阅读:1126回复:0
请教:如何获得一个内核函数的入口地址?
dprintf("Address:%08X",PsSetLoadImageNotifyRoutine);
出来的结果是: Address:F9Fa89B2 而不是WinDbg中“u PsSetLoadImageNotifyRoutine”出来的地址 lkd> u PsSetLoadImageNotifyRoutine nt!PsSetLoadImageNotifyRoutine: 805cfa34 8bff mov edi,edi 805cfa36 55 push ebp 805cfa37 8bec mov ebp,esp 805cfa39 53 push ebx 805cfa3a 57 push edi 805cfa3b 33ff xor edi,edi 805cfa3d 57 push edi 805cfa3e ff7508 push dword ptr [ebp+0x8] 请高手指教一下,小菜感激不尽! ![]() |
|
|