驱动关闭/打开读写保护

2019-08-29  本文已影响0人  HAPPYers
KIRQL WPOFFx64() {
    KIRQL irql = KeRaiseIrqlToDpcLevel();
    UINT64 cr0 = __readcr0();
    cr0 &= 0xFFFFFFFFFFFEFFFF;
    __writecr0(cr0);
    return irql;
}

VOID WPONx64(KIRQL irql) {
    UINT64 cr0 = __readcr0();
    cr0 |= 0x10000;
    _enable();
    __writecr0(cr0);
    KeLowerIrql(irql);
}
上一篇 下一篇

猜你喜欢

热点阅读