Introduction - If you have any usage issues, please Google them yourself
This is a very good kernel-level HOOK API examples, I would like to look at the effects inside the bin folder can be compiled procedures, which did not materialize to monitor the kernel, processes and registry monitoring has been completed. This code is absolutely able to successfully compile, because the code is hookzwcreateprocess in process-driven equipment, so the compiler set up the environment more complex, so in this compression bag also contains a small tutorial to teach you to build in vc 6.0 device driver development program environment, and带了个samples. Statement: This program runs under XP, in 2000 will cause a blue screen
Packet : 27796735prmonitor.rar filelist
PRMonitor\bin\PRMonitor.exe
PRMonitor\bin\PRMonitor.sys
PRMonitor\bin
PRMonitor\src\hookzwcreateprocess\buildchk.log
PRMonitor\src\hookzwcreateprocess\dbghelp.h
PRMonitor\src\hookzwcreateprocess\ddkbuild.bat
PRMonitor\src\hookzwcreateprocess\hookzwcreateprocess.c
PRMonitor\src\hookzwcreateprocess\hookzwcreateprocess.dsp
PRMonitor\src\hookzwcreateprocess\hookzwcreateprocess.dsw
PRMonitor\src\hookzwcreateprocess\hookzwcreateprocess.h
PRMonitor\src\hookzwcreateprocess\hookzwcreateprocess.ncb
PRMonitor\src\hookzwcreateprocess\hookzwcreateprocess.plg
PRMonitor\src\hookzwcreateprocess\makefile
PRMonitor\src\hookzwcreateprocess\obj\_objects.mac
PRMonitor\src\hookzwcreateprocess\obj
PRMonitor\src\hookzwcreateprocess\objchk\i386
PRMonitor\src\hookzwcreateprocess\objchk
PRMonitor\src\hookzwcreateprocess\readme.txt
PRMonitor\src\hookzwcreateprocess\sources
PRMonitor\src\hookzwcreateprocess
PRMonitor\src\PRMonitor\Debug
PRMonitor\src\PRMonitor\Dlg.res
PRMonitor\src\PRMonitor\PRMDlg.aps
PRMonitor\src\PRMonitor\PRMDlg.rc
PRMonitor\src\PRMonitor\PRMonitor.cpp
PRMonitor\src\PRMonitor\PRMonitor.dsp
PRMonitor\src\PRMonitor\PRMonitor.dsw
PRMonitor\src\PRMonitor\PRMonitor.ncb
PRMonitor\src\PRMonitor\PRMonitor.plg
PRMonitor\src\PRMonitor\resource.h
PRMonitor\src\PRMonitor\_systemtray.ico
PRMonitor\src\PRMonitor
PRMonitor\src
PRMonitor\vc 6.0中开发驱动设备程序配置方法.txt
PRMonitor\样本\DIRS
PRMonitor\样本\HelloDriver\BuildDriver.bat
PRMonitor\样本\HelloDriver\HelloWDM.c
PRMonitor\样本\HelloDriver\MAKEFILE
PRMonitor\样本\HelloDriver\sources
PRMonitor\样本\HelloDriver\Test.dsp
PRMonitor\样本\HelloDriver\Test.dsw
PRMonitor\样本\HelloDriver\Test.plg
PRMonitor\样本\HelloDriver
PRMonitor\样本\文件说明.txt
PRMonitor\样本
PRMonitor