利用挂钩线程调度链表来检测进程的代码。基本能查出当前所有Rootkit隐藏的进程。系统编程爱好者必下
buildchk.log
buildchk_wnet_x86.log
buildchk_wxp_x86.log
kmodule.c
Makefile
Myklister.ncb
Myklister.sln
Myklister.sys
Myklister.vcproj
obj
...\_objects.mac
objchk
......\i386
......\....\kmodule.obj
......\....\Myklister.pdb
objchk_wnet_x86
...............\i386
...............\....\kmodule.obj
...............\....\Myklister.pdb
...............\_objects.mac
objchk_wxp_x86
..............\i386
..............\....\kmodule.obj
..............\....\Myklister.pdb
..............\_objects.mac
objfre
......\i386