How to make the "Replace Task Manager" function in Process Explorer?

Process Explorer has a nice feature Replace Task Manager

enter image description here

I just thought how Mark Russinovich does it.
What trick is used to implement it?

+7
source share
1 answer

You can use ProcMon to find out how this is done ...

To save you trouble, ProcExp is defined as the taskmgr.exe debugger in the Image File Execution Options in the registry. This means that ProcExp starts before taskmgr starts, regardless of how taskmgr was started. ProcExp can then easily close the task manager and show itself.

+12
source

All Articles