下你所需,载你所想!
汇集开发技术源码资料

易语言枚举驱动

:1.751KB :1 :2021-08-24 11:12:03

部分简介

NtQuerySystemInformation (11, Buffer, 0, Ret)
Buffer = LocalAlloc (64, Ret × 2)
NtQuerySystemInformation (11, Buffer, Ret × 2, 0)
RtlMoveMemory (ModulesInfo, Buffer, 284)
Number = ModulesInfo.dwNumberOfModules
.变量循环首 (0, Number, 1, )
Buffer = Buffer + 71 × 4
RtlMoveMemory (ModulesInfo, Buffer, 284)
Path = 到文本 (ModulesInfo.ModuleInformation.ImageName)
.如果真 (Path = “”)
到循环尾 ()
.如果真结束
调试输出 (Path, ModulesInfo.ModuleInformation.Index, ModulesInfo.ModuleInformation.dwBase, ModulesInfo.ModuleInformation.dwSize, ModulesInfo.ModuleInformation.dwFlags, ModulesInfo.ModuleInformation.Unknown, ModulesInfo.ModuleInformation.LoadCount, ModulesInfo.ModuleInformation.dwReserved, ModulesInfo.ModuleInformation.ModuleNameOffset)
.变量循环尾 ()
LocalFree (Buffer)

热门推荐

相关文章