Description: Killer.sys用DriverMonitor加载,KillerIoCTL.exe是通信程序。输入ProcessID结束进程
可终止卡巴,毒霸,360,冰刃,PowerTool,PcHunter等。
果然不能终止江民,在PsLookupProcessByProcessId()这步读取进程的EProcess失败,想必江民在这里挂了钩。
下一步准备搜索PsLookupProcessByProcessId恢复钩子试试看。-Killer.sys DriverMonitor KillerIoCTL.exe is loaded, the communication program. The input end of the process of ProcessID.
Termination of Kaba, 360, Duba, ice, PowerTool, PcHunter.
I can t stop Jiangmin, in PsLookupProcessByProcessId (EProcess) that reads the process failed, presumably Jiangmin here hanging hook.
The next step is to search the PsLookupProcessByProcessId recovery hooks to try.
Platform: |
Size: 34816 |
Author:薛晨曦 |
Hits: