///========= 3. 检测ProcessDebugFlags ==========///
#ifdef _WIN64
DWORD32 dwIsDebug = 0;
status = NtQueryInformationProcess(
ProcHandle, // 进程句柄
ProcessDebugFlags, // 调试标志
&dwIsDebug, // 如果当前被调试,isDebuggerPresent的值为0
sizeof(dwIsDebug), // 缓冲区大小
&returnLength // 实际返回进程信息的大小
);
cout << "NtQueryInformationProcess返回状态:" << hex << status << endl;
cout << "isDebuggerPresent:" << hex << dwIsDebug << endl;
if (status == STATE_SUCCUSS && dwIsDebug == 0) {
return true;
}
#else
DWORD32 dwIsDebug = 0;
status = NtQueryInformationProcess(
ProcHandle, // 进程句柄
ProcessDebugFlags, // 调试标志
&dwIsDebug, // 如果当前被调试,isDebuggerPresent的值为0
sizeof(dwIsDebug), // 缓冲区大小
&returnLength // 实际返回进程信息的大小
);
cout << "NtQueryInformationProcess返回状态:" << hex << status << endl;
cout << "isDebuggerPresent:" << hex << dwIsDebug << endl;
if (status == STATE_SUCCUSS && dwIsDebug == 0) {
return true;
}
#endif // _WIN64
return false;
}
64程序总是返回0xFFFFFFFFC0000004的状态码
STATUS_INFO_LENGTH_MISMATCH (0xC0000004):
这个错误表示传递的缓冲区大小不正确
ProcessDebugFlags 需要 4字节 的缓冲区,但您传递的是 sizeof(ULONG_PTR)
在64位系统上,sizeof(ULONG_PTR) 是8字节,导致了大小不匹配
最后于 2025-12-4 17:26
被CreateSun编辑
,原因: