PVOID *KeServiceTablePointers;
SERVICE_HOOK_DESCRIPTOR *HookDescriptors;
KeServiceTablePointers = RegmonMapServiceTable(&HookDescriptors);
if(!KeServiceTablePointers)
{
return FALSE;
}
HOOK_SYSCALL(ZwFlushKey, HookRegFlushKey, RealRegFlushKey);
HOOK_SYSCALL(ZwDeleteKey, HookRegDeleteKey, RealRegDeleteKey);
HOOK_SYSCALL(ZwSetValueKey, HookRegSetValueKey, RealRegSetValueKey);
HOOK_SYSCALL(ZwCreateKey, HookRegCreateKey, RealRegCreateKey);
HOOK_SYSCALL(ZwDeleteValueKey, HookRegDeleteValueKey, RealRegDeleteValueKey);
HOOK_SYSCALL(ZwCreateSection, HookCreateSection, RealCreateSection);
HOOK_SYSCALL(ZwTerminateProcess,HookTerminateProcess, RealTerminateProcess);//执行这句代码蓝屏
请问这是怎么回事