近日做期末計算機程式結課設計,題目是C#開發一個DLL并注入到explorer.exe并執行,好不容易貪黑寫完了終于能注入了,但是注入后無法自動執行,各種百度也不行,眼看日期臨近實在沒有辦法了,望各路大神出手相助,謝謝!
附C# dll注入源代碼(XP下可運行(32位)):
using System;
using System.Collections.Generic;
using System.Text;
using System.Runtime.InteropServices;
using System.Diagnostics;
namespace DllInjectA
{
class Program
{
[DllImport("kernel32.dll")] //宣告API函式
public static extern int VirtualAllocEx(IntPtr hwnd, int lpaddress, int size, int type, int tect);
[DllImport("kernel32.dll")]
public static extern int WriteProcessMemory(IntPtr hwnd, int baseaddress, string buffer, int nsize, int filewriten);
[DllImport("kernel32.dll")]
public static extern int GetProcAddress(int hwnd, string lpname);
[DllImport("kernel32.dll")]
public static extern int GetModuleHandleA(string name);
[DllImport("kernel32.dll")]
public static extern int CreateRemoteThread(IntPtr hwnd, int attrib, int size, int address, int par, int flags, int threadid);
static void Main(string[] args)
{
int ok1;
int baseaddress;
int temp = 0;
int hack;
int yan;
string dllname;
dllname = "c:\\test.dll";
int dlllength;
dlllength = dllname.Length + 1;
Process[] pname = Process.GetProcesses(); //取得所有行程
foreach (Process name in pname) //遍歷行程
{
//MessageBox.Show(name.ProcessName.ToLower());
if (name.ProcessName.ToLower().IndexOf("svchost") != -1) //所示記事本,那么下面開始注入
{
baseaddress = VirtualAllocEx(name.Handle, 0, dlllength, 4096, 4); //申請記憶體空間
if (baseaddress == 0) //回傳0則操作失敗
{
Console.WriteLine("申請記憶體空間失敗!!");
return;
}
ok1 = WriteProcessMemory(name.Handle, baseaddress, dllname, dlllength, temp); //寫記憶體
if (ok1 == 0)
{
Console.WriteLine("寫記憶體失敗!!");
return;
}
hack = GetProcAddress(GetModuleHandleA("Kernel32"), "LoadLibraryA"); //取得loadlibarary在kernek32.dll地址
if (hack == 0)
{
Console.WriteLine("無法取得函式的入口點!!");
return;
}
yan = CreateRemoteThread(name.Handle, 0, 0, hack, baseaddress, 0, temp); //創建遠程執行緒
if (yan == 0)
{
Console.WriteLine("創建遠程執行緒失敗!!");
return;
}
else
{
Console.WriteLine("已成功注入dll!");
Console.ReadKey();
return;
}
}
}
}
}
}
uj5u.com熱心網友回復:
這問題我們不敢回答,怕進“小黑屋”你要弄別的,技術上俺們聊聊
要弄explorer.exe,俺們就不能說啥了
uj5u.com熱心網友回復:
是你的老師讓你這么寫代碼注入托管dll到非托管行程的嗎?你確認老師自己親自測驗過嗎?托管dll的main不會被執行,除非你用c++/clr寫
轉載請註明出處,本文鏈接:https://www.uj5u.com/net/242628.html
標籤:C#
上一篇:C#中兩個專案之間相互呼叫
