Es decir que acabo de bajar el ultimo WDK al reverendo pedo
En ese hilo yo decia que hay que tener cuidado con los offsets hardcodeados. Bueno, el WDK no trae esa estructura definida por una razon: puede (y lo hace) cambiar de version a version.
The EPROCESS structure is an opaque structure that serves as the process object for a process.
Veamos el archivo ese:
This is a free version of the file ntifs.h, release 56.
The purpose of this include file is to build file system and
file system filter drivers for Windows NT®, Windows® 2000,
Windows® XP and Windows® Server 2003.DISCLAIMER: I do not encourage anyone to use this include file to build
drivers used in production. The information in this include file is
incomplete and intended only as an studying companion. The information
has been found in books, magazines, on the Internet and received from
contributors. Some of the information in this file may not be available
in other publications intended for similar use, these should be used with
extra care. Some of the information in this file may have different names
than in other publications even though they describe the same thing.En fin que no es el archivo oficial que deberias usar ... leelo y vas a ver como define EPROCESS y con que metodo.