![]() |
|
#4
|
|||
|
|||
|
Dear fyyre. I found out your hidecon example. Is it implemented by "just remove process from linked list and/or handle table"?
I still want to know a solution to locate the hooked function to the segment of SSDT table. Anybody to help me? |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Hiding a process | securedsolutions | x64 OS | 5 | 08-29-2013 17:59 |
| SSDT in Windows Vista/7 x86 | _MAX_ | General Discussion | 3 | 08-30-2012 02:56 |
| Best rootkit for win7? | suddenLy | General Discussion | 10 | 03-25-2011 08:52 |