NtQuerySystemInformation

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
#include "stdafx.h"
#include <Windows.h>
#include <winternl.h>
using namespace std;
 
typedef NTSTATUS (WINAPI *PFUN_NtQuerySystemInformation)(
    _In_      SYSTEM_INFORMATION_CLASS SystemInformationClass,
    _Inout_   PVOID                    SystemInformation,
    _In_      ULONG                    SystemInformationLength,
    _Out_opt_ PULONG                   ReturnLength
    );
int _tmain(int argc, _TCHAR* argv[])
{  
    PFUN_NtQuerySystemInformation pFun = NULL;
    pFun = (PFUN_NtQuerySystemInformation)GetProcAddress(GetModuleHandle(L"ntdll.dll"), "NtQuerySystemInformation");
 
    char szInfo[0x20000] = { 0 };
    ULONG uReturnedLEngth = 0;
    NTSTATUS status = pFun(SystemProcessInformation, szInfo, sizeof(szInfo), &uReturnedLEngth);
    if (status != 0)
        return 0;
    PSYSTEM_PROCESS_INFORMATION pSystemInformation = (PSYSTEM_PROCESS_INFORMATION)szInfo;
    DWORD dwID = (DWORD)pSystemInformation->UniqueProcessId;
    HANDLE hHandle = NULL;
    PWCHAR pImageName = (PWCHAR)*(DWORD*)((PCHAR)pSystemInformation + 0x3c);
    printf("ProcessID: %d\tprocessName: %ws \n", dwID, pImageName);
    while (true)
    {
        if (pSystemInformation->NextEntryOffset == 0)
            break;
 
        pSystemInformation = (PSYSTEM_PROCESS_INFORMATION)((PCHAR)pSystemInformation + pSystemInformation->NextEntryOffset);
        dwID = (DWORD)pSystemInformation->UniqueProcessId;
        hHandle = OpenProcess(PROCESS_QUERY_INFORMATION | PROCESS_VM_READ, FALSE, dwID);
        pImageName = (PWCHAR)*(DWORD*)((PCHAR)pSystemInformation + 0x3c);
        printf("ProcessID: %d\tprocessName: %ws \n", dwID, pImageName);
    }
    getchar();
}

  

posted on   lydstory  阅读(770)  评论(0编辑  收藏  举报

编辑推荐:
· 记一次.NET内存居高不下排查解决与启示
· 探究高空视频全景AR技术的实现原理
· 理解Rust引用及其生命周期标识(上)
· 浏览器原生「磁吸」效果!Anchor Positioning 锚点定位神器解析
· 没有源码,如何修改代码逻辑?
阅读排行:
· 全程不用写代码,我用AI程序员写了一个飞机大战
· DeepSeek 开源周回顾「GitHub 热点速览」
· MongoDB 8.0这个新功能碉堡了,比商业数据库还牛
· 记一次.NET内存居高不下排查解决与启示
· 白话解读 Dapr 1.15:你的「微服务管家」又秀新绝活了

导航

< 2025年3月 >
23 24 25 26 27 28 1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30 31 1 2 3 4 5

统计

点击右上角即可分享
微信分享提示