摘要
主要论述了Windows系统服务概念及如何通过HOOK系统服务对应的内核API函数ZwQueryDirectoryFile、ZwCreateFile等实现文件(夹)的隐藏、防打开、防删除等操作,并给出了相应的驱动程序示意例程。
Windows system service is explained, and how to hook corresponding native API to protect some file (directory) from being seen, opened and deleted. The routine in driver is demonstrated also.
出处
《河北省科学院学报》
CAS
2007年第2期15-17,21,共4页
Journal of The Hebei Academy of Sciences