__kernel_entry NTSYSCALLAPI NTSTATUS NtOpenProcess(
PHANDLE ProcessHandle,
ACCESS_MASK DesiredAccess,
POBJECT_ATTRIBUTES ObjectAttributes,
PCLIENT_ID ClientId
);
void hftestfunc()
{
HANDLE hProc; OBJECT_ATTRIBUTES oa; CLIENT_ID ci;
memset(&oa, 0, sizeof(oa));
memset(&ci, 0, sizeof(ci));
ci.UniqueProcess = pid;
NtOpenProcess(&hProc, MAXIMUM_ALLOWED, &oa, &ci);
}
重写OpenProcess功能
最新推荐文章于 2024-04-27 19:54:04 发布