-
-
对付DebugPort清零:WRK中全部访问DebugPort的函数总汇。
-
发表于:
2011-7-22 16:45
9383
-
对付DebugPort清零:WRK中全部访问DebugPort的函数总汇。
KiDispatchException //1处
NtQueryInformationProcess //1处
PspCreateProcess //1处
PsGetProcessDebugPort //1处
PsIsProcessBeingDebugged //1处
NtTerminateProcess //1处
PspTerminateProcess //1处
PspExitThread //1处
PspProcessDelete //3处
ObpCloseHandleTableEntry //1处
ObpCloseHandle //1处
MmCreatePeb //1处
DbgkCreateThread //1处
DbgkExitThread //1处
DbgkExitProcess //1处
DbgkMapViewOfSection //1处
DbgkUnMapViewOfSection //1处
DbgkpMarkProcessPeb //1处
DbgkpCloseObject //3处
DbgkCopyProcessDebugPort //4处
DbgkOpenProcessDebugPort //2处
DbgkpQueueMessage //1处
DbgkClearProcessDebugObject //2处
DbgkpSetProcessDebugObject //4处
DbgkForwardException //1处
[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)