NtQuerySystemInformation
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 | #include "stdafx.h" #include <Windows.h> #include <winternl.h> using namespace std; typedef NTSTATUS (WINAPI *PFUN_NtQuerySystemInformation)( _In_ SYSTEM_INFORMATION_CLASS SystemInformationClass, _Inout_ PVOID SystemInformation, _In_ ULONG SystemInformationLength, _Out_opt_ PULONG ReturnLength ); int _tmain( int argc, _TCHAR* argv[]) { PFUN_NtQuerySystemInformation pFun = NULL; pFun = (PFUN_NtQuerySystemInformation)GetProcAddress(GetModuleHandle(L "ntdll.dll" ), "NtQuerySystemInformation" ); char szInfo[0x20000] = { 0 }; ULONG uReturnedLEngth = 0; NTSTATUS status = pFun(SystemProcessInformation, szInfo, sizeof (szInfo), &uReturnedLEngth); if (status != 0) return 0; PSYSTEM_PROCESS_INFORMATION pSystemInformation = (PSYSTEM_PROCESS_INFORMATION)szInfo; DWORD dwID = ( DWORD )pSystemInformation->UniqueProcessId; HANDLE hHandle = NULL; PWCHAR pImageName = ( PWCHAR )*( DWORD *)(( PCHAR )pSystemInformation + 0x3c); printf ( "ProcessID: %d\tprocessName: %ws \n" , dwID, pImageName); while ( true ) { if (pSystemInformation->NextEntryOffset == 0) break ; pSystemInformation = (PSYSTEM_PROCESS_INFORMATION)(( PCHAR )pSystemInformation + pSystemInformation->NextEntryOffset); dwID = ( DWORD )pSystemInformation->UniqueProcessId; hHandle = OpenProcess(PROCESS_QUERY_INFORMATION | PROCESS_VM_READ, FALSE, dwID); pImageName = ( PWCHAR )*( DWORD *)(( PCHAR )pSystemInformation + 0x3c); printf ( "ProcessID: %d\tprocessName: %ws \n" , dwID, pImageName); } getchar (); } |
【推荐】国内首个AI IDE,深度理解中文开发场景,立即下载体验Trae
【推荐】编程新体验,更懂你的AI,立即体验豆包MarsCode编程助手
【推荐】抖音旗下AI助手豆包,你的智能百科全书,全免费不限次数
【推荐】轻量又高性能的 SSH 工具 IShell:AI 加持,快人一步
· 记一次.NET内存居高不下排查解决与启示
· 探究高空视频全景AR技术的实现原理
· 理解Rust引用及其生命周期标识(上)
· 浏览器原生「磁吸」效果!Anchor Positioning 锚点定位神器解析
· 没有源码,如何修改代码逻辑?
· 全程不用写代码,我用AI程序员写了一个飞机大战
· DeepSeek 开源周回顾「GitHub 热点速览」
· MongoDB 8.0这个新功能碉堡了,比商业数据库还牛
· 记一次.NET内存居高不下排查解决与启示
· 白话解读 Dapr 1.15:你的「微服务管家」又秀新绝活了