//
//
//
//
//
//
//
//
//
//
软件Tags:
易语言枚举进程所有句柄源码系统结构:获取系统所有句柄信息,获取句柄名,获取句柄类型,获取句柄引用数,List,Count,GetItem,GetCurrentProcessId,GetCurrentProcess,RtlMoveMemory_SYSTEM_HANDLE_INFORMATION,DuplicateHandle,OpenProcess,CloseHandle,ZwQuerySystemInformation,ZwQueryObject,ZwQueryObject_SYSTEM_HANDLE_STATE,RtlUnicodeStringToAnsiString,RtlFreeAnsiString, ======程序集1 || ||------_启动子程序 || || ======窗口程序集_窗口1 || ||------_窗口1_创建完毕 || ||------_按钮1_被单击 || ||------获取系统所有句柄信息 || ||------获取句柄名 || ||------获取句柄类型 || ||------获取句柄引用数 || || ======List || ||------_初始化 || ||------_销毁 || ||------List || ||------Count || ||------GetItem || || ======程序集2 || || ======调用的Dll || ||---[dll]------GetCurrentProcessId || ||---[dll]------GetCurrentProcess || ||---[dll]------RtlMoveMemory_SYSTEM_HANDLE_INFORMATION || ||---[dll]------DuplicateHandle || ||---[dll]------OpenProcess || ||---[dll]------CloseHandle || ||---[dll]------ZwQuerySystemInformation || ||---[dll]------ZwQueryObject || ||---[dll]------ZwQueryObject_SYSTEM_HANDLE_STATE || ||---[dll]------RtlUnicodeStringToAnsiString || ||---[dll]------RtlFreeAnsiString 调用的DLL命令: .DLL命令GetCurrentProcessId,整数型,"kernel32.dll","GetCurrentProcessId" .DLL命令GetCurrentProcess,整数型,"kernel32.dll","GetCurrentProcess" .DLL命令RtlMoveMemory_SYSTEM_HANDLE_INFORMATION,,"kernel32.dll","RtlMoveMemory" .参数Destination,SYSTEM_HANDLE_INFORMATION .参数Source,整数型 .参数Length,整数型 .DLL命令DuplicateHandle,逻辑型,"kernel32.dll","DuplicateHandle" .参数hSourceProcessHandle,整数型 .参数hSourceHandle,整数型 .参数hTargetProcessHandle,整数型 .参数lpTargetHandle,整数型,传址 .参数dwDesiredAccess,整数型 .参数bInheritHandle,逻辑型 .参数dwOptions,整数型 .DLL命令OpenProcess,整数型,"kernel32.dll","OpenProcess" .参数dwDesiredAccess,整数型 .参数bInheritHandle,逻辑型 .参数dwProcessId,整数型 .DLL命令CloseHandle,逻辑型,"kernel32.dll","CloseHandle" .参数hObject,整数型 .DLL命令ZwQuerySystemInformation,整数型,"ntdll.dll","ZwQuerySystemInformation" .参数SystemInformationClass,整数型 .参数SystemInformation,字节集 .参数SystemInformationLength,整数型 .参数ReturnLength,整数型,传址 .DLL命令ZwQueryObject,整数型,"ntdll.dll","ZwQueryObject" .参数ObjectHandle,整数型 .参数ObjectInformationClass,整数型 .参数ObjectInformation,字节集 .参数ObjectInformationLength,整数型 .参数ReturnLength,整数型,传址 .DLL命令ZwQueryObject_SYSTEM_HANDLE_STATE,整数型,"ntdll.dll","ZwQueryObject" .参数ObjectHandle,整数型 .参数ObjectInformationClass,整数型 .参数ObjectInformation,SYSTEM_HANDLE_STATE .参数ObjectInformationLength,整数型 .参数ReturnLength,整数型,传址 .DLL命令RtlUnicodeStringToAnsiString,整数型,"ntdll.dll","RtlUnicodeStringToAnsiString" .参数DestinationString,STRING .参数SourceString,字节集 .参数AllocateDestinationString,逻辑型 .DLL命令RtlFreeAnsiString,整数型,"ntdll.dll","RtlFreeAnsiString" .参数AnsiString,STRING
