Skip to content

Commit 9b38729

Browse files
committed
添加 Win11 24H2 测试效果图
添加 Win11 24H2 测试效果图
1 parent b52f96c commit 9b38729

File tree

3 files changed

+9
-3
lines changed

3 files changed

+9
-3
lines changed

InfinityHookPro/hook.cpp

+3-3
Original file line numberDiff line numberDiff line change
@@ -106,7 +106,7 @@ namespace KHook
106106
// 开始查找当前栈中的ssdt调用
107107
for (void** pStackCurrent = pStackMax; pStackCurrent > pStackFrame; --pStackCurrent)
108108
{
109-
/*
109+
/* 函数 PerfInfoLogSysCallEntry逆向
110110
Win11 23606 以前 栈中ssdt调用特征, 分别是
111111
mov r9d, 0F33h
112112
mov [rsp+48h+var_20], 501802h
@@ -630,14 +630,14 @@ namespace KHook
630630
}
631631
else
632632
{
633-
633+
634634
UNICODE_STRING usObDereferenceObject = RTL_CONSTANT_STRING(L"ObDereferenceObject");
635635
ObDereferenceObjectPtr fnObDereferenceObject = (ObDereferenceObjectPtr)MmGetSystemRoutineAddress(&usObDereferenceObject);
636636
if (fnObDereferenceObject)
637637
{
638638
fnObDereferenceObject(m_DetectThreadObject);
639639
}
640-
else
640+
else
641641
{
642642
DbgPrintEx(0, 0, "[%s] Can't Find ObDereferenceObject or ObfDereferenceObject \n", __FUNCTION__);
643643
}

README.md

+6
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,7 @@ InfinityHook 支持Win7 到 Win11 最新版本,虚拟机环境及物理机环
1111
* Windows 11 22621 物理机上测试了 24 小时未触发
1212
* Windows 11 22631 物理机上测试了 48 小时未触发
1313
* Windows 11 26016 预览版 物理机上测试了 48 小时未触发
14+
* Windows 11 24H2 物理机上测试了 48 小时未触发
1415

1516
**PS**
1617

@@ -91,4 +92,9 @@ InfinityHook 支持Win7 到 Win11 最新版本,虚拟机环境及物理机环
9192
</p>
9293
Win11 26016
9394
<img src="ScreenShot\Win11_26016.jpg" alt="Win11 26016"/>
95+
<p>
96+
&nbsp;
97+
</p>
98+
Win11 24H2
99+
<img src="ScreenShot\Win11_24H2.png" alt="Win11 24H2"/>
94100
</h4>

ScreenShot/Win11_24H2.png

1.28 MB
Loading

0 commit comments

Comments
 (0)