怎么这个问题脱了这么就还没完结啊!
procedure TForm1.Button1Click(Sender: TObject);
var
FSnapshotHandle:THandle;
FProcessEntry32:TProcessEntry32;
Ret : BOOL;
ProcessID : integer;
ProcessHndle : THandle;
lpBuffer
byte;
nSize: DWORD;
lpNumberOfBytesWrite: DWORD;
i:integer;
s:string;
begin
FSnapshotHandle:=CreateToolhelp32Snapshot(
TH32CS_SNAPPROCESS,0);
//创建系统快照
FProcessEntry32.dwSize:=Sizeof(FProcessEntry32);
//先初始化 FProcessEntry32 的大小
Ret:=Process32First(FSnapshotHandle,FProcessEntry32);
while Ret do
begin
s:=ExtractFileName(FProcessEntry32.szExeFile);
if s='xxxx.EXE' then //你要修改的exe文件名
begin
ProcessID:=FProcessEntry32.th32ProcessID;
s:='';
break;
end;
Ret:=Process32Next(FSnapshotHandle,FProcessEntry32);
end;
//循环枚举出系统开启的所有进程,找出“G:/xxx/xxx.exe”
CloseHandle(FSnapshotHandle);
//Memo1.Lines.Clear
//memo1.lines.add('Process ID '+IntToHex(FProcessEntry32.th32ProcessID));
//memo1.lines.Add('File name '+FProcessEntry32.szExeFile);
////输出进程的一些信息
nSize:=2;
lpBuffer:=AllocMem(nSize);
ProcessHndle:=OpenProcess(PROCESS_VM_WRITE,false,ProcessID);
//现在可以开始修改了。i是内存偏移地址,lpbuffer是要修改的数值
i:=$00451ebd;
lpbuffer^:=$84;
WriteProcessMemory(
ProcessHndle,
Pointer(i),
lpBuffer,
nSize,
lpNumberOfBytesWRite
);
//下面是读内存的方法
ReadProcessMemory(
ProcessHndle,
Pointer(i),
lpBuffer,
nSize,
lpNumberOfBytesWRite
);
edit1.text:=inttohex(i)+' value Is:'+intTohex(lpBuffer^);
FreeMem(lpBuffer,nSize);
CloseHandle(ProcessHndle);
application.Terminate;
//关闭句柄,释放内存
end;
记得把 TLHelp32加入到use,单这个单元只能在win9x下,nt下不能用的。