-
-
[旧帖] [求助]x64 Hook NtCreateThreadEx 0.00雪花
-
发表于: 2016-5-19 16:06 2021
-
在x64上HookNtCreateThreadEx后,打不开文件夹和软件,求解是参数有问题吗?
typedef DWORD (*LPTHREAD_START_ROUTINE) (LPVOID lpThreadParameter); typedef NTSTATUS (*PFNTCREATETHREADEX) ( PHANDLE ThreadHandle, ACCESS_MASK DesiredAccess, POBJECT_ATTRIBUTES ObjectAttributes, HANDLE ProcessHandle, LPTHREAD_START_ROUTINE lpStartAddress, PVOID lpParameter, BOOL CreateSuspended, SIZE_T ZeroBits OPTIONAL, SIZE_T StackSize OPTIONAL, SIZE_T MaximumStackSize OPTIONAL, PVOID AttributeList ); PFNTCREATETHREADEX MyNtCreateThreadEx = NULL; ULONG OldTpVal; NTSTATUS Fake_NtCreateThreadEx( PHANDLE ThreadHandle, ACCESS_MASK DesiredAccess, POBJECT_ATTRIBUTES ObjectAttributes, HANDLE ProcessHandle, LPTHREAD_START_ROUTINE lpStartAddress, PVOID lpParameter, BOOL CreateSuspended, SIZE_T ZeroBits, SIZE_T StackSize, SIZE_T MaximumStackSize OPTIONAL, PVOID AttributeList ) { DbgPrint("11111\n"); return MyNtCreateThreadEx(ThreadHandle, DesiredAccess, ObjectAttributes, ProcessHandle, lpStartAddress, lpParameter, CreateSuspended, ZeroBits, StackSize, MaximumStackSize, AttributeList); }
赞赏
他的文章
- [分享]只为学习。只为进步。只为交流 。 1201
- [求助]没加壳软件的难题 808
- [求助]请教DLL的问题! 1041
- [求助]使用OD加载外挂出现这种情况... 1354
看原图
赞赏
雪币:
留言: