能力值:
( LV5,RANK:70 )
|
-
-
2 楼
RtlSetProcessIsCritical-->ZwQueryInformationProcess(ProcessBreakOnTermination)
|
能力值:
( LV3,RANK:20 )
|
-
-
3 楼
_EPROCESS里边的flag.看wrk里边NtTerminateProcess,有breakonterminate
if (Process->Flags & PS_PROCESS_FLAGS_BREAK_ON_TERMINATION) {
PspCatchCriticalBreak ("Terminating critical process 0x%p (%s)\n",
Process,
Process->ImageFileName);
}
|
能力值:
( LV2,RANK:10 )
|
-
-
4 楼
感谢两位大侠的指点~~
|
能力值:
( LV4,RANK:50 )
|
-
-
5 楼
NtSetInformationProcess
|
能力值:
( LV4,RANK:50 )
|
-
-
6 楼
b0cK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6h3q4G2k6$3!0K6L8$3k6@1i4K6u0W2j5$3!0E0i4K6u0r3j5X3u0K6i4K6u0r3N6X3W2W2N6#2)9J5k6h3q4K6M7q4)9K6c8X3W2V1i4K6y4p5x3K6f1H3y4U0f1`.
|
|
|