暂无签名
鏆傛棤浠嬬粛
发布时间:2006-12-01 11:53:37
lkd> dt _IRP Tail.. +0x040 Tail : +0x000 Overlay : // !thread .... .... IRP List: 86873d90: (0006,0094) Flags: 00000070 Mdl: 00000000[@more@]lkd> dt _IRP Tail.. +0x040 Tail : +0x000 Overlay : // !thread .... .... IRP List: 86873d90: (0006,0094) Flags: 00000070 Mdl: 00000000// +0x000 DeviceQueueEntry : _KDEVICE_QUEUE_ENTRY --->线程的IRP列表 +0x000 DriverContext : [4] Ptr32 Void +0x010 T......【阅读全文】
发布时间:2006-12-01 11:22:42
公文包的跟踪[@more@]Registry:"SoftwareMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks{AEB6717E-7E19-11d0-97EE-00C04FD91972}CLSID{AEB6717E-7E19-11d0-97EE-00C04FD91972}InProcServer32 ->LoadWithoutCOMSHELL32!CShellExecute::_TryHooks:call SHELL32!TryShellExecuteHooks SHELL32!UEMIsLoaded: "ole32.dll""browseui.dll""SoftwareMicrosoftWindowsCurrentVersionExplorer" -->"MaximizeApps""SoftwareMicrosoftWindowsCurrentVersionExplorerShellExec......【阅读全文】