Description: Correlation function of the process HOOK code VOID DisplayProcess () listing process VOID DisplayThread () listing thread ULONG GetCidAddr () listing process needs Cid Table DWORD GetDllFunctionAddress () active defense be the path through the handle PVOID GetDriverBaseAdress () DWORD base address for the specified drive GetPlantformDependentInfo () to obtain platform information BOOL GetProcessName () handle to get through the main anti-process name ULONG GetProcessType () handle to get through the process of type int GetProNum () Get the current number of processes PTHREAD_INFO GetThread () Get thread information BOOL GoOrNot () primary prevention allows users to determine whether the release VOID IsValidProcess () record process information
To Search:
File list (Check if you may need any files):
KsBinSword\KsBinSword.dsw
..........\KsBinSword.dsp
..........\buildchk_wxp_x86.log
..........\dbghelp.h
..........\readme.txt
..........\sources
..........\makefile
..........\ddkbuild.bat
..........\ntifs.h
..........\KBSProcess.c
..........\KBSscsi.c
..........\KsBinSword.plg
..........\KsBinSword.h
..........\KsBinSword.c
..........\KBSmon.c
..........\KsBinSword.suo
KsBinSword