0.ring0-__STDCALL inline HOOK 和 __declspec(naked) inline HOOK区别
两者差别1.__STDCALLinlineHOOK是针对整个函数的hook,好处是变量清楚,坏处时肯定只能在函数头hookNTSTATUS__stdcall
NewNtQueryDirectoryFile(
INHANDLEFileHandle,
INHANDLEEventOPTIONAL,
.......
)
{
returnOldNtQueryDirectoryFile(FileHandle,