示例#1
0
        public static Int64 FindKernelProcedure(string szName)
        {
            var procAddress = Natives.GetProcAddress((IntPtr)ntoskrnlHandle, szName);

            return((Int64)((UInt64)KernelBase.ToInt64() + ((UInt64)procAddress.ToInt64() - (UInt64)ntoskrnlHandle.ToInt64())));
        }