HollowsHunter
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
Go to the source code of this file.
Functions | |
bool | suspend_process (DWORD processId) |
bool | resume_process (DWORD processId) |
bool | is_process_associated (DWORD remote_pid) |
DWORD | GetParentProcessID (DWORD dwPID) |
DWORD GetParentProcessID | ( | DWORD | dwPID | ) |
Definition at line 70 of file suspend.cpp.
bool is_process_associated | ( | DWORD | remote_pid | ) |
bool resume_process | ( | DWORD | processId | ) |
Definition at line 26 of file suspend.cpp.
bool suspend_process | ( | DWORD | processId | ) |
Definition at line 7 of file suspend.cpp.