我使用ntdll.dll
winapi函数动态地从GetProcAddress
获取函数:
HMODULE ntdllh = LoadLibrary(L"ntdll.dll");
unsigned char* ptrToNtLoadDriver
= (unsigned char*)GetProcAddress(ntdllh, "NtLoadDriver");
如何通过NtLoadDriver
致电ptrToNtLoadDriver
功能?我想到了这样的事情:((NTSTATUS NtLoadDriver(PUNICODE_STRING driverServiceName))ptrToNtLoadDriver)(fooString)
答案 0 :(得分:1)
答案 1 :(得分:0)
((NTSTATUS(WINAPI *)(PUNICODE_STRING))ptrToNtLoadDriver)(fooStrin);