-
Notifications
You must be signed in to change notification settings - Fork 53
Expand file tree
/
Copy pathwinutils.h
More file actions
67 lines (50 loc) · 1.61 KB
/
Copy pathwinutils.h
File metadata and controls
67 lines (50 loc) · 1.61 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
#ifndef WINUTILS_H
#define WINUTILS_H
#include <windows.h>
#include <QSet>
#include <QString>
#include <string>
#include <tlhelp32.h>
struct ProcessInfo
{
DWORD pid;
DWORD parentPid;
QString name;
DWORD threadCount;
bool is64Bit;
DWORD priorityClass;
SIZE_T memoryUsage;
};
class winutils
{
public:
winutils();
public:
// DLL 注入
static bool injectDll(DWORD processId, const std::wstring& dllPath);
// 远程 DLL 注入
static bool injectDllViaCRT(DWORD processId, const std::wstring& dllPath);
// APC DLL 注入
static bool injectDllViaAPC(DWORD processId, const std::wstring& dllPath);
// 汇编注入
static bool injectDllViaASM(DWORD processId, const std::wstring& dllPath);
// Windows Hooks 注入
static bool injectDllViaWHK(DWORD processId, const std::wstring& dllPath);
// DLL 卸载
static bool unhookDll(DWORD processId, const std::wstring& dllPath);
// 检查DLL是否已挂载
static bool checkDllExist(DWORD processId, const std::wstring& dllPath);
static bool checkProcessProtection(DWORD processId);
static BOOL getWindowsVersion(DWORD* majorVersion,
DWORD* minorVersion,
DWORD* buildNumber);
static QString getWindowsVersion();
// 获取进程快照
static QList<ProcessInfo> getProcessList();
// 获取进程路径
static QString getProcessPath(DWORD processId);
// 获取进程中的主线程
static DWORD getProcessMainThread(DWORD processId);
static bool enableAllPrivilege();
};
#endif // WINUTILS_H