- 注册时间
 - 2010-8-21
 
- 最后登录
 - 2017-5-30
 
- 在线时间
 - 5 小时
 
 
 
 
 
编程入门 
  
	- 魔鬼币
 - 592 
 
 
 
 | 
 
#include <ntddk.h> 
 
 
NTKERNELAPI 
PVOID 
MmGetSystemRoutineAddress ( 
    __in PUNICODE_STRING SystemRoutineName 
); 
NTKERNELAPI 
NTSTATUS 
PsLookupProcessByProcessId( 
    __in HANDLE ProcessId, 
    __deref_out PEPROCESS *Process 
); 
 
NTKERNELAPI 
NTSTATUS 
NTAPI 
ObOpenObjectByPointer( 
    IN PVOID   Object, 
    IN ULONG   HandleAttributes, 
    IN PACCESS_STATE   PassedAccessState   OPTIONAL, 
    IN ACCESS_MASK   DesiredAccess   OPTIONAL, 
    IN POBJECT_TYPE   ObjectType   OPTIONAL, 
    IN KPROCESSOR_MODE   AccessMode, 
    OUT PHANDLE   Handle 
); 
NTKERNELAPI 
UCHAR * 
PsGetProcessImageFileName( 
    __in PEPROCESS Process 
); 
 
 |   
 
 
 
 |