資源描述:
《從內(nèi)存中加載并啟動(dòng)一個(gè)exe》由會(huì)員上傳分享,免費(fèi)在線閱讀,更多相關(guān)內(nèi)容在工程資料-天天文庫(kù)。
1、從內(nèi)存中加載并啟動(dòng)一個(gè)exe(C++版)原理:1.把你的程序讀要內(nèi)存2.以CREATE_SUSPENDED模式CreateProcess打開svchost.exe3.修改svchost.exe頁(yè)面的屬性,然后把要運(yùn)行的那個(gè)程序的內(nèi)容拷貝到svchost.exe頁(yè)面4.然后再運(yùn)行實(shí)質(zhì)想當(dāng)于是披著/svchost.exe進(jìn)程的相關(guān)信息/這張皮,而皮里面的肉都被改了原文來自哪里忘記了,。呵呵//#include#include#include//
2、#include"ntpsapi.h"structPEHeader{??unsignedlongsignature;??unsignedshortmachine;??unsignedshortnumSections;??unsignedlongtimeDateStamp;??unsignedlongpointerToSymbolTable;??unsignedlongnumOfSymbols;??unsignedshortsizeOfOptionHeader;??unsignedshortcharact
3、eristics;};typedefstructPEHeaderPE_Header;structPEExtHeader{??unsignedshortmagic;??unsignedcharmajorLinkerVersion;??unsignedcharminorLinkerVersion;??unsignedlongsizeOfCode;??unsignedlongsizeOfInitializedData;??unsignedlongsizeOfUninitializedData;??unsign
4、edlongaddressOfEntryPoint;??unsignedlongbaseOfCode;??unsignedlongbaseOfData;??unsignedlongimageBase;??unsignedlongsectionAlignment;??unsignedlongfileAlignment;??unsignedshortmajorOSVersion;??unsignedshortminorOSVersion;??unsignedshortmajorImageVersion;??
5、unsignedshortminorImageVersion;??unsignedshortmajorSubsystemVersion;??unsignedshortminorSubsystemVersion;??unsignedlongreserved1;??unsignedlongsizeOfImage;??unsignedlongsizeOfHeaders;??unsignedlongchecksum;??unsignedshortsubsystem;??unsignedshortDLLChara
6、cteristics;??unsignedlongsizeOfStackReserve;??unsignedlongsizeOfStackCommit;??unsignedlongsizeOfHeapReserve;??unsignedlongsizeOfHeapCommit;??unsignedlongloaderFlags;??unsignedlongnumberOfRVAAndSizes;??unsignedlongexportTableAddress;??unsignedlongexportTa
7、bleSize;??unsignedlongimportTableAddress;??unsignedlongimportTableSize;??unsignedlongresourceTableAddress;??unsignedlongresourceTableSize;??unsignedlongexceptionTableAddress;??unsignedlongexceptionTableSize;??unsignedlongcertFilePointer;??unsignedlongcer
8、tTableSize;??unsignedlongrelocationTableAddress;??unsignedlongrelocationTableSize;??unsignedlongdebugDataAddress;??unsignedlongdebugDataSize;??unsignedlongarchDataAddress;??unsignedlongarchDataSize;??unsignedlongglobalPtrA