NTSTATUS __stdcall MyHOOK_NtQueryVirtualMemory( IN HANDLE ProcessHandle, //目标进程句柄 IN PVOID BaseAddress, //目标内存地址 IN MEMORY_INFORMATION_CLASS MemoryInformationClass, //查询内存信息的类别 OUT PVOID Buffer, //用于存储获取到的内存信息的结构地址 IN SIZE_T Length, //Buffer的最大长度 OUT PSIZE_T ResultLength OPTIONAL) //存储该函数处理返回的信息的长度的ULONG的地址
{ NTSTATUS status = STATUS_SUCCESS; PEPROCESS Process;
status = OdNtQueryVirtualMemory(ProcessHandle, BaseAddress, MemoryInformationClass, Buffer, Length, ResultLength);