Пример #1
0
HOOKDEF(NTSTATUS, WINAPI, NtSetContextThread,
  __in  HANDLE ThreadHandle,
  __in  const CONTEXT *Context
) {
    IS_SUCCESS_NTSTATUS();

    NTSTATUS ret = Old_NtSetContextThread(ThreadHandle, Context);
    LOQ("p", "ThreadHandle", ThreadHandle);
    return ret;
}
Пример #2
0
HOOKDEF(NTSTATUS, WINAPI, NtSetContextThread,
    __in  HANDLE ThreadHandle,
    __in  const CONTEXT *Context
) {
    NTSTATUS ret = Old_NtSetContextThread(ThreadHandle, Context);
    LOQ("p", "ThreadHandle", ThreadHandle);

    pipe("PROCESS:%d", pid_from_thread_handle(ThreadHandle));
    return ret;
}