, a free and open source process viewer. |
||
![]() |
||
molotov
Moderator Group
Joined: 04 October 2006 Online Status: Offline Posts: 17492 |
Post Options
Quote Reply
Posted: 07 May 2009 at 5:50pm |
|
|
||
|
Daily affirmation:
net helpmsg 4006 |
||
![]() |
||
GamingMasteR
Senior Member
Joined: 10 August 2008 Online Status: Offline Posts: 210 |
Post Options
Quote Reply
Posted: 07 May 2009 at 5:24pm |
|
|
I wish to help but i know nothing about .NET development :)
|
||
![]() |
||
Post Reply
|
Page 12> |
| Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |