fu.h

来自「windows rootkit,可以列举出内核驱动程序以及就可以把自己的.sys」· C头文件 代码 · 共 36 行

H
36
字号
///////////////////////////////////////////////////////////////////////////////////////
// Filename fu.h
// 
// Author: fuzen_op
// Email:  fuzen_op@yahoo.com or fuzen_op@rootkit.com
//
// Description: fu.h has prototypes, etc. that fu.cpp needs.
//
// Date:    5/27/2003
// Version: 1.0

static BOOL Initialized = FALSE;
HANDLE gh_Device = INVALID_HANDLE_VALUE;

typedef struct _vars {
	DWORD the_pid;
	PLUID_AND_ATTRIBUTES pluida;
	DWORD num_luids;
} VARS;


typedef struct _vars2 {
	DWORD the_pid;
	void * pSID;
	DWORD d_SidSize;
} VARS2;

DWORD Init();
DWORD ListProc(IN void *, IN int);
DWORD HideProc(IN char *, IN int);
DWORD ListAuthID(IN void *, IN int);
DWORD SetPriv(IN char *, IN void *, IN int);

int	  ListPriv(void);
DWORD SetSid(IN DWORD, IN PSID, IN DWORD);

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?