前言:2014-05-08记录在hi baidu,现移过来。
看代码
unsigned long functionAddress = (unsigned long)GetProcAddress(GetModuleHandle(L"kernel32.dll"),"VirtualProtect");
unsigned char *instructions = NULL;
unsigned long *eip = &functionAddress;
unsigned char b = instructions[*eip];
输出的数据是“VirtualProtect”函数的第一个字节