I want to get the PEB from the "notepad.exe" process. Does someone know how to do it?
I tried the GetModuleHandle
API, but it doesn't return a valid pointer (it return zero every time) because I have to be the caller process of that module.
For that reason, I want to know how to get it to work with EnumProcessModules
or CreateToolhelp32Snapshot
.
See Question&Answers more detail:
os 与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…