日期:2014-05-17 浏览次数:20962 次
  typedef   HMODULE   (__stdcall   *LOADLIB)(  
          LPCWSTR   lpwLibFileName,  
          HANDLE   hFile,  
          DWORD   dwFlags);  
   
  extern   "C"   {  
                  DETOUR_TRAMPOLINE(HMODULE   __stdcall   Real_LoadLibraryExW(  
                                                                                                                    LPCWSTR   lpwLibFileName,  
                                                                                                                    HANDLE   hFile,  
                                                                                                                    DWORD   dwFlags),  
                                                                                                                  LoadLibraryExW);  
  }  
   
  ULONG   user32   =   0;  
   
  HMODULE   __stdcall   Mine_LoadLibraryExW(  
                                                      LPCWSTR   lpwLibFileName,  
                                                      HANDLE   hFile,  
                                                      DWORD   dwFlags)  
  {  
                  ULONG   addr;  
   
                  _asm   mov   eax,   [ebp+4]  
                  _asm   mov   addr,   eax  
   
                  if   ((user32   &   0xFFFF0000)   ==   (addr   &   0xFFFF0000))  
                  {  
                                  return   0;  
                  }  
   
                  HMODULE   res   =   (LOADLIB(Real_LoadLibraryExW))   (  
                                                                                                  lpwLibFileName,  
                                                                                                  hFile,  
                                                                                                  dwFlags);  
   
                  return   res;  
  }  
   
  BOOL   ProcessAttach()  
  {  
                  DetourFunctionWithTrampoline((PBYTE)Real_LoadLibraryExW,  
                                                                    (PBYTE)Mine_LoadLibraryExW);  
                  return   TRUE;  
  }  
   
  BOOL   ProcessDetach()  
  {  
                  DetourRemove((PBYTE)Real_LoadLibraryExW,