[摘要]'X' != pIndx->bDirID [3] ) { return ; }while ( TRUE ) { if ( ( (ULONG)( pIndxA... 'X' != pIndx->bDirID [3] ) { return ; } while ( TRUE ) { if ( ( (ULONG)( pIndxAttr ) - (ULONG)(pIndx) ) >= pIndx->dwUseSize ) { if ( 0 == uAlcSize - ( pIndx->dwAllocSize + 0x18 ) ) break; else { uAlcSize -= ( pIndx->dwAllocSize + 0x18 ); pIndx = ( LPINDX )( (LPSTR)pIndx + ( pIndx->dwAllocSize+ 0x18 ) ); if ( 'I' != pIndx->bDirID [0] |
关键词: 基于Cache的隐藏文件(与注册表)检测的一些思路