驱动层虚拟机检测参考爱写驱动的女装大佬
#include <ntddk.h>#include <windef.h>typedef struct _SYSTEM_MODULE_INFORMATION{ HANDLE Section; PVOID MappedBase; PVOID base; ULONG Size; ULONG Flags; USHORT LoadOrderIndex; ...