ntquerysysteminformation.h
来自「使用驱动技术可以关闭任意指定进程提升应用程序权限」· C头文件 代码 · 共 32 行
H
32 行
#include <stdio.h>
#include <windows.h>
typedef struct _SYSTEM_MODULE_INFORMATION {
ULONG Reserved[2];
PVOID Base;
ULONG Size;
ULONG Flags;
USHORT Index;
USHORT Unknown;
USHORT LoadCount;
USHORT ModuleNameOffset;
CHAR ImageName[256];
} SYSTEM_MODULE_INFORMATION, *PSYSTEM_MODULE_INFORMATION;
typedef struct _tagSysModuleList {
ULONG ulCount;
SYSTEM_MODULE_INFORMATION smi[1];
} SYSMODULELIST, *PSYSMODULELIST;
#define SystemModuleInfo 0x0B
typedef ULONG \
(__stdcall *NTQUERYSYSTEMINFORMATION)( \
IN ULONG SysInfoClass,
IN OUT PVOID SystemInformation,
IN ULONG SystemInformationLength,
OUT PULONG nRet
);
NTQUERYSYSTEMINFORMATION NtQuerySystemInformation = NULL;
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?