lpOutBuffer, //输出参数指针
DWORD nOutBufferSize, //输出参数大小
LPDWORD lpBytesReturned,//指向变量的指针
LPOVERLAPPED...lpOverlapped //指向OVERLAPPED结构的指针
);
因此,通过逆向能获取到DeviceIoControl()函数的参数dwIoControlCode为0x9876C094,并且lpInBuffer...,
&pid, sizeof(pid),
&dwOut, sizeof(dwOut),
&junk,
(LPOVERLAPPED...&dwOut, sizeof(dwOut),
&junk,
(LPOVERLAPPED...&pid, sizeof(pid),
&dwOut, sizeof(dwOut),
&junk,
(LPOVERLAPPED