以下是编译信息
OACR monitor running already
C:\WinDDK\7600.16385.1>cd c:\3\
C:\3>build
BUILD: Compile and Link for x86
BUILD: Loading c:\winddk\7600.16385.1\build.dat...
BUILD: Computing Include file dependencies:
BUILD: Start time: Fri Dec 03 16:43:29 2010
BUILD: Examining c:\3 directory for files to compile.
c:\3 Invalidating OACR warning log for 'root:x86chk'
BUILD: Saving c:\winddk\7600.16385.1\build.dat...
BUILD: Compiling and Linking c:\3 directory
Configuring OACR for 'root:x86chk' - <OACR on>
_NT_TARGET_VERSION SET TO WINXP
Compiling - procguard.c
Linking Executable - objchk_wxp_x86\i386\processesguard.sys
1>errors in directory c:\3
1>c:\3\procguard.obj : error LNK2019: unresolved external symbol __imp__ZwWriteV
irtualMemory@20 referenced in function _DriverEntry@8
1>c:\3\objchk_wxp_x86\i386\processesguard.sys : error LNK1120: 1 unresolved exte
rnals
BUILD: Finish time: Fri Dec 03 16:43:32 2010
BUILD: Done
3 files compiled - 13 Warnings
1 executable built - 2 Errors
C:\3>
这个是我的函数定义
我不知道错在哪里
帮忙看下 谢谢了
typedef struct _DEVICE_EXTENSION
{
PDEVICE_OBJECT pDevObj;
UNICODE_STRING uniSymLink;
PMDL pMdl;
PULONG pulSSDTMapped;
}DEVICE_EXTENSION, *PDEVICE_EXTENSION;
typedef NTSTATUS (*ZWOPENPROCESS)(
OUT PHANDLE ProcessHandle,
IN ACCESS_MASK DesiredAccess,
IN POBJECT_ATTRIBUTES ObjectAttributes,
IN PCLIENT_ID PCLIENT_ID OPTIONAL
);
typedef NTSTATUS (__stdcall *ZWOPENTHREAD) (
OUT PHANDLE ProcessHandle,
IN ACCESS_MASK DesiredAccess,
IN POBJECT_ATTRIBUTES ObjectAttributes,
IN PCLIENT_ID PCLIENT_ID OPTIONAL
);
NTSYSAPI
NTSTATUS
NTAPI
ZwOpenThread( OUT PHANDLE ProcessHandle,
IN ACCESS_MASK AccessMask,
IN POBJECT_ATTRIBUTES ObjectAttributes,
IN PCLIENT_ID ClientId);
typedef NTSTATUS (__stdcall *ZWWRITEVIRTUALMEMORY) (
IN HANDLE ProcessHandle,
IN PVOID BaseAddress,
IN PVOID Buffer,
IN ULONG NumberOfBytesToWrite,
OUT PULONG NumberOfBytesWritten OPTIONAL
);
NTSYSAPI
NTSTATUS
NTAPI
ZwWriteVirtualMemory( IN HANDLE ProcessHandle,
IN PVOID BaseAddress,
IN PVOID Buffer,
IN ULONG NumberOfBytesToWrite,
OUT PULONG NumberOfBytesWritten OPTIONAL);
这个是我的函数定义
我不知道错在哪里
帮忙看下 谢谢了
[课程]FART 脱壳王!加量不加价!FART作者讲授!