阅读:1191回复:1
关于获得远程 访问进程问题!!!
PCWSTR GetCurrentProcessFileName()
{ PCWSTR processfullname = NULL ; processfullname = (PCWSTR)PsGetCurrentProcess() + 0x1B0; DbgPrint("%s----------------1--progress_name\n", (char*)processfullname); processfullname += 0x10; DbgPrint("%s----------------2--progress_name\n", (char*)processfullname); processfullname += 0x3C; DbgPrint("%s----------------3--progress_name\n", (char*)processfullname); DbgPrint("%ws----------------4--progress_name\n", (PCWSTR)PsGetCurrentProcess()); return(PCWSTR)processfullname; } //我得到的是乱码啊 郁闷中!!!! ![]() |
|
|
驱动老牛
![]() |
沙发#
发布于:2005-07-21 13:05
如果是远程访问,当前进程是空的。
|
|