void* PsGetCurrentThreadTeb()
{
struct _KTHREAD *Thread; // rcx
void *result; // rax
Thread= KeGetCurrentThread();
if ( Thread->MiscFlags & 0x400 || Thread->ApcStateIndex == 1 )
{
//如果当前线程是系统线程,或者当前线程处于附加的状态
result = NULL;
}
else
{
result = Thread->Teb;
}
return result;
}
PsGetCurrentThreadTeb()
最新推荐文章于 2025-05-31 19:41:15 发布