|
发表于 2013-6-29 14:46:07
|
显示全部楼层
本帖最后由 zer0 于 2013-6-29 14:52 编辑
不好!!! E语言写的,而且还是拖魔x作坊的模块的!!!! 晕了..{:1_1:}
给你看看C++的: 大概流程
- typedef DWORD(WINAPI *PFSuspendProcess)(HANDLE hProcess);
- typedef DWORD(WINAPI *PFResumeProcess)(HANDLE hProcess);
- PFSuspendProcess SuspendProcess;
- PFResumeProcess ResumeProcess;
- HMODULE hNtDllLib = LoadLibrary("ntdll.dll");
-
- SuspendProcess = (PFSuspendProcess)GetProcAddress(hNtDllLib,"ZwSuspendProcess");//挂起线程
- ResumeProcess = (PFResumeProcess)GetProcAddress(hNtDllLib,"ZwResumeProcess");//恢复线程
- 调用的时候是这样:
- SuspendProcess(hProcess);
- ResumeProcess(hProcess);
复制代码
|
|