ntdll.dll导出的,通过int 2e进入内核,在系统服务列表(SDT)中有对应的相同名字的函数入口.
typedef
NTSTATUS
(__stdcall * PFN_ZWSETVALUEKEY)(
IN HANDLE KeyHandle,
IN PUNICODE_STRING ValueName,
IN ULONG TitleIndex,
IN ULONG type1,
IN PVOID Data,
IN ULONG DataSize
);
我有一个程序就是监视注册表的,你可以看看:)
5cfK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4u0W2k6r3y4G2k6r3g2J5i4K6u0W2j5X3I4G2k6#2)9J5k6i4y4G2K9s2g2Q4x3X3g2U0L8$3#2Q4x3V1j5I4y4o6t1I4y4K6V1%4y4#2)9J5k6h3S2@1L8h3H3`.