| 367 | } |
| 368 | |
| 369 | bool IScanner::ScanProcesses() |
| 370 | { |
| 371 | SCANNER_LOG(LL_SYS, "Process scanner routine started!"); |
| 372 | |
| 373 | // Check SystemExtendedProcessInformation and SystemProcessInformation and compare both of them |
| 374 | auto vDifferentProcesses = GetDifferentProcessList(); |
| 375 | if (vDifferentProcesses.empty() == false) |
| 376 | { |
| 377 | SCANNER_LOG(LL_ERR, "Unknown process(es) found! Size: %u", vDifferentProcesses.size()); |
| 378 | |
| 379 | for (const auto & pCurrProc : vDifferentProcesses) |
| 380 | { |
| 381 | SCANNER_LOG(LL_CRI, "Different process id: %u", pCurrProc->dwProcessId); |
| 382 | // TODO: Send to quarentine |
| 383 | } |
| 384 | } |
| 385 | |
| 386 | // Scan alive processes |
| 387 | auto vProcesses = ListProcessesM1(); |
| 388 | if (vProcesses.empty()) |
| 389 | { |
| 390 | return false; |
| 391 | } |
| 392 | |
| 393 | for (const auto & pCurrProc : vProcesses) |
| 394 | { |
| 395 | if (IS_VALID_SMART_PTR(pCurrProc)) |
| 396 | { |
| 397 | OnScanProcess(pCurrProc->dwProcessId); |
| 398 | } |
| 399 | } |
| 400 | |
| 401 | // Check terminated processes with NtGetNextProcess |
| 402 | auto processEnumerator = std::make_unique<CSafeProcessHandle>(PROCESS_QUERY_INFORMATION); |
| 403 | if (!IS_VALID_SMART_PTR(processEnumerator)) |
| 404 | { |
| 405 | return false; |
| 406 | } |
| 407 | |
| 408 | auto vTerminatedProcesses = processEnumerator->EnumerateProcesses(false); |
| 409 | if (vTerminatedProcesses.empty()) |
| 410 | { |
| 411 | return false; |
| 412 | } |
| 413 | |
| 414 | auto dwExitCode = 0UL; |
| 415 | for (const auto & hCurrProc : vTerminatedProcesses) |
| 416 | { |
| 417 | if (g_winapiApiTable->GetExitCodeProcess(hCurrProc, &dwExitCode) && dwExitCode == STILL_ACTIVE) |
| 418 | continue; |
| 419 | |
| 420 | OnScanTerminatedProcess(hCurrProc); |
| 421 | } |
| 422 | |
| 423 | return true; |
| 424 | } |
| 425 | |
| 426 | // ---------------------------------------------------------------------- |
nothing calls this directly
no test coverage detected