急需:C#语句如何HOOK API

huangwentao658 2008-11-27 05:12:29
急需:C#语句如何HOOK API 最好是代码的实现
比如说:HOOK OpenProcess/FileMove
...全文
139 4 打赏 收藏 转发到动态 举报
写回复
用AI写文章
4 条回复
切换为时间正序
请发表友善的回复…
发表回复
aimeast 2008-11-27
  • 打赏
  • 举报
回复
严重关注事态!
renfei0730 2008-11-27
  • 打赏
  • 举报
回复
用于进程注入其他的类似
using System;
using System.Collections.Generic;
using System.ComponentModel;
using System.Data;
using System.Drawing;
using System.Text;
using System.Windows.Forms;
using System.Runtime.InteropServices;
using System.Diagnostics;
namespace dllinject
{
public partial class Form1 : Form
{
[DllImport("kernel32.dll")]
public static extern int VirtualAllocEx(IntPtr hwnd, int lpaddress, int size, int type, int tect);
[DllImport("kernel32.dll")]
public static extern int WriteProcessMemory(IntPtr hwnd, int baseaddress, string buffer, int nsize, int filewriten );
[DllImport("kernel32.dll")]
public static extern int GetProcAddress(int hwnd, string lpname);
[DllImport("kernel32.dll")]
public static extern int GetModuleHandleA(string name);
[DllImport("kernel32.dll")]
public static extern int CreateRemoteThread(IntPtr hwnd, int attrib, int size, int address, int par, int flags, int threadid);

public Form1()
{
InitializeComponent();
}

private void button1_Click(object sender, EventArgs e)
{
int ok1;
int baseaddress;
int temp=0;
int hack;
int yan;
string dllname;
dllname = "c:\\Ren.dll";
int dlllength;
dlllength = dllname.Length + 1;
Process[] pname = Process.GetProcesses();
foreach (Process name in pname)
{

if (name.ProcessName.ToLower().IndexOf("360tray") != -1)
{

baseaddress = VirtualAllocEx(name.Handle, 0, dlllength , 4096, 4);
if (baseaddress == 0)
{
MessageBox.Show("申请内存空间失败!!");
return;
}
ok1 = WriteProcessMemory(name.Handle, baseaddress, dllname, dlllength, temp);
if (ok1 == 0)
{
  MessageBox.Show("写内存失败!!");
return;
}
hack = GetProcAddress(GetModuleHandleA("Kernel32"), "LoadLibraryA");
if (hack == 0)
{
MessageBox.Show("无法取得函数的入口点!!");
return;
}
yan = CreateRemoteThread(name.Handle, 0, 0, hack, baseaddress, 0, temp);
if (yan == 0)
{
MessageBox.Show("创建远程线程失败!!");
return;
}
else
{
MessageBox.Show("已成功注入dll!!");
}

}

}

}

private void Form1_Load(object sender, EventArgs e)
{

}


}
}
net5i 2008-11-27
  • 打赏
  • 举报
回复
我感觉既然C#能调用下面API Hook窗口的键盘鼠标消息,应该也能实现搂主需求,不过我没做过
[DllImport("user32.dll")]
private static extern IntPtr SetWindowsHookEx(HookType code, HookProc func, IntPtr hInstance, int threadID);

[DllImport("user32.dll")]
private static extern int UnhookWindowsHookEx(IntPtr hhook);

[DllImport("user32.dll")]
private static extern int CallNextHookEx(IntPtr hhook, int code, IntPtr wParam, IntPtr lParam);
xu_2007 2008-11-27
  • 打赏
  • 举报
回复
C#估计是做不了,要做的话用VC++吧!

111,130

社区成员

发帖
与我相关
我的任务
社区描述
.NET技术 C#
社区管理员
  • C#
  • Creator Browser
  • by_封爱
加入社区
  • 近7日
  • 近30日
  • 至今
社区公告

让您成为最强悍的C#开发者

试试用AI创作助手写篇文章吧