1
/**/
/******************************************************************************
2
Module: VMQuery.cpp
3
Notices: Copyright (c) 2000 Jeffrey Richter
4
******************************************************************************/
5![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
6![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
7![ExpandedBlockStart.gif](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedBlockStart.gif)
#include
"
..\CmnHdr.h
"
/**/
/* See Appendix A. */
8
#include
<
windowsx.h
>
9
#include
"
VMQuery.h
"
10![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
11![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
12![ExpandedBlockStart.gif](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedBlockStart.gif)
/**/
///
13
14![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
15
//
Helper structure
16![ExpandedBlockStart.gif](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedBlockStart.gif)
typedef
struct
{
17
SIZE_T RgnSize; //段大小
18
//段类型
19
DWORD dwRgnStorage; // MEM_*: Free, Image, Mapped, Private
20
//该段内的块的数量
21
DWORD dwRgnBlocks;
22
DWORD dwRgnGuardBlks; // If > 0, region contains thread stack
23
//是否是线程栈
24
BOOL fRgnIsAStack; // TRUE if region contains thread stack
25
}
VMQUERY_HELP;
26![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
27![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
28
//
This global, static variable holds the allocation granularity value for
29
//
this CPU platform. Initialized the first time VMQuery is called.
30
static
DWORD gs_dwAllocGran
=
0
;
31![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
32![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
33![ExpandedBlockStart.gif](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedBlockStart.gif)
/**/
///
34
35![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
36
//
Iterates through a region's blocks and returns findings in VMQUERY_HELP
37
static
BOOL VMQueryHelp(HANDLE hProcess, LPCVOID pvAddress,
38![ExpandedBlockStart.gif](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedBlockStart.gif)
VMQUERY_HELP
*
pVMQHelp)
{
39![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
40
// Each element contains a page protection
41
// (i.e.: 0=reserved, PAGE_NOACCESS, PAGE_READWRITE, etc.)
42![ExpandedSubBlockStart.gif](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedSubBlockStart.gif)
DWORD dwProtectBlock[4] =
{ 0 };
43
//将*pVMQHelp指向的结构体的内存置0
44
ZeroMemory(pVMQHelp, sizeof(*pVMQHelp));
45![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
46
// Get address of region containing passed memory address.
47
//通过指定的内存地址获得段的地址
48
MEMORY_BASIC_INFORMATION mbi;
49
//没有填充mbi则失败
这是一种很另类的判断方法?
50
BOOL fOk = (VirtualQueryEx(hProcess, pvAddress, &mbi, sizeof(mbi))
51
== sizeof(mbi));
52![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
53
if (!fOk)
54
return(fOk); // Bad memory address, return failure
55![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
56
// Walk starting at the region's base address (which never changes)
57
//存储段的基地址这个地址不会改变
58
PVOID pvRgnBaseAddress = mbi.AllocationBase;
59![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
60
// Walk starting at the first block in the region (changes in the loop)
61
//存储段中第一个块的基地址,其实也就是这个段的基地址,不过当前块的基地址一会会变成别的块的基地址
62
PVOID pvAddressBlk = pvRgnBaseAddress;
63![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
64
// Save the memory type of the physical storage block.
65
//给dwRgnStorage赋值当前段的类型 重申一下类型的分配MEM_IMAGE、MEM_MAPPED、MEM_PRIVATE只有这三种
66
pVMQHelp->dwRgnStorage = mbi.Type;
67![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
68![ExpandedSubBlockStart.gif](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedSubBlockStart.gif)
for (;;)
{
69
// Get info about the current block.
70
// 获取当前块的信息
71
//调试了一阵程序纠正了自己理解上的一些偏差
72
//VirtualQueryEx返回的是页面类型以及保护属性完全相同的相邻的页面的集合的信息
73
//换句话说就是一个内存块的信息
74
//基于内存区域和内存块分析一下_MEMORY_BASIC_INFORMATION 的成员到底存的是什么!!
75
// typedef struct _MEMORY_BASIC_INFORMATION
76
// {
77
// PVOID BaseAddress;//这是内存块的基地址
78
// PVOID AllocationBase;//这是内存区域的基地址,也就是VirtualAlloc的第一个参数的值
79
// DWORD AllocationProtect;//区域的保护属性
80
// SIZE_T RegionSize;//这个是内存块的大小
81
// DWORD State;//内存块的状态
82
// DWORD Protect;//内存块的保护属性
83
// DWORD Type;//内存块的类型这个也可以说是内存区域的类型两者是一样的(在值上和定义上可以推导)。
84
// } MEMORY_BASIC_INFORMATION, *PMEMORY_BASIC_INFORMATION;
85
//VirtualAlloc这个函数是标准是内存区域不是内存块
86
//它里面的保护属性是准许段内部的页面设置的保护属性,区域中的所有页保护的属性是它的子集
87
//LPVOID VirtualAlloc(
88
// LPVOID lpAddress,
89
// SIZE_T dwSize,
90
// DWORD flAllocationType,
91
// DWORD flProtect
92
//);
93
//好了知道了这些在通过对VirtualAlloc参数的比较我可以肯定页面类型相同的地址相邻的页面构成了一个内存区域
![ExpandedBlockStart.gif](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedBlockStart.gif)
![ContractedBlock.gif](https://www.cnblogs.com/Images/OutliningIndicators/ContractedBlock.gif)
2
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
3
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
4
![](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedBlockEnd.gif)
5
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
6
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
7
![ExpandedBlockStart.gif](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedBlockStart.gif)
![ContractedBlock.gif](https://www.cnblogs.com/Images/OutliningIndicators/ContractedBlock.gif)
8
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
9
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
10
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
11
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
12
![ExpandedBlockStart.gif](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedBlockStart.gif)
![ContractedBlock.gif](https://www.cnblogs.com/Images/OutliningIndicators/ContractedBlock.gif)
13
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
14
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
15
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
16
![ExpandedBlockStart.gif](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedBlockStart.gif)
![ContractedBlock.gif](https://www.cnblogs.com/Images/OutliningIndicators/ContractedBlock.gif)
![](https://www.cnblogs.com/Images/dot.gif)
17
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
18
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
19
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
20
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
21
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
22
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
23
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
24
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
25
![](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedBlockEnd.gif)
26
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
27
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
28
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
29
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
30
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
31
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
32
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
33
![ExpandedBlockStart.gif](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedBlockStart.gif)
![ContractedBlock.gif](https://www.cnblogs.com/Images/OutliningIndicators/ContractedBlock.gif)
34
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
35
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
36
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
37
![](https://www.cnblogs.com/Images/OutliningIndicators/None.gif)
38
![ExpandedBlockStart.gif](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedBlockStart.gif)
![ContractedBlock.gif](https://www.cnblogs.com/Images/OutliningIndicators/ContractedBlock.gif)
![](https://www.cnblogs.com/Images/dot.gif)
39
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
40
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
41
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
42
![ExpandedSubBlockStart.gif](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedSubBlockStart.gif)
![ContractedSubBlock.gif](https://www.cnblogs.com/Images/OutliningIndicators/ContractedSubBlock.gif)
![](https://www.cnblogs.com/Images/dot.gif)
43
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
44
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
45
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
46
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
47
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
48
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
49
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
![](https://www.cnblogs.com/Images/dot.gif)
50
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
51
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
52
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
53
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
54
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
55
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
56
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
57
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
58
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
59
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
60
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
61
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
62
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
63
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
64
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
65
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
66
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
67
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
68
![ExpandedSubBlockStart.gif](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedSubBlockStart.gif)
![ContractedSubBlock.gif](https://www.cnblogs.com/Images/OutliningIndicators/ContractedSubBlock.gif)
![](https://www.cnblogs.com/Images/dot.gif)
69
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
70
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
71
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
72
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
73
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
74
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
75
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
76
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
77
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
78
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
79
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
80
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
81
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
82
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
83
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
84
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
85
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
86
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
87
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
88
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
89
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
90
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
91
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
92
![](https://www.cnblogs.com/Images/OutliningIndicators/InBlock.gif)
93
![](https://www.cnblogs.com/Images/OutliningIndicators/ExpandedBlockEnd.gif)