A routine of inline HOOK-inline LoadLibrary
August 18, 2012 12:26:25
The purpose is to achieve anti-HOOK function: eventually because it is incompatible with other module codes, it is not used. But still note...
The idea behind inline hook is to modify the first few bytes of the API to become jmp's own function.
In this case, you need to save the first few bytes of the original function and put them in a block of memory as a springboard to jump back to the original function.
A simple diagram describes the process:
After HOOK, in order not to destroy other load library calls, you can modify the address back.
The idea is that this code is not posted.
- End of story.