Hi
I am hooking Shadow SSDT
got the help from sssdt.h from http://www.kernelmode.info/forum/viewto ... Task#p3368
In the file GetCsrPid() is called to get the pid of csrss.exe and it is called in system context
I am not calling from system context and in GetCsrPid() "NtOpenProcess" is failing with 0XC0000005 for all the process
I don't know why. :(
I am hooking Shadow SSDT
got the help from sssdt.h from http://www.kernelmode.info/forum/viewto ... Task#p3368
In the file GetCsrPid() is called to get the pid of csrss.exe and it is called in system context
I am not calling from system context and in GetCsrPid() "NtOpenProcess" is failing with 0XC0000005 for all the process
I don't know why. :(