Этот код хоть на паскале но WinAPI он должен видеть все 64 разрядные процессы
| Код | unit Unit1;
interface
uses TLHelp32, PsAPI, Windows, Messages, SysUtils, Variants, Classes, Graphics, Controls, Forms, Dialogs, StdCtrls;
type TForm1 = class(TForm) Button1: TButton; ListBox1: TListBox; procedure Button1Click(Sender: TObject); private { Private declarations } public { Public declarations } end;
function QueryFullProcessImageNameW(Process: THandle; Flags: DWORD; Buffer: PChar; Size: PDWORD): DWORD; stdcall; external 'kernel32.dll';
var Form1: TForm1;
implementation
{$R *.dfm}
Function GetProcessFilePath(PID: Cardinal): String; Function IsWin2k: Boolean; begin Result := (Win32MajorVersion = 5) and (Win32Platform = VER_PLATFORM_WIN32_NT); end;
Function IsWinNT4: Boolean; begin Result := (Win32MajorVersion = 4) and (Win32Platform = VER_PLATFORM_WIN32_NT); end; Const PROCESS_QUERY_LIMITED_INFORMATION = $1000; var hP : THandle; Buffer : Array[0..MAX_PATH] of Char; S : DWORD; begin Result := '';
if PID > 0 then begin if IsWinNT4 or IsWin2K then begin hP := OpenProcess(PROCESS_QUERY_INFORMATION, False, PID); if hP > 0 then if GetModuleFileNameEx(hP, 0, Buffer, Length(Buffer)) > 0 then Result := StringReplace(Buffer, '\??\', '', [rfReplaceAll, rfIgnoreCase]); end else begin hP := OpenProcess(PROCESS_QUERY_LIMITED_INFORMATION, False, PID); if hP > 0 then if QueryFullProcessImageNameW(hP, 0, @Buffer, @S) > 0 then Result := String(Buffer); end; CloseHandle(hP); end; end;
procedure TForm1.Button1Click(Sender: TObject); var hSnapShot: THandle; ProcInfo: TProcessEntry32;
hToken : THandle; SeDebugNameValue : Int64; tkp : TOKEN_PRIVILEGES; ReturnLength : Cardinal; begin ListBox1.Clear;
/// Добавляем привилегию ///////////////////////////////////////////////////////////////////////////////// if not OpenProcessToken(GetCurrentProcess(), TOKEN_ADJUST_PRIVILEGES or TOKEN_QUERY, hToken) then /// exit; /// /// if not LookupPrivilegeValue( nil, 'SeDebugPrivilege', SeDebugNameValue ) then /// begin /// CloseHandle(hToken); /// exit; /// end; /// /// tkp.PrivilegeCount:= 1; /// tkp.Privileges[0].Luid := SeDebugNameValue; /// tkp.Privileges[0].Attributes := SE_PRIVILEGE_ENABLED; /// /// AdjustTokenPrivileges(hToken,false,tkp,SizeOf(tkp),tkp,ReturnLength); /// if GetLastError() <> ERROR_SUCCESS then exit; /// //////////////////////////////////////////////////////////////////////////////////////////////////////////////
hSnapShot := CreateToolHelp32Snapshot(TH32CS_SNAPPROCESS, 0); if (hSnapShot <> THandle(-1)) then begin ProcInfo.dwSize := SizeOf(ProcInfo); if (Process32First(hSnapshot, ProcInfo)) then begin while (Process32Next(hSnapShot, ProcInfo)) do Begin case ProcInfo.th32ProcessID of 4: ListBox1.Items.Add('[System]'); else ListBox1.Items.Add(GetProcessFilePath(ProcInfo.th32ProcessID)); end; End; end; CloseHandle(hSnapShot); end;
/// Удаляем привилегию /////////////////////////////////////////////////////////// tkp.Privileges[0].Attributes := 0; /// AdjustTokenPrivileges(hToken, FALSE, tkp, SizeOf(tkp), tkp, ReturnLength); /// if GetLastError() <> ERROR_SUCCESS then exit; /// ////////////////////////////////////////////////////////////////////////////////////// end;
end.
|
|