概述:汇编获取进程和系统的信息
获取进程id
来源:KERNELBASE!GetCurrentProcessId
1 | 762a2b20 64a118000000 mov eax, dword ptr fs:[00000018h] |
获取TickCount
来源:KERNELBASE!GetTickCount:
1 | 762a1ed0 8bff mov edi, edi |
获取TickCount64
来源:KERNELBASE!GetTickCount64
1 | 762a2e30 8bff mov edi, edi |