枚举进程模块

 typedef BOOL (_stdcall *ENUMPROCESSES)(DWORD* pProcessIds,DWORD cb,DWORD* pBytesReturned);
 typedef BOOL (_stdcall *ENUMPROCESSMODULES)(HANDLE hProcess,HMODULE* lphModule,DWORD cb,LPDWORD lpcbNeeded);
 typedef DWORD (_stdcall *GETMODULEFILENAMEEX)(HANDLE hProcess,HMODULE hModule,LPTSTR lpFilename,DWORD nSize );

 HMODULE hModule = LoadLibrary("psapi.dll");
 if(hModule == NULL)
  return;
 ENUMPROCESSES pEnumProcesses  = (ENUMPROCESSES)GetProcAddress(hModule, "EnumProcesses");
 ENUMPROCESSMODULES pEnumProcessModules  = (ENUMPROCESSMODULES)GetProcAddress(hModule, "EnumProcessModules");
 GETMODULEFILENAMEEX pGetModuleFileNameEx  = (GETMODULEFILENAMEEX)GetProcAddress(hModule, "GetModuleFileNameExA");

 ListView_DeleteAllItems(hProcessList1);
 HMODULE hMods[1024];
    HANDLE hProcess;
    DWORD cbNeeded;
    unsigned int i;
 char szModName[MAX_PATH];
 DWORD pids= 388;
 int k=0;
    hProcess = OpenProcess(PROCESS_QUERY_INFORMATION |PROCESS_VM_READ,FALSE,atoi(pid));
    if( hProcess &&  pEnumProcessModules(hProcess, hMods, sizeof(hMods), &cbNeeded))
    {
        for ( i = 0; i <=(cbNeeded / sizeof(HMODULE)); i++ )
        {           
            if(pGetModuleFileNameEx( hProcess, hMods[i], szModName,sizeof(szModName)))
            {
    char name[1024]={0},addr[32]={0};
    strcpy(name,szModName);
    wsprintf(addr,"0x%08x",hMods[i]);
            }
        }
    }
 else 
 {
  CloseHandle(hProcess);
  FreeLibrary(hModule);
  return;
    }
 CloseHandle(hProcess);
 FreeLibrary(hModule);
 return;

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值