能力值:
( LV3,RANK:20 )
|
-
-
2 楼
NtCreateUserProcess( PHANDLE ProcessHandle,
PHANDLE ThreadHandle,
ACCESS_MASK ProcessDesiredAccess,
ACCESS_MASK ThreadDesiredAccess,
POBJECT_ATTRIBUTES ProcessObjectAttributes,
POBJECT_ATTRIBUTES ThreadObjectAttributes,
ULONG CreateProcessFlags,
ULONG CreateThreadFlags,
PRTL_USER_PROCESS_PARAMETERS ProcessParameters,
PVOID Parameter9,
PVOID AttributeList)
最后倒数第三个参数应该是你想获取的吧
|
能力值:
( LV2,RANK:10 )
|
-
-
3 楼
这年头就不要在HOOK SSDT了吧?
|
能力值:
( LV7,RANK:110 )
|
-
-
4 楼
现在能用回调解决的就不用hook
|
能力值:
( LV2,RANK:10 )
|
-
-
5 楼
想了下……你肯定要干坏事……
|
|
|