Win 32 API 调用 Kernel mode User mode Application NTExecutives Kernel 32. dll (Create. File. W) Int 2 E Ntdll. dll (Zw. Create. File) Ki. Service. Table (Nt. Create. File)
类型 User-Mode API 截获 Kernel-Mode 数据结构修改
检测Rootkit Offline OS检测 API副作用检测 Rootkit检测 具 Strider/Ghostbuster,MS Research Rootkit. Revealer,Sysinternals