1
0
"Process Explorer" is the TOOL for Windows, one use for me is too see system drivers, that's watching DLLs in the process "System" (Pid 4 - always?). The drivers aren't, of course, DLLs, BUT for the system they are some kind of drivers (kernel extensions), that's why probably they are show there. My question - why the search ("Find Handle or DLL") doesn't work for them?
Windows 7, Process Explorer v15.12
seems to be PID of 4 on my comp and if I right click the system process and click properties, then threads, i see some files. like testing on xp, i see some sys files and ntoskernel.exe or something like that.. don't see any dlls at the moment there but i'm over vnc and things a bit sluggish.. but it may be there are no dlls that it uses in which case that could explain it – barlop – 2013-12-30T23:39:45.713
on both win7 and win xp. system idle has(or is shown to have) pid 0 and system has pid 4. – barlop – 2013-12-30T23:42:10.550
No right click: Ctrl-L (View/Show lower pane), Ctrl-H (View/Lower pane view) to switch between DLLs and Handles – Liviu – 2013-12-30T23:42:59.140
Asking "Why?" here would probably need someone who has the source code. You could try to write Mark Russinovich an Email instead. – Thomas Weller – 2014-01-14T14:38:20.440
What is your search term? It seems to work for me with Process Explorer 15.40 – Thomas Weller – 2014-01-14T14:40:44.543
At work I have
Xp
and15.40
: it still doesn't work, tried to search "BEEP" (from "BEEP.sys"). – Liviu – 2014-01-14T15:21:27.323Or "hal.dll", eveybody has one ;) – Liviu – 2014-01-14T15:24:10.523