Etw - Event Tracing for Windows


There are only a few Etw routines (33 in Windows 2003 Server). This group includes the following:

  • EtwTraceEvent

  • EtwEnableTrace

  • EtwGetTraceEnableLevel

  • EtwGetTraceEnableFlags

If you are hooking trace operations, you will need to look further into the Etw functional group.




Professional Rootkits
Professional Rootkits (Programmer to Programmer)
ISBN: 0470101547
EAN: 2147483647
Year: 2007
Pages: 229
Authors: Ric Vieler

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net