最近做程序來hook系統(WIN10)的文件刪除操作,本以為就是簡單的DeleteFile接口,試了下發現並不是,也用API monitor等工具跟蹤了也無果,求大神幫忙。
Let's start your job with the NtSetFileInformation (undocumented) function. It's the function called by anything else when a file need to be deleted (with the FileDispositionInformation structure).
Hook這個API試試NtSetFileInformation