取得某进程的命令行

 '*************************************************************************
'**模 块 名:ModGetRemoteCmdLine
'**说    明:取得某进程的命令行
'**创 建 人:马大哈 http://www.m5home.com/
'**日    期:2007年6月19日
'**版    本:V1.0
'*************************************************************************
Option Explicit

Private Declare Function OpenProcess Lib "kernel32" (ByVal dwDesiredAccess As Long, ByVal bInheritHandle As Long, ByVal dwProcessId As Long) As Long

Private Declare Function ReadProcessMemory Lib "kernel32" (ByVal hProcess As Long, ByVal lpBaseAddress As Long, lpBuffer As Any, ByVal nSize As Long, _
                                                                                                                    lpNumberOfBytesWritten As Long) As Long
Private Declare Function LoadLibrary Lib "kernel32.dll" Alias "LoadLibraryW" (ByVal lpLibFileName As Long) As Long
Private Declare Function FreeLibrary Lib "kernel32.dll" (ByVal hLibModule As Long) As Long
Private Declare Function GetProcAddress Lib "kernel32.dll" (ByVal hModule As Long, ByVal lpProcName As String) As Long

Private Const PROCESS_VM_READ As Long = (&H10)
Private Const kernel32 As String = "kernel32.dll"

Public Function GetRemoteCmdLine(ByVal hPId As Long) As String
    '返回指定进程的命令行
    'hPId - 目标进程PID
    '返回值:
    '           成功返回命令行,失败返回空字符串
    Dim hDll As Long, hProcess As Long, APIPtr As Long, CmdLinePtr As Long, lRet As Long, lRet2 As Long
    Dim CmdLineStr As String, CmdLineByte(511) As Byte
   
    GetRemoteCmdLine = ""
   
    hDll = LoadLibrary(StrPtr(kernel32)):                 Debug.Assert hDll

    APIPtr = GetProcAddress(hDll, "GetCommandLineA") + 1    '取得GetCommandLineA地址 + 1
                                                            'kernel32.dll中的反汇编代码(Win2003版):
                                                            'mov eax,dword ptr [7C88B5D4]
                                                            '机器码:
                                                            'A1D4B5887C
                                                            '+1跳过mov指令,后面4个字节就是指向命令行的指针
                                                            '这个地址在每个进程里都是一样的,可以直接使用
                                                           
    Call FreeLibrary(hDll)

    hProcess = OpenProcess(PROCESS_VM_READ, 0, hPId)        '打开进程
    If hProcess = 0 Then Exit Function
   
    lRet = ReadProcessMemory(hProcess, APIPtr, CmdLinePtr, 4, lRet2)    '得到7C88B5D4
    If lRet <> 1 Then Exit Function
   
    lRet = ReadProcessMemory(hProcess, CmdLinePtr, CmdLinePtr, 4, lRet2)    '再取个指针(竟是两个指针-_-!)
    If lRet <> 1 Then Exit Function
   
    lRet = ReadProcessMemory(hProcess, CmdLinePtr, CmdLineByte(0), 512, lRet2)  '拉一块内存过来
    If lRet <> 1 Then Exit Function
   
    CmdLineStr = StrConv(CmdLineByte, vbUnicode)        '处理一下,可以输出了
    CmdLineStr = Mid(CmdLineStr, 1, InStr(1, CmdLineStr, Chr(0), vbTextCompare) - 1)
    Debug.Print CmdLineStr
    GetRemoteCmdLineEx = CmdLineStr
End Function

保存为ModGetRemoteCmdLine.bas

使用:

Msgbox GetRemoteCmdLine([PID])
http://community.csdn.net/Expert/topic/5601/5601470.xml?temp=.9897425

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值