More specifically Im looking on info for PsSetCreateProcessNotifyRoutine.
When the driver function gets notification of this, has the primary thread for the process already been created.
If so, shouldnt I be able to get the thread handle and suspend it?

any guidance woul d be grtegt.

Posted on 2004-08-24 21:38:15 by packetvb
check this, maybe it will helps you
Posted on 2004-08-28 14:36:02 by Funbit
Look the Four-F ProcessMon source

It is 100% assembly :-D
Posted on 2004-08-28 20:21:12 by Opcode