《Rootkits——Subverting the Windows Kernel》第226页有详细讲述 网上也有相关代码,基本上是从这本书里来的,比如: 2a2K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3u0D9L8$3N6Q4x3X3g2U0M7$3c8F1i4K6u0W2L8X3g2@1i4K6u0r3L8r3g2A6N6r3W2S2L8X3A6#2L8W2)9J5c8X3q4J5N6r3W2U0L8r3g2Q4x3V1k6V1k6i4c8S2K9h3I4K6i4K6u0r3y4K6t1$3z5e0b7^5y4W2)9K6c8X3I4G2j5$3q4@1K9h3!0F1e0Y4g2E0i4K6y4p5x3e0l9`.