Even though APCs are undocumented to decent extent, the technique of using them to inject a DLL into a user-mode process is not new and has been talked through many times. Such APC can be queued from ...
6bd0 inject_dll 297 DLL: C:\Users\a\AppData\Local\Temp\clink\dll_cache\1.8.0.553299_99c250e2\clink_dll_x64.dll 6bd0 inject_dll 299 Parent pid: 5288 6bd0 check_dll_version 168 DLL version: 00010008 ...
一部の結果でアクセス不可の可能性があるため、非表示になっています。
アクセス不可の結果を表示する