More specifically Im looking on info for PsSetCreateProcessNotifyRoutine.
When the driver function gets notification of this, has the primary thread for the process already been created.
If so, shouldnt I be able to get the thread handle and suspend it?

any guidance woul d be grtegt.

thankls
Posted on 2004-08-24 21:38:15 by packetvb
check this, maybe it will helps you
http://www.thecodeproject.com/threads/procmon.asp
Posted on 2004-08-28 14:36:02 by Funbit
Look the Four-F ProcessMon source
http://wasm.ru/pub/21/files/kmd14.zip.

It is 100% assembly :-D
Posted on 2004-08-28 20:21:12 by Opcode