能力值:
( LV2,RANK:10 )
|
-
-
2 楼
MyNtOpenProcessProc:
pushad
pushfd
invoke GetModuleHandleEx,4,[esp+40h+24h+4],offset ModuleBase
.if eax != 0
invoke GetModuleBaseName,-1,ModuleBase,offset ModuleName,100
.if eax != 0
invoke lstrcmp,$CTA0("yyyyyyyyyyyy.dll"),offset ModuleName
.if eax == 0
popfd
popad
xor eax,eax
ret
.endif
invoke lstrcmp,$CTA0("xxxxxxxxxxx.dll"),offset ModuleName
.if eax == 0
popfd
popad
xor eax,eax
ret
.endif
.endif
.endif
popfd
popad
jmp dword ptr ds:[7FFE0300h]
|
能力值:
( LV12,RANK:760 )
|
-
-
3 楼
还是R3简单!
|
|
|