[{"title":"(9个子文件8KB)ring0驱动级隐藏进程的源代码_在驱动层通过替换ssdt地址表中的api函数来隐藏进程","children":[{"title":"hideprocess","children":[{"title":"objfre","children":[{"title":"i386","children":[{"title":"WinHook.sys <span style='color:#111;'>3.25KB</span>","children":null,"spread":false}],"spread":true}],"spread":true},{"title":"20080220_e94b685e8ade47350e9cb35XBZPwEgnQ.txt <span style='color:#111;'>0B</span>","children":null,"spread":false},{"title":"Sources <span style='color:#111;'>122B</span>","children":null,"spread":false},{"title":"WinHook.dsw <span style='color:#111;'>539B</span>","children":null,"spread":false},{"title":"WinHook.dsp <span style='color:#111;'>3.33KB</span>","children":null,"spread":false},{"title":"buildfre.log <span style='color:#111;'>2.02KB</span>","children":null,"spread":false},{"title":"WinHook.c <span style='color:#111;'>8.27KB</span>","children":null,"spread":false},{"title":"Makefile <span style='color:#111;'>46B</span>","children":null,"spread":false},{"title":"WinHook.h <span style='color:#111;'>3.01KB</span>","children":null,"spread":false}],"spread":true}],"spread":true}]