当前位置:网站首页>Record the process of reverse task manager
Record the process of reverse task manager
2022-07-06 03:22:00 【Yulong_】
keyword :
Task manager , reverse ,WdcSafeOpenProcess,ResolveImagePath_Desktop,OpenProcess
Preface
Record the process of this reverse task manager , The whole process is relatively pleasant and easy .
There is no detailed analysis of the function implementation of the task manager , In this reverse , only Focus on a function point —— How does the task manager get the process id by 4 Of system Of relevant information ? Because I've done Windows The process related programming is clear , Microsoft offers API Function except to get System Process name and pid Outside , Other information ( Such as path 、 Command line, etc ) It's impossible to get .
Text
Let's take a look at the display of the task manager :
Where did the description information of this process come from ? We can even right-click to open the location of the file ...
First , open IDA, Let's start with a wave of Static analysis :
From the import table , See how the task manager gets the process handle ( Guess there is special treatment here ?)
We see OpenProcess function , Take a look at how it is called in the task manager , View the of this function Cross reference
边栏推荐
猜你喜欢
three.js网页背景动画液态js特效
Performance analysis of user login TPS low and CPU full
Who is the winner of PTA
My C language learning records (blue bridge) -- files and file input and output
codeforces每日5题(均1700)-第六天
Mysql database operation
The next industry outlet: NFT digital collection, is it an opportunity or a foam?
指针笔试题~走近大厂
Tomb. Weekly update of Finance (February 7 - February 13)
Sign SSL certificate as Ca
随机推荐
Who is the winner of PTA
教你用Pytorch搭建一个自己的简单的BP神经网络( 以iris数据集为例 )
How to do function test well
MySQL learning notes-10-tablespace recycling
Exness foreign exchange: the governor of the Bank of Canada said that the interest rate hike would be more moderate, and the United States and Canada fell slightly to maintain range volatility
[padding] an error is reported in the prediction after loading the model weight attributeerror: 'model' object has no attribute '_ place‘
Overview of OCR character recognition methods
Arabellacpc 2019 (supplementary question)
My C language learning record (blue bridge) -- under the pointer
SWC introduction
Redis SDS principle
SD卡報錯“error -110 whilst initialising SD card
Game theory matlab
蓝色样式商城网站页脚代码
How to choose PLC and MCU?
Detailed use of dbutils # yyds dry goods inventory #
Cross origin cross domain request
[rust notes] 18 macro
银行核心业务系统性能测试方法
My C language learning records (blue bridge) -- files and file input and output