Windows-Rootkits/LoadImageCallBack
2016-08-29 12:54:03 +08:00
..
Dll/Dll Create ReadMe.txt 2016-08-29 12:54:03 +08:00
ReadMe.txt Create ReadMe.txt 2016-08-29 12:52:16 +08:00

use PsSetLoadImageNotifyRoutine to monitor dll load
when dll load , scan it's IAT