看各位大神说这个玩意检测dll,说得神乎其神:
https://www.chinapyg.com/thread-83538-1-1.html
我就直接上码了:
[C++] 纯文本查看 复制代码 static HANDLE (WINAPI *Kernel_FindFirstFileW)( IN LPCWSTR lpFileName, OUT LPWIN32_FIND_DATAW lpFindFileData ) = FindFirstFileW;
HANDLE WINAPI MyFindFirstFileW( IN LPCWSTR lpFileName, OUT LPWIN32_FIND_DATAW lpFindFileData )
{
if (wcsstr(lpFileName, L"*.dll"))
{
OutputDebugStringW(L"[++++] 射射你~~AiQi");
lpFileName = NULL;
}
return Kernel_FindFirstFileW(lpFileName, lpFindFileData);
}
VOID HookAPI()
{
DetourTransactionBegin();
DetourUpdateThread(GetCurrentThread());
DetourAttach(&(PVOID&)Kernel_FindFirstFileW, MyFindFirstFileW);
DetourTransactionCommit();
}
|