(Main functions 1. Process, thread, process module, process window, process memory information view, hot key information view, kill process, kill thread, uninstall module and other functions 2. Kernel driver module view, support memory copy of kernel driver module 3. View SSDT, ShadowSSDT, FSD, KBD, TCPIP, IDT information, and can view and restore NotifyRoutine information such as ssdthook and inlinehook4.CreateProcess, CreateThread, LoadImage, CmpCallback, BugCheckCallback, Shutdown, Lego, etc., and support the deletion of these NotifyRoutines5 .Port information view, currently does not support 2000 system 6. View message hooks 7. View and restore iat, eat, inlinehook, patches of kernel modules . Registry correction 10. Process iat, eat, inlinehook, patches view and restore 11. File system view, support basic file operations 12. View (amend) IE plug-ins, SPI, startup items, services, H/OST files, images Kidnapping, file association 13. ObjectTypeHook view and restore 14. DPC timer view and delete 15: Configuration tools: prevent the creation of threads, processes, files, registry values, load modules, inject message hooks, prevent standby, publication, shutdown , restart, fix system time, switch desktop, lock computer, prevent resetting registry value Shutdown: force restart Other: window on top)