能力值:
( LV1,RANK:0 )
|
-
-
2 楼
bool ModifyRegCompetence(LPSTR Group, LPSTR key) { PACL pOldDacl = NULL; PACL pNewDacl = NULL; DWORD dRet; EXPLICIT_ACCESS_A eia; PSECURITY_DESCRIPTOR pSID = NULL; dRet = GetNamedSecurityInfoA(key, SE_REGISTRY_KEY, DACL_SECURITY_INFORMATION, NULL, NULL, &pOldDacl, NULL, &pSID); if (dRet != ERROR_SUCCESS) goto END;
ZeroMemory(&eia, sizeof(EXPLICIT_ACCESS_A)); BuildExplicitAccessWithNameA(&eia, Group, KEY_ALL_ACCESS, SET_ACCESS, SUB_CONTAINERS_AND_OBJECTS_INHERIT);
dRet = SetEntriesInAclA(1, &eia, pOldDacl, &pNewDacl); if (dRet != ERROR_SUCCESS) goto END;
dRet = SetNamedSecurityInfoA(key, SE_REGISTRY_KEY, DACL_SECURITY_INFORMATION, NULL, NULL, pNewDacl, NULL); if (dRet != ERROR_SUCCESS) goto END; END:
if (pNewDacl) LocalFree(pNewDacl); if (pSID) LocalFree(pSID); return 1; }
|
能力值:
( LV1,RANK:0 )
|
-
-
3 楼
你 hook是干啥了?蓝屏显示应该是 校验注册表出问题了
|
能力值:
( LV1,RANK:0 )
|
-
-
4 楼
当检测到ZwCreateKey是创建账号的时候,那么阻止创建账号
|
|
|