能力值:
( LV2,RANK:10 )
|
-
-
2 楼
static void init_win7() { name = 0x2D8; pid = 0x180; base = 0x270; link = 0x188; protection = 0x43C; flags2 = 0; objecttable = 0x200; vadroot = 0x448; }
源代码太长了,是关于进程保护的。驱动我只会输出helloworld,所以求助大家了!
|
能力值:
( LV4,RANK:45 )
|
-
-
3 楼
找相应版本的内核文件,下载PDB然后用PDB分析工具转成头文件,然后CTRL+F,找具体的偏移就行了
|
能力值:
( LV2,RANK:10 )
|
-
-
4 楼
ookkaa
找相应版本的内核文件,下载PDB然后用PDB分析工具转成头文件,然后CTRL+F,找具体的偏移就行了
找不到……
|
能力值:
( LV2,RANK:10 )
|
-
-
5 楼
8aeK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3u0D9L8$3N6Q4x3X3g2K6K9h3&6S2i4K6u0W2j5$3!0E0i4K6u0W2j5$3&6Q4x3V1k6K6i4K6u0r3j5X3I4G2k6#2)9#2k6U0k6W2y4o6j5@1x3K6p5K6x3o6p5H3x3h3x3J5x3Y4y4Q4x3X3g2Z5N6r3#2D9i4K6t1$3L8X3u0K6M7q4)9K6b7W2)9J5y4X3&6T1M7%4m8Q4x3@1u0Q4x3U0k6F1j5Y4y4H3i4K6y4n7i4@1f1^5i4@1u0r3i4K6V1&6i4@1f1@1i4@1t1^5i4@1q4m8i4@1f1$3i4K6V1^5i4@1q4r3i4K6t1$3L8X3u0K6M7q4)9K6b7Y4N6A6L8U0N6Q4c8e0N6Q4z5f1q4Q4z5o6c8Q4x3U0k6F1j5Y4y4H3i4K6y4n7i4@1f1@1i4@1u0p5i4K6R3$3i4@1f1$3i4K6V1^5i4@1q4r3i4@1f1#2i4@1p5#2i4@1u0p5i4@1f1#2i4K6R3K6i4K6S2r3i4@1f1&6i4K6R3K6i4@1p5^5i4@1f1#2i4K6R3^5i4K6R3$3i4@1f1^5i4@1t1%4i4K6W2r3i4@1f1$3i4@1u0m8i4K6V1H3i4@1f1%4i4@1p5H3i4K6R3I4i4@1f1&6i4K6R3%4i4K6S2o6i4@1f1&6i4K6W2p5i4@1p5J5i4@1f1%4i4K6W2m8i4K6R3@1i4@1f1@1i4@1t1^5i4K6S2p5i4@1f1@1i4@1t1^5i4K6R3H3i4@1f1$3i4@1p5H3i4@1t1%4i4@1g2r3i4@1u0o6i4K6S2o6N6$3W2F1x3e0m8Q4c8e0N6Q4z5f1q4Q4z5o6c8Q4c8e0k6Q4z5o6S2Q4z5e0q4Q4c8e0k6Q4z5o6W2Q4b7V1g2Q4c8e0c8Q4b7U0S2Q4z5p5c8Q4c8e0g2Q4z5o6S2Q4b7U0l9`.
|
能力值:
( LV4,RANK:45 )
|
-
-
6 楼
大鲤鱼
3f1K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3u0D9L8$3N6Q4x3X3g2K6K9h3&6S2i4K6u0W2j5$3!0E0i4K6u0W2j5$3&6Q4x3V1k6K6i4K6u0r3j5X3I4G2k6#2)9#2k6U0k6W2y4o6j5@1x3K6p5K6x3o6p5H3x3h3x3J5x3Y4y4Q4x3X3g2Z5N6r3#2D9 这个是 win7的 但是好像部分跟源码里面的不一样,win10的我找不到
我不是发你了两个文件,直接记事本打开CTRL+F
|
能力值:
( LV4,RANK:45 )
|
-
-
7 楼
大鲤鱼
31aK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3u0D9L8$3N6Q4x3X3g2K6K9h3&6S2i4K6u0W2j5$3!0E0i4K6u0W2j5$3&6Q4x3V1k6K6i4K6u0r3j5X3I4G2k6#2)9#2k6U0k6W2y4o6j5@1x3K6p5K6x3o6p5H3x3h3x3J5x3Y4y4Q4x3X3g2Z5N6r3#2D9 这个是 win7的 但是好像部分跟源码里面的不一样,win10的我找不到
/*0x418*/ struct _HANDLE_TABLE* ObjectTable; 这不是很简单吗
|
能力值:
( LV2,RANK:10 )
|
-
-
8 楼
ookkaa
/*0x418*/ struct _HANDLE_TABLE* ObjectTable;
这不是很简单吗
19041的,我刚才装了下虚拟机,测试生效了。但是你的另一份:1809对应的17736,源代码里面已经有了哈。缺少1903 1909 20H2 21H1,这几个你有吗?
|
能力值:
( LV4,RANK:45 )
|
-
-
9 楼
没有,你自己都下一遍虚拟机,要么github搜一下
|
能力值:
( LV2,RANK:10 )
|
-
-
10 楼
ookkaa
没有,你自己都下一遍虚拟机,要么github搜一下
网速好慢啊……装个虚拟机老半天。网上应该有人总结这个才好……
|
能力值:
( LV2,RANK:10 )
|
-
-
11 楼
我已经自己 安装虚拟机,把剩下的4个版本代码都找出来了。
|
|
|