下你所需,载你所想!
汇集开发技术源码资料

APIHOOK拦截指定进程,创建新进程

:415.482KB :1 :2020-12-19 12:44:28

部分简介

#####################在这里可以根据自己拦截参数修改
信息框 (“CreateProcess拦截成功”, 0, , )
hook.暂停 (“kernel32.dll”, “CreateProcessA”)
拷贝内存1 (局_lpStartupInfo, lpStartupInfo, LocalSize (lpStartupInfo)) ' hook回调参数不支持自定义数据类型
拷贝内存2 (局_lpProcessInformation, lpProcessInformation, LocalSize (lpProcessInformation))
CreateProcessA (lpApplicationName, lpCommandLine, lpProcessAttributes, lpThreadAttributes, bInheritHandles, dwCreationFlags, lpEnvironment, lpCurrentDriectory, 局_lpStartupInfo, 局_lpProcessInformation)
hook.继续 (“kernel32.dll”, “CreateProcessA”)

热门推荐

相关文章