作者: Peter Szor
DOI:
关键词:
摘要: A kernel mode memory scanning driver for use in safely loaded drivers the of computer systems utilizing Windows® NT based operating systems, such as 2000, XP, and other base, viruses. Prior to viruses, hooks a unload function system, stalls any calls prevent from being unloaded during scanning. After is complete, stalled are released. In one embodiment, implemented 4.0 driver, thus can be used on 2000 or without platform specific code.