1 kd> u PsGetCurrentThread 2 3 nt!PsGetCurrentThread: 4 83c6cd19 64a124010000 mov eax,dword ptr fs:[00000124h] 5 83c6cd1f c3 ret 6 83c6cd20 90 nop 7 83c6cd21 90 nop 8 83c6cd22 90 nop 9 83c6cd23 90 nop 10 83c6cd24 90 nop 11 nt!KeReadStateMutant: 12 83c6cd25 8bff mov edi,edi 13 14 15 kd> u KeGetCurrentThread 16 17 nt!PsGetCurrentThread: 18 83c6cd19 64a124010000 mov eax,dword ptr fs:[00000124h] 19 83c6cd1f c3 ret 20 83c6cd20 90 nop 21 83c6cd21 90 nop 22 83c6cd22 90 nop 23 83c6cd23 90 nop 24 83c6cd24 90 nop
1 PETHREAD ethread_ptr += 0xbc;
1 BYTE* byte_ptr += 0xbc;
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课
hzqst 关掉写保护就完事了