Intercept and Cleanup Message Hooks in Windows Operating System

郭津之,龙海,黄皓
DOI: https://doi.org/10.16208/j.issn1000-7024.2009.18.036
2009-01-01
Abstract:To prevent code injection by using message hook,a method of intercepting message hook and clean up the message hook objects in kernel mode is introduced based on analyzing Windows system service and message hook mechanism.Compared to current methods,this method can prevent intercept and cleanup from being bypassed by malware and works more effectively.Experiment proved that the method can prevent code injection effectively.
What problem does this paper attempt to address?