Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- void *lpOrg_WOW32Dispatcher = nullptr;
- NTSTATUS WINAPIV NtQueryInformationProcess(
- HANDLE ProcessHandle,
- int ProcessInformationClass,
- PVOID ProcessInformation,
- ULONG ProcessInformationLength,
- PULONG ReturnLength )
- {
- __asm mov esp, ebp
- __asm pop ebp
- __asm jmp lpOrg_WOW32Dispatcher
- }
- __declspec( naked ) void hk_WOW32Reserved_Dispatcher( void )
- {
- __asm
- {
- cmp eax, 0x19
- je NtQueryInformationProcess
- jmp lpOrg_WOW32Dispatcher
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement