struct Query_Pass
{
char ProcessName[256];
int PID; //进程PID
int TID; //线程TID
int LoadDriver; //是否加载驱动
int CreateRemoteThread; //是否创建远程线程
int CreatePro; //是否创建敏感进程
int FileOperation; //是否操作敏感文件夹
int RegOperation; //是否操作敏感注册表
int ConnectInternet;
char Pid[16];
char Tid[16];
BOOL IsMulware;
};