You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

C语言DLL注入记事本失败求助:无弹窗且注入未成功

问题:DLL注入记事本进程失败,无弹窗且注入未成功

问题概述

尝试将一个DLL注入到记事本进程中,使其弹出MessageBox,但完全没有反应,且DLL未成功注入。已确认进程架构为64位,且编译的是64位DLL,知道DllMain内不能直接调用MessageBox,因此在DLL中创建线程执行逻辑,但问题仍未解决。

DLL代码与编译

使用的DLL文件(Dllinj.dll)代码如下:

#include <windows.h>

DWORD WINAPI MyThreadFunction(LPVOID lpParam) {
    MessageBoxA(NULL, "Dll in the thread.", "DLL Thread", MB_OK);
    
    return 0;
}

__declspec(dllexport) void CreateThreadInDLL() {
    HANDLE hThread = CreateThread(NULL, 0, MyThreadFunction, NULL, 0, NULL);

    if (hThread == NULL) {
        MessageBoxA(NULL, "Error creating thread", "DLL Thread", MB_OK | MB_ICONERROR);
    } else {
        WaitForSingleObject(hThread, INFINITE);
        CloseHandle(hThread);
    }
}

BOOL WINAPI DllMain(HINSTANCE hinstDLL, DWORD fdwReason, LPVOID lpvReserved) {
    switch (fdwReason) {
         case DLL_PROCESS_ATTACH:{
            CreateThreadInDLL();
         }
    }
    return TRUE;
}

编译命令:

gcc dllinj.cpp -o dllinj.dll -shared

注入尝试与错误信息

  • 使用Nefarius Injector工具,返回错误:Call to LoadLibraryW in remote process failed.

  • 使用自定义注入器代码尝试注入:
    注入器代码:

    #include <stdio.h>
    #include <stdlib.h>
    #include <string.h>
    #include <windows.h>
    #include <tlhelp32.h>
    
    char evilDLL[] = "C:\\Users\\ACER\\Desktop\\tcc\\Dllinj.dll";
    unsigned int evilLen = sizeof(evilDLL) + 1;
    
    void HandleError(const char* message) {
        perror(message);
        exit(EXIT_FAILURE);
    }
    
    void LastErrorBox()
    {
        printf("eeee");
        LPWSTR pBuffer = NULL;
        int ret = FormatMessageW(FORMAT_MESSAGE_ALLOCATE_BUFFER | FORMAT_MESSAGE_FROM_SYSTEM, 0, GetLastError(), 0, (LPWSTR)&pBuffer, 0, 0);
        if (!(ret && pBuffer))
        {
            MessageBoxW(0, pBuffer, L"failed to read error", 0);
            return;
        }
    
        MessageBoxW(0, pBuffer, L"", 0);
        LocalFree(pBuffer);
    }
    
    int main(int argc, char* argv[]) {
        DWORD ipthr = 10008; // process id  
    
        HANDLE ph = OpenProcess(PROCESS_ALL_ACCESS, FALSE, ipthr);
        if (ph == NULL) {
            HandleError("Error opening process");
        }
    
        LPVOID rb = VirtualAllocEx(ph, NULL, evilLen, MEM_RESERVE | MEM_COMMIT, PAGE_EXECUTE_READWRITE);
        if (rb == NULL) {
            CloseHandle(ph);
            HandleError("Error allocating memory in the remote process");
        }
    
        if (!WriteProcessMemory(ph, rb, evilDLL, evilLen, NULL)) {
            CloseHandle(ph);
            VirtualFreeEx(ph, rb, 0, MEM_RELEASE);
            HandleError("Error writing to remote process memory");
        }
    
        HMODULE hKernel32 = GetModuleHandle("Kernel32");
        if (hKernel32 == NULL) {
            CloseHandle(ph);
            VirtualFreeEx(ph, rb, 0, MEM_RELEASE);
            HandleError("Error getting handle to Kernel32");
        }
    
        FARPROC lb = GetProcAddress(hKernel32, "LoadLibraryW");
        if (lb == NULL) {
            CloseHandle(ph);
            VirtualFreeEx(ph, rb, 0, MEM_RELEASE);
            HandleError("Error getting address of LoadLibraryW");
        }
    
        printf("%lu",ipthr);
    
        HANDLE rt = CreateRemoteThread(ph, NULL, 0,
                                          (LPTHREAD_START_ROUTINE)lb,
                                          rb, 0, &ipthr);
        LastErrorBox();
    
        if (rt == NULL) {
            CloseHandle(ph);
            VirtualFreeEx(ph, rb, 0, MEM_RELEASE);
            HandleError("Error creating remote thread");
        }
    
        // Wait for the remote thread to finish
        WaitForSingleObject(rt, INFINITE);
    
        CloseHandle(rt);
        VirtualFreeEx(ph, rb, 0, MEM_RELEASE);
        CloseHandle(ph);
    
        return 0;
    }
    

    编译命令:

    g++ -O2 injector.cpp -o injector.exe -s -ffunction-sections -fdata-sections -Wno-write-strings -fno-exceptions -fmerge-all-constants -static-libstdc++ -static-libgcc -fpermissive
    

    运行命令:

    injector.exe 10008
    

    得到输出:Error creating remote thread: No error,且LastErrorBox();弹出提示“Invalid identifier”。已确认进程PID为10008(通过Process Hacker和任务管理器验证)。

  • 额外尝试:使用Process Hacker查看记事本进程,未发现注入的Dllinj.dll;尝试Cheat Engine注入器也报错。

求助

怀疑问题出在DLL编译流程或代码本身,但无法确定具体原因,作为Windows内核底层操作的新手,恳请帮助排查问题。

内容的提问来源于stack exchange,提问作者Yeet

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 03:58:10