能力值:
( LV2,RANK:10 )
|
-
-
2 楼
#define CI_DLL "ci.dll" #define CI_PATTERN "89 0D ? ? ? ? 49 8B F8" #define NTOS_EXE "ntoskrnl.exe" #define NTOS_PATTERN "C6 05 ? ? ? ? ? 8D 7B 06" /* Initialize Dynamic Data */ if (dwBuildNumber < 9200) // Windows 7 { ImageName = NTOS_EXE; // Global Variable Is Located In ntoskrnl.exe VariablePattern = NTOS_PATTERN; AddressOffset = 7; } else // Rest of the supported OS { ImageName = CI_DLL; // Global Variable Is Located In CI.dll VariablePattern = CI_PATTERN; AddressOffset = 6; } 在ida里面搜一下这个特征码就行了
|
|
|