Article ID: 182559
Article Last Modified on 11/21/2006
INT WINAPI VDMEnumProcessWOW( PROCESSENUMPROC fp, LPARAM lparam );The return value for this function is the number of VDMs currently running, or the number enumerated before enumeration was terminated. fp is a pointer to a callback function. The function is called for each VDM that is enumerated. lParam is a user-defined value that is passed to the callback function.
typedef BOOL ( WINAPI *PROCESSENUMPROC )(
DWORD dwProcessId,
DWORD dwAttributes,
LPARAM lpUserDefined
);
The function should return TRUE to stop enumeration or FALSE to continue
enumeration. dwProcessId is the process ID of the NTVDM.exe process. You
will need this ID when calling the other VDM functions mentioned below.
INT WINAPI VDMEnumTaskWOW( DWORD dwProcessId, TASKENUMPROC fp,
LPARAM lparam );
INT WINAPI VDMEnumTaskWOWEx( DWORD dwProcessId, TASKENUMPROCEX fp,
LPARAM lparam );
The return value for each of these functions is the number of tasks
currently running within the indicated VDM, or the number enumerated before
enumeration was terminated. dwProcessId is the process ID of the VDM. fp is
a pointer to a callback function. The function is called for each task that
is enumerated. lparam is a user-defined value that is passed to the
callback function.
typedef BOOL ( WINAPI *TASKENUMPROC )(
DWORD dwThreadId,
WORD hMod16,
WORD hTask16,
LPARAM lpUserDefined
);
typedef BOOL ( WINAPI *TASKENUMPROCEX )(
DWORD dwThreadId,
WORD hMod16,
WORD hTask16,
PSZ pszModName,
PSZ pszFileName,
LPARAM lpUserDefined
);
These functions should return TRUE to stop enumeration or FALSE to continue
enumeration. You can use hTask16 in a call to terminate the task.
// Enumerate all 16-bit tasks on the system.
#include <windows.h>
#include <stdio.h>
#include <vdmdbg.h>
BOOL WINAPI ProcessEnumProc( DWORD, DWORD, LPARAM );
BOOL WINAPI TaskEnumProcEx( DWORD, WORD, WORD, PSZ, PSZ, LPARAM );
void main()
{
// Enumerate VDMs.
VDMEnumProcessWOW(
(PROCESSENUMPROC)ProcessEnumProc,
(LPARAM)NULL
);
}
BOOL WINAPI ProcessEnumProc( DWORD dwProcessId, DWORD dwAttrib,
LPARAM t )
{
printf("\nProcess ID: %d\n", dwProcessId);
// Use process ID of VDM to enumerate through its tasks.
VDMEnumTaskWOWEx(
dwProcessId,
(TASKENUMPROCEX)TaskEnumProcEx,
(LPARAM)NULL
);
// Keep enumerating.
return FALSE;
}
BOOL WINAPI TaskEnumProcEx( DWORD dwThreadId, WORD hMod16, WORD hTask16,
PSZ pszModName, PSZ pszFileName, LPARAM lParam )
{
//print task's information
printf("Thread ID: %d\n", dwThreadId);
printf("Module handle: %d\n", hMod16);
printf("Task handle: %d\n", hTask16);
printf("Module Name: %s\n", pszModName);
printf("File Name: %s\n", pszFileName);
// Keep enumerating.
return FALSE;
}
BOOL WINAPI VDMStartTaskInWOW( DWORD dwProcessId, LPSTR lpCommandLine,
WORD wShow );
The return value of this function is TRUE if the task is successfully
started, otherwise it is FALSE. dwProcessId is the VDM process ID.
lpCommandLine is a string indicating the filename of the 16-bit application
along with any command-line parameters. wShow indicates how the window will
be shown. wShow can be any value that is valid for the 16-bit ShowWindow()
function.
BOOL WINAPI VDMTerminateTaskWOW( DWORD dwProcessId, WORD htask );The return value of this function is TRUE if the task is successfully terminated, otherwise it is FALSE. dwProcessId is the VDM process ID. hTask is the handle to the task. This task handle can be obtained through VDMEnumTaskWOW() or VDMEnumTaskWOWEx().
175030 How To Enumerate Applications in Win32
Keywords: kbapi kbhowto kbkernbase kbthread KB182559