Find open handles of a program #819
-
Beta Was this translation helpful? Give feedback.
Replies: 4 comments 4 replies
-
PH is working correctly. Here is an example screenshot with Microsoft Windows File Explorer. Maybe that program is not working the way you are thinking it would be. |
Beta Was this translation helpful? Give feedback.
-
Finding handles or dlls requires access to the original process to enumerate its handles. So to be able to find all handles you need to:
If you don't have these enabled then you won't be able to locate/search for handles properly... Also more recently some 'security' products such as Avast/AVG are currently using DKOM (direct kernel object manipulation) exploitation for zeroing the names of handles so you cannot find open handles to disk/usb devices created by their software. |
Beta Was this translation helpful? Give feedback.
-
Have you tried searching for |
Beta Was this translation helpful? Give feedback.
-
@diversenok commented on Mar 4, 2021:
I am interested in the issue. Sadly the original site is unreachable to me, and the Internet Archive seems to have no copy of this particular page: |
Beta Was this translation helpful? Give feedback.
Have you tried searching for
\Device\ImDisk0
instead of a drive letter? I remember some compatibility issues were preventing Process Hacker from correctly converting native paths to the Win32 format in some cases.