Как Process Explorer подменяет Task Manager.
? ??????, ??? Process Explorer ????????? ????? ??????????? Task Manager?
??????????? ??? ????? ?????? ? ????????. ?? ????????????? ???? ? ???????? ????????? ??? taskmgr.exe!
???????????? ?????? ?????? ?????????:
- ??????? ?????????? ? ?????? CreateProcess. ??????? ??? ? ??? ????????? taskmgr.exe, ?????? ????? ??????? Process Explorer;
- ?? ????? ???????? Windows File Protection (WPF), ??????? ????????? ??????????? ???? Task Manager’? ? %windir%\system32.
??????????:
- ??????? ?????????? ??? ??????????? ?? ????????? ??????????????? taskmgr.exe. ??? ????? ???? ? ?? Task Manager ?????, ?????? ??? ???????. ??? ????? ?????? ???? ????? ??????? Process Explorer;
- ??? ???????????? ????? “taskmgr.exe” ?????????? ? ????????? ?????? ???????????? ????????. ?.?. ??? ?????? ???????? ???????? notepad.exe ?? ?????? ???????? ?? ?????????.
?? ??????-?? ????? ????????? ???????.
Cross-posted from blog.not-a-kernel-guy.com.