mirror of
https://github.com/mirror/processhacker
synced 2026-06-08 16:03:24 +00:00
31c9fe1033
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@2517 21ef857c-d57f-4fe0-8362-d861dc6d29cd
136 lines
3.7 KiB
C
136 lines
3.7 KiB
C
#ifndef NTMMAPI_H
|
|
#define NTMMAPI_H
|
|
|
|
typedef enum _MEMORY_INFORMATION_CLASS
|
|
{
|
|
MemoryBasicInformation,
|
|
MemoryWorkingSetInformation,
|
|
MemoryMappedFilenameInformation,
|
|
MemoryRegionInformation,
|
|
MemoryWorkingSetExInformation
|
|
} MEMORY_INFORMATION_CLASS;
|
|
|
|
typedef enum _SECTION_INFORMATION_CLASS
|
|
{
|
|
SectionBasicInformation,
|
|
SectionImageInformation,
|
|
MaxSectionInfoClass
|
|
} SECTION_INFORMATION_CLASS;
|
|
|
|
typedef struct _SECTION_BASIC_INFORMATION
|
|
{
|
|
PVOID BaseAddress;
|
|
ULONG AllocationAttributes;
|
|
LARGE_INTEGER MaximumSize;
|
|
} SECTION_BASIC_INFORMATION, *PSECTION_BASIC_INFORMATION;
|
|
|
|
typedef struct _SECTION_IMAGE_INFORMATION
|
|
{
|
|
PVOID TransferAddress;
|
|
ULONG ZeroBits;
|
|
SIZE_T MaximumStackSize;
|
|
SIZE_T CommittedStackSize;
|
|
ULONG SubSystemType;
|
|
union
|
|
{
|
|
struct
|
|
{
|
|
USHORT SubSystemMinorVersion;
|
|
USHORT SubSystemMajorVersion;
|
|
};
|
|
ULONG SubSystemVersion;
|
|
};
|
|
ULONG GpValue;
|
|
USHORT ImageCharacteristics;
|
|
USHORT DllCharacteristics;
|
|
USHORT Machine;
|
|
BOOLEAN ImageContainsCode;
|
|
BOOLEAN Spare1;
|
|
ULONG LoaderFlags;
|
|
ULONG ImageFileSize;
|
|
ULONG Reserved[1];
|
|
} SECTION_IMAGE_INFORMATION, *PSECTION_IMAGE_INFORMATION;
|
|
|
|
typedef enum _SECTION_INHERIT
|
|
{
|
|
ViewShare = 1,
|
|
ViewUnmap = 2
|
|
} SECTION_INHERIT;
|
|
|
|
#define SEC_BASED 0x200000
|
|
#define SEC_NO_CHANGE 0x400000
|
|
#define SEC_FILE 0x800000
|
|
#define SEC_IMAGE 0x1000000
|
|
#define SEC_RESERVE 0x4000000
|
|
#define SEC_COMMIT 0x8000000
|
|
#define SEC_NOCACHE 0x10000000
|
|
#define SEC_GLOBAL 0x20000000
|
|
#define SEC_LARGE_PAGES 0x80000000
|
|
|
|
#define MEM_EXECUTE_OPTION_DISABLE 0x1
|
|
#define MEM_EXECUTE_OPTION_ENABLE 0x2
|
|
#define MEM_EXECUTE_OPTION_DISABLE_THUNK_EMULATION 0x4
|
|
#define MEM_EXECUTE_OPTION_PERMANENT 0x8
|
|
#define MEM_EXECUTE_OPTION_EXECUTE_DISPATCH_ENABLE 0x10
|
|
#define MEM_EXECUTE_OPTION_IMAGE_DISPATCH_ENABLE 0x20
|
|
#define MEM_EXECUTE_OPTION_VALID_FLAGS 0x3f
|
|
|
|
typedef NTSTATUS (NTAPI *_NtAllocateVirtualMemory)(
|
|
__in HANDLE ProcessHandle,
|
|
__inout PVOID *BaseAddress,
|
|
__in ULONG_PTR ZeroBits,
|
|
__inout PSIZE_T RegionSize,
|
|
__in ULONG AllocationType,
|
|
__in ULONG Protect
|
|
);
|
|
|
|
typedef NTSTATUS (NTAPI *_NtFreeVirtualMemory)(
|
|
__in HANDLE ProcessHandle,
|
|
__inout PVOID *BaseAddress,
|
|
__inout PSIZE_T RegionSize,
|
|
__in ULONG FreeType
|
|
);
|
|
|
|
typedef NTSTATUS (NTAPI *_NtReadVirtualMemory)(
|
|
__in HANDLE ProcessHandle,
|
|
__in_opt PVOID BaseAddress,
|
|
__out_bcount(BufferSize) PVOID Buffer,
|
|
__in SIZE_T BufferSize,
|
|
__out_opt PSIZE_T NumberOfBytesRead
|
|
);
|
|
|
|
typedef NTSTATUS (NTAPI *_NtWriteVirtualMemory)(
|
|
__in HANDLE ProcessHandle,
|
|
__in_opt PVOID BaseAddress,
|
|
__in_bcount(BufferSize) PVOID Buffer,
|
|
__in SIZE_T BufferSize,
|
|
__out_opt PSIZE_T NumberOfBytesWritten
|
|
);
|
|
|
|
typedef NTSTATUS (NTAPI *_NtProtectVirtualMemory)(
|
|
__in HANDLE ProcessHandle,
|
|
__inout PVOID *BaseAddress,
|
|
__inout PSIZE_T RegionSize,
|
|
__in ULONG NewProtect,
|
|
__out PULONG OldProtect
|
|
);
|
|
|
|
typedef NTSTATUS (NTAPI *_NtQueryVirtualMemory)(
|
|
__in HANDLE ProcessHandle,
|
|
__in PVOID BaseAddress,
|
|
__in MEMORY_INFORMATION_CLASS MemoryInformationClass,
|
|
__out_bcount(MemoryInformationLength) PVOID MemoryInformation,
|
|
__in SIZE_T MemoryInformationLength,
|
|
__out_opt PSIZE_T ReturnLength
|
|
);
|
|
|
|
typedef NTSTATUS (NTAPI *_NtQuerySection)(
|
|
__in HANDLE SectionHandle,
|
|
__in SECTION_INFORMATION_CLASS SectionInformationClass,
|
|
__out_bcount(SectionInformationLength) PVOID SectionInformation,
|
|
__in SIZE_T SectionInformationLength,
|
|
__out_opt PSIZE_T ReturnLength
|
|
);
|
|
|
|
#endif
|