Click here to Skip to main content
15,891,905 members
Please Sign up or sign in to vote.
0.00/5 (No votes)
See more:
Hi, guys!

I need to replace some user process to other process in kernel mode of Windows. For example, user try to execute calc.exe, so I need to replace it to notepad.exe. I think I need to hook ZwCreateProcess/ZwCreateProcessEx/ZwCreateUserProcess and change parameter ImageName. Does it make sense? Maybe there are some other ways? Thanks!
Posted

This content, along with any associated source code and files, is licensed under The Code Project Open License (CPOL)



CodeProject, 20 Bay Street, 11th Floor Toronto, Ontario, Canada M5J 2N8 +1 (416) 849-8900