Windows-Rootkits/CheckKernelEATHook
2016-08-30 09:50:12 +08:00
..
CheckKernelHook Add files via upload 2016-08-30 09:46:35 +08:00
CheckKernelHookDrv Add files via upload 2016-08-30 09:48:50 +08:00
ReadMe.txt Create ReadMe.txt 2016-08-30 09:50:12 +08:00

1.Reload the first kernel module
2.check EAT function (Zwxx) 
3.check InlineHook (not Zwxx)