|
扫描完毕,钩子/代码修改: 9
挂钩位置 类型 当前函数地址 挂钩处当前值 挂钩处原始值 当前函数地址所在模块
ntdll.dll: RtlQueryPerformanceCounter (len:5) inline 0x0000000077D810F0 -> 0x000000001D1F0440 E9 4B F3 46 A5 8B FF 55 8B EC
kernel32.dll: QueryPerformanceCounter (len:8) inline 0x0000000075C09970 -> 0x0000000075C09A5A B8 40 04 E7 1C FF E0 90 8B FF 55 8B EC 5D FF 25 c:\windows\syswow64\kernel32.dll
kernel32.dll: GetTickCount64 (len:8) inline 0x0000000075C0BA50 -> 0x0000000075C0BB3A E9 5B 49 5E A7 FF E0 90 8B FF 55 8B EC 51 53 56 c:\windows\syswow64\kernel32.dll
kernel32.dll: GetTickCount (len:8) inline 0x0000000075C0DC60 -> 0x0000000075C0DD4A E9 CB 26 5E A7 FF E0 90 51 FF 15 6C 1A C7 75 59 c:\windows\syswow64\kernel32.dll
kernel32.dll+0x00000000000688B0 (len:5) inline 0x0000000075C588B0 -> 0x000000001D1F0330 E9 7B 7A 59 A7 6A 00 6A 00 68
kernelbase.dll: GetTickCount (len:5) inline 0x00000000761C09C0 -> 0x000000001D1F0330 E9 6B F9 02 A7 8B FF 55 8B EC
kernelbase.dll: GetTickCount64 (len:5) inline 0x00000000761C1730 -> 0x000000001D1F03B0 E9 7B EC 02 A7 8B FF 55 8B EC
user32.dll+0x00000000000A25D4 (len:8) inline 0x00000000764925D4 -> 0x000000007649255C 70 86 9C 01 80 86 9C 01 CB 5A 0A 00 F2 5A 0A 00 c:\windows\syswow64\user32.dll
user32.dll+0x00000000000A25F0 (len:8) inline 0x00000000764925F0 -> - B0 85 9C 01 C0 85 9C 01 6A 5B 0A 00 94 5B 0A 00
|
|