Hello everyone
I know one method to confirm is "process comndlinearg" running is when process is loading it can make a file and that we can check...but am not satisfied since user may remove the file. I would like to know any other way to which can process can create in some stuff in kernal
any thoughts guys?
Bookmarks