;****************************************************
;DevName:进程导入表API_HOOK
;开发者:GhostHand
;****************************************************
.386
.model flat,stdcall
option casemap:none
;****************************************************
include windows.inc
include user32.inc
includelib user32.lib
include kernel32.inc
includelib kernel32.lib
include rsrc.inc
include psapi.inc
includelib psapi.lib
AFD_RECV equ 12017h
AFD_SEND equ 1201fh
AFD_WSABUF struct
len dd ?
buf dd ?
AFD_WSABUF ends
AFD_INFO struct
lpWsaBuf dd ?
BufferCount dd ?
AfdFlags dd ?
TdiFlags dd ?
AFD_INFO ends
;****************************************************
.data?
hHook dd ?
hWinMain dd ?
hWinSetting dd ?
.data
hInstance dd ?
hCurProc dd ?
lpNtDeviceIoControl dd ? ;存放旧NtDeviceIoControl
lpNewNtDeviceIoControl dd ? ;存放新NtDeviceIoControl
ImportNtDeviceIoControl dd ? ;导入表中用于存放NtDeviceIoControl地址的内存
.const
szCaption db '提示!',0
szMswsock db 'mswsock.dll',0
szNtDll db 'ntdll.dll',0
szNtDeviceIoControlFile db 'NtDeviceIoControlFile',0
.code
;------------------------------------------------------
;NtDevice
WIN32汇编实现进程导入表HOOK API
最新推荐文章于 2024-01-29 22:56:55 发布