От: | -prus- | ||
Дата: | 24.03.17 20:50 | ||
Оценка: | +1 |
pva> PsSetLoadImageNotifyRoutine(ModuleImageLoadedNotify);
pva>
pva>void ModuleImageLoadedNotify(PUNICODE_STRING FullImageName, HANDLE ProcessId, PIMAGE_INFO ImageInfo, BOOLEAN Create) {
pva> moduleDebugPrint((__FUNCTION__"(name: %wZ, base: 0x%p, size: 0x%08x, create: %d)\n",
pva> FullImageName, ImageInfo->ImageBase, ImageInfo->ImageSize, Create));
pva>}
Called by the operating system to notify the driver when a driver image or a user image (for example, a DLL or EXE) is mapped into virtual memory
Create [in]
Indicates whether the process was created (TRUE) or deleted (FALSE).
typedef UCHAR BOOLEAN;