Filename | Size | Date |
---|
【专题四】Rootkit的学习与研究\Read me.txt |
.............................\.ootkit\1。 内核hook\1)object hook\1)object hook.doc |
.............................\.......\............\2)ssdt hook\2)ssdt hook.doc |
.............................\.......\............\............\SSDT Hook的妙用-对抗ring0 inline hook .doc |
.............................\.......\............\............\swk0207\swk0207.Asm |
.............................\.......\............\............\.......\swk0207.Inc |
.............................\.......\............\............\swk0207.rar |
.............................\.......\............\3)inline-hook\360SuperKill学习之--恢复FSD的IRP处理函数.doc |
.............................\.......\............\..............\3)inline-hook.doc |
.............................\.......\............\..............\cnnic\cdnprot.idb |
.............................\.......\............\..............\.....\cdnprot.sys |
.............................\.......\............\..............\cnnic.rar |
.............................\.......\............\..............\ExpLookupHandleTableEntry.rar |
.............................\.......\............\..............\.........................2\Windows句柄表格式(2) - XP句柄表格式.mht |
.............................\.......\............\..............\..........................\【讨论】句柄啊,3层表啊,ExpLookupHandleTableEntry啊___[已解决] - 看雪软件安全论坛.mht |
.............................\.......\............\..............\..........................\句柄啊,3层表啊,ExpLookupHandleTableEntry啊___[已解决] DebugMan.mht |
.............................\.......\............\..............\ExpLookupHandleTableEntry2.rar |
.............................\.......\............\..............\kill_SecuritySoftware\sudami.exe |
.............................\.......\............\..............\kill_SecuritySoftware.rar |
.............................\.......\............\..............\PsLookupProcessByProcessId执行流程学习笔记.doc |
.............................\.......\............\..............\句柄啊,3层表啊,ExpLookupHandleTableEntry啊.doc |
.............................\.......\............\..............\干掉KV 2008 | Rising等大部分杀软.doc |
.............................\.......\............\..............\搜索未导出的函数地址.doc |
.............................\.......\............\4)idt hook\bhwin_keysniff.rar |
.............................\.......\............\...........\IDT Hook .doc |
.............................\.......\............\5)IRP hook\5)IRP hook.doc |
.............................\.......\............\...........\5)IRP hook.rar |
.............................\.......\............\...........\irphook1\irphook1\buildfre_wxp_x86.log |
.............................\.......\............\...........\........\........\irphook.c |
.............................\.......\............\...........\........\........\irphook.c.bak |
.............................\.......\............\...........\........\........\MAKEFILE |
.............................\.......\............\...........\........\........\obj\_objects.mac |
.............................\.......\............\...........\........\........\...fre_wxp_x86\i386\irphook.obj |
.............................\.......\............\...........\........\........\..............\....\irphook.pdb |
.............................\.......\............\...........\........\........\..............\....\irphook.sys |
.............................\.......\............\...........\........\........\..............\_objects.mac |
.............................\.......\............\...........\........\........\SOURCES |
.............................\.......\............\...........\irphook1.rar |
.............................\.......\............\...........\.......2\Src\bin\i386\Klog.pdb |
.............................\.......\............\...........\........\...\...\....\Klog.sys |
.............................\.......\............\...........\........\...\buildfre_wxp_x86.log |
.............................\.......\............\...........\........\...\KbdHook.cpp |
.............................\... |