重金求解函数的用法问题!! ( 积分: 60 )

  • 主题发起人 主题发起人 lebronjames
  • 开始时间 开始时间
L

lebronjames

Unregistered / Unconfirmed
GUEST, unregistred user!
1:如何根据任务管理程序里的进程名字来获得这个进程的PID??或者反过来根据PID获得进程名字.<br><br>2:打开,读取,修改进程内存的函数:openprocess,readprocessMemory,wirteprocessMemory,<br>具体怎么使用?和标准的语法格式,帮忙举3个例!!<br><br>3:使用这些API,在DELPHI里面定义哪些类型的变量?这个我一直没搞定,有些定义了没用,用了又出错(什么形参不一样)<br><br>谢谢谢谢!!<br>========我在网上搜了一些资料之后写出了这些,但是还是不太明白,还请帮我解释一下具体的含义..<br>var<br>Window:&nbsp;HWND;<br>Num:&nbsp;cardinal;<br>PHND:&nbsp;THandle;<br>PID,&nbsp;mft:&nbsp;Integer;<br>lppe:tprocessentry32;<br>begin<br>GetWindowThreadProcessId(Window,&nbsp;@PID);<br>try<br>PHND&nbsp;:=&nbsp;OpenProcess(PROCESS_VM_READ,&nbsp;False,&nbsp;1340);//1340是PID,但是是固定的,怎么<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;才能自动获取到?&nbsp;&nbsp;&nbsp;&nbsp;<br>if&nbsp;PHND&nbsp;&lt;&gt;&nbsp;0&nbsp;then<br>ReadProcessMemory(PHND,&nbsp;Pointer($00DC754f),&nbsp;@mft,&nbsp;4,&nbsp;Num)&nbsp;;//这里也不大明白<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;参数的意思<br><br>edit1.Text:=inttostr(mft);<br><br>except<br>end;
 
才60分懒得写
 
我一共才94分,还留几分旁身啊..
 
1、<br>枚举进程<br>uses&nbsp;TlHelp32;<br>function&nbsp;EmunProcess(EnumProc:&nbsp;TEnumProcessProc):&nbsp;Boolean;<br>var<br>&nbsp;&nbsp;hProcessSnap:&nbsp;THandle;<br>&nbsp;&nbsp;bMore,&nbsp;bContinue:&nbsp;Boolean;<br>&nbsp;&nbsp;ProcessEntry:&nbsp;TProcessEntry32;<br>begin<br>&nbsp;&nbsp;Result&nbsp;:=&nbsp;False;<br>&nbsp;&nbsp;bContinue&nbsp;:=&nbsp;True;<br>&nbsp;&nbsp;hProcessSnap&nbsp;:=&nbsp;CreateToolhelp32Snapshot(TH32CS_SNAPALL,&nbsp;0);<br>&nbsp;&nbsp;if&nbsp;hProcessSnap&nbsp;=&nbsp;INVALID_HANDLE_VALUE&nbsp;then<br>&nbsp;&nbsp;&nbsp;&nbsp;Exit;<br>&nbsp;&nbsp;bMore&nbsp;:=&nbsp;Process32First(hProcessSnap,&nbsp;ProcessEntry);<br>&nbsp;&nbsp;EnumProc(ProcessEntry,&nbsp;bContinue);<br>&nbsp;&nbsp;while&nbsp;bMore&nbsp;and&nbsp;bContinue&nbsp;do<br>&nbsp;&nbsp;begin<br>&nbsp;&nbsp;&nbsp;&nbsp;bMore&nbsp;:=&nbsp;Process32Next(hProcessSnap,&nbsp;ProcessEntry);<br>&nbsp;&nbsp;&nbsp;&nbsp;EnumProc(ProcessEntry,&nbsp;bContinue);<br>&nbsp;&nbsp;end;<br>&nbsp;&nbsp;CloseHandle(hProcessSnap);<br>end;<br><br>procedure&nbsp;TForm1.Button1Click(Sender:&nbsp;TObject);<br>begin<br>&nbsp;&nbsp;EmunProcess(EnumProc);<br>end;<br><br>procedure&nbsp;TForm1.EnumProc(ProcessEntry:&nbsp;TProcessEntry32;&nbsp;var&nbsp;bContinue);<br>begin<br>&nbsp;&nbsp;Memo1.Lines.Add(IntToStr(ProcessEntry.th32ProcessID)&nbsp;+&nbsp;'|'&nbsp;+&nbsp;ProcessEntry.szExeFile);<br>end;<br>2、<br><br>&nbsp;OpenProcess&nbsp;<br>&nbsp;API函数名&nbsp;OpenProcess&nbsp;<br>&nbsp;<br>将句柄返回给过程对象&nbsp;<br>&nbsp;<br>详细说明&nbsp;Win16:×&nbsp;Win9X:√&nbsp;WinNT:√&nbsp;<br><br>&nbsp;●&nbsp;说明&nbsp;<br>&nbsp;<br>函数OpenProcess是用来获得一个已经存在的进程对象的句柄。&nbsp;<br><br>&nbsp;<br>●&nbsp;原型&nbsp;<br>&nbsp;<br>HANDLE&nbsp;OpenProcess(DWORD&nbsp;dwDesiredAccess,&nbsp;BOOL&nbsp;bInheritHandle,&nbsp;<br>&nbsp;<br>DWORD&nbsp;dwProcessId);&nbsp;<br><br>&nbsp;<br>●&nbsp;参数&nbsp;<br>&nbsp;<br>dwDesiredAccess:是进程对象的访问权限,可以是一个或几个的组合,PROCESS_ALL_ACCESS为所有访问权限。&nbsp;<br>&nbsp;<br>bInheritHandle:若要子进程获得对该对象的访问权限,应设置为TRUE,否则设为FALSE。&nbsp;<br>&nbsp;<br>dwProcessId:是系统范围的进程标识符。&nbsp;<br><br>&nbsp;<br>●&nbsp;返回值&nbsp;<br>&nbsp;<br>若函数调用成功则返回进程对象的句柄,否则返回FALSE。&nbsp;<br><br><br>&nbsp;ReadProcessMemory&nbsp;<br>&nbsp;API函数名&nbsp;ReadProcessMemory&nbsp;<br>&nbsp;<br>在进程中读内存&nbsp;<br>&nbsp;<br>详细说明&nbsp;Win16:×&nbsp;Win9X:√&nbsp;WinNT:√&nbsp;<br>&nbsp;函数功能描述:该函数用来读取指定进程的空间的数据,此空间必须是可以访问的,否则读取操作会失败!&nbsp;<br><br>&nbsp;<br>函数原型&nbsp;<br>&nbsp;BOOL&nbsp;ReadProcessMemory(&nbsp;<br>&nbsp;HANDLE&nbsp;hProcess,&nbsp;//&nbsp;目标进程句柄&nbsp;<br>&nbsp;LPCVOID&nbsp;lpBaseAddress,&nbsp;//&nbsp;读取数据的起始地址&nbsp;<br>&nbsp;LPVOID&nbsp;lpBuffer,&nbsp;//&nbsp;存放数据的缓存区地址&nbsp;<br>&nbsp;DWORD&nbsp;nSize,&nbsp;//&nbsp;要读取的字节数&nbsp;<br>&nbsp;LPDWORD&nbsp;lpNumberOfBytesRead&nbsp;//&nbsp;实际读取数存放地址&nbsp;<br>&nbsp;);&nbsp;<br><br>&nbsp;<br>参数&nbsp;<br>&nbsp;hProcess&nbsp;<br>&nbsp;目标进程的句柄,该句柄必须对目标进程具有PROCESS_VM_READ&nbsp;的访问权限。&nbsp;<br>&nbsp;<br>lpBaseAddress&nbsp;<br>&nbsp;从目标进程中读取数据的起始地址。&nbsp;在读取数据前,系统将先检验该地址的数据是否可读,如果不可读,函数将调用失败。&nbsp;<br>&nbsp;<br>lpBuffer&nbsp;<br>&nbsp;用来接收数据的缓存区地址。&nbsp;<br>&nbsp;<br>nSize&nbsp;<br>&nbsp;从目标进程读取数据的字节数。&nbsp;<br>&nbsp;<br>lpNumberOfBytesRead&nbsp;<br>&nbsp;实际被读取数据大小的存放地址。如果被指定为NULL,那么将忽略此参数。&nbsp;<br><br>&nbsp;<br>返回值&nbsp;<br>&nbsp;如果函数执行成功,返回值非零。&nbsp;<br>&nbsp;<br>如果函数执行失败,返回值为零。调用&nbsp;GetLastError&nbsp;函数可以获取该函数执行错误的信息。&nbsp;<br>&nbsp;如果要读取一个进程中不可访问空间的数据,该函数就会失败。&nbsp;<br><br>&nbsp;<br>备注&nbsp;<br>&nbsp;ReadProcessMemory&nbsp;函数从目标进程复制指定大小的数据到自己进程的缓存区,任何拥有PROCESS_VM_READ&nbsp;权限句柄的进程都可以调用该函数,目标进程的地址空间很显然要是可读的,但也并不是必须的,如果目标进程处于被调试状态的话。&nbsp;<br><br>WriteProcessMemory&nbsp;<br>&nbsp;API函数名&nbsp;WriteProcessMemory&nbsp;<br>&nbsp;<br>在指定进程中写内存&nbsp;<br>&nbsp;<br>详细说明&nbsp;Win16:×&nbsp;Win9X:√&nbsp;WinNT:√&nbsp;<br>&nbsp;BOOL&nbsp;WriteProcessMemory(&nbsp;<br>&nbsp;&nbsp;&nbsp;HANDLE&nbsp;hProcess,&nbsp;//&nbsp;要写进程的句柄&nbsp;<br>&nbsp;&nbsp;&nbsp;LPVOID&nbsp;lpBaseAddress,&nbsp;//&nbsp;写内存的起始地址&nbsp;<br>&nbsp;&nbsp;&nbsp;LPVOID&nbsp;lpBuffer,&nbsp;//&nbsp;写入数据的地址&nbsp;<br>&nbsp;&nbsp;&nbsp;DWORD&nbsp;nSize,&nbsp;//&nbsp;要写的字节数&nbsp;<br>&nbsp;&nbsp;&nbsp;LPDWORD&nbsp;lpNumberOfBytesWritten&nbsp;//&nbsp;实际写入的子节数&nbsp;<br>&nbsp;);
 
楼上的高人,能简单一点吗?我才接触这方面,所以有些很多不懂..<br>就拿那3个函数随便写个例子,表明下每个参数的意思就OK了.<br>还有您的代码开始编译提示:<br>Undeclared&nbsp;identifier:&nbsp;'TEnumProcessProc'...
 
type下面加上<br>&nbsp;&nbsp;TEnumProcessProc&nbsp;=&nbsp;procedure&nbsp;(ProcessEntry:&nbsp;TProcessEntry32;&nbsp;var&nbsp;bContinue)&nbsp;of&nbsp;object;
 
还是报错:<br>[&amp;acute;í&amp;Icirc;ó]&nbsp;Unit1.pas(10):&nbsp;Undeclared&nbsp;identifier:&nbsp;'TProcessEntry32'.<br>请把完整的贴出来吧,从UNIT开始,好吗谢谢
 
uses&nbsp;TlHelp32;<br>上面不是写了么
 
建议楼主搜索&nbsp;读写内存&nbsp;你就会明白下面这句是什么意思<br>OpenProcess(PROCESS_VM_READ,&nbsp;False,&nbsp;1340);<br><br><br>$00DC754f&nbsp;这个则是某个进程的基地址.<br>ReadProcessMemory(PHND,&nbsp;Pointer($00DC754f),&nbsp;@mft,&nbsp;4,&nbsp;Num)&nbsp;;<br>从这个基地址读取四个字节的内存.<br>不同的进程在这个地址上有不同的数值
 
后退
顶部