mirror of
https://github.com/ciyze0101/Windows-Rootkits
synced 2024-06-26 00:38:06 +00:00
|
||
---|---|---|
.. | ||
Dll | ||
inject | ||
LoadImageCallBack | ||
ReadMe.txt |
use PsSetLoadImageNotifyRoutine to monitor dll load when dll load , scan it's IAT