Is there a way to inject behavior to csrss.exe and modify/enhance windows console?

I'm aware of Console2 and similar solutions, but I would really like to enhance every console window in my system. Any ideas?

csrss.exe: Is it possible to get the “Image Path Name” of csrss.exe which is a SYSTEM process?

The windows system process (in Windows 7 for this example) 'csrss.exe' runs as a SYSTEM process and when I go to get (programmatically, of course) the process list with pid, command line, and image path name I get no values for command line or image path name because Windows won't let you grab that information for a SYSTEM process (I believe).

Is there a way I can grab image path name from a SYSTEM process? Does Windows actually prevent you from doing this? Is there a workaround?


csrss.exe: Hunting down application errors coming from csrss.exe

I'm the maintainer of a legacy Delphi application. On machines running this program an Application Error appears sometimes with the caption referring to this Delphi app and a message like the following:

The instruction at '...' referenced memory at '...'. The memory could not be 'read'.

Click on OK to terminate the program.

Task Manager says the process belonging to this message box is csrss.exe. What would be a systematic way to find the root cause of this e

csrss.exe: batch or vbs forced BSOD

Is there a way is batch or vbs to force the blue screen of death to appear, or a forced crash. This can happen from stopping the process 'csrss.exe' but it wont close via simple batch or vbs script. How can this be done?

csrss.exe: Is there a way to inject behavior to csrss.exe and modify/enhance windows console?

I'm aware of Console2 and similar solutions, but I would really like to enhance every console window in my system. Any ideas?

csrss.exe: make a windows 7 machine crash on BSOD

I'm trying to write a windows debug utility and I would need to automatically crash a Windows machine and make a Blue Screen Of Death appear.

I can obviously kill the csrss.exe process from the task manager, but the command TASKKILL /F /IM csrss.exe in a .bat file doesn't work.

Is there another way to make a Windows machine crash on bsod? Maybe some external library able to kill any process.

I would prefer to use a command line approach since I'm more familiar with it.

csrss.exe: What does the csrss.exe process do?

What is the purpose of the csrss.exe (Client/Server Runtime Server Subsystem) on Windows?

Maybe someone could give a good explanation or pointers to documentation? Unfortunately Google results are pretty noisy when searching a core process of Windows.

The reason I'm asking is that I got a BSOD from my service application which seems to be related to the csrss.exe process, at least this is what the analysis of the memory dump shows:



csrss.exe: is ??c:windows path legitimate

I am going to check loading and memory path of process to find malicious processes. for example if csrss.exe is executaed from other path than windows/system32 would be considered malicious. But the result of volatility for common process such as csrss.exe is as follow:

loading path : ??C:WINDOWSsystem32csrss.exe

mapped path : WINDOWSsystem32csrss.exe

or for sms.exe I have

loading path : SystemRootSystem32smss.exe

mapped path : WINDOWSsystem32smss.

dw20.exe: What is the correct way for a program to terminate its own process (Windows)

C# .NET 3.5

I have a console application that is being called by another application on the computer. This console app runs continuously, and listens for data on stdin from the 'parent' process.

However, when the parent is stopped or killed, the console app that it started continues. Under normal circumstances, it sits and idles waiting for input from stdin, using minimal resources. However, as soon as the parent goes away, this console app spikes the CPU and starves the core

lsass.exe: get a process id from process name

i am trying to do a project using windows API in C language. The small part in my project is to get process ID of lsass.exe.

i have tried the program below but it wont work.
i have read about the CreateToolhelp32Snapshot, Process32First, Process32Next functions can anyone help me explaining how to use them in the code.

So please help me.
i am a beginner to windows API so i will appreciate it if anyone can suggest me an good ebook to refer.

kernel32.dll: When you edit dll in memory, do other applications see changes?

Let's say I'm editing kernel32.dll code in memory with Cheat Engine. I want to ask, when I edit it, is there any chance that there are other programs using the same address space where that dll is loaded? Or does each process get separate copy of the dll and you can change it however you want, yet the only crashes that may occur will be for that process only?

excel.exe: excel.exe doesn't quit ( [duplicate]

This question already has an answer here:

How to properly clean up Excel interop objects

30 answers

Dim oXL As Object
Dim oWB As Object
Dim oSheet As Object
' Start Excel and get Application object.
oXL = CreateObject('Excel.Application')
oXL.Visible = True
' Get a new workbook.

javaw.exe: Javaw.exe problem with Eclipse 5.0

I've a problem with Javaw.exe process. I am developping an application relative to media acknowledgment using jdsk & Eclipse 5 for Plugin Developpment. every time i want test my web cam (JUnit) then i've got a message : 'Javaw.exe will close,we're sorry'.Anyone can help me please??

msiexec.exe: PSRemotingTransportException when calling Start-Process “MsiExec.exe” on remote machine

I am trying to run the following command on a remote computer to uninstall the previous version of a product before I install another version. This is uninstalling using MsiExec.exe.

Whenever I call Start-Process, the process actually runs and the product is uninstalled on the remote computer, but I get the below exception thrown. If the product is not already installed and the Start-Process line does not run, the remote command works fine with no thrown exception. (i.e. it actually se

daemon.exe: andlinux slirp network failed

I have installed andlinux Beta 2 on my WinXP. Everything works fine until last night, I don't recall that I ever changed anything on network configuration or andlinux setup, the network stop working inside andlinux. With that said, I mean open a KDE console, I do 'ping', I see DNS is resolved correctly, however, no response at all.

My andlinux is startup as a WinXP service. Open windows task manager I can see following services are up and running:colinux-daemon.exe colinux-net-d

winlogon.exe: Why can I not see winlogon.exe using Python on top of Cygwin?

This is the file I'm searching for on a Windows XP computer


I have displayed file extensions for all files, checked Show Hidden Files, checked Show Hidden System Files, and I can see the file using Explorer but cannot see the file with python. I cannot even see the file using:

os.system( 'dir C:/Windows/System32/winlogon.exe' )

I can see the file by using command prompt by running

dir C:WindowsSystem32winlogon.exe

wrapper.exe: Execute batch file(in turn executes exe) from powershell

I am trying to execute a install activeMq service from powershell, for which I am trying to call a batch file (which inturn calls the wrapper.exe) using:

& 'C:apache-activemq-5.6.0inwin64InstallService.bat'

I am getting ''wrapper.exe'' is not recognized as an internal or external command,or batch file'

But when I execute InstallService.bat from command prompt I am able to run the service

Any help would be appreciated


-system process-: How do you parse and process HTML/XML in PHP?

How can one parse HTML/XML and extract information from it?

This is a General Reference question for the php tag

