Re: Image Name from Process Handle in Kernel mode

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: qfel (RemIt.q_tmp_at_aster.pl)
Date: 12/02/04


Date: Thu, 2 Dec 2004 14:20:01 +0100

Look at http://undocumented.ntinternals.net/
Most of those Nt* functions are avalible in kernel mode (you just have to
change preffix from 'Nt' to 'Zw')