in reply to Process Monitor

i was wondering if there is any way to check a process BEFORE it starts.
Is that the same as getting a health check before conception? If the process hasn't started, it isn't there. And there's nothing to check.

Replies are listed 'Best First'.
Re^2: Process Monitor
by iea (Beadle) on Apr 04, 2009 at 16:47 UTC
    Well before windows starts the process it calls NtCreateProcess() or NtCreateSection() and so on... i would like to deny some processes before they are able to start theire code.
    It must be possible to tell windows
    Windows: I want to start this process. Me : Ok ... but please wait i check name and checksum Windows: failed to start process Me: check is ok now i start process xyz || Me : check failed i won't start process

    here my inspiration http://www.codeproject.com/KB/system/soviet_protector.aspx
    thanks for your reply
      here my inspiration
      There is your example.