-
-
对付DebugPort清零:WRK中全部访问DebugPort的函数总汇。
-
发表于:
2011-7-22 16:45
9382
-
对付DebugPort清零:WRK中全部访问DebugPort的函数总汇。
KiDispatchException //1处
NtQueryInformationProcess //1处
PspCreateProcess //1处
PsGetProcessDebugPort //1处
PsIsProcessBeingDebugged //1处
NtTerminateProcess //1处
PspTerminateProcess //1处
PspExitThread //1处
PspProcessDelete //3处
ObpCloseHandleTableEntry //1处
ObpCloseHandle //1处
MmCreatePeb //1处
DbgkCreateThread //1处
DbgkExitThread //1处
DbgkExitProcess //1处
DbgkMapViewOfSection //1处
DbgkUnMapViewOfSection //1处
DbgkpMarkProcessPeb //1处
DbgkpCloseObject //3处
DbgkCopyProcessDebugPort //4处
DbgkOpenProcessDebugPort //2处
DbgkpQueueMessage //1处
DbgkClearProcessDebugObject //2处
DbgkpSetProcessDebugObject //4处
DbgkForwardException //1处
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课