diff --git a/README.md b/README.md index 1587241..557abc7 100644 --- a/README.md +++ b/README.md @@ -21,6 +21,9 @@ VOID RtlSetProcessIsCritical(BOOLEAN NewValue, PBOOLEAN OldValue, BOOLEAN IsWinl VOID RtlSetThreadIsCritical(BOOLEAN NewValue, PBOOLEAN OldValue, BOOLEAN IsWinlogon); ``` +### 所在DLL + - ntdll.dll + ## 关于NtQueryInformationProcess ### 函数原型 @@ -28,9 +31,6 @@ VOID RtlSetThreadIsCritical(BOOLEAN NewValue, PBOOLEAN OldValue, BOOLEAN IsWinlo NTSTATUS NtQueryInformationProcess(IN HANDLE ProcessHandle, IN PROCESSINFOCLASS ProcessInformationClass, OUT PVOID ProcessInformation, IN ULONG ProcessInformationLength, OUT PULONG ReturnLength); ``` -### 所在DLL - - ntdll.dll - ### 未导出类型 ```c++ enum PROCESSINFOCLASS