能力值:
( LV2,RANK:10 )
|
-
-
2 楼
PsGetProcessExitStatus
|
能力值:
( LV9,RANK:210 )
|
-
-
3 楼
够冷够强悍!这个API,好象不支持2000,PsGetProcessExitTime又不够精确
|
能力值:
( LV9,RANK:610 )
|
-
-
4 楼
判断ObjectTable是否为0
|
能力值:
( LV9,RANK:210 )
|
-
-
5 楼
每个系统的结构又不同 算了自己写吧 看来没好的通用的了
|
能力值:
( LV5,RANK:60 )
|
-
-
6 楼
NotifyRoutine
|
能力值:
( LV9,RANK:210 )
|
-
-
7 楼
PULONG PsGetProcessObjectTable(ULONG mPEPROCESS)
{
ULONG result;
if (yourWinVer==WINDOWS_VERSION_2K)
{
memmove(&result,(PULONG)(mPEPROCESS+0x128),4);
}
else
{
if ((yourWinVer==WINDOWS_VERSION_XP)||(yourWinVer==WINDOWS_VERSION_2K3))
{
memmove(&result,(PULONG)(mPEPROCESS+0x0c4),4);
}
else
{
if (yourWinVer==WINDOWS_VERSION_2K3_SP1_SP2)
{
memmove(&result,(PULONG)(mPEPROCESS+0x0d4),4);
}
else
{
if (yourWinVer==WINDOWS_VERSION_VISTA)
{
memmove(&result,(PULONG)(mPEPROCESS+0x0dc),4);
}
else
{
result=0;
}
}
}
}
return (PULONG)result;
}
|
能力值:
( LV12,RANK:420 )
|
-
-
8 楼
ZwQueryInformationProcess ProcessBasicInformation->ExitStatus
标准做法
|
能力值:
( LV2,RANK:10 )
|
-
-
9 楼
如果该进程ID又被新的进程占用了呢
|
|
|