楼主小白一个 伸手党 大家高抬贵手
typedef struct _INSIDE_ADDR_
{
DWORD PspGetSetContextSpecialApc;//ok
DWORD DbgkForwardException;//
DWORD PsResumeThread;
DWORD PsSuspendThread;
DWORD ObDuplicateObject;
DWORD KeFreezeAllThreads;
DWORD KeThawAllThreads;
DWORD PspUserThreadStartup;
DWORD PspExitThread;
DWORD DbgkMapViewOfSection;
DWORD DbgkUnMapViewOfSection;
DWORD KiDispatchException;
DWORD PsGetNextProcessThread;
DWORD PsSuspendProcess;
DWORD PsResumeProcess;
DWORD KiAttachProcess;
DWORD KiSwapProcess;
DWORD KiMoveApcState;
DWORD ObpReferenceSecurityDescriptor;
DWORD ObpRemoveObjectRoutine;
DWORD MmGetFileNameForAddress;
DWORD MmGetFileNameForSection;
DWORD ExMapHandleToPointerEx;
DWORD ObpKernelHandleTable;
DWORD ObpTranslateGrantedAccessIndex;
DWORD ObpAuditObjectAccess;
DWORD ExpGetHandleInfo;
//DWORD KeInterlockedSwapPte;////////////////////////没解析出来
DWORD MmAccessFault;
DWORD ObClearProcessHandleTable;
//DWORD PspTerminateProcess;/////////////////////////没解析出来
DWORD KdSendPacket;
DWORD KdRecvPacket;
//DWORD DbgkpSectionToFileHandle;
}INSIDEADDR,*PINSIDEADDR;
驱动编译:
我是makefile加了这个
MSC_WARNING_LEVEL=/W1
然后删了重定义
还有删了2处 v;乱码的函数申明
环境是win7 32 这两个函数貌似是没有的把
、、备注:
大神们其他的源码 我都编译成功了
在xp环境下测试 要不没效果 要不蓝屏
dvpDebug xp下 开启框架 符号解析好后蓝屏 或者时间久了 关了吧
总之,源码基本没看 就看了agp
好了睡觉 今晚继续测试
[课程]FART 脱壳王!加量不加价!FART作者讲授!