创建远程线程

#include <windows.h>
#include <tlhelp32.h>

char* pszlibfilename = "D://dllT.dll";
DWORD GetProcessIdFromName(LPCTSTR name)
{
 PROCESSENTRY32 pe;
 DWORD id = 0;
 HANDLE hSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS,0);
 pe.dwSize = sizeof(PROCESSENTRY32);
 if( !Process32First(hSnapshot,&pe) )
  return 0;
 do
 {
  pe.dwSize = sizeof(PROCESSENTRY32);
  if( Process32Next(hSnapshot,&pe)==FALSE )
   break;
  if(strcmp(pe.szExeFile,name) == 0)
  {
   id = pe.th32ProcessID;
   break;
  }
 } while(1);
 CloseHandle(hSnapshot);
 return id;
}

void main()
{
 HINSTANCE   hinstDLL=NULL;
 DWORD dwremoteprocessid = GetProcessIdFromName("ipmsg.exe");
 HANDLE h = OpenProcess(PROCESS_CREATE_THREAD | PROCESS_VM_OPERATION | PROCESS_VM_WRITE,
    false, dwremoteprocessid );


 if(h==NULL){

  return;
 }
 int   cb = (1 + strlen(pszlibfilename)) * sizeof(char);
 char* pszlibfileremote = (char*)VirtualAllocEx( h, NULL, cb,MEM_COMMIT,PAGE_READWRITE);
 
 BOOL b   =   WriteProcessMemory(h,(void *)pszlibfileremote,
     (PVOID)pszlibfilename, cb, NULL);  
 if(b==FALSE){
  return;
 }

 LPTHREAD_START_ROUTINE  pfnstartaddr=(LPTHREAD_START_ROUTINE )
       GetProcAddress(GetModuleHandle(TEXT("kernel32.dll")), "LoadLibraryA");  

 HANDLE  thrH = CreateRemoteThread(h,NULL,0, pfnstartaddr,pszlibfileremote,0,NULL);
 if(thrH ==NULL)
  return;

 FreeLibrary(hinstDLL);
 CloseHandle(h);
 CloseHandle(thrH);

}

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值