Board logo

标题: [原创]利用Native Api查看系统进程 [打印本页]

作者: wxf    时间: 2006-9-2 14:35     标题: [原创]利用Native Api查看系统进程

该程序利用系统Native api: NtQuerySystemInformation来获取系统进程列表及其相关信息,从该函数的名字就可以看出,其功能强大,不仅仅能查看系统进程,包括其他进程线程信息,内存页表信息,io读写信息,CPU缓存信息,基本上我们平时所用的任务管理器中的大部分功能就是依靠该函数来实现的.Native api 都位于NTDLL.DLL中,是用户层最底层的逻辑实现方式. 开发环境:VC6.0 + WinXp Sp2 首先,我们需要定义一些相关的结构体和常量:
  1. #ifndef NTQUERY_H
  2. #define NTQUERY_H
  3. typedef unsigned long NTSTATUS;
  4. typedef unsigned long SYSTEM_INFORMATION_CLASS;
  5. #define NT_PROCESS_LIST 5
  6. #define BLOCK_SIZE 0x1000
  7. #define STATUS_SUCCESS 0
  8. #define STATUS_INFO_LEN_MISMATCH 0xC0000004
  9. typedef struct{
  10. USHORT Length;
  11. USHORT MaxLen;
  12. USHORT *Buffer;
  13. }UNICODE_STRING;
  14. typedef struct _SYSTEM_PROCESSES{
  15. ULONG NextEntryDelta; //构成结构序列的偏移量;
  16. ULONG ThreadCount; //线程数目;
  17. ULONG Reserved1[6];
  18. LARGE_INTEGER CreateTime; //创建时间;
  19. LARGE_INTEGER UserTime; //用户模式(Ring 3)的CPU时间;
  20. LARGE_INTEGER KernelTime; //内核模式(Ring 0)的CPU时间;
  21. UNICODE_STRING ProcessName; //进程名称;
  22. ULONG BasePriority; //进程优先权;
  23. ULONG ProcessId; //进程标识符;
  24. }SYSTEM_PROCESSES, * PSYSTEM_PROCESSES;
  25. typedef NTSTATUS (__stdcall * NTQUERYSYSTEMINFORMATION)( SYSTEM_INFORMATION_CLASS, PVOID, ULONG, PULONG);
  26. #endif
复制代码
关于NTQUERYSYSTEMINFORMATION的定义 typedef NTSTATUS (__stdcall *NTQUERYSYSTEMINFORMATION)   (IN   SYSTEM_INFORMATION_CLASS SystemInformationClass,   IN OUT PVOID          SystemInformation,   IN   ULONG          SystemInformationLength,   OUT   PULONG         ReturnLength OPTIONAL); NTQUERYSYSTEMINFORMATION NtQuerySystemInformation; 在这里需要查看进程表的CLASS_INFO为5,在头文件中我定义为NT_PROCESS_LIST, 第二个参数为存放返回信息的地址,在此之前需要先为其申请一段内存.如果该段内存小了,则函数会返回STATUS_INFO_LEN_MISMATCH,在头文件中可以见到其值为0xC0000004.如果成果返回,则值为STATUS_SUCCESS即0.下面程序实现的代码:
  1. &#35;include <stdio.h>
  2. &#35;include <windows.h>
  3. &#35;include <tchar.h>
  4. &#35;include "ntQuery.h"
  5. int _tmain(void)
  6. {
  7. size_t blocklen = 0;
  8. PSYSTEM_PROCESSES bufForProcessesInfo = NULL, bufNext = NULL;
  9. NTSTATUS ns = 0;
  10. DWORD dwPcount = 0;
  11. HANDLE hHeap;
  12. int i = 2;
  13. HMODULE hNtdll = LoadLibrary(TEXT("NTDLL.DLL"));
  14. if(hNtdll == NULL)
  15. {
  16. printf("LaodLibrary ntddl.dll error...\n");
  17. return -1;
  18. }
  19. NTQUERYSYSTEMINFORMATION NtQuerySystemInformation =
  20. (NTQUERYSYSTEMINFORMATION)GetProcAddress(hNtdll, TEXT("NtQuerySystemInformation"));
  21. if(NtQuerySystemInformation == NULL)
  22. {
  23. printf("GetProcAddress error...\n");
  24. return -1;
  25. }
  26. hHeap = GetProcessHeap();
  27. if(hHeap == NULL)
  28. {
  29. printf("Get heap error...\n");
  30. FreeLibrary(hNtdll);
  31. return -1;
  32. }
  33. bufForProcessesInfo = (PSYSTEM_PROCESSES)HeapAlloc(hHeap, HEAP_ZERO_MEMORY, BLOCK_SIZE);
  34. if(bufForProcessesInfo == NULL)
  35. {
  36. printf("HeapAlloc error...\n");
  37. FreeLibrary(hNtdll);
  38. return -1;
  39. }
  40. bufNext = bufForProcessesInfo;
  41. ns = NtQuerySystemInformation(NT_PROCESS_LIST, bufForProcessesInfo, BLOCK_SIZE, NULL);
  42. while(ns == STATUS_INFO_LEN_MISMATCH)
  43. {
  44. bufNext = (PSYSTEM_PROCESSES)HeapReAlloc(hHeap, HEAP_ZERO_MEMORY, bufNext, BLOCK_SIZE * i);
  45. if(bufForProcessesInfo == NULL)
  46. {
  47. printf("Relloc error..\n");
  48. HeapFree(hHeap, HEAP_ZERO_MEMORY, bufForProcessesInfo);
  49. FreeLibrary(hNtdll);
  50. return -1;
  51. }
  52. ns = NtQuerySystemInformation(NT_PROCESS_LIST, bufNext, BLOCK_SIZE * i, NULL);
  53. i++;
  54. }
  55. while(bufNext->NextEntryDelta != 0)
  56. {
  57. wprintf(L"PID:%.4d\tBasePriority:%.2d\t%s\n", bufNext->ProcessId, bufNext->BasePriority, bufNext->ProcessName.Buffer);
  58. bufNext = (PSYSTEM_PROCESSES)((BYTE*)bufNext + bufNext->NextEntryDelta);
  59. dwPcount ++;
  60. }
  61. _tprintf(TEXT("------------------------------------------------"\
  62. "\nAll %d processes running...\n"), dwPcount);
  63. HeapFree(hHeap, HEAP_ZERO_MEMORY, bufForProcessesInfo);
  64. FreeLibrary(hNtdll);
  65. Sleep(10000);
  66. return 0;
  67. }
复制代码

作者: 无条件为你    时间: 2006-9-2 18:04     标题: [原创]利用Native Api查看系统进程

[这个贴子最后由无条件为你在 2006/09/02 07:21pm 第 1 次编辑]

希望能把工程文件以附件的形式上传到贴子中。




欢迎光临 黑色海岸线论坛 (http://bbs.thysea.com/) Powered by Discuz! 7.2