> I would definitely enjoy finding this value in the
EPROCESS - the only thing there I’ve ever seen is
the eyecatcher name, not the full path name.
I would definitely enjoy finding this value in the EPROCESS - the
only thing there I’ve ever seen is the eyecatcher name, not the full
path name.
There is pointer to section object (maybe it was handle in Win2000),
you can get SEGMENT pointer from that, then CONTROL_AREA, then
FileObject.
L.